Locily
SupportBack home
PrivacyTermsPaymentsCookiesGuidelinesDelete account
Privacy

Locily Privacy Policy

Effective: 3 August 2026 · Version 2026-08-03

This Policy explains how Locily ApS processes personal data in the Locily app, locily.dk and related support, event, community, business and payment services.

1. Controller and contact

Locily ApS, CVR 46567722, Rødovre Port 11, 1. 5., 2610 Rødovre, Denmark is the data controller unless another controller is identified at collection. Contact info@locily.dk. We have not appointed a data protection officer; privacy requests are handled through this address.

2. Data we collect

  • Identity and account: email, authentication user ID, login provider, session/security data, account role, display name, unique tag, profile photo, biography, verification state and blocked-account state.
  • Company and host: company name, CVR if supplied, industry, website, contacts, logo, application material, company role, subscription, Stripe onboarding/payout state and host settings.
  • Content and social activity: events, media, venue/location, comments and replies, votes, saves, follows, groups, membership, invites, messages, reports, moderation decisions, event-ended reports and notification state.
  • Location: location permission state, device coordinates used for map and distance, and, when you use attendance or location-verified interaction features, check-in coordinates, horizontal accuracy, verification method and timestamp. Event location and venue address are public when an event is public.
  • Payments and tickets: ticket type, quantity, price, fees, currency, Stripe customer/checkout/payment/refund/dispute and organizer settlement references, Apple product and transaction identifiers, entitlement state, purchase/expiry/revocation data, ticket ownership, QR-token hashes and scan records. Locily does not receive full card numbers.
  • Device and operations: push token, app/build and iOS version, device-safe identifiers, IP address and request metadata available to our infrastructure, security/audit logs, errors, connectivity and support correspondence.
  • Website: forms, company applications, email verification, language preference stored locally and technical hosting/anti-spam information.

3. Sources

We receive data from you, your device, other users interacting with you, company representatives, Apple, Google or Facebook login, Stripe, Supabase, Netlify and other service providers. Locily Discovery may collect factual event details, organizer names, public contact details, public images and source links from organizer, venue, municipal, cultural and other publicly accessible event pages. If that information relates to you and did not come from you, this Policy provides the information required for that indirect collection.

4. Purposes and legal bases

  • Contract: create and authenticate accounts; deliver profiles, feed, map, groups, event publishing, interactions, tickets, subscriptions, promotion, notifications you request, support and account deletion.
  • Legitimate interests: secure the service, prevent fraud and spam, enforce access rules, moderate content, maintain audit records, diagnose failures, improve reliability, rank relevant public events, protect users and document transactions. We balance these interests against user rights and offer objections where required.
  • Consent: iOS location, photos, camera, notifications and optional communications where consent is the appropriate basis. You can withdraw device permissions in iOS and notification choices in Locily.
  • Legal obligations: bookkeeping, tax, payment, consumer, safety, sanctions, lawful requests, disputes and data-protection compliance.
  • Public event curation: our legitimate interest in making accurate public event information discoverable, subject to source checks, data minimization and correction, objection and removal rights.

5. Location and attendance

Map and distance features use your current location when authorized. A separate discovery center or dropped pin changes what area is browsed, but does not replace your location for displayed distance where the app has a current location. For attendance integrity, Locily may store exact check-in evidence and accuracy when you invoke a location-gated action, including to prevent fraudulent votes or attendance claims. Location is not continuously collected in the background by Locily unless a future feature expressly asks for separate permission. You can deny location, but nearby, distance, attendance or voting features may be limited.

6. Public and restricted information

Public profiles, company pages, events, event media, unique tags, public comments, counts and open groups can be viewed by others and may be indexed on locily.dk. Closed-group content is restricted to authorized members and moderators. Messages, email, payment data, check-in coordinates, blocked lists and security records are not intended to be public. Blocking restricts visibility and contact but does not prevent necessary safety, payment or moderation processing.

7. Recommendations, ranking and promotion

Locily may rank events using time, distance, selected discovery area, interests, follows, interactions, availability, popularity and safety signals. Paid promotion may affect placement and is labelled. Interest-based event notifications use first-party activity and your settings. We do not use these systems to make decisions that produce legal or similarly significant effects, and we do not sell personal data or use private messages for third-party advertising.

8. Recipients and processors

Data is shared only as needed with: Supabase (authentication, database, storage and functions); Apple (iOS, Sign in with Apple, APNs and App Store purchases); Google and Facebook when chosen for login; Stripe (ticket payments, identity/payout onboarding, refunds and disputes); Netlify (website hosting, forms and functions); Resend or another configured transactional email provider; Apple MapKit/geocoding; professional advisers; competent authorities; and a successor in a lawful corporate transaction. Hosts receive the buyer and ticket information necessary to admit attendees and handle the event, but not full card data.

9. International transfers

Some providers may process data outside Denmark or the EEA. Where GDPR requires it, we rely on an adequacy decision, Standard Contractual Clauses and supplementary measures, or another valid transfer mechanism. You may request information about the applicable safeguard at info@locily.dk.

10. Retention

  • Account, profile and active content: while the account/service is active, then deleted or anonymized subject to the exceptions below.
  • Financial, tax, ticket, payout and invoice records: for the statutory bookkeeping/tax period, generally five years after the relevant financial year in Denmark, and longer if a dispute or legal hold requires it.
  • Security, moderation, reports, bans and fraud evidence: only as long as reasonably necessary for safety, enforcement and legal claims, generally up to three years after closure or last relevant incident unless a longer period is justified.
  • Support and company applications: generally up to 24 months after resolution, unless converted into an active account, required for a dispute or deleted earlier.
  • Precise check-in evidence: while needed to support the associated attendance, vote, fraud-control or dispute record; it is then deleted or minimized under the applicable retention schedule.
  • Push tokens and sessions: until replaced, invalidated, logout/deletion or no longer needed. Backups are access-restricted and removed through normal rotation.

These periods are maxima or criteria, not a promise to keep data for the full period. We may delete data sooner where it is no longer needed.

11. Your rights

Subject to GDPR conditions, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time without affecting earlier processing. We normally respond within one month and may extend by up to two additional months for a complex request, with notice. We may verify identity and may refuse or charge for manifestly unfounded or excessive requests where law allows. Send requests to info@locily.dk.

You may complain to Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark, or another competent supervisory authority.

12. Account deletion

Initiate deletion under Profile settings or follow Account deletion. Deletion removes the authentication identity and ordinary public access after server confirmation. Open financial obligations, disputes, bans, safety evidence and statutory records may be retained in restricted form. Deleting Locily does not automatically cancel an Apple subscription.

13. Security and incidents

We use authentication, role and row-level access controls, server-side authorization, encryption in transit, provider encryption at rest, signed payment webhooks, hashed QR credentials, logging, least-privilege access and deletion controls. No system is risk-free. We assess personal-data breaches and notify Datatilsynet and affected users where GDPR requires. Report suspected vulnerabilities to info@locily.dk without including passwords or unnecessary personal data.

14. Children

Locily accounts are intended for people aged 16 or older. We do not knowingly offer accounts to younger children. If you believe a younger child has supplied personal data, contact us. Age-restricted events may impose a higher minimum age, and payment or hosting may require adult legal capacity.

15. Changes

We update this Policy when processing changes. Material changes will be communicated in the app, by email or another appropriate channel where required. The effective date and version identify the applicable text.

© 2026 Locily ApS · CVR 46567722Terms · Payments · Contact