Privacy Policy
Effective: July 12, 2026
1. Controller
Val is a platform for organising local gatherings. Data controller: Metrica d.o.o.. For privacy questions: info@metrica.hr.
2. Data we collect
- Account data: email address, name, city, UI language
- Profile data: interests, circles, bio, profile photo (optional)
- Security data: password hash, passkey credential metadata (no private keys)
- Push notifications: subscription endpoint + encryption keys for delivery to your device
- Plima: separate notification preferences, gathering city, delivery history, and your voluntary attendance response
- Attendance history: each attendance-answer change appends a timestamped record while the latest answer remains editable; history supports honest aggregate measurement of realized meetings
- Confirmed-participant cohort: the first application confirmation is retained as a timestamped fact so a later withdrawal cannot retroactively distort aggregate response rates
- Plima prompt decline: the
promptDismissedAt timestamp records a permanent decline so we can honor it without repeated pressure
- First-gathering reminder: once you have two self-reported attendances and have not yet published your own gathering, we may offer you once, with separate consent, one reminder to organize a first gathering; the reminder never invents a venue
- Idea after a break: only with your separate consent we record a
reactivationLastActiveAt activity timestamp; if you do not return for 10 days we may send you one real, relevant idea from your city, at most once every 30 days, within the usual message limits; you can turn this consent off yourself at any time, which deletes that timestamp, and the message never invents an event
- Weekend recommendation snapshot: one to three gathering IDs shown in the weekend message, so a tap opens the promised options after a fresh safety check; the snapshot does not contain precise location
- Plima delivery attempts: delivery/user linkage, provider name, timestamps, and a bounded delivery-attempt outcome code; never message content or credentials
- Plima emergency-control audit: administrator identity, bounded reason, pause/resume action, and timestamp for security accountability
- Content you create: gathers, applications, chat messages, photos, ratings, blocks, reports
- Technical data: IP address, basic browser metadata (for security and abuse prevention)
3. Purposes and legal bases
- Contract performance (GDPR art. 6(1)(b)): authentication, creating and joining gatherings, chat, notifications
- Legitimate interest (GDPR art. 6(1)(f)): platform security, abuse prevention, service quality
- Consent (GDPR art. 6(1)(a)): anonymous usage analytics (loaded only after you consent)
- Consent (GDPR art. 6(1)(a)): each Plima prompt category stays disabled until you enable it
- Legitimate interest and data protection by design (GDPR art. 6(1)(f)): we remember a permanent decline only to respect your choice and prevent the same prompt from being offered again
- Legitimate interest (GDPR art. 6(1)(f)): bounded voluntary attendance history supports verifiable aggregate meeting outcomes; metrics accept answers no later than seven days after the gathering ends
4. Cookies and local storage
| Name | Purpose | Lifetime |
session | HttpOnly session cookie for authentication | 8 hours |
val-consent (localStorage) | Stores your analytics consent choice | Until you clear it |
val-ref (localStorage) | Temporarily remembers invite code during signup | Until registration |
val-lang (localStorage) | UI language preference | Until you clear it |
We do not use tracking or marketing cookies.
5. Third parties that process your data
| Provider | Purpose | Data category |
| Resend | Transactional email (OTP, notifications) | Email address, message content |
| Google Firebase | Android mobile push delivery | FCM device token and notification content |
| Google (optional) | "Sign in with Google", when enabled | Email, name, ID — only if you click "Sign in with Google" |
| Umami (self-hosted) | Anonymous usage analytics (only after consent) | Anonymous events, device type (no IP) |
| Sentry (optional) | Error tracking, if configured | Technical error data (no message content) |
| Netcup | Hosting infrastructure (data centres in Germany) | All data above (at rest) |
6. Retention
- Account and profile: while your account is active
- Gatherings and applications: retained in host history unless you delete your account
- Chat messages: retained until you delete your account
- Plima delivery history: notification content, destination link, provider, and error details are retained for 90 days and then permanently redacted; category, status, and timestamps remain while the account is active for measurement and audit
- Weekend recommendation snapshot: gathering IDs form part of delivery history, are retained for at most 90 days, and are then permanently redacted
- Plima delivery attempts: linkage, provider, timestamp, and bounded outcome metadata are retained for 90 days and then permanently deleted
- Plima emergency-control audit: administrator identity, bounded reason, action, and timestamp are retained for 24 months for security accountability
- Attendance responses: the current answer and timestamped change history remain while the account is active and are removed with account deletion
- Participation confirmation: the first-confirmed timestamp remains while the account is active to keep aggregate denominators stable and is removed with account or gathering deletion
- Plima prompt decline:
promptDismissedAt is retained while the preference or user account exists and is removed with account deletion
- IP addresses (rate limit): up to 15 minutes for abuse prevention
- Verification codes: 10 minutes, then purged
7. Your rights (GDPR art. 15–22)
- Access and portability: download all your data as JSON under Profile → Settings → Download my data, or directly at /api/users/me/export
- Minimized Plima export: includes preferences, attendance, and sanitized delivery metadata, but omits endpoints, encryption keys, tokens, device IDs, content, provider detail, and internal errors
- Response-history access: your timestamped records are included as
attendanceResponses; administrators have aggregate-only access rather than user-level behavioral lists
- Confirmation-history access: your participation confirmations are included as
participationConfirmations; administrators have aggregate-only access
- Prompt-choice access: the
promptDismissedAt timestamp is included in the preference export and is erased with account deletion
- Weekend snapshot access: until redaction, freshly revalidated options are available through the message destination and their ID list is included in the export as
recommendationGatherIds; account deletion removes the snapshot
- Rectification: edit name, city, bio, and photo in the app
- Erasure: Profile → Settings → Delete account — permanently removes all your data (cascading)
- Withdraw consent: you can change the
val-consent choice at any time
- Plima and push: you can disable each Plima category in Profile → Settings, including the ability to independently disable the first-gathering reminder, and can also disable master push
- Objection: contact info@metrica.hr
- Complaint: Croatian Personal Data Protection Agency (AZOP), Ulica Metela Ožegovića 16, 10000 Zagreb — azop.hr
8. Security
We use HTTPS encryption, HttpOnly session cookies, bcrypt password hashes, rate limiting, CSP headers, and passkey (WebAuthn) login.
9. Changes
We will notify you of material changes via email or in-app notice at least 14 days in advance.