Privacy Policy
Last updated: June 2026
Information We Collect
- Email address
- Display name
- Date of birth for adult eligibility
- City
- Phone number (optional)
- Activity preferences
- Event participation history
- Feedback you provide
- First-party product analytics, such as signup, onboarding, notification, suggestion, RSVP, and feedback milestones
- Campaign attribution fields from signup links, such as UTM source, medium, campaign, content, term, referral code, landing path, and referrer host
How We Use Your Information
- To run matching and create events
- To confirm that accounts meet SymTribe's 18-and-over eligibility rule
- To send event notifications, reminders, and account emails
- To review feedback, moderation, and safety reports
- To investigate documented safety, support, policy, legal, or incident issues involving private groups
- To derive aggregate age segments for product and safety analysis without exposing exact dates of birth
- To operate, debug, and improve the service
- To measure launch health, activation, retention, notification delivery, and event participation using aggregate reports
Product Analytics
SymTribe uses first-party, server-side analytics stored in our own database. We do not use third-party analytics SDKs, advertising pixels, advertising cookies, or click identifiers such as gclid, fbclid, or ttclid.
Analytics events are limited to structured product milestones and safe dimensions, such as activity type, market, event, group, meeting point, notification type, RSVP status, onboarding step, and high-level campaign fields. We do not store exact date of birth, exact age, passwords, email content, free-text profile content, IP address, full user agent, full referrer URL, raw address, or authentication tokens in analytics payloads.
Admin analytics reports are aggregate. They are intended to show cohort counts, funnel movement, suggestion conversion, retention, and notification health rather than raw user-level exports.
Private Group Content
Private group posts, comments, and photos are intended for group members. Authorized platform administrators may inspect private group activity only for a documented safety, support, policy, legal, or incident purpose, and that access is time-limited and logged.
Audit records for this access store metadata such as purpose, reference, actor, timestamps, and expiry. They do not store post bodies, comment bodies, photo URLs, storage keys, or join tokens.
Data Sharing
We do not sell your personal data. We share data with the following service providers to operate the platform:
Your date of birth is private account data. It is not shown on your profile, public event recaps, group pages, or admin user detail pages, and it is not sent to advertising providers.
Authentication
- Google OAuth (optional): If you sign up with Google, we receive your email address and basic profile from Google to create your account.
- Resend: We send transactional emails (verification, event invitations, reminders) through Resend. Your email address and email content are processed by Resend.
Location services
- Google Maps JavaScript: Used as a visual map layer when maps are enabled.
- Google Geocoding & Google Places API: Disabled by default for normal user location selection. If legacy discovery is explicitly enabled, city or place queries may be sent to Google.
- Nominatim (OpenStreetMap): Disabled by default for normal user location selection. If legacy geocoding is explicitly enabled, city or address queries may be sent to the public Nominatim service.
- Geoapify: Disabled by default for normal user location selection. If legacy geocoding or city-boundary lookup is explicitly enabled, city or address queries may be sent to Geoapify.
Weather
- Open-Meteo: Event location coordinates and dates are sent to Open-Meteo to retrieve weather forecasts for event advisories.
Error monitoring
- Sentry (optional): If enabled, application errors and performance data are sent to Sentry for debugging. Personal data collection is disabled in our configuration.
Fonts in emails
- Google Fonts: Our emails load fonts from Google's CDN. When you open an email, your email client may send your IP address to Google.
Data Retention
Account data, including date of birth and the timestamp of the eligibility check, is retained while your account is active. Raw product analytics use the configured retention target for this deployment; scheduled cleanup or aggregate archival applies only when that maintenance job is enabled. If you delete your account from Settings, SymTribe removes your profile data, date of birth, preferences, memberships, uploaded media, and related participation history. Some safety or audit records may be retained with user references removed.
Cookies & Local Storage
- Essential cookies for authentication (session token, CSRF protection)
- Functional cookie for your language preference (
symtribe_locale, stored for up to one year) - Local storage for cookie consent preference
- No tracking or advertising cookies
Your Rights
- Access and update the profile data shown in Settings
- Correct your information, including date of birth, through Account settings where available
- Delete your account. Some safety or audit records may remain with user references removed.
- Opt out of invitation, reminder, and feedback request emails through email preferences or unsubscribe links
- Data export is not yet available. Contact privacy@symtribe.com if you need a copy of your data
Security
- Data is sent over HTTPS in deployed environments
- Passwords are hashed before storage
- The app uses CSRF protection, rate limiting, and security headers
Israeli Privacy Law
SymTribe operates under Israeli privacy regulations (Protection of Privacy Law, 5741-1981). You have rights to access, correct, and delete your personal information.
Changes to This Policy
We may update this policy from time to time. Significant changes will be communicated via email.
Contact
For privacy inquiries, contact us at privacy@symtribe.com.