Privacy Policy

Effective Date: November 27, 2025
Last Updated: November 27, 2025

1. Introduction

Hangouty ("we," "our," "us," or "Hangouty") operates an AI-powered social event planning and discovery platform. We respect your privacy and are committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information.

Scope: This Privacy Policy applies to all information collected through Hangouty's web application, iOS mobile application, and Android mobile application (collectively, the "Service"), including your use of our social event planning features, personalized recommendations, location-based services, user-generated content, and interactions with our platform.

2. Information Collection

We collect information in the following ways:

Information You Provide Directly:

  • Account Information: Name, email address, password, phone number (optional), profile photo, and demographic information (age, gender - optional).
  • Payment Information: Payment details for premium subscriptions processed through our payment processor (Stripe). We do not directly store full payment card details.
  • Preferences and Interests: Your event preferences, favorite venues, cuisine preferences, activity interests, budget preferences, accessibility needs, dietary restrictions, and other personalization settings.
  • User-Generated Content: Reviews, ratings, photos, comments, event descriptions, group messages, and other content you create or share on the platform.
  • Social Connections: Friend connections, group memberships, and social graph information within Hangouty.
  • Calendar Information: Event RSVPs, saved events, and calendar integrations (with your permission).
  • Communications: Messages you send through our support channels, feedback forms, or in-app messaging.

Location Data:

Location data is essential to Hangouty's core functionality. We collect location information to provide personalized recommendations and services:

  • Precise Location: With your permission, we collect GPS coordinates, WiFi access points, and cell tower information from your mobile device to show nearby venues, events, and activities.
  • Approximate Location: IP address-based location for web users or when precise location is disabled.
  • Location History: We may store your location history to improve recommendations and show you places you've visited.
  • Search Locations: Locations you manually enter or search for within the app.
  • Check-ins: Venue check-ins and attendance confirmations you voluntarily share.

Location Controls: You can control location permissions through your device settings (iOS/Android) or browser settings (web). Disabling location services will limit certain features but you can still use the Service with manual location entry.

Information Collected Automatically:

  • Usage Data: Features used, pages viewed, events browsed, venues saved, search queries, recommendations clicked, time spent, navigation patterns, and interaction data.
  • Device Information: Device type, operating system, browser type, device identifiers (IDFA on iOS, Advertising ID on Android), mobile carrier, screen resolution, and app version.
  • Log Data: IP address, access times, crash reports, error logs, and performance data.
  • Cookies and Tracking Technologies: Cookies, web beacons, local storage, and similar technologies to track activity and personalize experience (see Section 5).
  • Camera and Photos: With permission, access to camera and photo library for uploading venue photos and profile pictures.
  • Notifications: With permission, push notification tokens and notification interaction data.

Information from Third Parties:

  • Google Maps API: Location data, place information, directions, and mapping services.
  • Yelp API: Business information, reviews, ratings, photos, and operating hours.
  • Ticketmaster API: Event listings, ticket availability, venue information, and performer data.
  • OpenTable: Restaurant information, availability, and reservation data.
  • Weather Services: Weather forecasts for event planning.
  • Payment Processor (Stripe): Transaction confirmation and fraud detection information.
  • Social Media: If you connect social media accounts, we may receive profile information and friend lists (with your permission).
  • Calendar Services: Calendar event data if you grant integration permissions.
  • Enterprise SSO Providers: For business accounts, authentication data from your organization's identity provider.

3. How We Use Your Information

We use the information we collect for the following purposes:

Core Service Provision:

  • Create and manage your account
  • Process subscriptions, payments, and billing
  • Authenticate your identity and maintain secure sessions
  • Provide customer support and respond to inquiries
  • Send transactional communications (confirmations, receipts, updates)
  • Enable social features (friend connections, group planning, messaging)

Personalization and Recommendations:

  • Provide personalized event, venue, and activity recommendations based on your location, preferences, and history
  • Customize your feed and discover page based on your interests
  • Show nearby events and venues relevant to your current or saved locations
  • Suggest friends and groups based on common interests and connections
  • Generate AI-powered itineraries and event plans
  • Remember your favorite places and preferences
  • Tailor search results to your preferences

Analytics and Improvement:

  • Analyze usage patterns to improve the Service
  • Monitor Service performance and troubleshoot technical issues
  • Conduct research and analytics to understand user behavior
  • Test new features and measure their effectiveness
  • Improve our AI recommendation algorithms
  • Generate aggregated statistics and insights

Communications:

  • Send event reminders and notifications
  • Notify you of friend activity and group updates
  • Inform you of material changes to Terms of Service or Privacy Policy
  • Send promotional emails and newsletters (with your consent; opt-out anytime)
  • Deliver push notifications about events, friends, and recommendations (with your permission)

Legal, Security, and Safety:

  • Comply with applicable laws, regulations, and court orders
  • Detect, investigate, and prevent fraudulent transactions and security incidents
  • Protect the rights, property, and safety of Hangouty, our users, and the public
  • Enforce our Terms of Service and community guidelines
  • Moderate user-generated content to ensure compliance with policies
  • Verify enterprise user credentials and access controls

4. Information Sharing and Disclosure

WE DO NOT SELL YOUR PERSONAL INFORMATION to third parties for marketing or advertising purposes.

We share information only in the following circumstances:

Third-Party Service Providers:

  • Google Maps: Location data, search queries, and map interactions to provide mapping and directions.
  • Yelp: Location data and search queries to retrieve business information and reviews.
  • Ticketmaster: Location and event preferences to show relevant events and ticket options.
  • OpenTable: Dining preferences and party size for restaurant reservations.
  • Weather Services: Location data to provide weather forecasts.
  • Payment Processor (Stripe): Payment and billing information to process subscriptions and transactions.
  • Cloud Hosting Providers: AWS, Vercel, and other infrastructure providers that host our Service.
  • Analytics Services: Anonymized usage data for analytics (Google Analytics, Mixpanel, etc.).
  • Email Services: Email addresses for transactional and marketing emails.
  • Push Notification Services: Device tokens for mobile push notifications (Apple Push Notification Service, Firebase Cloud Messaging).
  • AI/ML Services: Usage data and preferences to power our recommendation algorithms.

These service providers act as data processors and are contractually obligated to protect your information and use it only for the purposes we specify.

Social Sharing Within Hangouty:

  • Your profile information, reviews, ratings, and photos are visible to other Hangouty users based on your privacy settings
  • Event attendance and check-ins may be visible to your friends
  • Group planning information is shared with group members
  • You control what information is public vs. visible only to friends through privacy settings

Enterprise Accounts:

  • For users with enterprise accounts (PMI, corporate clients), we may share usage data and analytics with your organization's administrators as specified in the enterprise agreement
  • Enterprise administrators have access to user management, usage reports, and administrative controls
  • We share data with your organization's SSO provider for authentication

Legal Requirements:

  • We may disclose information if required by law, court order, subpoena, or government request
  • We may disclose information to enforce our Terms of Service, protect our rights, or prevent harm
  • We may disclose information to comply with GDPR, CCPA, or other privacy regulations

Business Transfers:

If Hangouty is acquired, merged, or sold, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have.

Aggregate and Anonymized Data:

We may share aggregated or anonymized data that cannot identify you personally (e.g., "Popular venues in San Francisco" or "Average event attendance trends").

With Your Consent:

We may share your information with other parties when you explicitly consent or request such sharing (e.g., sharing your itinerary with external calendar apps).

5. Cookies and Tracking Technologies

What are Cookies?
Cookies are small data files stored on your device by your web browser or mobile app. We use cookies and similar technologies (web beacons, pixels, local storage, mobile identifiers) for several purposes:

Types of Cookies and Technologies We Use:

  • Essential Cookies: Required for core functionality (authentication, session management, security, login state). These cannot be disabled without breaking the Service.
  • Preference Cookies: Remember your settings, preferences, saved locations, favorite venues, and personalization choices.
  • Analytics Cookies: Measure app performance, user behavior, feature usage, and engagement through services like Google Analytics, Mixpanel, and Amplitude.
  • Location Cookies: Store recent locations and search history for faster recommendations.
  • Third-Party Cookies: Google Maps, Yelp, Ticketmaster, and other integrated services may set cookies to track interactions with their content.
  • Mobile Identifiers: iOS IDFA and Android Advertising ID for analytics and attribution (can be reset in device settings).

Cookie Consent:

  • We do not require consent for essential functional cookies required for the Service to operate
  • For non-essential cookies (analytics, tracking), we obtain your consent through a cookie banner on first visit
  • By continuing to use the Service after dismissing the cookie notice, you consent to non-essential cookies
  • You can modify your cookie preferences through our cookie settings panel

Controlling Cookies and Tracking:

  • Browser Settings: Disable cookies in your browser settings, but this may affect Service functionality
  • Clear Cookies: Clear existing cookies through your browser preferences
  • Google Analytics Opt-Out: Install the Google Analytics Opt-Out Browser Extension
  • Mobile Advertising: Disable ad tracking or reset your advertising ID in iOS Settings or Android Settings
  • Do Not Track: We honor browser "Do Not Track" signals where feasible
  • App Permissions: Manage app tracking permissions in iOS Settings > Privacy or Android Settings > Privacy

6. Data Security

We implement appropriate security measures to protect your personal information:

Security Practices:

  • Encryption: HTTPS/TLS encryption for data in transit; AES-256 encryption for sensitive data at rest
  • Access Controls: Role-based access control (RBAC) limiting access to personal information to authorized personnel only
  • Payment Security: Payment processing complies with PCI DSS (Payment Card Industry Data Security Standard)
  • Authentication: Secure password hashing (bcrypt), multi-factor authentication options, and session management
  • Infrastructure: Secure cloud hosting with AWS and Vercel, firewalls, DDoS protection
  • Monitoring: 24/7 security monitoring, intrusion detection, and automated threat response
  • Code Security: Regular security audits, penetration testing, and SAST/DAST scanning in CI/CD pipeline
  • Employee Training: Security awareness training and background checks for employees with data access

Security Limitations:

  • No security system is 100% secure. We cannot guarantee absolute security of information transmitted over the internet
  • You are responsible for maintaining the confidentiality of your account credentials
  • Notify us immediately at amr.metwaly1@outlook.com if you suspect unauthorized access to your account
  • Use strong, unique passwords and enable two-factor authentication

Data Breach Notification:

  • In the event of a data breach involving your personal information, we will notify you as required by law (typically within 72 hours for GDPR, 30 days for CCPA)
  • Notification will be sent via email to the address associated with your account and/or prominent in-app notice
  • We will provide information about the breach, data affected, and steps to protect yourself

7. Data Retention

How Long We Keep Your Information:

  • Account Information: Retained while your account is active and for 3 years after account closure for legal and compliance purposes.
  • Location Data: Precise location data retained for 12 months; aggregated location trends retained indefinitely.
  • Preferences Data: Retained while active and for 2 years after last activity to maintain personalization.
  • User-Generated Content: Reviews, photos, and ratings retained indefinitely unless you delete them or request deletion.
  • Payment Information: Payment card details not stored by us; Stripe retains per their policies. Billing transaction records retained for 7 years for legal and tax compliance.
  • Analytics Data: Aggregated analytics retained indefinitely. Individual-level tracking data retained for 24 months.
  • Communication Logs: Support communications retained for 3 years.
  • Cookies: Most cookies expire after 12 months; you can clear cookies anytime.
  • Backups: Deleted data may remain in backups for up to 90 days but will not be actively used.

Data Deletion:

  • You may request deletion of your account and associated personal information at any time
  • Upon deletion, we will remove your information except where retention is required by law or legitimate business purposes
  • Some anonymized data derived from your usage may be retained for analytics
  • User-generated content may be retained if it was shared publicly or incorporated into others' experiences

8. Your Privacy Rights

Universal Rights (All Users):

  • Access Your Information: Request a copy of personal information we hold about you by emailingamr.metwaly1@outlook.com with "Data Access Request" in the subject line.
  • Correct Your Information: Update account information through account settings or contact us for assistance.
  • Delete Your Information: Request deletion by emailing amr.metwaly1@outlook.com with "Data Deletion Request" in the subject line.
  • Opt Out of Communications: Unsubscribe from promotional emails using the unsubscribe link; disable push notifications in app settings or device settings.
  • Manage Cookies: Control cookies through our cookie settings panel or browser settings.
  • Control Location Data: Disable location services in device settings or app settings.
  • Privacy Settings: Control visibility of your profile, reviews, and activity through privacy settings.

We will respond to privacy requests within 30 days.

California Consumer Privacy Act (CCPA) Rights:

If you are a California resident, you have the following rights under CCPA:

  • Right to Know: Request what personal information we collect, use, disclose, and sell (if any).
  • Right to Delete: Request deletion of personal information (with limited exceptions for legal compliance).
  • Right to Opt-Out: Request that we do not sell or share your personal information (note: we do not sell personal information).
  • Right to Correction: Request correction of inaccurate personal information.
  • Right to Limit: Request that we limit use of sensitive personal information (location, preferences).
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

How to Exercise CCPA Rights:

  • Submit requests to amr.metwaly1@outlook.com with "CCPA Request" in the subject line
  • Provide sufficient information to verify your identity (email address, account details)
  • We will respond within 45 days (or up to 90 days for complex requests with notice)
  • You may designate an authorized agent to submit requests on your behalf

CCPA Categories of Information Collected:

  • Identifiers (name, email, IP address, device ID)
  • Commercial information (purchase history, subscriptions)
  • Geolocation data (precise and approximate location)
  • Internet activity (browsing history, interactions)
  • Inferences (preferences, characteristics, behavior)

GDPR Rights (EU/EEA/UK Residents):

If you are located in the EU, EEA, or UK, you have rights under GDPR:

  • Right to Access: Request a copy of your personal data
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure: Request deletion ("right to be forgotten")
  • Right to Restriction: Limit how we process your data
  • Right to Data Portability: Receive your data in a machine-readable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent for processing at any time
  • Right to Lodge a Complaint: File a complaint with your local supervisory authority

Legal Basis for Processing: We process your data based on consent, contract performance, legal obligations, and legitimate interests (service improvement, security, analytics).

Contact our EU representative or DPO at amr.metwaly1@outlook.com for GDPR inquiries.

Enterprise Users:

If you use Hangouty through an enterprise account, some privacy rights may be managed by your organization's administrator. Contact your organization's IT department or privacy officer for assistance, or contact us atamr.metwaly1@outlook.com.

9. International Data Transfers

Data Processing Location:

  • Our servers and service providers are primarily located in the United States (AWS us-east-1, us-west-2 regions)
  • By using Hangouty, you consent to the transfer and processing of your information internationally
  • For EU/EEA/UK users, we implement Standard Contractual Clauses (SCCs) approved by the European Commission to protect data transfers to the US
  • We comply with applicable data transfer frameworks and regulations (GDPR, Privacy Shield successor mechanisms)
  • Some third-party services (Google Maps, Yelp) may process data in multiple countries

10. Children's Privacy

Hangouty is intended for individuals 13 years of age or older (or the applicable age of digital consent in your jurisdiction: 16 in EU). We do not knowingly collect personal information from children under 13.

  • By using Hangouty, you represent that you are at least 13 years old
  • If we become aware that we have collected information from a child under 13, we will delete such information promptly
  • Parents or guardians who believe we have collected information from a child under 13 should contact us atamr.metwaly1@outlook.com
  • We comply with COPPA (Children's Online Privacy Protection Act) in the United States

11. Third-Party Links and Services

Hangouty integrates with and links to third-party services including Google Maps, Yelp, Ticketmaster, OpenTable, and others. These services have their own privacy policies:

  • Google Maps: Review Google's Privacy Policy at policies.google.com/privacy
  • Yelp: Review Yelp's Privacy Policy at yelp.com/tos/privacy_policy
  • Ticketmaster: Review Ticketmaster's Privacy Policy at ticketmaster.com/h/privacy.html
  • OpenTable: Review OpenTable's Privacy Policy at opentable.com/legal/privacy-policy
  • Stripe: Review Stripe's Privacy Policy at stripe.com/privacy

Disclaimer: We are not responsible for the privacy practices of third-party services. When you interact with third-party content or services through Hangouty, those parties may collect data about you. Please review their privacy policies.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

Notification of Changes:

  • Material changes will be communicated via email to your registered email address
  • We will post an updated "Last Updated" date at the top of this policy
  • Prominent in-app notifications for significant changes
  • Your continued use of Hangouty after updates constitutes acceptance of the revised Privacy Policy
  • For significant changes affecting your rights, we may request your affirmative consent

Review Regularly:

We recommend reviewing this Privacy Policy periodically to stay informed of how we protect your information. The most current version is always available at hangouty.com/privacy.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Contact Information:

Response Time:

We will respond to privacy inquiries within 30 days (45 days for CCPA requests, 30 days for GDPR requests). For complex requests, we may extend the response time and will notify you of the delay.

14. Compliance and Certifications

Hangouty is committed to maintaining high standards of data protection and privacy:

  • GDPR Compliance: We comply with EU General Data Protection Regulation for all EU/EEA/UK users
  • CCPA Compliance: We comply with California Consumer Privacy Act for California residents
  • COPPA Compliance: We comply with Children's Online Privacy Protection Act
  • PCI DSS: Payment processing through Stripe complies with Payment Card Industry Data Security Standards
  • SOC 2 Type II: Our infrastructure providers (AWS, Vercel) maintain SOC 2 Type II compliance
  • ISO 27001: Working toward ISO 27001 information security management certification
  • Privacy Shield Successor: We monitor and comply with new US-EU data transfer frameworks as they develop

15. Data Processing Addendum for Enterprise Customers

Enterprise customers (PMI, corporate clients) may execute a separate Data Processing Addendum (DPA) that includes:

  • Standard Contractual Clauses (SCCs) for GDPR compliance
  • Data processing roles and responsibilities
  • Sub-processor lists and approval processes
  • Data security requirements and audit rights
  • Data breach notification procedures
  • Data retention and deletion obligations
  • Cross-border data transfer mechanisms

Contact amr.metwaly1@outlook.com for enterprise Data Processing Addendum requests.

This Privacy Policy is effective as of November 27, 2025 and was last updated on November 27, 2025.

By using Hangouty, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and disclosure of your information as described herein.