Privacy Policy
Last updated: 31 August 2026
Introduction
OpStap is committed to protecting personal data. This privacy policy explains what personal data we collect, the purposes for which it is used, the legal bases on which we process it, and how we ensure secure and careful handling.
Data controller: Pascal Services, Hoornsediep 34, 9725 HK Groningen, the Netherlands — opstap@pascal.services.
1. Personal data we process
Account data: first name, username, email address, phone number, date of birth, gender, spoken languages, profile photo, and optional bio.
Profile data: interests, favourite venues, preferences (including group size and travel radius), uploaded photos.
Identity verification: verification via our partner Didit. This may process first name, last name, date of birth, age, gender, and nationality to confirm your identity. We do not store the underlying identity documents or selfies ourselves.
App usage: technical data (IP address, device data, push token), time and frequency of check-ins, match and group data, trust score, and location data when you use the map, check in, or set a meeting point. We do not keep an ongoing location history beyond what is needed to provide the service.
Moderation and reports: warning content, ban status, ban appeals, reports about users, reports about incorrect venue or event information, bug reports and feedback (including optional screenshots).
Analytics events: pseudonymised usage events (possibly linked to your account or a session ID) to improve the app and detect abuse. We do not use this data for advertising.
2. Purposes of processing
- Providing the OpStap application, matching (on the configured match day(s), default Thursday) and group chat
- Login and account security via SMS verification
- Identity verification for the safety of users
- Calculating and maintaining the trust score
- Communication via push notifications about matches, updates and moderation
- Moderation: warnings, bans, appeals and handling reports
- Improving the service and detecting abuse (security & monitoring)
- Compliance with legal obligations
3. Legal bases
- Performance of a contract: data necessary for providing the app, login, matching and chat
- Legitimate interest: security, fraud and abuse prevention, trust score, moderation and product improvement
- Consent: identity verification via Didit and use of push notifications (where required)
- Legal obligation: disclosure of data to competent authorities
4. Automated decision-making
OpStap uses automated systems for:
- Matching: composing groups based on interests, preferences and availability
- Trust score: tracking attendance and cancellations, which may affect future matches
These decisions affect your participation in match evenings but do not produce legal consequences. You may ask questions, explain your position or object via opstap@pascal.services.
5. Sub-processors
| Processor | Country | Purpose |
|---|---|---|
| Didit | Netherlands / EEA | Identity verification |
| Twilio | US | SMS for login (OTP) |
| Stream | US | Group chat and messaging |
| Mapbox | US | Map and location services |
| Supabase | US / EEA* | Database, authentication and storage |
| Resend | US | Transactional emails |
| Expo | US | Push notifications to devices |
* Where data is transferred outside the EEA, we use appropriate safeguards (including standard contractual clauses) where applicable.
6. Retention periods
| Data type | Retention period |
|---|---|
| Account data (active or deactivated) | For as long as the account is active or deactivated |
| Account data (permanently deleted) | Erased immediately; technical backups and logs up to 6 months |
| Match data and chat messages | Up to 90 days after the match |
| Trust score | For as long as the account is active |
| Verification result (Didit) | For as long as the account is active |
| Moderation (warnings, bans, appeals) | As long as needed for safety and handling, then up to 12 months |
| Reports (users, content, bugs, feedback) | Up to 12 months after resolution |
| Analytics / technical logs | Up to 12 months |
7. Your rights
As a data subject, you have the following rights under the GDPR:
- Right of access to your personal data
- Right to rectification of inaccurate data
- Right to erasure (via permanent account deletion in the app)
- Right to restriction of processing
- Right to data portability
- Right to object to processing based on legitimate interest
- Right to withdraw consent (where processing is based on consent), without affecting lawfulness before withdrawal
You can pause your account via deactivation (data is retained) or permanently erase everything via account deletion. See opstap.app/en/account-deletion.
Requests can be sent to opstap@pascal.services. We will respond within one month.
8. Complaints
Complaints may be submitted to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), P.O. Box 93374, 2509 AJ The Hague — autoriteitpersoonsgegevens.nl
9. Contact
Pascal Services
Hoornsediep 34, 9725 HK Groningen, the Netherlands
Tel: 085 301 6480
Email: opstap@pascal.services
Website: opstap.app
CoC: 92166474 · VAT: NL004941205B42
Questions? Send an email to opstap@pascal.services