WivMe — Privacy Policy
Effective date: [PLACEHOLDER] Last updated: [PLACEHOLDER]
This Privacy Policy explains how [PLACEHOLDER — legal entity name] ("WivMe", "we", "us") collects and uses your personal data when you use the WivMe app and website (wivme.app).
We are the data controller. Our contact for data protection is [PLACEHOLDER — email]. We are registered with the UK Information Commissioner's Office (ICO), registration number [PLACEHOLDER — ICO registration number]. [LEGAL REVIEW — confirm ICO registration is complete before launch.]
1. The data we collect
You give us:
- Account details: name, email, password, date of birth.
- Profile details: photo, bio, interests, gender, and other information you choose to add.
- Activity content: activities you post, requests, messages, and check-ins.
- Verification data: your mobile number and the date you confirmed it, plus the one-time code check carried out by our SMS provider (see section 2).
- Payment-related data: we use Stripe for payments; we don't store your full card number, but we hold a record of purchases.
- Support and correspondence you send us.
We collect automatically:
- Approximate/derived location for showing nearby activities (as governed by our staged location-reveal design). [DECISION — confirm exactly what location granularity you store.]
- Device and usage data: device type, app interactions, log data.
- Safety and moderation data: to keep the community safe, we automatically scan the content of messages, profile text, and images, and monitor account behaviour (such as messaging patterns). This can generate safety flags and moderation records. See section 5 for full detail.
- Cookies and similar technologies on our website (see our Cookie Notice).
2. Mobile number verification
Before you can post a plan, apply to one, or RSVP to an event, we ask you to confirm a phone number. We send a one-time code by SMS using Didit, our identity verification provider.
- We store your number in international format and the date you confirmed it.
- Your number is never shown to other members and is not used for marketing.
- Each number can be linked to one WivMe account, so we can spot duplicate accounts.
- Confirming a number is not an identity, age, or background check. We do not collect identity documents or facial images.
3. Why we use your data and our lawful bases
| Purpose | Lawful basis (UK GDPR) |
|---|---|
| Create and manage your account | Contract (Art. 6(1)(b)) |
| Show and match activities, run core features | Contract |
| Process payments for credits | Contract |
| Mobile number verification (anti-bot / one account per person) | Contract and legitimate interests (Art. 6(1)(b)/(f)) |
| Automated content moderation and safety monitoring (scanning messages, profile text and images; behavioural monitoring) — see section 5 | Legal obligation and legitimate interests (Art. 6(1)(c)/(f)); for detecting illegal content, the substantial-public-interest / safeguarding conditions where special category data is involved |
| Human review of flagged content, and enforcement action | Legal obligation and legitimate interests (Art. 6(1)(c)/(f)) |
| Meeting our Online Safety Act duties | Legal obligation (Art. 6(1)(c)) |
| Service emails and waitlist (via MailerLite) | Consent and/or legitimate interests |
| Marketing emails | Consent |
| Analytics and website cookies | Consent |
| Complying with law and handling disputes | Legal obligation / legitimate interests |
[LEGAL REVIEW — confirm each lawful basis, especially: (a) the safety/legitimate-interests balancing (you should hold a Legitimate Interests Assessment); (b) the Art. 9 condition relied on where moderation may process special-category data, e.g. CSAM detection; and (c) the legitimate-interests balancing for mobile number verification.]
4. Who we share data with
We share data with service providers who help us run WivMe, under contract and only as needed:
- Supabase — database and backend hosting.
- Stripe — payment processing.
- Didit — confirming mobile numbers by one-time code.
- MailerLite — email and waitlist automation.
- Netlify — website hosting.
- [PLACEHOLDER — image moderation provider, e.g. Hive / Sightengine, once integrated] — automated image content scanning.
- [PLACEHOLDER — any others, e.g. Geoapify for venue lookup, analytics providers].
Other users see the profile and activity information you choose to make visible, in line with your privacy settings and our staged location-reveal design.
We may share data where required by law, to protect users, or to comply with our Online Safety Act duties (for example, reporting illegal content to the appropriate authorities, including reporting child sexual abuse material to the relevant bodies). We do not sell your personal data.
5. Content moderation and safety monitoring
To keep WivMe safe and to meet our legal duties, we operate automated systems that check content and behaviour, with human review of anything flagged. Specifically:
- Message and profile-text scanning. When you send a message or save profile text, our systems automatically check it against a list of prohibited terms and for signs of harmful, illegal, or rule-breaking content. Content that seriously breaches our rules may be blocked from being sent or saved, and you'll be told why.
- Contact-information detection. We detect attempts to share contact details (phone numbers, emails, social handles, links) in messages. We don't block these, but we show a safety reminder to keep chats on WivMe and we may record a safety flag, because moving off-platform is a common safety and scam risk.
- Behavioural monitoring. We monitor patterns such as how many people a new account messages in a short period, and how many reports an account receives, to detect spam, harassment, and abuse. This may temporarily limit activity (for example, rate-limiting a very new account sending a high volume of messages).
- Image scanning. [Once integrated] Images you upload are automatically checked for nudity, violence, and other prohibited content, and are matched against databases of known child sexual abuse material. Confirmed matches are blocked and reported to the relevant authorities. [LEGAL REVIEW — describe accurately once the image classifier and hash-matching are live; do not state this is operational before it is.]
- Reporting and human review. You can report content and users. Reports and automated flags go to a human reviewer, who decides what action to take.
Automated decisions. Our automated systems can flag content, show warnings, block a specific message or profile update, and temporarily rate-limit an account. Significant actions that affect your access to WivMe — such as suspending or removing an account — are decided by a human, not by automation alone. If a decision affects you, we tell you and you can appeal it (see also our Terms and Community Guidelines). [LEGAL REVIEW — confirm this satisfies UK GDPR Art. 22 on automated decision-making; the human-in-the-loop for consequential actions is the key safeguard.]
6. International transfers
Some providers may process data outside the UK. Where they do, we rely on appropriate safeguards (such as UK-approved transfer mechanisms). [LEGAL REVIEW / PLACEHOLDER — confirm where each provider processes data and the safeguard used.]
7. How long we keep data
We keep your data for as long as your account is active, and afterwards only as long as needed for legal, safety, or dispute reasons.
- Account and profile data: deleted [DECISION — e.g. within 30 days] of account closure, unless we need to keep some for legal/safety reasons.
- Mobile number and confirmation date: kept for the life of the account, then deleted with your account data.
- Safety and moderation records (reports, flags, moderation actions, appeals): [DECISION — retention, likely longer for safety and legal-defence reasons].
[LEGAL REVIEW — set a full retention schedule; this is an ICO expectation.]
8. Your rights
Under UK GDPR you have the right to: access your data; correct it; delete it; restrict or object to processing; data portability; and withdraw consent at any time. You can exercise most of these in Account & Settings or by contacting [PLACEHOLDER — email].
You also have the right to complain to the ICO (ico.org.uk), though we'd appreciate the chance to help first.
9. Security
We use appropriate technical and organisational measures to protect your data, including access controls and encryption in transit. No system is completely secure; tell us immediately at [PLACEHOLDER — email] if you're concerned about your account.
10. Children
WivMe is not intended for anyone under [DECISION — minimum age]. We do not knowingly collect data from people under that age. [LEGAL REVIEW — how the self-declared age gate interacts with Online Safety Act children's-access duties.]
11. Changes
We may update this policy. If changes are significant we'll tell you. The "last updated" date shows the current version.
12. Contact
Data protection queries: [PLACEHOLDER — email]. Postal: [PLACEHOLDER — address].