PartySpot
Moods Memories Pricing FAQ
DE / EN
Get the app
← Back to home

Privacy Policy for the PartySpot App

Status: June 2026. This version is undergoing final legal review; individual items marked in italics in parentheses are still being completed.

This Privacy Policy describes the processing of personal data by the provider of the mobile application “PartySpot” (hereinafter the “App”). It supplements and gives concrete form to the data protection notices in Sec. 17 of the Terms and Conditions (AGB) and contains the complete mandatory disclosures pursuant to Art. 13 and Art. 14 GDPR.

As of: 19 June 2026


1. Controller and Contact

The controller within the meaning of Art. 4(7) GDPR and the service provider within the meaning of Sec. 5 of the German Digital Services Act (DDG) is:

SZuCO – Dr.-Ing. Piotr Szegvári Sole proprietor Zum Weizenring 14 14469 Potsdam Germany

Email: info@partyspot.app Rapid electronic means of contact: Contact form in the PartySpot app (Settings → Help & Support) Value Added Tax Identification Number pursuant to Sec. 27a UStG (German VAT Act): DE458930351

(hereinafter “we”, “us”, “PartySpot” or the “Provider”)

The address for service of process, the rapid electronic means of contact and — where available — the VAT ID no. are mandatory components pursuant to Art. 13(1)(a) GDPR and Sec. 5 DDG.

For all questions concerning data protection and the exercise of your rights, you may contact the above address or info@partyspot.app at any time.

Note on the role of the Host: Insofar as a Host (organizer of a Party) processes personal data of third parties (in particular photographs and videos of persons) beyond the purely private circle of personally connected individuals, the Host may incur its own data protection responsibility in this respect (see Section 9). This Privacy Policy primarily concerns the processing carried out by the Provider itself.


2. Data Protection Officer

We have not appointed a data protection officer. In our assessment, there is currently no obligation to designate one. The decisive provision is primarily Art. 37(1) GDPR: our core activity consists neither in extensive regular and systematic monitoring of data subjects (Art. 37(1)(b) GDPR) nor in the extensive processing of special categories of personal data (Art. 37(1)(c) GDPR). The location-based functions contained in the App are used exclusively on a voluntary opt-in basis and with coarse resolution or for one-time join verification (see Sections 4.9 and 4.10) and, in our assessment, do not constitute extensive systematic monitoring within the aforementioned meaning. In addition, there is also no numerically based obligation under Sec. 38 BDSG (German Federal Data Protection Act), as a rule at least 20 persons are not constantly engaged in the automated processing of personal data. For all data protection matters, you can reach us using the contact details set out in Section 1. Should the actual circumstances change, we will reconsider the appointment of a data protection officer and adjust this Policy accordingly.


3. General Notes on Data Processing

(1) The App is a purely mobile application for Apple iOS/iPadOS and Google Android. A web version is not offered.

(2) The App is financed exclusively through one-time in-app purchases. There is no advertising; there is no advertising-related tracking and no advertising-related profiling by us or by third parties (see Section 13).

(3) Insofar as we cite a legitimate interest (Art. 6(1)(f) GDPR) as the legal basis below, we expressly state the respective interest. You may object to such processing under the conditions of Art. 21 GDPR (see Section 11).

(4) The provision of certain data may be necessary for the use of the App or of individual functions. Insofar as processing is necessary for the performance of a contract (Art. 6(1)(b) GDPR), the respective contract cannot be performed or the respective function cannot be provided without such data. Insofar as processing is based on consent (Art. 6(1)(a) GDPR), it is voluntary; the failure to grant or the withdrawal of consent has no disadvantages other than the loss of the respective optional function.


4. Processing in Detail

4.1 Account / Registration (Host Account)

  • Purpose: Provision and management of a user account, in particular for creating and managing Parties, for the delivery of legally required confirmations in connection with in-app purchases, and for recognition across multiple sessions.
  • Categories of data: Email address, display name, time of log-in/log-out (login timestamp), technical user identifier (UID). In the case of sign-in via a login provided by the operating system or a third-party provider (e.g., “Sign in with Apple” / Google), the identification data transmitted in this process.
  • Legal basis: Art. 6(1)(b) GDPR (performance of the user agreement and pre-contractual measures); insofar as legal obligations are concerned (e.g., confirmations on a durable medium pursuant to Sec. 312f, Sec. 356a BGB (German Civil Code)), Art. 6(1)(c) GDPR.
  • Recipients / Processors: Google Firebase (Firebase Authentication) as processor (see Section 7).

4.2 Anonymous Guest Use (Joining Without Registration)

  • Purpose: Participation in a Party without creating a full account, by joining via QR code or an eight-digit join code with a freely selectable pseudonym (“Alias”).
  • Categories of data: Freely chosen Alias, technically generated anonymous user identifier (anonymous Firebase Auth session), assignment to the respective Party (participant status), where applicable a push token (see Section 4.4). In this respect, we do not collect any real names or email addresses.
  • Legal basis: Art. 6(1)(b) GDPR (provision of the participation function). Insofar as the processing additionally serves stable operation and the prevention of misuse, Art. 6(1)(f) GDPR (legitimate interest: technical functionality and protection against abusive use).
  • Recipients / Processors: Google Firebase (Authentication, Firestore).

4.3 Party, Photo, Video, Comment and Voting Data

  • Purpose: Conducting the respective Party, in particular collaborative music control (song selection, setlists, queue), music and photo voting, provision of the shared Party gallery (photos and videos up to 30 seconds, compressed on-device), commenting, and display of the content to the authorized participants of the respective Party.
  • Categories of data: Song selection/setlists, votes, photos and videos together with associated metadata (e.g., upload time, uploader identifier, file size, media type, duration, preview images, download URLs). Comments including author Alias and time.
  • Legal basis: Art. 6(1)(b) GDPR (performance of the user agreement / provision of the gallery and voting functions). With regard to persons depicted in photos/videos, see additionally Section 9 (image rights; Sec. 22 KUG (German Art Copyright Act — right to one’s own image), Art. 6/7 GDPR) and Section 4.11 (screenshot notice).
  • Access / Visibility: Content is technically restricted to the participant group of the respective Party defined by QR code/join code (closed group). Non-members can view neither the content nor its metadata.
  • Recipients / Processors: Google Firebase (Firestore for metadata/comments/votes; Cloud Storage for photo/video files), insofar as PartySpot Storage is selected as the storage location. For external storage, see Section 4.7.

4.3.1 Embedding of Personal Data into the Image File (EXIF “Baking”) — Important Notice

When a photo is downloaded or exported by a participant, the App processes the JPG image file and in doing so writes personal content permanently into the metadata (EXIF) of the image file. Specifically, the following are embedded:

  • the Alias of the creating person (EXIF field “Artist”);
  • the Party name and, where applicable, the Party description (EXIF field “ImageDescription”);
  • the photo rating (plus/minus votes, star rating; EXIF “Rating” and in the comment field);
  • the Aliases of all commenting persons as well as their comment texts in plain text (EXIF fields “UserComment” and “XPComment”, currently up to approx. 1,800 characters, truncated thereafter);
  • a software/copyright notice (“PartySpot”).

Note on the implications: This data is written permanently into the downloaded file. As soon as the file is saved, exported or shared out of the App, the embedded personal data (creator Alias, commenter Aliases and comment texts) leaves the closed participant group of the Party and is removed from the App-side access control (members-only). Anyone who receives the exported file can read out the embedded metadata using common tools. Please take this into account before passing on downloaded photos outside the Party.

  • Purpose of the embedding: Preservation of the context (authorship, Party reference, ratings and comments) within the exported file.
  • Legal basis: Art. 6(1)(b) GDPR (download/export requested by the user with context) as well as Art. 6(1)(f) GDPR (legitimate interest: preservation of the attribution and context within the exported file). With regard to the third-party data captured in this process (commenter Aliases and texts), the exporting person is jointly responsible for the further use outside the App.
  • Data minimization: We continuously review whether and to what extent the embedding of personal content of third parties (in particular third-party comment Aliases and texts) should be reduced or made subject to separate consent (Art. 5(1)(c) GDPR).

4.4 Push Notifications / FCM Token (Including for Anonymous Use)

  • Purpose: Sending push notifications via five individually activatable/deactivatable channels: (1) new photos on one’s own Party, (2) new comments on one’s own photos, (3) music updates (track change), (4) app announcements, (5) “Parties Nearby” (see Section 4.9). The push function is additionally used for advance warnings of deletions (see Section 10).
  • Categories of data: Device push token (FCM token), stored in the subcollection users/{uid}/fcmTokens; assignment to the user or anonymous session identifier; channel settings (opt-in/opt-out per channel). A push token may also be processed in the case of anonymous guest use.
  • Two separate processing levels and their legal bases:
  • (a) Storage and management of the FCM token as a technical prerequisite for being able to address the device at all: Art. 6(1)(b) GDPR (provision of the notification infrastructure as part of the function) or Art. 6(1)(f) GDPR (legitimate interest: technical operation of delivery, removal of invalid tokens). The storage of the token does not, in and of itself, serve any substantive notification purpose.
  • (b) Substantive push channels: The sending of substantive notifications per channel is based on Art. 6(1)(a) GDPR (consent through activation of the respective channel; the platform-side push permission is additionally granted at the operating system level) as well as, additionally, Art. 6(1)(b) GDPR insofar as the notification is necessary for the provision of the desired function. Service/notice notifications (e.g., deletion advance warnings, Section 10) are based on Art. 6(1)(f) GDPR (legitimate interest: timely information before data loss) or Art. 6(1)(b) GDPR.
  • Note on the “Parties Nearby” channel: This channel requires two separate consents: on the one hand, the activation of the push channel (lit. a, here) and, on the other hand, the separate Geohash consent for the location rasterization (Section 4.9). Both can be withdrawn independently of each other.
  • Withdrawal / Control: Each channel can be individually deactivated in the App; in addition, the push permission can be withdrawn at the operating system level. Tokens that are no longer valid are automatically removed.
  • Recipients / Processors: Google Firebase Cloud Messaging (FCM) as well as the push delivery services of the platform operators (Apple Push Notification service / Google).

4.5 In-App Purchases and Receipt Validation

  • Purpose: Processing of one-time in-app purchases (Party tiers, stackable storage add-ons, Party Recap), unlocking of the acquired functions, fraud prevention through server-side validation of purchase receipts, as well as fulfillment of legal obligations (e.g., confirmations, warranty, withdrawal).
  • Categories of data: Purchase receipt/transaction data of the platform (Apple/Google), product/tier identifier, platform identifier, time, a receipt fingerprint as well as the assigned user identifier; validation result. The actual payment processing (payment means/data) is carried out exclusively via the platform operators; we do not receive any complete payment data.
  • Legal basis: Art. 6(1)(b) GDPR (performance of the purchase contract / provision of the digital product); Art. 6(1)(c) GDPR (legal obligations, including evidentiary, confirmation, and commercial- and tax-law retention obligations); Art. 6(1)(f) GDPR (legitimate interest: protection against fraud and manipulated or revoked purchase receipts).
  • Processing: The validation is carried out server-side via the Cloud Functions validatePartyPurchase, validateStoragePurchase and validateRecapPurchase; purchase transactions are logged for evidentiary purposes.
  • Storage period: see Section 10(3) (retention until expiry of the commercial- and tax-law periods).
  • Recipients / Processors: Apple (App Store) or Google (Google Play) as independent controllers for the payment processing; Google Firebase (Cloud Functions, Firestore) as processor for the validation and logging.

4.6 Music Control (Spotify / Apple Music)

  • Purpose: Remote control of a third-party music app already installed on the Host’s device (Spotify via the App Remote SDK or Apple Music via MusicKit), in particular selection, start/pause and order of playback. PartySpot does not itself stream music and does not store any audio recordings, but merely transmits control commands and reads the playback/context information required for the function.
  • Categories of data: OAuth access/refresh tokens as well as account identifiers of the respective third-party service; playback/context data processed within the scope of control (e.g., track identifiers, playlist information, genre of the first artist for cluster sorting). The tokens are stored protected and user-specific (users/{uid}/secrets).
  • Legal basis: Art. 6(1)(b) GDPR (provision of the music control function desired by the Host). The connection to the third-party provider is established upon the active initiation of the Host (OAuth authorization).
  • Own responsibility of the third-party provider: Spotify or Apple are independent controllers with regard to the processing taking place within their services (in particular playback via the Host’s Premium account). Their own data protection provisions apply in this respect.
  • Recipients: Spotify; Apple Music. Storage of the tokens with Google Firebase (processor).

4.7 External Cloud Storage (Dropbox / Google Drive)

  • Purpose: Optional storage of the Party photos and videos in an external cloud managed by the Host itself instead of in PartySpot Storage.
  • Provider’s own transfer act: If the Host selects external storage, the App actively transfers the photo/video content into the storage connected by the Host via OAuth; in addition, a Cloud Function refreshes the OAuth tokens in the background (e.g., users/{uid}/secrets/storage_dropbox) so that long-running Parties are not interrupted. This transfer to the external service is a processing operation carried out by the Provider; insofar as the recipient is located in a third country, the recipient-specific third-country basis pursuant to Section 8 applies to this.
  • Categories of data: OAuth access/refresh tokens for the respective cloud provider (stored protected and user-specific), required account/path information, the transferred photo/video content.
  • Legal basis: Art. 6(1)(b) GDPR (provision of the storage function selected by the Host, including the transfer of the content); with regard to the background refresh of the tokens, additionally Art. 6(1)(f) GDPR (legitimate interest: uninterrupted provision of the storage function during ongoing Parties).
  • Role of the providers / own responsibility of the Host: In relation to the Host, the storage and data protection relationship exists directly between the Host and the respective cloud provider; Dropbox and Google are independent controllers in relation to the Host in this respect. In this case, PartySpot does not store the files in PartySpot Storage but, as a rule, merely retains metadata/references. The data protection provisions of the respective cloud provider apply additionally.
  • Recipients: Dropbox Inc., Google (Google Drive) — depending on the Host’s selection; Google Firebase (for the token refresh function and metadata).

4.8 Pseudonymous/Aggregated Usage Statistics and Archived Setlists (parties-data)

  • Purpose: Statistical analysis per Party (counters), improvement and further development of the App, as well as recommendation/playlist functions. When a Party is permanently deleted (cf. Section 10), an archive snapshot is created beforehand — provided songs exist — in the parties-data collection in order to retain setlists for future recommendations.
  • Categories of data: During archiving, both direct personal identifiers and directly identifying Party details are removed: no ownerId, no participantIds, no song-related UIDs/voter identifiers, no Party name, no Party description, no location text and no coordinates, and no exact timestamps. Only non-personally-referable data is carried over: the song list — per track the provider ID (Spotify track id or Apple Music catalog id) and the provider-neutral ISRC, without title/artist/album —, genres, the party’s streaming provider (Spotify/Apple Music), rating aggregates (up/down votes, sums), relative play-time offsets (without an absolute date/time), the coarse time of day (UTC hour and weekday), Party duration, participant count, the purchased tier, and a coarse Geohash (geohash5, approx. 5 km cell accuracy). In addition, an aggregated cost snapshot (participant count, cost metrics) is stored. The data in this collection is accessible exclusively on the server side.
  • Classification / Legal basis: The archive snapshot is designed so that it contains no details that identify or make re-identifiable an individual Party or person; it constitutes anonymous data to which the GDPR does not apply (cf. Recital 26 GDPR). The upstream act of anonymization (converting the personal source data into the anonymous snapshot) is based on Art. 6(1)(f) GDPR (legitimate interest: statistical analysis, product improvement, and the provision of recommendation/playlist functions).
  • Storage period: As anonymous data, the anonymized snapshot is not subject to any data-protection deletion period and may be retained indefinitely for the recommendation/statistics purposes. Any aggregated cost snapshot is deleted as soon as it is no longer needed for internal cost analysis.
  • Note on consistency with the Terms and Conditions: The designation “anonymized/not traceable to an individual Party and its location” used in Sec. 8(6) and Sec. 17 of the Terms and Conditions corresponds to the actual technical implementation (archive schema version 2): name, description, location text, coordinates, and exact timestamps are removed during archiving; only a coarse, non-re-identifiable setlist remains.
  • Recipients / Processors: Google Firebase (Firestore, Cloud Functions).

4.9 “Parties Nearby” — Geohash (Opt-in)

  • Purpose: Display of publicly listed Parties in the approximate vicinity of the user via a coarse geographic rasterization.
  • Categories of data: Geohash with coarse resolution (5 characters, corresponding to approx. 5 km cell accuracy). An exact determination of the user’s location for this purpose does not take place.
  • Legal basis: Art. 6(1)(a) GDPR (express, voluntary consent / opt-in). The consent can be withdrawn at any time with effect for the future (Art. 7(3) GDPR); the lawfulness of the processing carried out up to the withdrawal remains unaffected. This consent is to be distinguished from the activation of the “Parties Nearby” push channel (Section 4.4).
  • Storage period: Deletion of the Geohash after the end of the respective Party.
  • Recipients / Processors: Google Firebase.

4.10 Location/On-Site Verification (GPS, Opt-in) and Public Party Location

  • Purpose: Optional verification of whether a guest is actually present at the event venue for the purpose of joining a Party configured as “on-site only” (GPS on-site verification).
  • Categories of data: Location data (GPS) of the device at the time of verification, insofar as required for the comparison.
  • Legal basis: Art. 6(1)(a) GDPR (express, voluntary consent / opt-in); the platform-side location release is additionally granted at the operating system level. The consent can be withdrawn at any time with effect for the future (Art. 7(3) GDPR); the platform-side permission can be withdrawn in the device settings.
  • Storage period of the GPS verification data: The location check serves exclusively the one-time join comparison; permanent storage of the guest’s raw GPS location for this purpose is not provided for — only the verification result (yes/no) is processed or retained, insofar as required. (The specific, short storage period of any raw GPS data will be added.)
  • Public Party location: If a Host marks a Party as public and stores a location, the location data of the Party is processed for the purpose of display on a map; on the map view, the exact position is obfuscated (offset). The decision on the publication of the Party location lies with the Host. Storage period of the Party location data: The stored Party location is retained for the duration of the Party and is thereafter subject to the deletion periods for the Party pursuant to Section 10; regarding the treatment in the anonymized parties-data archive, see Section 4.8 (only a coarse Geohash remains there, no location text and no coordinates).
  • Recipients / Processors: Google Firebase; for the map display, Google Maps (Maps SDK, see Section 7.3).

4.11 Screenshot Notice (“Screenshot Guard”)

  • Purpose: Protection of the image rights and personality rights of the persons depicted in the gallery. Participants can be informed when a screenshot is taken of content in the gallery; the Host can deactivate this function.
  • Categories of data: Technical event information about a detected screenshot within the respective Party (insofar as detectable on the platform used), where applicable assigned to the triggering participant identifier.
  • Legal basis: Art. 6(1)(f) GDPR (legitimate interest: protection of the rights of depicted persons and containment of unwanted further dissemination of content within the closed Party group).
  • Recipients / Processors: Google Firebase, insofar as server-side processing takes place.

4.12 Service and Notice Emails

  • Purpose: Sending of transaction- and operation-related emails, in particular advance warnings before the deletion of photos/videos and before the deletion of inactive accounts (see Section 10), as well as legally required confirmations in connection with in-app purchases.
  • Categories of data: Email address, occasion of the communication, associated contract/Party/period information.
  • Legal basis: For deletion advance warnings and comparable operational notices, Art. 6(1)(f) GDPR (legitimate interest: timely information before data loss and transparent contract execution); for legally required confirmations, Art. 6(1)(c) GDPR. These notice emails can be switched off; mandatorily prescribed legal confirmations remain unaffected by this.
  • Recipients / Processors: Google Firebase or the service used for sending (processor).

4.13 Wishes and Feedback

  • Purpose: Receipt and processing of feature requests, feedback and support inquiries.
  • Categories of data: The text entered by you (limited to 2,000 characters), your user identifier, processing status.
  • Legal basis: Art. 6(1)(f) GDPR (legitimate interest: improvement of the App and handling of inquiries) or Art. 6(1)(b) GDPR insofar as your inquiry concerns the performance of the contract.
  • Recipients / Processors: Google Firebase.

5. Technically Required Processing and Device Integrity Attestation in the Operation of the App

(1) Technically required processing: During the operation of the App, technically required data is processed in order to provide the App (e.g., device/session identifiers, connection and error information). The legal basis for the processing mandatorily required for the provision of the App and its functions is Art. 6(1)(b) GDPR.

(2) Security, fraud and abuse protection: Insofar as processing additionally serves secure, stable and fraud-resistant operation (in particular the following device integrity attestation as well as measures to limit abuse), we base it on Art. 6(1)(f) GDPR (legitimate interest: protection of the App and its users against manipulation, abuse and automated attacks).

(3) Device integrity attestation (App Check): In release builds, we use Firebase App Check. In this process, the platform-native procedures App Attest/DeviceCheck (Apple, iOS/iPadOS) or Play Integrity (Google, Android) are used to verify whether requests originate from a genuine, unmodified instance of the App. For this purpose, device- and app-related integrity/attestation tokens are generated and transmitted to Apple Inc. or Google; Apple or Google are, in this respect, separate recipients or independent controllers within the scope of their respective services (see Section 7.3). This processing serves exclusively the purpose of security and abuse protection; it does not serve advertising and no advertising-related profiling.


6. Origin of the Data (Art. 14 GDPR)

Insofar as we do not collect personal data directly from you, it originates from the following sources, in each case with the categories of data stated below (Art. 14(1)(d), (2)(f) GDPR):

  • from other participants of the same Party: likeness (photo/video recordings in which you may be depicted), comments concerning you (text), ratings/votes as well as associated Aliases and times;
  • from the platform operators Apple/Google (in-app purchases): purchase receipt/transaction data, product/tier identifier, platform identifier, time, receipt fingerprint, validation result;
  • from the platform operators Apple/Google (device integrity attestation, Section 5): result of the integrity check or associated attestation information;
  • from the third-party services Spotify, Apple Music, Dropbox, Google Drive: account/profile identifiers as well as context/path information required for the respective function from the connection initiated by you.

Supplementary details on the purposes and legal bases per category of data are set out in Section 4.


7. Recipients and Processors

7.1 Google Firebase (Processor, Art. 28 GDPR)

We use the services of Google (Google Ireland Limited or Google LLC) within the scope of the Firebase platform, in particular:

  • Firebase Authentication (account and anonymous guest sessions),
  • Cloud Firestore (database for Party data, photo metadata, comments, votes, settings),
  • Cloud Storage for Firebase (storage of the photo/video files in PartySpot Storage),
  • Cloud Functions (server-side logic, including receipt validation, notification triggers, token refresh, archiving/deletion processes),
  • Cloud Messaging (FCM) (push notifications),
  • Firebase App Check (device integrity attestation, Section 5).

A data processing agreement pursuant to Art. 28 GDPR exists or will be concluded with Google. Google processes this data exclusively in accordance with our instructions for the purposes described herein.

Processing regions: The Cloud Functions are operated in the region europe-west3 (Frankfurt am Main, Germany/EEA). The processing region for Cloud Firestore and Cloud Storage for Firebase is europe-west1 (Belgium, EU/EEA). By virtue of their function, certain services (in particular Cloud Messaging/FCM) are operated globally and may have a third-country reference (see Section 8).

7.2 Platform Operators Apple and Google (In-App Purchases)

Apple (App Store) and Google (Google Play) process the payment for in-app purchases and issue the purchase receipts. They act in this respect as independent controllers in accordance with their own data protection provisions; we receive from them the receipt/transaction data required for unlocking and validation (see Section 4.5).

7.3 Further Recipients

  • Spotify / Apple (music control, Section 4.6) — independent controllers.
  • Dropbox Inc. / Google (external cloud storage, Section 4.7) — independent controllers in relation to the Host; upon corresponding selection, the Provider actively transfers the content to them.
  • Apple Push Notification service / Google (push delivery, Section 4.4).
  • Apple Inc. (App Attest / DeviceCheck) and Google (Play Integrity) — recipients of the device integrity attestation (Section 5).
  • Google (Google Maps Maps SDK) — recipient within the scope of the map display for public Party locations (Section 4.10); when using the map view, data is regularly transmitted to Google.
  • Where applicable, state bodies or authorities, insofar as we are legally obligated to do so (Art. 6(1)(c) GDPR).

8. Data Transfer to Third Countries (Art. 44 et seq. GDPR)

(1) Principle: Insofar as Cloud Firestore and Cloud Storage are operated in an EU/EEA region (cf. Section 7.1) and the Cloud Functions run in europe-west3 (Frankfurt), the core processing of the content and metadata takes place within the EEA. A third-country reference nevertheless remains, in particular, in the case of services that are operated globally by virtue of their function or provided by US providers (e.g., Cloud Messaging/FCM and Apple Push Notification service, in-app purchases via Apple/Google, device integrity attestation via Apple/Google, music control via Spotify, as well as — upon the corresponding choice of the Host — external cloud storage with Dropbox/Google).

(2) Recipient-specific safeguards: For transfers to recipients in the USA, we rely, per recipient, on the following safeguards. Insofar as a recipient is certified under the EU-US Data Privacy Framework (EU-US DPF), the transfer takes place on the basis of the European Commission’s adequacy decision of 10 July 2023 (Art. 45 GDPR); otherwise or additionally, on the basis of the EU Standard Contractual Clauses (SCC) pursuant to Art. 46(2)(c) GDPR together with supplementary protective measures.

RecipientFunction (Section)Safeguard for US transfer
Google LLCFirebase/FCM/Maps/IAP (4.x, 5, 7)(Any certification of the named US providers under the EU-US Data Privacy Framework is currently being verified.) or SCC + supplementary measures
Apple Inc.IAP, Push, App Attest (4.5, 4.4, 5)(Any certification of the named US providers under the EU-US Data Privacy Framework is currently being verified.) or SCC + supplementary measures
Spotify (USA)music control (4.6)(Any certification of the named US providers under the EU-US Data Privacy Framework is currently being verified.) or SCC + supplementary measures
Dropbox Inc.external storage (4.7)(Any certification of the named US providers under the EU-US Data Privacy Framework is currently being verified.) or SCC + supplementary measures

The specific safeguard applicable per recipient (active DPF certification with reference to the official DPF list or SCC) must be entered as binding before publication on the basis of the respective current DPF list and the contractual bases.

(3) Note on the legal status of the DPF: The EU-US DPF adequacy decision is currently in effect; however, an appeal against it is pending before the Court of Justice of the European Union (proceedings C-703/25 P). Should the decision be annulled or suspended, we will base affected transfers on the EU Standard Contractual Clauses together with supplementary measures and adjust this Policy.

(4) Information / Safeguards: Upon request, we will provide information on the appropriate safeguards and their availability or make a copy available (Art. 13(1)(f), Art. 14(1)(f) GDPR).


9. Image Rights of Depicted Persons; Role of the Host

(1) Persons may be recognizably depicted in photos and videos. Images of identifiable persons are personal data (Art. 4(1) GDPR); their storage and sharing within the Party gallery require a legal basis, in particular the consent of the depicted persons (Sec. 22 KUG (German Art Copyright Act — right to one’s own image); Art. 6(1)(a), Art. 7 GDPR). In the case of minors, the additional requirements pursuant to Section 12 must be observed.

(2) Responsibility: For purely private Parties within the circle of personally connected individuals, the household exemption (Art. 2(2)(c) GDPR) may apply. If content is made accessible beyond this circle, the household exemption regularly does not apply; in this case, the Host as the organizer may incur its own data protection responsibility for the photos of persons shared within its Party. Obtaining the necessary consents of the depicted persons is then incumbent on the Host or the uploading person.

(3) Processing by the Provider: We are responsible for the technical processing that we ourselves carry out (in particular storage, hosting and compression in PartySpot Storage as well as the EXIF embedding upon download pursuant to Section 4.3.1); in this respect, the Provider is its own data protection controller or — vis-à-vis the Host — processor. Any joint controllership (Art. 26 GDPR) between the Provider and the Host must be regulated separately insofar as it exists in an individual case. The household exemption does not relieve the Provider.

(4) Protective measures and their limits: Content is in principle restricted to the closed participant group of the respective Party (members-only access); the uploader and the Host can delete individual content at any time; a screenshot notice (Section 4.11) as well as time-limited retention periods (Section 10) limit the persistence and the further dissemination. However, this protective effect ends as soon as content is exported/shared out of the App; in particular, upon photo download, personal data (including that of third parties) migrates into the EXIF metadata of the file (see Section 4.3.1). Upon the first photo upload, we actively point out the responsibility for the content posted.


10. Storage Period and Deletion Periods

(1) We store personal data only for as long as is necessary for the respective purposes or as legal retention obligations require. In PartySpot Storage, the following standard periods apply — subject to legal retention obligations and the advance warning set out below:

a) Photos and videos: Deletion 30 days after the end of the respective Party.

b) Parties: Deletion 12 months after the last Party purchase assigned to the respective Party.

c) User accounts: Deletion after 12 months of inactivity.

d) Geohash (“Parties Nearby”, Section 4.9): Deletion after the end of the respective Party.

e) Archive snapshot parties-data (Section 4.8): The snapshot is anonymized at the moment it is created (no names, no location text/coordinates, no exact timestamps). As anonymous data, it is not subject to any data-protection deletion period; any aggregated cost snapshot is deleted as soon as it is no longer needed for internal cost analysis.

(2) Advance warning: Before a deletion pursuant to paragraph 1 lit. a–c, we will inform you in good time by push notification and — insofar as an email address is available — by email, so that you can back up affected content in good time.

(3) Tokens and purchase-related data: OAuth tokens (music control, external storage) are stored for the duration of the existing connection and are deleted upon disconnection or withdrawal. We retain purchase-related data and validation logs insofar as and for as long as this is necessary for the fulfillment of commercial- and tax-law retention obligations; the applicable statutory retention period in this respect is generally up to ten years (cf. Sec. 257 HGB (German Commercial Code), Sec. 147 AO (German Fiscal Code)), calculated from the end of the respective business/calendar year. Data that serves exclusively for fraud prevention/validation and is not subject to any legal retention obligation will be deleted or anonymized by us as soon as the validation purpose ceases to apply. After the expiry of the statutory periods, the affected receipt data is deleted; components not subject to retention obligations are deleted or anonymized beforehand.

(4) External storage: If the Host has chosen a self-managed external cloud (Dropbox, Google Drive), the above deletion periods do not apply to the content stored there; the Host is responsible for its retention and deletion in accordance with its contract with the respective provider.

(5) You can request the deletion of your content and your account at any time via the functions provided in the App or by notice to info@partyspot.app. Statutory deletion claims (Art. 17 GDPR) remain unaffected; they may be restricted by legal retention obligations (paragraph 3).


11. Your Rights as a Data Subject

In accordance with the statutory requirements, you have the following rights:

  • Access to the personal data processed concerning you (Art. 15 GDPR);
  • Rectification of inaccurate data or completion of incomplete data (Art. 16 GDPR);
  • Erasure (“right to be forgotten”, Art. 17 GDPR);
  • Restriction of processing (Art. 18 GDPR);
  • Data portability (Art. 20 GDPR);
  • Objection to processing operations based on Art. 6(1)(f) GDPR, on grounds relating to your particular situation (Art. 21 GDPR);
  • Withdrawal of consent granted with effect for the future (Art. 7(3) GDPR) — in particular for the opt-in functions GPS on-site verification (Section 4.10) and Geohash “Parties Nearby” (Section 4.9) as well as for activated push channels (Section 4.4). The lawfulness of the processing carried out up to the withdrawal remains unaffected.

To exercise these rights, a notice to the contact details stated in Section 1 is sufficient.

Right to lodge a complaint with a supervisory authority (Art. 77 GDPR): You have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority presumably competent for us is the state data protection supervisory authority responsible for the company’s registered office:

The State Commissioner for Data Protection and the Right to Access Information of Brandenburg (LDA Brandenburg), Stahnsdorfer Damm 77, 14532 Kleinmachnow, Germany

Notwithstanding this, you may also contact the supervisory authority of your habitual residence or of the place of the alleged infringement.


12. Minors

(1) The App and in particular paid in-app purchases are not directed at children. For the conclusion of contracts by minors, Sec. 104 et seq. BGB (German Civil Code) applies.

(2) A data protection consent to information society services (Art. 8 GDPR) is, in Germany, only effective from the completion of the 16th year of age. For younger persons, the consent or approval of the holders of parental responsibility is required.

(3) For consent to the use of one’s own likeness (photo/video), from the point at which the minor person has the capacity of understanding (regularly from the 14th year of age), the minor’s own consent is additionally required alongside the consent of the holders of parental responsibility (see also Section 9).

(4) We do not knowingly collect personal data from children below the respectively relevant age threshold without the required approval. If we become aware of processing to the contrary, we will delete the affected data without undue delay.


13. No Automated Decision-Making in Individual Cases; No Advertising Profiling

(1) A decision based solely on automated processing — including profiling — which produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR) does not take place.

(2) The App contains no advertising. There is no advertising-related tracking and no advertising-related profiling by us or by third parties. The sorting/voting and Auto-DJ functions used in the App serve exclusively the control of playback within the respective Party and do not constitute personal profiling for advertising or assessment purposes.


14. Data Security

We take appropriate technical and organizational measures to protect your data against loss, misuse and unauthorized access (Art. 32 GDPR). These include, in particular: transport encryption of the data transmission, access-restricting security rules (access to Party content and metadata only for members of the respective Party), separate and access-restricted storage of sensitive access data/tokens, server-side validation of purchase receipts, device integrity attestation in release builds (Section 5) as well as measures to limit abuse (e.g., size and quantity limitations, access throttling). With regard to files exported from the App and the metadata embedded therein (Section 4.3.1), the effect of these measures ends upon export. Our security measures are continuously adapted to the state of the art.


15. Amendments to This Privacy Policy

We reserve the right to adjust this Privacy Policy in order to adapt it to changed legal situations, official requirements, or changes to our services and the underlying data processing. The current version available in the App and in the respective store entry applies in each case. We will inform of material changes in an appropriate manner.


In the event of discrepancies, the German version shall prevail.

As of: 19 June 2026 · Version 1.1 (Draft)


Additional notes on this website (partyspot.app)

The privacy policy above concerns the PartySpot app. For the partyspot.app website itself — a pure information and sign-up page — the following applies in addition. This website deliberately avoids cookies, tracking and external analytics services.

Hosting

The website is hosted by Strato AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. Strato processes the data generated on access on our behalf (Art. 28 GDPR) for secure provision (Art. 6 (1) (f) GDPR).

Server log files

On access, information is automatically stored in server log files (browser type/version, operating system, referrer URL, hostname, time, IP address). The legal basis is Art. 6 (1) (f) GDPR (technical operation and security). Logs are deleted after a short period.

Launch notification sign-up

If you enter your email address on this website, we process that address, the chosen language, the time and possibly your IP address (abuse prevention) in order to notify you once about the app's launch. The legal basis is your consent (Art. 6 (1) (a) GDPR), which you can withdraw at any time by message to info@partyspot.app. Your data is not shared with third parties for advertising purposes.

Cookies, tracking & fonts

This website sets no cookies and embeds no analytics, tracking or advertising services. All fonts are loaded locally from our own server (no Google Fonts CDN), so your IP address is not transmitted to third parties for that purpose.

Imprint Privacy Terms Withdrawal EULA Community Contact
© 2026 PartySpot — Made for nights that stay.
Spotify is a trademark of Spotify AB. Apple and Apple Music are trademarks of Apple Inc. Other named trademarks belong to their respective owners. No partnership, endorsement or sponsorship by these providers.