Privacy Policy for HustleWithMe

Effective Date: December 27, 2025

1. Introduction

Welcome to HustleWithMe ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application (the "App").

We process your data in compliance with the General Data Protection Regulation (GDPR) and strictly adhere to the principles of lawfulness, fairness, and transparency.

Responsible Controller:

NeskCC - HustleWithMe
c/o flexdienst – #12306
Kurt-Schumacher-Straße 76
67663 Kaiserslautern
Deutschland
Email: [email protected]

2. Personal Data We Collect

We collect only the data necessary to provide our services and improve your experience.

2.1. Data You Provide to Us

  • Account Information: When you sign up, we collect your email address and username to create and manage your account.
  • Profile Data: You may optionally provide a profile picture (Avatar).
  • User-Generated Content: Photos you upload ("Hustles"), emojis, captions, and reactions.
  • Communications: If you contact us via email, we collect the content of your message.

2.2. Data Collected Automatically

  • Device Information: We may collect device model, operating system (iOS/Android), and unique device identifiers to ensure app compatibility and security.
  • Usage Data: Logs of your interactions within the App (e.g., creating circles, viewing events) to ensure service stability.

3. How We Use Your Data

We process your data for the following purposes:

  • Service Provision (Art. 6(1)(b) GDPR): To allow you to create accounts, join circles, and share photos.
  • Notifications (Art. 6(1)(a) GDPR): To send you push notifications about activity in your circle (e.g., new photos). You can revoke this consent at any time in settings.
  • Security & Improvement (Art. 6(1)(f) GDPR): To prevent fraud, fix bugs, and improve app performance.

4. Third-Party Data Processors

We use trusted third-party service providers to help us operate the App. These providers process data on our behalf and are bound by Data Processing Agreements (DPA).

4.1. Supabase (Backend & Storage)

We use Supabase (Supabase, Inc.) for authentication, database hosting, and secure file storage.

  • Data Processed: Email, Username, User-Generated Images, Auth Tokens.
  • Location: Data is stored on secure servers (AWS). Supabase ensures GDPR compliance via Standard Contractual Clauses (SCCs).

4.2. Firebase (Notifications & Crashlytics)

We use Google Firebase (Google Ireland Ltd.) for Push Notifications (FCM) and Crash Reporting.

  • Data Processed: Device Tokens (FCM Tokens), crash logs (anonymized where possible).
  • Location: Data transfer to the US is protected under the EU-US Data Privacy Framework or SCCs.

5. Data Access & Permissions

To function correctly, the App requires access to certain device features. You will be prompted to grant these permissions:

  • Camera: To capture photos directly within the app.
  • Photo Library: To select and upload existing photos.
  • Notifications: To receive alerts about friend activity.

You can manage or revoke these permissions at any time in your device settings.

6. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right to Access (Art. 15): Request a copy of your stored data.
  • Right to Rectification (Art. 16): Correct inaccurate or incomplete data.
  • Right to Erasure ("Right to be Forgotten") (Art. 17): Request deletion of your account and data. You can delete your account directly within the App settings.
  • Right to Restriction of Processing (Art. 18): Request that we restrict how we use your data.
  • Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format.
  • Right to Object (Art. 21): Object to processing based on legitimate interests.

To exercise these rights, please contact us at: [email protected]

7. Data Retention

We retain your personal data only as long as necessary to provide our services.

  • Account Data: Retained until you delete your account.
  • Images: Retained until you delete them or your account is deleted.
  • Backup/Logs: Retained for technical security for a limited period (e.g., 30 days).

8. Updates to This Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes through the App.

Last Updated: 27.12.2025