Privacy Policy
Effective Date: April 16, 2026 · Version 1.1
Spontlr Inc. · 131 Continental Drive, Suite 305, Newark, Delaware 19713, USA
1. Who We Are
Spontlr is a verified lifestyle community app. We connect real, ID-verified people with each other and with local businesses so you can explore your city, earn real rewards, and be part of something genuine.
We are not a social media app. We don't sell advertising. We don't profile you. We exist to help you do life — not to monetise your attention.
Spontlr Inc. is the data controller for all personal data described in this policy. This means we are responsible for how your data is used and protected.
2. What Data We Collect
We collect the minimum we need to make Spontlr work safely. Here is everything, explained plainly.
Data you give us directly
- Full name and date of birth — required to verify your identity and confirm you are 16 or older
- Email address and password — to create and access your account
- Profile photo, bio, location (city), job title, and any other profile fields you choose to fill in
- Posts, photos, and content you share on Spontlr — visible to other verified members
- Messages you send to other members — private and encrypted in transit
- Government-issued ID — submitted once for identity verification. Not stored by Spontlr after verification is complete.
- Business information — business name, address, category, contact details, and any promotional content you create
- Payment information — processed securely via our payment provider. We do not store card details.
Data we collect automatically
- Device type and operating system — for technical compatibility and security
- IP address — for security, fraud prevention, and detecting suspicious activity
- Location — only when you open the app and only if you grant permission (explained in Section 5)
- App usage data — which features you use, to improve the product
What we deliberately do NOT collect
- Browsing history or activity outside Spontlr
- Contacts, call logs, or SMS data
- Behavioural profiles for advertising purposes
- Sensitive personal data (race, religion, political views, health) — we never ask for this
- Permanent location tracking — we do not track you in the background
3. Why We Use Your Data
Every piece of data we collect has a specific reason. Here they are:
To run Spontlr for Business
- Create and manage your business account
- Verify your business identity so the platform stays real, safe, and fraud-free
- Show your business to verified members near your location
- Enable you to post offers, events, and content visible to verified members
- Process subscriptions, payments, and manage your points/rewards balance
To keep Spontlr safe
- Detect and prevent fake accounts, bots, and abuse
- Enforce our Community Standards and respond to reports
- Protect against account takeovers and unauthorised access
- Ensure users who misrepresent their identity are removed
To communicate with you
- Send important security and account notifications (you cannot opt out of these as they are necessary)
- Send activity updates and relevant offers — you can opt out any time in Settings
- Occasional product updates and non-essential messages — opt out any time in Settings
4. Our Legal Basis for Using Your Data (EU / GDPR)
If you are in the European Union or EEA, data law requires us to have a documented legal reason for each use of your data. Here they are:
- Contract performance — because you signed up and agreed to our Terms of Service. We need your data to deliver the service.
- Legitimate interests — for security, fraud prevention, and improving the product, where this does not override your rights.
- Legal obligation — for tax purposes and regulatory compliance.
- Consent — for optional features such as location-based discovery and non-essential communications. You can withdraw consent at any time.
5. Location Data
Location is core to how Spontlr works — it helps members discover local businesses and experiences near them.
How it really works
- We request your location only when you open the app and only if you grant permission
- We do not track your location in the background
- We do not store a log of where you have been
- We only show you what is near you right now — we do not share your precise location with anyone, ever
- If you deny location permission the app still works — you just won't see distance-based results
- You can revoke location permission at any time in your device Settings
On iOS, location permission is requested via the Apple App Store standard prompt. On Android, via the Google Play standard prompt. We comply with both platform privacy requirements and incorporate their privacy frameworks.
6. Data Sharing
We do not sell your data. We do not share your data with advertisers. The only parties who may access your data are:
- Identity verification provider — to verify your ID (data is not retained after verification)
- Payment processor — to handle subscriptions and transactions securely
- Cloud infrastructure providers — to host the app and store data securely (currently Google Firebase / Google Cloud)
- Regulators or law enforcement — only if required by law, and only to the minimum extent required
All third-party providers are bound by data processing agreements and must comply with applicable privacy law.
7. How Long We Keep Your Data
- Account data — kept while your account is active. Deleted within 30 days of account closure.
- Government ID — deleted immediately after verification is complete. We do not retain it.
- Messages — kept while the conversation exists. Deleted when either party deletes the conversation.
- Financial records — kept for 7 years as required by tax law.
- Security logs (IP addresses etc.) — kept for up to 12 months, then deleted.
8. Your Rights
You have the following rights over your personal data:
- Access — request a copy of the data we hold about you
- Correction — ask us to correct inaccurate data
- Deletion — ask us to delete your data (subject to legal retention requirements)
- Portability — request your data in a machine-readable format
- Objection — object to certain uses of your data
- Withdraw consent — for any processing based on consent, withdraw it at any time
To exercise any right, email us at privacy@spontlr.com. We will respond within 30 days.
9. EU / EEA Representative (Article 27)
Spontlr Inc. is incorporated in the United States. For EU/EEA users, we have appointed a representative in accordance with Article 27 of the GDPR. Contact details are available on request at privacy@spontlr.com.
10. Supervisory Authorities
If you believe we have mishandled your data, you have the right to lodge a complaint with your national data protection authority:
11. Children
Spontlr is not intended for anyone under 16. We verify age as part of identity verification. If we discover a user is under 16, their account is immediately removed and their data deleted.
12. California Residents (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act:
- The right to know what personal information we collect, use, and disclose
- The right to delete your personal information
- The right to opt out of the sale or sharing of your personal information — we do not sell or share your data
- The right to non-discrimination for exercising your privacy rights
To exercise these rights, email privacy@spontlr.com.
13. Changes to This Policy
If we make significant changes to this policy, we will notify you via the app and update the effective date above. Continued use of Spontlr after changes take effect constitutes acceptance of the updated policy.
14. Contact Us
Spontlr Inc.
131 Continental Drive, Suite 305
Newark, Delaware 19713, USA
privacy@spontlr.com
Spontlr Inc. · Privacy Policy v1.1 · Effective April 16, 2026