Firebase OTP verifies you're a real person. No passwords.
Used to show nearby happenings. You control this in device settings.
We have never sold, and will never sell, your personal information.
Stripe handles payment data. We never see your card details.
Request full deletion of your account and data at any time.
We verify each person holds only one Unite account.
This Privacy Policy describes how Unite ("we," "us," "our") collects, uses, and protects your information when you use the Unite mobile application and related services. Questions? Email connect[at]unite.earth.
| Data | Why we collect it |
|---|---|
| Phone number | Primary identity verification via Firebase OTP. Ties your real identity to one account and enforces the one-account rule. |
| Name & display name | Your public identity on the platform. |
| Profile photo | Helps other members recognise you at happenings. |
| Interests | Powers personalised happening discovery (up to 80 categories). |
| Happening activity | Records happenings you've attended, hosted, or joined. |
| Family memberships | Tracks which Families you belong to and your role within them. |
| Messages & chat content | Stored and delivered for happening group chats and Family channels. |
With your permission, we access your device's GPS location to show happenings nearby and display them on the live map. We do not track your location in the background. You can revoke location permission in device settings at any time.
We request camera and photo library access only when you upload a profile photo or family image.
If you offer bookable services and choose to connect a calendar, we access your calendar's busy/free times — on your device and, if you link a Google Calendar, via read-only calendar access — solely to work out which time slots you're available for and to add confirmed bookings. We do not read the content, titles, or guests of your events for any other purpose, and you can disconnect at any time. If you do not use availability features, we never access your calendar.
When you choose to invite someone from your address book, we check the phone numbers you select against Unite to see who is already a member. This check is transient — we do not upload, store, or sell your contacts. If you never open the contacts inviter, we never access your contacts.
For users in the EEA, UK, and Canada, we rely on the following legal bases:
We do not sell your personal data. We share data only in these specific circumstances:
| Service | Purpose |
|---|---|
| Firebase (Google) | Phone OTP authentication and push notifications. Governed by Google's Privacy Policy. |
| Supabase | Database, file storage, and real-time features. Your profile, happenings, Families, and messages are stored here. |
| Stripe | Payment processing under PCI DSS compliance. We never store your card details. |
| Expo / EAS | App build and distribution infrastructure. |
| Google Maps | Location services powering the live happenings map. |
| Google Calendar | Optional, read-only calendar sync to calculate your availability for bookings. Governed by Google's Privacy Policy. |
| Sentry | Crash reporting and performance diagnostics to help us find and fix bugs. |
All payments are processed by Stripe. Your card details are entered directly into Stripe's secure interface and are never transmitted to or stored on Unite's servers. We receive only a transaction confirmation and masked card identifier.
Subscriptions are tied to your single Unite account. If your account is terminated for violating the one-account rule, your subscription ends and no refund is issued for the unused period.
We retain your personal data for as long as your account is active. When you delete your account, your profile and happening history are deleted from active databases within 30 days. We may retain financial records for up to 7 years where required by law. Anonymised aggregated data may be retained indefinitely.
You can request deletion of your account and associated data here — verify with your phone number to delete instantly, or email us if you no longer have the app.
We implement row-level security (Supabase RLS), encrypted transmission (HTTPS/TLS), token-based authentication (Firebase JWT), and Stripe PCI-DSS compliance. No system is completely secure, but we take our responsibility seriously and respond promptly to any incidents.
Depending on your location, you may have the right to access, correct, delete, or port your personal data; to restrict or object to processing; and to withdraw consent at any time. To delete your account and data, use our account deletion page. For any other request, contact us at connect[at]unite.earth and we will respond within 30 days.
You have the right to lodge a complaint with your local data protection authority if you believe we are processing your data unlawfully.
You have the right to know what personal information we collect, request deletion, and not be discriminated against for exercising your rights. We do not sell personal information.
Unite is not intended for users under 18. We do not knowingly collect data from minors. If we become aware that we have, we will delete it promptly. Contact us immediately if you believe a minor has created an account.
We may update this Privacy Policy from time to time. We will update the "Last updated" date above and notify you of material changes via push notification or in-app message. Continued use after changes take effect constitutes acceptance.
Whether you want to delete your data or just have a question — a real person will respond.
connect@unite.earth