Privacy Policy

Effective date: 1 June 2026  ·  Last updated: 1 June 2026

Draft awaiting counsel review. Controller: Apex Crypto VOF (KvK 96603577, BTW NL867679542B01), trading as Bivvy. Effective from 1 June 2026.

This Privacy Policy describes how Apex Crypto VOF, trading as Bivvy ("we", "us", "our"), collects, uses, shares, and protects personal data when you use the Bivvy mobile application and any related services (together, the "Service"). We have written this policy in plain language. Where you see a term in bold it has the meaning given in the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK Data Protection Act 2018 ("UK GDPR"), or, where it applies to you, the California Consumer Privacy Act as amended ("CCPA/CPRA"). If you do not agree with this policy, please do not use the Service.

1. Summary at a glance

2. Who is the data controller

The controller for personal data processed through Bivvy, within the meaning of Article 4(7) GDPR, is:

Apex Crypto VOF, trading as Bivvy
Katwijkerbroek 75, 2223 XN Katwijk, the Netherlands
KvK no.: 96603577
VAT (BTW) no.: NL867679542B01
Email: support@bivvy-app.com

Apex Crypto VOF is a vennootschap onder firma organised under the laws of the Netherlands. Bivvy is registered as a handelsnaam of Apex Crypto VOF. We are established in the Netherlands and are not required to appoint a representative under Article 27 GDPR. We are not currently required to appoint a Data Protection Officer under Article 37 GDPR; if that changes, contact details will be published here. If you are in the United Kingdom and we are required to appoint a UK representative under Article 27 UK GDPR, the details will be added here.

3. Information we collect

3.1 Information you provide directly

CategoryExamplesCollected
Account informationEmail address, chosen username, password (stored only as a one-way bcrypt hash)When you register or update your profile
Social-login identifierApple / Google subject ID and (if shared) verified emailWhen you sign in with Apple or Google
Profile activitySpots, reviews, ratings, photos, check-ins, saved spots, collections, follows, blocks, reportsWhen you use the feature
CommunicationsMessages you post in public per-spot chat; messages to support; appealsWhen you write them
Location dataLat/lon of (a) spots you submit, (b) check-ins, and (c) the GPS reading used to verify you are within 250 mOnly on user action — never in the background
Builder Programme enrolmentOpt-in timestamp and count of approved contributionsWhen you enrol

We do not collect your real name, phone number, postal address, gender, date of birth, or any government identifier. Your username is the only identifier displayed publicly.

3.2 Information collected automatically

CategoryExamplesPurpose
Device / technical dataOS version, app version, device model class, preferred language, time zoneCompatibility, debugging
Diagnostic dataCrash logs, stack traces, request IDsDetecting and fixing bugs
Network metadataIP address (kept in server access logs for up to 30 days), HTTP request paths, status, latencySecurity, abuse prevention, telemetry
Product-analytics eventsAnonymised event names tied to your username as distinct identifier on our self-hosted PostHog instance; no IP, fingerprint, or ad IDUnderstanding which features are used
Push notification tokenThe Firebase Cloud Messaging device tokenDelivering the notifications you have opted in to

We do not use cookies, advertising identifiers, web beacons, fingerprinting, or any form of cross-app or cross-website tracking.

3.3 Information disclosed to map and tile providers

When you open the map, your device makes direct HTTP requests to load tiles. Those requests necessarily disclose your IP address and the map coordinates of the area you are viewing to:

These providers act as independent controllers for the tile data they receive; their privacy policies are linked in §6.

3.4 Information from third parties

We do not buy personal data from data brokers or social networks. When you sign in with Apple or Google we receive the data in §3.1. When you use "Sign in with Apple — Hide my Email", Apple sends us a relay address (*@privaterelay.appleid.com); if no email is shared at all, we generate a non-deliverable placeholder so the account remains valid. Because outbound email to either of these addresses is unreliable or undeliverable, we will reach you only through in-app channels for any communication that would otherwise have gone by email.

3.5 Information we deliberately do not collect

4. How we use your information and the legal basis

PurposeExamplesLegal basis (Art. 6 GDPR)
Operating the ServiceAccount creation, authentication, map rendering, check-ins, chat delivery, thumbnails, CDNPerformance of a contract — Art. 6(1)(b)
Keeping the Service secureRate limiting, abuse detection, access logs, webhook verification, content moderationLegitimate interests — Art. 6(1)(f) — preventing fraud, abuse, harm to other users
Push notifications"Your spot was approved", "X started following you", "A new spot is near you"Consent — Art. 6(1)(a), withdrawable at any time
Crash diagnostics & improving the appAggregated stack traces, anonymous feature-usage eventsLegitimate interests — Art. 6(1)(f)
In-app purchasesVerifying Bivvy Pro subscription via RevenueCat webhooksPerformance of a contract — Art. 6(1)(b)
Legal obligationsRetaining payment records for 7 years under Dutch tax law; responding to lawful authority requestsLegal obligation — Art. 6(1)(c)
Defending or pursuing legal claimsPreserving evidence for an actual or anticipated claimLegitimate interests — Art. 6(1)(f)
DSA moderationReviewing reports, applying restrictions, transparency reporting, statements of reasonsLegal obligation — Art. 6(1)(c) + Legitimate interests — Art. 6(1)(f)

You can object to processing based on legitimate interests at any time by emailing support@bivvy-app.com. We will stop unless we have compelling legitimate grounds that override your interests. We do not carry out automated decision-making within the meaning of Article 22 GDPR that produces legal or similarly significant effects on you.

5. Information that is public by design

The following is public by design and visible to anyone using the Service, including users who are not logged in:

Messages in public per-spot chat threads are visible to every signed-in user for the 24 hours they remain. They are not visible to logged-out users.

The following is never displayed publicly: your email address, your password hash, your saved spots, the underlying follower / following lists, your blocks, your content reports, your payment status, or your IP address.

6. Recipients of personal data

We do not sell, rent, or trade your personal data.

6.1 Processors acting on our instructions (Art. 28 GDPR)

ProviderWhat they processWherePrivacy policy
Hetzner Online GmbHApplication servers, PostgreSQL hostingGermany (EU)link
Cloudflare, Inc.DNS, TLS, edge caching, photo CDN, R2 storage (photos + encrypted DB backups)EU region with global CDN edgeslink
Google LLC (Firebase Cloud Messaging)Push-notification deliveryGlobal Google infrastructure — SCCs + EU-US DPFlink
Functional Software, Inc. (Sentry)Crash and error diagnostics — EU ingestion endpointEU regionlink
PostHog, Inc. — self-hostedAnonymous product analytics identified by usernameEU (on our Hetzner servers)link
RevenueCat, Inc.Subscription management, receipt validation, webhooks — Pro / IAP users onlyUnited States; SCCslink

6.2 Independent controllers

PartyWhat they receivePrivacy policy
CARTO / OpenStreetMapYour IP and map area being viewed, every time tiles are loadedCARTO · OSM
Stadia Maps, Inc. (Pro users only)Your IP and viewport when satellite / terrain overlays are loadedlink
Apple Inc. / Google LLC (App Stores)App distribution and IAP processingApple · Google
Apple Inc. (Sign in with Apple)Subject ID and, optionally, an email relaylink
Google LLC (Sign in with Google)Subject ID, email, display namelink

6.3 Authorities

We may disclose personal data when legally required — for example, in response to a valid court order, subpoena, or law-enforcement request from a competent authority. Where we can do so lawfully, we will notify you and will challenge requests we consider overbroad. We publish an annual transparency report under Article 24 of the Digital Services Act.

6.4 Business transfers

If we are involved in a merger, acquisition, or asset sale, your personal data may be transferred. We will notify you in the app and (if your email is deliverable) by email before your data becomes subject to a different privacy policy.

7. International data transfers

We aim to keep your personal data within the European Economic Area. Where a recipient may process data outside the EEA — principally Google (FCM), Apple (App Store, Sign in with Apple), and RevenueCat — the transfer is protected by the European Commission's Standard Contractual Clauses (2021/914) and, where applicable, the EU-US Data Privacy Framework. You may request a summary of the safeguards in place by emailing support@bivvy-app.com.

8. How long we keep your data

DataRetention
Account record (email, username, password hash)Until you delete your account; PII is wiped on deletion. Anonymised row retained so foreign keys to your content remain valid.
Spot submissionsKept indefinitely after account deletion, attributed to "deleted".
Reviews, chat messagesKept indefinitely attributed to "deleted". Chat additionally expires automatically 24 hours after posting.
Check-ins, saved spots, follows, blocks, content reports, device tokensDeleted on account deletion.
IP address in access logsMaximum 30 days.
Encrypted database backupsRolling 35 days; older backups removed automatically.
Tax records of payments7 years from the financial year of the transaction (Art. 52 AWR).
Webhook event log (RevenueCat)90 days, then purged.
Moderation records (statements of reasons, appeals)5 years from the date of the decision.
Records of legal requestsAs required by law.

If you delete your account, residual copies may remain in backups for up to 35 days until the relevant snapshot rotates out.

9. Your rights

RightWhat it meansHow to exercise it
Access (Art. 15)A copy of the personal data we hold about youEmail support@bivvy-app.com
Rectification (Art. 16)Correction of inaccurate personal dataEdit your profile in the app or email us
Erasure (Art. 17)Deletion of your personal dataSettings → Delete account, or email us. See §8.
Restriction (Art. 18)Pausing our processing while a dispute is resolvedEmail us
Portability (Art. 20)Machine-readable export of the data you providedEmail us
Objection (Art. 21)Object to processing based on legitimate interestsEmail us
Withdraw consent (Art. 7)Withdraw consent (e.g. notifications)Toggle in Settings or system settings
Complain to a regulator (Art. 77)Lodge a complaint with your local DPANL: Autoriteit Persoonsgegevens; other EU: EDPB members; UK: ICO

We respond within 30 days, extendable by up to two further months for complex requests. We do not charge a fee unless the request is manifestly unfounded or excessive. We may ask you to confirm a request from the email address associated with your account, or — for Apple Hide-My-Email accounts — from another channel that proves account ownership.

10. Children's privacy

Bivvy is intended for users aged:

We do not knowingly collect personal data from children below those ages. If you believe a child has provided us with personal data, contact support@bivvy-app.com and we will delete the account. Wild camping involves real-world physical risks; the Service is not designed for use by minors without adult supervision and we do not market it to children.

11. Security

No system is perfectly secure. If we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the Autoriteit Persoonsgegevens within 72 hours under Article 33 GDPR and notify affected users without undue delay under Article 34 GDPR.

12. App Store and Play Store data declarations

Data typeCollectedLinked to youTrackingPurpose
Email addressYesYesNoApp functionality
User ID (username)YesYesNoApp functionality
Coarse locationYesYesNoApp functionality
PhotosYesYesNoApp functionality
User-generated contentYesYesNoApp functionality
Crash dataYesNoNoApp functionality, analytics
Product interactionYesYesNoAnalytics (identified by username)

We do not track you across apps or websites owned by other companies. Apple's App Tracking Transparency prompt therefore does not appear in this app.

13. California residents (CCPA / CPRA)

If you are a California resident you have the following rights:

To exercise any of these rights, email support@bivvy-app.com. We respond within 45 days. We have not sold or shared personal information in the preceding 12 months and have no plans to do so.

14. Changes to this policy

We may update this Privacy Policy from time to time. When we make a material change we will (a) update the date at the top, (b) notify you in the app and, where significant and your email is deliverable, by email at least 30 days before the change takes effect, and (c) where required by law, ask for your renewed consent. Continued use of the Service after the effective date constitutes acceptance.

15. Contact us

Apex Crypto VOF, trading as Bivvy
Katwijkerbroek 75, 2223 XN Katwijk, the Netherlands
KvK no.: 96603577
VAT (BTW) no.: NL867679542B01
Email: support@bivvy-app.com

If you are not satisfied with our response you may lodge a complaint with the Autoriteit Persoonsgegevens or your local supervisory authority (see §9).