FNDPrivacy Policy

Documents · Agreements

Privacy Policy

What FND collects, what it refuses to collect, and who can see it.

Version
v2.0
In force since
1 July 2026
Last updated
1 July 2026
Contents
13 · 7 min read

In short

A child's live location is never collected, so no one can ever look it up: not a parent, not staff, not us.

Everything a participant posts stays inside their own verified organization.

Data sits in the EU, on infrastructure we name at /subprocessors.

No ads, no resale, no model training on partner content.

  1. 1.Who this applies to

    This policy covers the FND app, the web cabinet and findndo.app. For participant data inside an organization's world, the organization is the controller and FND is the processor: they decide what happens, we execute. For our own website, sales and billing, FND is the controller.

  2. 2.What we collect

    Only what the service needs to run inside one organization.

    CategoryExamplesWhy
    Account basicsname, username, optional avatar and interestsso people recognise each other inside the group
    Membershipwhich organization, verification status, staff or participantto keep a world closed to outsiders
    Activitymeets and planned activities created or joinedthe live map is the product
    Messagestext inside a meetthe conversation about that activity
    Presencezone check-in eventspresence display, and auto-revoke when someone leaves
    Safety recordsreports, incident log entries, a 30-day audit trailso a report can be reviewed and a pattern seen
    Billingdirector's name, organization, email, payment metadata from Stripeto sell a pass and issue a receipt

    No advertising identifiers, no third-party analytics inside the app, no contact-list upload, no background tracking.

  3. 3.The live location of a child is not collected

    This is a design decision, not a setting. FND cannot answer the question "where is my child right now", because that datum never enters the system.

    1. 3.1Presence is derived from zone check-in events only: a person was seen at a zone at a time, not a continuous trail.
    2. 3.2Meet locations stay blurred to about 150 m until a participant joins.
    3. 3.3There is no map of people. There is a map of activities.
  4. 4.Photos

    Meet photos are visible only inside the verified organization that produced them. Nothing is public, nothing is shareable outside the group, and there is no external link to an image.

    1. 4.1We do not use participant photos in marketing.
    2. 4.2We do not use partner content to train models, ours or anyone else's.
    3. 4.3Deleting a meet deletes its photos, in full cascade.
  5. 6.Where data lives

    Participant data is stored in the European Union, on Supabase infrastructure hosted with AWS in Ireland. In the normal operation of the service no participant data leaves the EEA.

    1. 6.1Push notifications travel through Apple's APNs, which carries a device token and the notification text.
    2. 6.2Payment and transactional email involve providers with US operations, under Standard Contractual Clauses. Neither ever receives participant data.
    3. 6.3The full list, with regions and each provider's own DPA, is at /subprocessors, and changes are announced 30 days in advance.
  6. 7.Who we share with

    Sub-processors listed at /subprocessors, and no one else.

    1. 7.1We do not sell data. There is nothing to sell, and there is no version of FND funded by advertising.
    2. 7.2We do not share content between organizations. A world is closed by construction.
    3. 7.3Lawful requests are answered only where they are legally binding and specific, and the affected organization is told unless we are forbidden to. See /security.
  7. 8.How long we keep it

    Every category has a published period, in the schedule at /retention. The short version: safety audit records expire on a 30-day cycle, a revoked participant is removed in full cascade, and an organization's data is deleted after its term unless it asks us to keep it for the next season.

  8. 9.Your rights

    Access, rectification, erasure, restriction, portability and objection under the GDPR. How to exercise each one, and how fast we answer, is at /rights.

    1. 9.1Participants and parents normally address the organization, which holds the relationship; we assist it within two business days.
    2. 9.2Anyone may also write directly to privacy@findndo.app and we will route it correctly rather than bounce it.
    3. 9.3A complaint can always go to the Belgian Data Protection Authority, whose details are at the bottom of this document.
  9. 10.Children and minors

    Most FND participants are minors. The rules that apply to them, the role of parents and guardians, and what a camp must do before an account exists are in a document of their own at /children.

  10. 11.Emergency

    The in-app emergency button dials 112 directly from the device. No data passes through our servers for it, and we do not learn that it was pressed.

  11. 12.This website

    findndo.app runs without advertising trackers. What is set, and why, is listed at /cookies. Booking a call or requesting a pilot stores what you typed, so we can answer you.

  12. 13.Changes to this policy

    Material changes are announced to partner organizations at least 30 days in advance, and every version is numbered and dated in the change log below.

Change log

  1. v2.01 July 2026

    • Restructured into numbered clauses with a data category table.
    • Added legal basis, sharing, lawful requests, website and children clauses.
    • Split retention and data-subject rights into their own documents.
  2. v1.016 May 2026

    • First published version, at launch.

Issued by

FND (Find 'n Do)

Belgium

Supervisory authority

Gegevensbeschermingsautoriteit / Autorité de protection des données

www.gegevensbeschermingsautoriteit.be

Need a countersigned copy, a filled-in vendor questionnaire, or a clause explained? One email, one business day.

Write to us