Privacy Policy
CrowdMate
Last updated: September 29, 2026
1. Introduction
CrowdMate ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application CrowdMate (the "App") or our website.
This policy complies with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Data Controller
ClairAI SASU
122 rue Amelot
75011 Paris, France
Email: support@crowdmate.app
3. Information We Collect
3.1 Information You Provide
- Account Information: When you create an account, we collect your email address and username.
- Onboarding Emails: After you create an account, we send a welcome email and at most one getting-started follow-up to your account email address. They are delivered by Resend on our behalf. Every one carries an unsubscribe link, and opting out stops the sequence.
- Optional Concert Newsletter: The London and Paris newsletters have a separate signup and email-confirmation step. We store your email address, chosen city, subscription status and consent timestamps to deliver your chosen edition and honour your preferences. Creating an app account does not subscribe you. Each newsletter includes an unsubscribe link. Pending signups expire and are removed after seven days; short-lived, hashed network identifiers help limit abusive signup requests. Delivery records help prevent duplicate emails and honour bounces, complaints and opt-outs. We use Resend to deliver these emails on our behalf, and do not give sponsors your address or subscriber list.
- Profile Information: Name, profile picture, and other information you choose to add to your profile.
- Concert Data: Information about concerts you attend, mark as interested, or search for.
- User-Generated Content: Reviews, ratings, comments, and other content you create within the App.
- Concert Group Content: If you create or join a concert group, we collect the group name and description, the pinned night plan, the invitations you send, your membership record, and the text messages you send in the group chat.
- Reports and Blocks: When you report a message, a group or a person, we collect your report, the reason you give, and a copy of the reported content as evidence. We also record the people you block.
3.2 Automatically Collected Information
- Device Information: Device type, operating system version, unique device identifiers.
- Usage Data: How you interact with the App, features used, pages viewed, and other analytics.
- Location Data: With your permission, we collect your approximate location to show nearby concerts.
- Log Data: IP address, browser type, access times.
3.3 Information from Third Parties
- Social Media: If you connect social media accounts, we may receive information from those platforms.
- Concert Data Providers: We receive concert and venue information from third-party data providers.
4. How We Use Your Information
- Service Provision: To provide, maintain, and improve the App.
- Personalization: To personalize your experience and show relevant concert recommendations.
- Communication: To send you updates and notifications about concerts.
- Analytics: To understand how users interact with the App.
- Concert Groups: To deliver the messages, invitations and night plans you post to the other members of that group, and to manage who is admitted.
- Safety and Moderation: To check group text automatically against a baseline list of prohibited phrases and malicious links when it is sent, to review reports, and to act on them.
- Security: To detect and prevent fraudulent activity.
- Legal Compliance: To comply with legal obligations.
5. Legal Basis for Processing (GDPR)
- Consent: You have given explicit consent for specific purposes.
- Contract Performance: Processing is necessary to provide the services, including delivering the messages, invitations, night plans and membership of any concert group you choose to join.
- Legitimate Interests: We have a legitimate interest in improving our services and in keeping them safe. Content screening, handling reports and blocks, and moderating concert groups rest on this basis.
- Legal Obligation: We must process data to comply with legal requirements.
6. Data Sharing and Disclosure
We do not sell your personal information. We may share data with:
- Cloud Hosting: Firebase (Google Cloud Platform) for data storage
- Analytics: Firebase Analytics for app performance analysis
- Authentication: Firebase Authentication for secure user login
- Email Delivery: Resend for onboarding emails and separately confirmed concert newsletters
- Push Notifications: Firebase Cloud Messaging
Concert group content — messages, group names and descriptions, pinned plans, membership records and report evidence — is stored in our primary Firebase project and is not shared with any third party, not sold, and never used for advertising. Google acts only as our processor for that storage. Within the App it is readable by the members of that group who are authorised to see it, and by our moderators when a report or a safety issue requires it.
We may also disclose information if required by law or to protect our rights.
7. Data Storage and Security
Your data is stored on servers in the European Union through Firebase. We implement:
- Encryption of data in transit and at rest
- Regular security audits
- Access controls and authentication
Concert group messages are not end-to-end encrypted. They travel over TLS and are stored encrypted at rest in the European Union, but the other authorised members of your group can read them, and we can read them when moderation, a report, a safety issue or a legal obligation requires it. Please do not use group chat for anything you would not want a moderator to see.
We retain data only as long as necessary. When you delete your account, data is permanently deleted within 30 days. The retention periods specific to concert groups are set out in section 13.
8. Your Rights (GDPR)
- Right of Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate data
- Right to Erasure: Request deletion of your data
- Right to Restrict Processing: Limit how we use your data
- Right to Data Portability: Request a copy in a portable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time
Contact us at support@crowdmate.app to exercise these rights. You can also lodge a complaint with CNIL (www.cnil.fr).
Inside the App you can also block another person and report a message, a group or a person. A block hides that person's messages from you in both directions and prevents either of you from being admitted to a group where the other is an active member; it does not remove either of you from a group you already share, and it does not erase content already seen.
9. Children's Privacy
CrowdMate is for adults aged 18 and over. The App is not directed to anyone under 18, and we do not knowingly collect data from anyone under 18. When you create an account you confirm that you are 18 or older. This is a self-declaration: we do not operate an age-verification mechanism. If we learn that we hold data about someone under 18, we delete that data and close the account. This applies to concert groups, which include text chat between users: the App as a whole, and this feature with it, is restricted to adults aged 18 and over. If you believe someone under 18 has given us personal data, contact us at support@crowdmate.app.
10. International Data Transfers
Data may be transferred to and processed in the EU or other countries with appropriate safeguards including Standard Contractual Clauses.
11. Cookies and Tracking
Our website (crowdmate.app) uses cookies and similar tracking technologies. We use Google Tag Manager to manage these cookies.
Types of Cookies We Use:
- Essential Cookies: Required for basic website functionality. These cannot be disabled.
- Analytics Cookies: Help us understand how visitors interact with our website through Google Analytics. These cookies collect information anonymously.
- Preference Cookies: Remember your settings, such as your cookie consent choice.
Your Cookie Choices:
When you first visit our website, you will see a cookie consent banner. You can choose to:
- Accept: All cookies will be enabled, including analytics cookies that help us improve our service.
- Decline: Only essential cookies will be used. Analytics tracking will be disabled.
Your choice is stored in your browser's local storage. To change your preference, clear your browser's local storage for crowdmate.app and refresh the page.
Third-Party Services:
When you accept cookies, data may be shared with Google Analytics for website usage analysis. Google's privacy policy applies to this data: policies.google.com/privacy
12. Push Notifications
With permission, we send notifications about upcoming concerts, ticket sales, and app updates. You can disable these in your device settings.
Concert group notifications are generic: they carry only the group identifier and the type of event, never the text of a message and never an invitation link. You can turn group notifications off in the App's notification preferences, or mute an individual group.
13. Concert Groups
Concert groups let you organise a night out with other CrowdMate users. A group contains membership records, text messages, a group name and description, a pinned night plan and invitation links. Joining a group does not change your attendance and does not make anyone your friend. A public group listing shows the organizer's chosen display name; a private group is unlisted. In both cases the chat and the member list stay restricted to members, and a member sees the current plan and the messages posted from their latest join onward.
Group messages are transmitted over TLS and stored, encrypted at rest, in our primary Firebase project in the European Union, with Google acting as our processor. They are not end-to-end encrypted: the authorised members of the group can read them, and we can read them for moderation and safety. Group text is checked automatically against a baseline list of prohibited phrases and malicious links when it is sent. Group content is not shared with third parties and is not used for advertising.
Private invitation links can be forwarded. Opening one does not join a group. Organizers can revoke a link or require approval before someone is admitted. Sharing an invitation uses your device's own share sheet: the App does not read your contacts and does not read your clipboard. Blocks restrict admission and hide the blocked person's messages in both directions; staying in a group you already share does not hide plans or information posted by other people.
You can report a message, a group or a person from inside the App. A human operator reviews reports and may dismiss the report, hide a message, archive a group, or suspend an account's participation in groups, and may restore participation after review. Every action is recorded with its reason. A report on its own never causes an automatic ban. If someone is in immediate danger, contact your local emergency services.
Retention. A group becomes read-only seven days after the concert. Group content — messages, invitations, receipts and membership records — is removed 90 days after the group is archived. Report evidence is held separately for moderation and removed 90 days after the report is resolved; an unresolved report stays in the queue until an operator reviews it. When you delete your account, our backend cleanup removes your group memberships and the messages you wrote, transfers ownership of a group you organised to an eligible member or archives it, revokes the invitation links you created, and removes identifying report evidence.
14. Changes to This Policy
We may update this policy and will notify you by email or app notification. Continued use constitutes acceptance.
15. Contact Information
Email: support@crowdmate.app
Mail: ClairAI SASU, 122 rue Amelot, 75011 Paris, France
Data Protection Officer: Nicolas MATHIEU