Draft. A Maltese lawyer should review this document before it is published or shown to users.
This policy explains what personal data Imxi collects, why, who sees it, how long we keep it, and what you can do about it. It is written to meet the EU General Data Protection Regulation (GDPR), the Maltese Data Protection Act (Chapter 586 of the Laws of Malta) and the ePrivacy rules, and to satisfy Apple's and Google's app store requirements.
1. Who is responsible for your data
The controller is:
[Company name] [address], Malta Company number [C 00000] Email: [privacy@imxi.mt]
[If a data protection officer is appointed: Our data protection officer can be reached at [dpo@imxi.mt].]
2. The short version
- We collect what we need to run a social app for adults in Malta: your phone number, email, name, photo, town, date of birth, interests, availability, the plans you post and join, and your messages.
- We log your IP address and basic device details for security.
- Location is optional. Approximate location is used for "plans near me" only while you use that feature. Precise location is only collected if you switch it on, and during a safety alert.
- Contact matching is optional. Your contacts are hashed on your phone before they reach us, we match the hashes against users, and we do not keep them unless you invite someone.
- Chat is not end to end encrypted, so that we can act on reports.
- The "I feel unsafe" button sends us a bundle of your location, IP, device, current plan and recent contacts. We may pass it to the Malta Police if you ask us to or if someone is at risk.
- Tickets to venue events are paid through Viva.com. Viva sees your card; we never do. We keep the order, the amount and the receipt link.
- We never sell your data and we do not use advertising trackers.
- You can delete your account in the app. Some data is kept afterwards for safety and legal reasons, listed in section 8.
3. What we collect
| Data | Where it comes from | Notes |
|---|---|---|
| Mobile phone number | You, at sign up | Verified by SMS code. Your identity anchor. Stored in full, plus a SHA-256 hash for contact matching and ban checks. |
| Email address | You, at sign up | Verified by email code. Used for recovery and receipts. |
| Apple or Google sign in identifier | Apple or Google, if you use Sign in with Apple or Google | We store the stable identifier they give us, and your name if you share it. We do not receive your Apple or Google password. |
| Name, profile photo, town, short bio | You | Shown to other users. |
| Date of birth | You | Used to check you are 18 or over and to show your age band. Not shown in full to other users. |
| Age signal | Apple Declared Age Range or Google Play Age Signals, where your device offers it | A yes or no adult signal, used to confirm eligibility. |
| Interests and availability | You | Which activity categories you like and when you are free. Shown on your profile. |
| Plans | You | Title, description, category, date, place, cover image, who joined. Public plans are visible to all users; "contacts" plans only to matched contacts. |
| Messages and chat content | You and the people you chat with | Text, images, shared locations, pins, event proposals, votes. Stored on our servers. Not end to end encrypted. |
| Ratings | You and other users | Stars, tags and optional comment, given after a completed plan. Shown to the rated person as an aggregate, anonymously. |
| Reports | You and other users | Reason, details, and a snapshot of the reported message or plan as evidence. |
| Blocks | You | Who you have blocked. |
| Trusted contacts | You, optionally | Name, phone number and email of people you want to be able to alert. Only used for the safety share feature. |
| Device and push token | Your device | Device model, operating system version, app version, a device identifier we generate, and an Expo push token so we can send notifications. |
| IP address | Your device | Recorded at sign in, on each session, on sign in code requests, and on each safety alert. |
| Approximate location | Your device, if you allow it | Used to show plans near you. Not stored as a history. |
| Precise location | Your device, if you switch on location logging, and during a safety alert | Stored with the safety alert. Live location during an alert is recorded for up to 30 minutes. |
| Contacts (hashed) | Your phone's address book, if you allow it | Each phone number is turned into a SHA-256 hash on your phone. Only hashes are sent. See section 5. |
| Ticket orders | You, and Viva when you buy a ticket | Which event, how many tickets, the amount, our fee, the order status, the Viva order code and transaction identifier and the receipt link Viva gives us. Your card details go to Viva directly from the Viva checkout page and never reach our servers. We do not store your card number, not even the last four digits. |
| Tickets and door scans | Created when an order is paid or a free ticket is issued, and by the organiser at the door | Ticket code, status, who holds it, any transfer between users, and a scan log: when the ticket was scanned and by which door staff account. The organiser sees the holder's name and photo at the door. |
| Organisation purchases | Apple, Google and RevenueCat | For venues and workplaces: which subscription (Venue Pro, Team, sponsored placement), when it expires. We do not receive card details. |
| Organiser payout details | You and Viva, if you run a venue | Your Viva Merchant ID and payment source code, whether payments are active, and whether Viva pays you directly or you are paid through Imxi. If you are paid through Imxi, the bank account you give us for settlements and a record of each settlement. Identity documents are collected and held by Viva, not by us. |
| Usage information | Your device | When you were last active, and basic diagnostics such as crashes. |
| Safety alert bundle | Created when you press "I feel unsafe" | See section 6. |
| Support correspondence | You | Emails you send us. |
We do not deliberately collect special category data (such as health, religion, sexual orientation or political views). If you choose to put such information in your bio, messages or a safety note, we treat it with the care the law requires, and you can remove it at any time.
4. Why we use your data and the legal basis
| Purpose | Data used | Legal basis (GDPR Article 6) |
|---|---|---|
| Creating and running your account, verifying your phone and email | Phone, email, sign in identifiers, device | Contract (6(1)(b)) |
| Showing your profile and plans to other users, matching people to plans, group and direct chat | Profile, plans, messages, interests, availability | Contract (6(1)(b)) |
| Checking you are 18 or over | Date of birth, age signal | Legal obligation and legitimate interest in keeping minors off an adult service (6(1)(c), 6(1)(f)) |
| Sending you notifications about messages, requests, plan changes and reminders | Push token, device | Contract (6(1)(b)). You control categories in Settings. |
| Marketing notifications about new features | Push token, email | Consent (6(1)(a)). Off by default. |
| Showing plans near you | Approximate location | Consent (6(1)(a)) via the device permission prompt, and Article 5(3) of the ePrivacy Directive |
| Location logging and live location during a safety alert | Precise location | Consent (6(1)(a)) via the opt in switch. During an alert: consent by pressing the button, and vital interests (6(1)(d)) |
| Finding friends through your contacts | Hashed phone numbers | Consent (6(1)(a)) via the device permission prompt and the in app switch |
| Ratings after a plan | Ratings | Contract (6(1)(b)) and legitimate interest in a trustworthy community (6(1)(f)) |
| Reports, moderation and enforcement, including reading reported conversations, suspending and banning accounts | Reports, messages, plans, profile, IP, device | Legitimate interest in the safety of users and the integrity of the service (6(1)(f)), and legal obligations under the Digital Services Act (6(1)(c)) |
| Keeping banned phone numbers off the service | Hash of the phone number | Legitimate interest (6(1)(f)) |
| Safety alerts: receiving your alert, contacting you, and sharing the bundle with police | Safety bundle (section 6) | Vital interests (6(1)(d)), consent by pressing the button (6(1)(a)), legitimate interest (6(1)(f)), and legal obligation where police lawfully request it (6(1)(c)) |
| Security, fraud prevention, rate limiting, detecting duplicate or automated accounts | IP, device, session data, phone hash | Legitimate interest (6(1)(f)) |
| Selling and issuing tickets as the organiser's agent, sending receipts, refunds, admitting you at the door | Ticket orders, tickets, scan logs | Contract (6(1)(b)) |
| Preventing ticket fraud, resale and chargeback abuse | Ticket orders, scan logs, device, IP | Legitimate interest (6(1)(f)) |
| Organisation subscriptions (Venue Pro, Team, sponsored placement) | Purchase data from Apple, Google, RevenueCat | Contract (6(1)(b)) |
| Paying venues for ticket sales | Viva payment status, payout mode and, for venues paid through Imxi, bank details | Contract (6(1)(b)) and legal obligations on payment platforms (6(1)(c)) |
| Counting sponsored card impressions and taps | Anonymous counts only | Legitimate interest (6(1)(f)). Sponsors never receive personal data. |
| Responding to lawful requests from police, courts and regulators | Whatever is lawfully requested | Legal obligation (6(1)(c)) |
| Improving the app, fixing crashes | Diagnostics, aggregated usage | Legitimate interest (6(1)(f)) |
| Keeping records for accounting and tax | Purchase records, ticket orders | Legal obligation (6(1)(c)) |
Where we rely on legitimate interest we have balanced it against your rights. You can object at any time (section 9).
Automated decisions. If a user, plan or message receives three reports from different people within seven days, it is suspended automatically until a person reviews it, normally within two working days. This is a temporary protective step, not a final decision. Every ban and every lasting restriction is decided by a person. You can ask for a human review of any automated step by emailing [appeals@imxi.mt].
5. Contact matching, in detail
If you choose to find friends through your contacts:
- The app reads the phone numbers in your address book on your device.
- Each number is normalised and turned into a SHA-256 hash on your device. Names and other details never leave your phone.
- The hashes are sent to our server over an encrypted connection and compared with the hashes of registered users' phone numbers.
- We return the matching Imxi users to you. We do not tell them you have their number, unless you go on to contact them.
- The hashes you sent are then discarded. They are not stored, not linked to your account, and not used for any other purpose.
- If you choose to invite someone who is not on Imxi, we keep the hash of that number, linked to you, so that when they join we can show you that they did. We keep nothing readable, and we do not message them; the invite goes from your phone via your own SMS or share sheet.
You can switch contact matching off in Settings or in your phone's permissions at any time.
6. Safety alerts, in detail
When you press "I feel unsafe" the app immediately creates a safety bundle containing:
- your account details (name, phone number, email, photo);
- your current location (if permission is granted) and, if you opted in, live location for up to 30 minutes;
- your IP address and device details;
- the plan you are currently on, if any, including its host and accepted members;
- the people you have chatted with in the last 48 hours and the last messages exchanged with them;
- any note you type.
The bundle is stored on our servers and in our secure file storage, an alert is posted to our internal safety channel, and it is flagged to our safety team. Our Safety centre explains what happens next.
We share the bundle with the Malta Police when you ask us to, when the police lawfully request it, or when we believe there is a credible threat to your or someone else's life or safety. If you share your situation with a trusted contact from the app, the link you send them shows a short summary and your location; you choose who receives it.
The bundle includes data about other people (the people on your plan and in your recent chats). We include it because it is what the police would need. We process their data on the basis of vital interests and legitimate interest, we restrict access to the safety team, and we do not use it for any other purpose.
7. Who we share your data with
We do not sell personal data. We do not use advertising networks or tracking SDKs. We share data only with the providers below, each under a written data processing agreement, and with authorities where the law requires.
| Recipient | What | Why | Where |
|---|---|---|---|
| Twilio Inc. | Phone number, sign in code, IP | SMS verification | USA and EU. EU-US Data Privacy Framework and standard contractual clauses |
| Resend, Inc. | Email address, message content | Email verification and receipts | USA. Standard contractual clauses |
| Cloudflare, Inc. (R2 storage) | Photos, chat images, safety bundles | File storage | [EU jurisdiction setting confirmed]. EU-US Data Privacy Framework and standard contractual clauses |
| Railway Corp. | All service data | Hosting of our servers and database | [EU region: confirm]. Standard contractual clauses |
| Expo (650 Industries, Inc.) | Push token, notification content | Push notification delivery | USA. Standard contractual clauses |
| Apple Inc. | Push token, purchase data, sign in identifier, age signal | App distribution, Sign in with Apple, payments, notifications on iOS | Apple's own terms. Data Privacy Framework |
| Google LLC | Push token, purchase data, sign in identifier, age signal | App distribution, Sign in with Google, payments, notifications on Android | Google's own terms. Data Privacy Framework |
| RevenueCat, Inc. | App user identifier, purchase and subscription status | Managing Venue Pro, Team and sponsored placement across stores | USA. Standard contractual clauses |
| Viva Payment Services S.A., an e-money institution licensed in the EU [exact legal entity and registered address to be confirmed by the lawyer] | Name, email, amount, event, payment method details you enter on the Viva checkout page, IP and device signals for fraud checks; for venues, identity and bank details entered when opening a Viva account | Processing ticket payments, refunds and chargebacks, paying venues through Viva (Imxi is a Viva partner, so payments are taken on the venue's Viva account, or on ours where the venue is paid through Imxi). Viva is our processor for the order flow and an independent controller for its own fraud prevention and regulatory duties | Greece (EU) [to be confirmed by the lawyer against Viva's current data processing terms] |
| The venue that organises an event you hold a ticket to | Your name, photo, ticket code, scan time, and the order amount and status | Admitting you at the door, managing the event, handling refunds. The venue is a separate controller for what it does with this data and may only use it to run the event | Malta |
| Slack Technologies, LLC | Safety alert and report summaries | Internal alerts to our safety team | USA. Data Privacy Framework and standard contractual clauses |
| Malta Police Force and other law enforcement or judicial authorities | What is lawfully requested, or the safety bundle in an emergency | Legal obligation, protecting life and safety | Malta |
| Professional advisers (lawyers, accountants, auditors) | What they need to advise us | Legal and accounting duties | Malta and EU |
| A buyer of our business | Your account data | If we are sold or merge, under the same protections | Wherever the buyer is, with notice to you |
Other users see your profile, your plans, your messages in shared conversations, your aggregate rating, and whether you are online. If you transfer a ticket, the person receiving it sees that it came from you. Sponsors see only anonymous counts.
8. How long we keep your data
| Data | Kept for |
|---|---|
| Account and profile | While your account is active, then 14 days' grace after you delete it, then removed |
| Messages and chat images | 2 years from sending, or until you delete your account or the message, whichever is sooner. Messages kept as evidence in a report follow the report retention below |
| Plans | While active, then 2 years as part of your history, or until account deletion |
| Ratings | While your account and the rated person's account exist. On deletion, ratings you gave are kept anonymised in the other person's aggregate |
| Reports and evidence snapshots | 3 years from the report, then deleted, unless needed for a legal claim or investigation |
| Safety alert bundles, live location trails and related notes | 3 years from the alert, then deleted, unless needed for a legal claim or investigation |
| Banned phone number hashes | Indefinitely while the ban is in force, on the basis of legitimate interest. Nothing readable is kept |
| Sign in codes | 10 minutes, then deleted. Attempt logs 30 days |
| Sessions, sign in IP addresses, device records | Until the session expires (30 days) or you sign out, then 90 days in security logs |
| Server logs including IP addresses | 90 days |
| Approximate location for "near me" | Not stored beyond the request |
| Opted in precise location outside an alert | [Until you switch it off, and no more than 30 days of history] |
| Contact hashes | Discarded immediately after matching. Invite hashes kept until the invited person joins or 12 months, whichever is sooner |
| Ticket orders, receipts and refund records | 7 years from the order, for accounting and tax. Kept even after you delete your account, with your name reduced to what the record needs |
| Tickets and door scan logs | 12 months after the event, then deleted, unless the order record or a dispute needs them |
| Organisation purchase and subscription records | 10 years, as Maltese accounting law requires |
| Viva Merchant ID, payment status and payout mode | While the venue exists on Imxi, then removed. Viva keeps its own records under its policy |
| Trusted contacts | Until you remove them or delete your account |
| Support emails | 2 years |
| Admin audit log | 3 years |
Backups are overwritten within [35] days of deletion.
9. Your rights
Under the GDPR you can:
- Access your data and get a copy.
- Correct anything inaccurate. Most profile fields you can edit yourself in the app.
- Delete your data ("right to erasure"). Delete your account in Settings, or ask us. Some data is kept as explained in section 8, and we will tell you what and why.
- Restrict processing while a dispute about accuracy or lawfulness is resolved.
- Object to processing based on legitimate interest, including moderation signals and the banned hash, and we will stop unless we have compelling grounds. You can object to marketing at any time and we will always stop.
- Port the data you gave us to another service in a machine readable format.
- Withdraw consent for location, contacts and marketing at any time, in Settings or your device permissions. Withdrawing does not affect what happened before.
Ticket orders are kept for the accounting period even if you ask for erasure, because the law requires it; we reduce them to what the record needs.
- Not be subject to solely automated decisions with legal or similarly significant effects. See section 4 on automatic suspension.
To exercise a right, email [privacy@imxi.mt] from the email address on your account, or write to us at the address in section 1. We may ask you to confirm your identity by responding to a code sent to your phone. We reply within one month, and we will tell you if we need up to two more months for a complex request. There is no fee unless a request is clearly unfounded or excessive.
10. Complaints
If you are unhappy with how we handle your data, please tell us first at [privacy@imxi.mt]. You also have the right to complain to the supervisory authority:
Office of the Information and Data Protection Commissioner (IDPC) Floor 2, Airways House, Triq Il-Kbira, Tas-Sliema SLM 1549, Malta Telephone: +356 2328 7100 Email: idpc.info@idpc.org.mt Online complaint form: https://idpc.org.mt
If you live in another EU country you may complain to your local data protection authority instead.
11. Children
Imxi is for people aged 18 and over. We do not knowingly collect data from anyone under 18. If we learn that an account belongs to someone under 18 we delete it, and we keep only the phone number hash to prevent re registration until the person is old enough. If you believe a minor is using Imxi, report the profile in the app or email [safety@imxi.mt].
12. International transfers
We are based in Malta and our main servers are in [the EU]. Some of our providers (section 7) are in the United States. Where data leaves the European Economic Area we rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework for certified companies, and otherwise on the Commission's standard contractual clauses, with additional safeguards such as encryption in transit and at rest. You can ask us for a copy of the relevant clauses at [privacy@imxi.mt].
13. Security
Data travels over encrypted connections (TLS). Card details are entered on Viva's checkout page and go straight to Viva; our servers never see them and we are outside the scope of card data storage under PCI DSS as a result. Passwords are not used; sign in is by one time code. Refresh tokens and sign in codes are stored hashed. Access to user data inside the company is limited to the people who need it for support, safety and engineering, every admin action is logged, and safety bundles are restricted to the safety team. No system is perfectly secure. If we discover a breach that is likely to put you at high risk we will tell you and the IDPC as the law requires.
14. Cookies and tracking
The Imxi app does not use cookies or third party advertising or analytics trackers. It stores a sign in token and your preferences on your device so the app works. Our website [imxi.mt] uses only strictly necessary cookies [confirm once the website is built; update this section if analytics are added].
15. Changes to this policy
We will update this policy when our practices or the law change. For significant changes we will notify you in the app or by email before they take effect. The date at the top shows the current version. Earlier versions are available on request.
16. Contact
[Company name] [address], Malta [privacy@imxi.mt] [+356 0000 0000]