Da Birthday Club Limited ("Company," "we," "our," or "us") operates the Smash App ("App"). This Privacy Policy explains our practices regarding the collection, use, and disclosure of your personal information when you use our App.

1. Information We Collect

Account Information

When you create an account, we collect:

Location Data

The App collects your precise location data (latitude, longitude) to:

You can disable location sharing in your device settings, but this will limit App functionality.

Photos & Profile Media

We collect and store photos you upload to your profile. All photos are:

Communication Data

We collect and temporarily store:

Messages are deleted automatically 24 hours after a match expires.

Contact Imports

If you choose to invite friends via the App's invite feature, we access your device contacts solely to:

We do not store your full contact list on our servers. Contacts are processed locally and deleted immediately after use.

Payment Information

Payment processing is handled by Stripe, Inc. We do not directly store credit card data. Stripe collects and secures:

Stripe's Privacy Policy is available at https://stripe.com/privacy.

Identity Verification (Optional)

Users who opt into the "Verified Profile" badge provide identity documents to Sumsub, Inc. for KYC (Know Your Customer) verification. Sumsub collects:

Sumsub's Privacy Policy is available at https://sumsub.com/privacy-policy/. Verification is optional; you can use the App without it.

Device & Usage Data

We automatically collect:

Apple Speech Recognition (On-Device)

If you use voice-to-text features, Apple's on-device Speech Recognition is used. Speech data:

2. How We Use Your Information

3. Data Retention & Deletion

Messages: Automatically deleted 24 hours after match expiration.

Account Data: Retained while your account is active. Upon account deletion, we retain some data for:

Photos: Deleted when you remove them from your profile or upon account deletion (unless required for legal proceedings).

Location Data: Not permanently stored; used in real-time for matching and ride coordination.

4. Data Security

We use industry-standard encryption (TLS 1.3) for all data in transit. Data at rest is encrypted using AES-256 on Supabase's secure infrastructure. However, no system is 100% secure. If you believe your data has been compromised, contact us immediately at team@smashapp.co.nz.

5. Third-Party Services

We share data with:

We do not sell your personal data to third parties for marketing or advertising purposes.

6. GDPR & CCPA Rights

For EU Residents (GDPR)

You have the right to:

To exercise these rights, email team@smashapp.co.nz with "GDPR Request" in the subject line.

For California Residents (CCPA)

You have the right to:

To submit a CCPA request, email team@smashapp.co.nz with "CCPA Request" in the subject line.

7. Children's Privacy

The App is not intended for anyone under 18 years old. We do not knowingly collect data from minors. If we discover we've collected data from someone under 18, we will delete it immediately and may terminate the account.

8. International Data Transfers

Your data may be transferred to and stored in countries outside your country of residence. By using the App, you consent to such transfers. If you are located in the EU, we use appropriate safeguards (Standard Contractual Clauses) for such transfers.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via in-App notification or email. Your continued use of the App after changes constitutes acceptance of the updated policy.

10. Contact Us

If you have questions about this Privacy Policy or our practices, contact us at:

Da Birthday Club Limited
Email: team@smashapp.co.nz
Website: smashapp.co.nz

This Privacy Policy is effective as of April 1, 2026, and supersedes all previous versions.