Privacy Policy

Last updated: 31 August 2026

Introduction

OpStap is committed to protecting personal data. This privacy policy explains what personal data we collect, the purposes for which it is used, the legal bases on which we process it, and how we ensure secure and careful handling.

Data controller: Pascal Services, Hoornsediep 34, 9725 HK Groningen, the Netherlands — opstap@pascal.services.

1. Personal data we process

Account data: first name, username, email address, phone number, date of birth, gender, spoken languages, profile photo, and optional bio.

Profile data: interests, favourite venues, preferences (including group size and travel radius), uploaded photos.

Identity verification: verification via our partner Didit. This may process first name, last name, date of birth, age, gender, and nationality to confirm your identity. We do not store the underlying identity documents or selfies ourselves.

App usage: technical data (IP address, device data, push token), time and frequency of check-ins, match and group data, trust score, and location data when you use the map, check in, or set a meeting point. We do not keep an ongoing location history beyond what is needed to provide the service.

Moderation and reports: warning content, ban status, ban appeals, reports about users, reports about incorrect venue or event information, bug reports and feedback (including optional screenshots).

Analytics events: pseudonymised usage events (possibly linked to your account or a session ID) to improve the app and detect abuse. We do not use this data for advertising.

2. Purposes of processing

  • Providing the OpStap application, matching (on the configured match day(s), default Thursday) and group chat
  • Login and account security via SMS verification
  • Identity verification for the safety of users
  • Calculating and maintaining the trust score
  • Communication via push notifications about matches, updates and moderation
  • Moderation: warnings, bans, appeals and handling reports
  • Improving the service and detecting abuse (security & monitoring)
  • Compliance with legal obligations

3. Legal bases

  • Performance of a contract: data necessary for providing the app, login, matching and chat
  • Legitimate interest: security, fraud and abuse prevention, trust score, moderation and product improvement
  • Consent: identity verification via Didit and use of push notifications (where required)
  • Legal obligation: disclosure of data to competent authorities

4. Automated decision-making

OpStap uses automated systems for:

  • Matching: composing groups based on interests, preferences and availability
  • Trust score: tracking attendance and cancellations, which may affect future matches

These decisions affect your participation in match evenings but do not produce legal consequences. You may ask questions, explain your position or object via opstap@pascal.services.

5. Sub-processors

ProcessorCountryPurpose
DiditNetherlands / EEAIdentity verification
TwilioUSSMS for login (OTP)
StreamUSGroup chat and messaging
MapboxUSMap and location services
SupabaseUS / EEA*Database, authentication and storage
ResendUSTransactional emails
ExpoUSPush notifications to devices

* Where data is transferred outside the EEA, we use appropriate safeguards (including standard contractual clauses) where applicable.

6. Retention periods

Data typeRetention period
Account data (active or deactivated)For as long as the account is active or deactivated
Account data (permanently deleted)Erased immediately; technical backups and logs up to 6 months
Match data and chat messagesUp to 90 days after the match
Trust scoreFor as long as the account is active
Verification result (Didit)For as long as the account is active
Moderation (warnings, bans, appeals)As long as needed for safety and handling, then up to 12 months
Reports (users, content, bugs, feedback)Up to 12 months after resolution
Analytics / technical logsUp to 12 months

7. Your rights

As a data subject, you have the following rights under the GDPR:

  • Right of access to your personal data
  • Right to rectification of inaccurate data
  • Right to erasure (via permanent account deletion in the app)
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing based on legitimate interest
  • Right to withdraw consent (where processing is based on consent), without affecting lawfulness before withdrawal

You can pause your account via deactivation (data is retained) or permanently erase everything via account deletion. See opstap.app/en/account-deletion.

Requests can be sent to opstap@pascal.services. We will respond within one month.

8. Complaints

Complaints may be submitted to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), P.O. Box 93374, 2509 AJ The Hague — autoriteitpersoonsgegevens.nl

9. Contact

Pascal Services

Hoornsediep 34, 9725 HK Groningen, the Netherlands

Tel: 085 301 6480

Email: opstap@pascal.services

Website: opstap.app

CoC: 92166474 · VAT: NL004941205B42

Questions? Send an email to opstap@pascal.services