Global Privacy Policy
Effective July 25, 2026 (Version 2.0 — 16+ Global Threshold)
Regulatory Compliance & Transparency
- Data Controller
- Circl Network Inc. (BC Incorporation No. NR 9289183)
- Corporate Address
- 1771 Robson Street, Vancouver, BC V6G 1C9, Canada
- Privacy Contact
- privacy@circlhq.com | dpo@circlhq.com
- Telephone (Toll-Free)
- +1 (866) 665-4055
- Frameworks
- GDPR · UK GDPR · PIPEDA · Quebec Law 25 · CCPA / CPRA
1Data Controller & Privacy Officer Contact
Circl Network Inc. acts as the legal data controller responsible for processing personal data across our software platforms, mobile applications, and connected backend infrastructure.
Designated Privacy Officer (Quebec Law 25 & GDPR Compliance):
- Title: Data Protection Officer & Privacy Officer
- Entity: Circl Network Inc.
- Address: 1771 Robson Street, Vancouver, BC V6G 1C9, Canada
- Direct Contact Email: privacy@circlhq.com
- Telephone (Toll-Free): +1 (866) 665-4055
2Categories of Personal Data We Collect
2.1Global 16+ Age Standard & Child Privacy Protection
Circl enforces a strict minimum age threshold of 16 years old globally. We do not knowingly collect, process, or solicit personal data from any person under 16 years of age. If Circl gains actual knowledge that an account belongs to a child under 16, we will immediately delete all associated account credentials, location histories, and personal data from our servers.
| Category | Data Points Collected | Primary Operational Purpose |
|---|---|---|
| Identity & Authentication | Mobile Phone Number, Email Address, Single Sign-On Tokens (Google, Apple, Facebook) | Account setup, secure session management, and passwordless OTP verification via Twilio. |
| Precise Geolocation | Real-time GPS coordinates, latitude/longitude, city, and postal region | Surface local events, map nearby circls (groups), and assist event arrival logistics. |
| Financial & Invoicing | Stripe Customer IDs, payment token histories, invoice logs, wallet transactions | Ticket processing, membership fee handling, fraud prevention, and audit records. |
| Social Communications | Friend lists, mutual connections, direct messages, and group chat logs | Enable peer-to-peer messaging, friend interactions, and circl (group) discussions. |
| Technical & Telemetry | IP Address, Device Identifier, operating system version, app usage analytics | App diagnostics, security monitoring, performance optimization via PostHog. |
| Profile & Demographics | Full name, username, date of birth, gender (optional), city/region, profile photo, biography | Account identity, enforcing the 16+ age threshold, and profile display to other members. |
| Photos & Media | Images and videos you attach to posts, chat messages, group channels, and your profile | Displaying the content you choose to share; stored in access-controlled storage buckets. |
| Push Notification Tokens | Device push token (Expo), per-device, linked to your account | Delivering the notifications you have enabled; removed on sign-out and after 90 days of inactivity. |
| Event Attendance & Check-In | Bookings and passes (event, date, seats, tier), and — when you check in at an event door — a check-in record including time, result (admitted or refused), and radio signal strength for tap check-ins | Admitting you to events you booked, preventing pass re-use, and giving hosts an attendance record; check-in logs are retained for 180 days. |
2.2Mobile Phone Number Protection & Telecommunications Compliance
Phone numbers collected for authentication (via Twilio Inc.) are strictly utilized for operational security and account verification. Circl Network Inc. does not sell, rent, lease, or share user phone numbers or SMS opt-in consent with third parties or external marketers for marketing or promotional campaigns.
2.3Precise Geolocation Notice (Opt-In Requirement)
In compliance with international privacy laws (including Quebec Law 25 and EU GDPR), Circl processes precise GPS location data exclusively upon receiving explicit device-level opt-in consent. Users may adjust or revoke location permissions at any time through their iOS or Android system settings.
2.4Camera, QR Codes & Bluetooth Check-In (Mobile App)
Camera and photo library. The mobile app requests camera or photo-library access only when you take an action that needs it (adding photos to a post, message, or profile; an event host scanning a pass QR code). Access is governed by the device-level permission and can be revoked at any time in system settings. The app does not record audio.
Event pass QR codes. Your event pass displays a QR code containing your account identifier, the event identifier, and the session date — no other personal data. When a host scans it, the app checks you against the event's attendee list; the scan does not grant access to any other information about you.
Bluetooth tap check-in. When you open a membership card or event pass in the app, your device may broadcast a short-lived, cryptographically authenticated pass token over Bluetooth Low Energy so a host's device can check you in by proximity. The token contains your account identifier and the circl identifier, rotates every 15 seconds, and is broadcast only while the card is open on screen — never in the background. The host's reader records the check-in attempt (including refusals) with a signal-strength measurement used solely to confirm physical proximity; these check-in logs are retained for 180 days and are visible only to the hosting circl's staff. Bluetooth is optional: QR and name-list check-in work with the radio off.
Offline wallet cache. So your membership cards and event passes work at a door without an internet connection, the app stores a copy of your own cards, passes, and saved payment-method display details (never full card numbers) on your device. This cache exists only on your device, is refreshed when the app is online, and is cleared when you sign out or delete your account.
3Lawful Basis for Processing (EU & UK GDPR)
Under Article 6 of the General Data Protection Regulation (GDPR), Circl processes personal data based on:
- Contractual Necessity (Art. 6(1)(b)): Delivering core application functionality, processing ticket wallet purchases, facilitating direct messages, and transmitting login passcodes.
- Legitimate Interests (Art. 6(1)(f)): Protecting platform safety, preventing event ticketing fraud, securing server infrastructure, and analyzing system performance.
- Explicit Consent (Art. 6(1)(a)): Capturing real-time precise GPS coordinates and sending promotional notifications.
4Third-Party Sub-Processors & Data Transfer Partners
We transmit data to verified third-party sub-processors bound by strict Data Processing Addendums (DPAs):
| Sub-Processor | Core Functionality | Headquarters Jurisdiction |
|---|---|---|
| Twilio Inc. | SMS One-Time Password (OTP) infrastructure | United States |
| Supabase, Inc. | Cloud database hosting, user tables, & authentication | United States / AWS Edge |
| Stripe, Inc. | Payment processing, tokenization, & digital wallet receipts | United States |
| PayPal, Inc. | PayPal payment-method vaulting & payment processing | United States |
| Vercel Inc. | Application deployment & serverless API hosting | United States |
| PostHog, Inc. | Privacy-compliant app analytics & system performance | United States / EU Servers |
| komoot GmbH (Photon) | Geocoding: place-name search & event-address lookup (receives search text and approximate coordinates only — never your identity) | Germany / EU |
| Expo (650 Industries, Inc.) | Push-notification delivery (device push tokens & notification content) | United States |
| Resend (Plus Five Five, Inc.) | Transactional email for support requests | United States |
5Jurisdiction-Specific Privacy Rights
5.1Canadian Rights (PIPEDA & Quebec Law 25)
Canadian residents hold rights to access, correct, and withdraw consent for data processing. Under Quebec Law 25, Quebec residents possess the statutory right to request a copy of their personal data exported in a structured, standard, machine-readable format.
5.2United States Rights (CCPA / CPRA & State Privacy Laws)
California and US state residents hold the right to request disclosure of categories of personal information collected, request account deletion, and opt out of data sharing. Circl does not sell personal data to data brokers.
5.3European Union & United Kingdom Rights (GDPR)
Data subjects in the EEA and UK may exercise statutory rights under GDPR Articles 15–22, including Right of Access, Right to Erasure (“Right to be Forgotten”), and Right to Data Portability by emailing privacy@circlhq.com.
5.4How to Exercise Your Rights; Sale/Sharing & Global Privacy Control
In the app: Settings → “Your data” provides self-service access to a machine-readable export of your personal data (satisfying access and portability requests), and Settings → “Delete account” performs full account erasure directly. By email: any request, including on behalf of another person or a child, can be made to privacy@circlhq.com; we verify and respond within the timelines your jurisdiction requires.
No sale or sharing. Circl does not sell personal information, and does not share it for cross-context behavioural advertising, as those terms are defined by the CCPA/CPRA and equivalent state laws. Because no sale or sharing occurs, there is nothing to opt out of; we nonetheless treat a Global Privacy Control (GPC) signal as a valid opt-out request should any such processing be introduced, and this policy will be updated before any such change.
6Data Retention & Erasure Protocols
Circl retains personal data as long as an account remains active. When a user requests account deletion via mobile app settings, personal identifiers and real-time GPS logs are permanently deleted or anonymized within 30 calendar days.
- Event check-in logs: deleted 180 days after the check-in.
- Push notification tokens: removed on sign-out, and automatically after 90 days without the device being seen.
- Payment, invoicing, and tax records: retained beyond account deletion only to the extent required by financial, tax, and payment-dispute law.
Reach us at privacy@circlhq.com — we read everything.
