Documents · Agreements
Privacy Policy
What FND collects, what it refuses to collect, and who can see it.
In short
A child's live location is never collected, so no one can ever look it up: not a parent, not staff, not us.
Everything a participant posts stays inside their own verified organization.
Data sits in the EU, on infrastructure we name at /subprocessors.
No ads, no resale, no model training on partner content.
1.Who this applies to
This policy covers the FND app, the web cabinet and findndo.app. For participant data inside an organization's world, the organization is the controller and FND is the processor: they decide what happens, we execute. For our own website, sales and billing, FND is the controller.
2.What we collect
Only what the service needs to run inside one organization.
Category Examples Why Account basics name, username, optional avatar and interests so people recognise each other inside the group Membership which organization, verification status, staff or participant to keep a world closed to outsiders Activity meets and planned activities created or joined the live map is the product Messages text inside a meet the conversation about that activity Presence zone check-in events presence display, and auto-revoke when someone leaves Safety records reports, incident log entries, a 30-day audit trail so a report can be reviewed and a pattern seen Billing director's name, organization, email, payment metadata from Stripe to sell a pass and issue a receipt No advertising identifiers, no third-party analytics inside the app, no contact-list upload, no background tracking.
3.The live location of a child is not collected
This is a design decision, not a setting. FND cannot answer the question "where is my child right now", because that datum never enters the system.
- 3.1Presence is derived from zone check-in events only: a person was seen at a zone at a time, not a continuous trail.
- 3.2Meet locations stay blurred to about 150 m until a participant joins.
- 3.3There is no map of people. There is a map of activities.
4.Photos
Meet photos are visible only inside the verified organization that produced them. Nothing is public, nothing is shareable outside the group, and there is no external link to an image.
- 4.1We do not use participant photos in marketing.
- 4.2We do not use partner content to train models, ours or anyone else's.
- 4.3Deleting a meet deletes its photos, in full cascade.
5.Legal basis
Under Art. 6 GDPR we rely on: performance of a contract with the organization, our legitimate interest in keeping a verified-only world safe and free of abuse, and legal obligation where accounting or a lawful request requires it.
- 5.1Where the organization relies on consent from participants or their parents, the organization collects it. See /children.
- 5.2We do not rely on consent for our own product analytics, because we do not run product analytics inside the app.
6.Where data lives
Participant data is stored in the European Union, on Supabase infrastructure hosted with AWS in Ireland. In the normal operation of the service no participant data leaves the EEA.
- 6.1Push notifications travel through Apple's APNs, which carries a device token and the notification text.
- 6.2Payment and transactional email involve providers with US operations, under Standard Contractual Clauses. Neither ever receives participant data.
- 6.3The full list, with regions and each provider's own DPA, is at /subprocessors, and changes are announced 30 days in advance.
8.How long we keep it
Every category has a published period, in the schedule at /retention. The short version: safety audit records expire on a 30-day cycle, a revoked participant is removed in full cascade, and an organization's data is deleted after its term unless it asks us to keep it for the next season.
9.Your rights
Access, rectification, erasure, restriction, portability and objection under the GDPR. How to exercise each one, and how fast we answer, is at /rights.
- 9.1Participants and parents normally address the organization, which holds the relationship; we assist it within two business days.
- 9.2Anyone may also write directly to privacy@findndo.app and we will route it correctly rather than bounce it.
- 9.3A complaint can always go to the Belgian Data Protection Authority, whose details are at the bottom of this document.
10.Children and minors
Most FND participants are minors. The rules that apply to them, the role of parents and guardians, and what a camp must do before an account exists are in a document of their own at /children.
11.Emergency
The in-app emergency button dials 112 directly from the device. No data passes through our servers for it, and we do not learn that it was pressed.
12.This website
findndo.app runs without advertising trackers. What is set, and why, is listed at /cookies. Booking a call or requesting a pilot stores what you typed, so we can answer you.
13.Changes to this policy
Material changes are announced to partner organizations at least 30 days in advance, and every version is numbered and dated in the change log below.
Change log
v2.01 July 2026
- Restructured into numbered clauses with a data category table.
- Added legal basis, sharing, lawful requests, website and children clauses.
- Split retention and data-subject rights into their own documents.
v1.016 May 2026
- First published version, at launch.
Issued by
FND (Find 'n Do)
Belgium
Supervisory authority
Gegevensbeschermingsautoriteit / Autorité de protection des données
Need a countersigned copy, a filled-in vendor questionnaire, or a clause explained? One email, one business day.
Write to us