Privacy Policy

Last Updated: October 21, 2025

Effective Date: October 21, 2025

IMPORTANT NOTICE: This Privacy Policy describes how we collect, use, disclose, and protect information in connection with the Ping&Wink mobile application. By accessing or using the Service, you consent to the data practices described in this policy. If you do not agree with this Privacy Policy, you must immediately discontinue use of the Service.

1. Introduction and Scope

This Privacy Policy ("Policy") governs the collection, use, storage, and disclosure of information by the operator of Ping&Wink ("we," "us," "our," "Service," "Application") in connection with your use of the mobile application and related services.

This Policy should be read in conjunction with our Terms of Service, available at https://pingandwink.com/terms.html, which is incorporated herein by reference.

1.1 Apple App Store Compliance Statement

2. Age Requirement and Eligibility

ADULT-ONLY SERVICE (18+ STRICT REQUIREMENT): This Service is exclusively for individuals who are at least 18 years of age or the age of majority in their jurisdiction, whichever is higher. Users under 18 are strictly prohibited under any circumstances. By accessing this Service, you represent, warrant, and covenant that you meet this age requirement.

Age Verification: During initial setup, the Service requires users to provide their birth year. While we implement this verification mechanism as a technical measure, we make no representations or warranties regarding:

Underage Use Discovery: If we discover or have reason to believe that a user is under 18 years of age, we reserve the right to immediately terminate access and delete associated data. However, we assume no liability for underage users who circumvent age verification or provide false information.

3. Information We Collect

3.1 Information You Provide Directly

The Service is designed to minimize personal information collection. Information you provide includes:

Data Type Purpose Retention Period
Birth Year Age verification and compliance Until account deletion
Emotional State Selection Display on map, enable connections 24 hours (automatic deletion)
Chat Messages Enable communication during Spark sessions 9 minutes maximum (automatic deletion)

3.2 Information Collected Automatically

The Service automatically collects certain technical information necessary for functionality:

Data Type Purpose Retention Period
Device Identifier (UUID) Anonymous user identification, session management Until account deletion
Location Data Map display, proximity-based matching 24 hours (overwritten with new data or deleted)
Usage Analytics Service improvement, feature development Anonymized aggregated data: indefinite
Push Notification Token Delivery of connection notifications Until notification opt-out or account deletion

3.3 Information We Do NOT Collect

The following information is not collected or stored by the Service:

4. How We Use Your Information

We process collected information for the following purposes, based on necessity for service provision and legitimate business interests:

4.1 Core Service Functionality

4.2 Safety and Compliance

4.3 Service Improvement and Analytics

4.4 Communications

Processing Limitation Disclaimer: While we describe intended uses above, we make no warranty that information will be used exclusively for these purposes or that unauthorized access, use, or disclosure will not occur. Data security is inherently subject to limitations described in Section 9.

5. Data Retention and Automatic Deletion

The Service is designed with privacy-by-default through automatic data expiration:

5.1 Automatic Expiration Schedule

Data Category Retention Period Deletion Method
Emotional state posts ("vibes") 24 hours Automatic permanent deletion
Chat messages 9 minutes maximum Automatic permanent deletion
Connection requests ("pings") 60 seconds Automatic expiration if not accepted
Active location data 24 hours Overwritten by new data or deleted

5.2 User-Initiated Deletion

Users may request complete account deletion through:

Upon deletion request, the following data is permanently removed:

Deletion Exceptions: The following data may be retained after account deletion:

Deletion Disclaimer: While we make commercially reasonable efforts to delete data as described, we cannot guarantee complete or immediate deletion from all systems, backups, or third-party services. Deleted data may persist in backups for up to 90 days or longer if required by law.

5.3 Data Retention Justification (GDPR Article 5 Compliance)

The Service implements the following retention periods based on legitimate operational requirements and user experience necessities:

6. Data Sharing and Disclosure

6.1 Information Visible to Other Users

By design, the following information is visible to other Service users:

Visibility Limitation: We implement technical measures to limit information visibility, but we make no warranty that determined users cannot infer additional information through patterns, timing, or other means.

6.2 Third-Party Service Providers

We engage third-party service providers to support Service operations. These providers have limited access to user information as necessary for their functions:

Service Provider Purpose Data Access
Supabase Database and backend infrastructure Device IDs, location data, messages, birth year
Mapbox Map display and geolocation services Location coordinates (anonymized usage)
OneSignal Push notification delivery Device tokens, notification preferences
Amplitude Analytics and service improvement Anonymized usage statistics

These third-party providers maintain their own privacy policies. We encourage you to review their policies, though we make no representations regarding their data practices or compliance.

6.3 Legal Compliance and Safety

We may disclose user information without notice or consent when we believe in good faith that disclosure is:

Law Enforcement Cooperation: We cooperate with law enforcement authorities when presented with valid legal process. We may disclose user information, including location data, chat logs (if not yet expired), and device identifiers in response to lawful requests. We provide no advance notice to users when legally prohibited from doing so.

6.4 Business Transfers

In the event of a merger, acquisition, bankruptcy, dissolution, reorganization, or similar transaction or proceeding involving the Service, user information may be transferred or sold as part of business assets. You acknowledge and consent to such transfers.

6.5 What We Do NOT Do

We do not engage in the following practices:

7. Location Information

7.1 Location Data Collection

Location data is essential for core Service functionality. The Service collects location information:

7.2 Location Privacy Controls

Users may control location access through:

Location Privacy Disclaimer: While we implement technical measures to protect location privacy, no system is perfect. Determined users or sophisticated attackers may be able to infer location information through patterns, timing analysis, or other means. Location randomization is a privacy enhancement, not a security guarantee. You assume all risks associated with location disclosure.

8. International Data Transfers

The Service is operated from France. User information may be transferred to, stored in, and processed in France, other European Union member states, or other countries where our service providers maintain facilities.

Cross-Border Transfer Implications:

For European Economic Area users, we ensure that third-party service providers located outside the EEA maintain adequate data protection safeguards through standard contractual clauses or other approved mechanisms.

9. Data Security

SECURITY DISCLAIMER: While we implement commercially reasonable security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your information.

9.1 Security Measures Implemented

We employ the following technical and organizational security measures:

9.2 Security Limitations

You acknowledge and accept the following security limitations:

9.3 User Security Responsibilities

You are responsible for:

9.4 Data Breach Notification

In the event of a data breach affecting personal information, we will:

However, we make no guarantee regarding the timing or content of breach notifications, which are subject to legal requirements and operational constraints.

10. Your Privacy Rights

10.1 Rights for All Users

Regardless of location, you have the following rights:

10.2 European Economic Area User Rights (GDPR)

If you are located in the European Economic Area, you have additional rights under the General Data Protection Regulation:

10.3 California Privacy Rights (CCPA/CPRA)

California residents have the following rights under the California Consumer Privacy Act:

10.4 Exercising Your Rights

To exercise any privacy rights, contact us at:

We will respond to verified requests within:

Rights Exercise Disclaimer: While we will make commercially reasonable efforts to honor privacy rights requests, we make no warranty regarding response times or outcomes. Requests may be denied if legally permissible, technically infeasible, or if they would compromise others' privacy or security.

11. Push Notifications

If you enable push notifications:

12. Changes to This Privacy Policy

We reserve the right to modify this Privacy Policy at any time, at our sole discretion. Changes become effective upon:

Your Responsibility: It is your responsibility to review this Policy periodically. Continued use of the Service following changes constitutes acceptance of the modified Policy.

For material changes that significantly affect your rights, we will make reasonable efforts to provide advance notice through in-app notifications or other available means.

13. Legal Basis for Processing (GDPR)

For users in the European Economic Area, we process personal data based on the following legal grounds:

Processing Activity Legal Basis
Core service functionality (map, chat, connections) Performance of contract / Consent
Age verification and eligibility enforcement Legal obligation / Legitimate interests
Safety features and content moderation Legitimate interests (user safety)
Service improvement and analytics Legitimate interests (service optimization)
Legal compliance and law enforcement requests Legal obligation
Push notifications Consent (can be withdrawn anytime)

14. Contact Information and Data Controller

Response Times: We aim to respond to privacy inquiries within 48-72 business hours. However, response times are not guaranteed and may be longer during periods of high volume, technical issues, or operational constraints. For urgent matters, clearly mark your communication as "URGENT" in the subject line.

EU Representative: As we are established in the EU (France), no separate EU representative is required under GDPR Article 27.

14.1 EU Representation and Data Protection Officer

15. Dispute Resolution

Privacy-related disputes are subject to the dispute resolution provisions in our Terms of Service, including binding arbitration and class action waiver clauses. You agree that privacy disputes shall be resolved through individual arbitration rather than court proceedings or class actions.

EEA Users: This arbitration clause does not affect your right to lodge a complaint with a data protection authority in your jurisdiction.

16. Final Disclaimers and Acknowledgments

BY USING THIS SERVICE, YOU ACKNOWLEDGE AND AGREE THAT:

Honesty Disclaimer: This Service is operated by a single individual, not a large corporation with dedicated privacy teams. While we make reasonable efforts to protect privacy and comply with applicable laws, our resources are limited. We provide this Service "as is" with respect to privacy and security. Users who require enterprise-grade data protection should not use this Service.