Privacy Policy
This Privacy Policy ("Policy") describes how Downtown Social Pvt. Ltd. ("Downtown," "we," "us," or "our") collects, uses, discloses, stores, and protects personal information when you use the Downtown mobile application ("App") or visit our website at downtownsocial.in ("Site"). By using the App or Site, you acknowledge you have read and understood this Policy.
This Policy is intended to comply with applicable data protection laws, including but not limited to: the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) as amended by CPRA, India's Digital Personal Data Protection Act (DPDPA) 2023, and the requirements of the Google Play Store and Apple App Store.
1. Who This Policy Applies To
This Policy applies to all users of the Downtown App and website globally. Additional rights for residents of the EU/EEA, UK, California, and India are detailed in Sections 12–15.
Our Commitment: Downtown is designed with privacy-first engineering. We pseudonymize location data before processing, enforce a strict 7-day ephemeral deletion policy on messages and map markers, and give you granular control over your visibility at all times.
2. Information We Collect
2.1 Information You Provide Directly
- Account Registration: Name, email address, and optionally a phone number, used for authentication and identity verification.
- Profile Information: Profile photo, username, and bio that you choose to display.
- User Content: Photos, videos, short-form posts, comments, and reactions that you voluntarily post to the App.
- Direct Messages: Content of private messages sent through Downtown's in-app messaging system.
- Support Requests: Communications you send to our support team, including email content.
- Waitlist Data (Website): Name, email, and city entered via our pre-launch waitlist form.
2.2 Information Automatically Collected
- Precise & Approximate Location: When you enable location access, the App collects your GPS coordinates to power the real-time social map. We apply spatial anonymization techniques before any location data is processed for discovery features, ensuring your exact coordinates are never exposed to other users.
- Device Identifiers: Device type, operating system version, unique device identifiers (e.g., advertising ID), and mobile network information, used for security, diagnostics, and crash reporting.
- Usage & Analytics Data: Actions you take within the App (e.g., screens visited, features used), session durations, and performance telemetry — collected in pseudonymized form via Firebase Analytics.
- Log Data: IP address, access timestamps, and error logs for security monitoring and fraud prevention.
2.3 Device Permissions & Hardware Access
Certain core features of the App require access to device hardware and operating system permissions. We request each permission only at the moment it is first needed, and only for the purposes stated below. You can revoke any permission at any time via your device OS settings (iOS: Settings → Privacy & Security; Android: Settings → Apps → Downtown → Permissions).
| Permission | Why We Need It | What We Collect | How to Revoke |
|---|---|---|---|
| Camera | To let you capture photos directly within the app for use in chat conversations and as your profile photo. | The photo image you choose to capture and submit. Raw camera feed is never recorded, stored, or transmitted. | iOS: Settings → Privacy & Security → Camera → Downtown (toggle off). Android: Settings → Apps → Downtown → Permissions → Camera (deny). |
| Photo Library / Media Storage (READ_MEDIA_IMAGES on Android) |
To let you select existing photos from your device gallery when creating posts, attaching images in chat, or updating your profile photo. | Only the specific photo(s) you explicitly select and submit. We do not scan or index your entire photo library. | iOS: Settings → Privacy & Security → Photos → Downtown → select "None". Android: Settings → Apps → Downtown → Permissions → Photos and Media (deny). |
| Precise Location (GPS) (ACCESS_FINE_LOCATION on Android) |
To power the real-time social map, show you content from nearby users, and display your presence on the live map to others (subject to your privacy controls). | Your GPS coordinates, collected while the app is in use. Coordinates are spatially anonymized before being processed for discovery features. Your exact coordinates are never exposed to other users. | iOS: Settings → Privacy & Security → Location Services → Downtown → Never. Android: Settings → Apps → Downtown → Permissions → Location → Deny. Revoking this permission completely stops all location processing. |
| Push Notifications (POST_NOTIFICATIONS on Android 13+) |
To send you event reminders for social posts you follow, direct message alerts, and important account security notices. | A Firebase Cloud Messaging (FCM) push token is stored on our servers to route notifications to your device. Notification content (e.g., message preview) is end-to-end encrypted in transit. | iOS: Settings → Notifications → Downtown → toggle off. Android: Settings → Apps → Downtown → Notifications → toggle off. You can also manage notification categories within the App under Settings → Notifications. |
2.4 Firebase Performance Monitoring
The App integrates Firebase Performance Monitoring (Google LLC) to measure app responsiveness and network reliability. This SDK automatically collects:
- Network request traces: URL host, response code, payload size, and request duration for HTTP/S calls made by the App — used to identify slow API endpoints and improve reliability.
- Screen rendering metrics: Frame rates and slow/frozen frame counts per screen — used to detect UI jank and optimize rendering performance.
- App start time: Cold and warm start durations.
All Firebase Performance data is attributed to a pseudonymous Firebase installation ID, not your personal identity. This data is processed by Google LLC under Google's Privacy Policy and our Data Processing Agreement. You can opt out of Firebase Performance data collection by disabling it in App Settings → Privacy & Security → Analytics & Performance.
2.5 Information From Third Parties
- Google Sign-In: If you authenticate via Google, we receive your name, email address, and profile photo from Google in accordance with your Google account settings and Google's Privacy Policy.
- Firebase: Remote configuration, push notification tokens, crash analytics (Crashlytics), and performance monitoring data are sourced from Google Firebase.
3. Legal Basis for Processing (GDPR)
| Processing Activity | Legal Basis |
|---|---|
| Account creation & authentication | Performance of Contract (Art. 6(1)(b)) |
| Displaying your content on the social map | Performance of Contract (Art. 6(1)(b)) |
| Location-based discovery features | Consent (Art. 6(1)(a)) |
| Security, fraud prevention & abuse detection | Legitimate Interests (Art. 6(1)(f)) |
| App analytics & performance monitoring | Legitimate Interests (Art. 6(1)(f)) |
| Complying with legal obligations | Legal Obligation (Art. 6(1)(c)) |
| Marketing communications (opt-in) | Consent (Art. 6(1)(a)) |
4. How We Use Your Information
- To operate, maintain, and improve the Downtown App and its core features.
- To personalize your local social discovery experience using pseudonymized location data.
- To send push notifications and in-app alerts relevant to your local area, including event reminders for posts you follow and direct message alerts (you may disable these in device settings or within the App).
- To allow you to capture and send photos via the device camera or select photos from your gallery for use in chat conversations and profile images.
- To detect, investigate, and prevent fraudulent activity, harassment, spam, and security breaches.
- To comply with applicable laws, respond to legal requests, and enforce our Terms of Service.
- To send transactional emails (account verification, security alerts) and, with consent, promotional communications about new features or city launches.
- To aggregate and anonymize data for statistical research and product improvement.
- To monitor App performance and network reliability via Firebase Performance Monitoring, enabling us to identify and resolve technical issues proactively.
5. Ephemeral Data Policy (7-Day Auto-Deletion)
Downtown's core design principle is that social content should be live and temporary:
- Direct Messages: All private messages and group channel messages are automatically and permanently deleted from our production systems 7 days after they are sent. This is enforced at the infrastructure level and cannot be recovered after deletion.
- Map Markers & Posts: All social posts pinned to the live map expire and are permanently removed from our servers 7 days after creation or last activity.
- Profile data, account information, and follow relationships are retained until you delete your account.
6. Your Privacy Controls In the App
You have granular, real-time control over your social visibility from within the App (Settings → Privacy & Security):
| Control | Options | Effect |
|---|---|---|
| Account Visibility | Public / Private | Private: only approved followers can see your posts. Public: all Downtown users can see your content. |
| Location Visibility | Everyone / Followers Only / Hidden | Controls who can see your presence on the live map. "Hidden" makes you completely invisible to other nearby users. |
| Blocking | Block user | Blocked users cannot see your profile, content, or location; you cannot see theirs. |
| OS Location Permission | Always / While Using / Never | Revoking location permission from your device OS completely stops all location processing. |
7. Data Sharing & Third-Party Processors
We do not sell, rent, or trade your personal data. We share data only with the following categories of processors, each bound by data processing agreements consistent with GDPR Article 28:
- Google Firebase (Google LLC): Authentication, cloud database, push notifications, crash analytics, and performance monitoring. Data processed in the US under Standard Contractual Clauses (SCCs).
- Cloudflare Inc.: Web application firewall, DDoS protection, and edge delivery of static web assets. Data processed globally under SCCs and EU-US Data Privacy Framework.
- MapLibre GL: Open-source map rendering library. Tile requests may be routed to tile servers you configure. No personal data is shared with MapLibre itself.
- Law Enforcement & Legal Process: We may disclose data in response to a valid court order, subpoena, or governmental authority request, to the extent required by applicable law.
8. International Data Transfers
Downtown operates globally. Your data may be transferred to and processed in countries other than your country of residence, including India, the United States, and countries in the European Economic Area. We ensure all cross-border data transfers are protected by appropriate safeguards as required by applicable law (e.g., Standard Contractual Clauses for EEA transfers).
Specifically, the following Google Firebase services may transfer and process data on Google's infrastructure in the United States and the European Union:
- Firebase Crashlytics: Crash logs, device model, OS version, and app version are transmitted to Google servers upon app crash. This data is used exclusively for diagnosing and resolving software defects.
- Firebase Performance Monitoring: Network trace metadata and rendering performance metrics are transmitted to Google servers in real time as the App is used.
- Firebase Cloud Messaging (FCM): Push notification tokens and notification payloads are routed through Google's FCM infrastructure.
All such transfers are governed by Standard Contractual Clauses (SCCs) between Downtown Social Pvt. Ltd. and Google LLC, ensuring an adequate level of protection consistent with GDPR Article 46.
8a. Play Store Data Safety Summary
The table below maps directly to Google Play's Data Safety form and is provided to help users and reviewers understand our data practices at a glance. For full details, refer to the relevant sections of this Policy.
| Data Type | Collected? | Purpose | Shared? | Required or Optional? | Encrypted? | User Can Delete? |
|---|---|---|---|---|---|---|
| Precise Location | Yes | App functionality & Advertising/Marketing | Yes — Firebase (pseudonymized) | Required for maps; optional for auth | Yes (TLS 1.3) | Yes — revoke OS permission; auto-deleted on account deletion |
| Photos & Videos | Yes (user-initiated) | App functionality & Advertising/Marketing | Yes — Firebase Storage | Optional — user-selected upload only | Yes (TLS 1.3) | Yes — delete in-app or via account deletion; 7-day auto-wipe |
| Name & Email Address | Yes | Account management & authentication | Yes — Firebase Auth | Required for registration | Yes (TLS 1.3) | Yes — account deletion removes within 30 days |
| Profile Photo | Yes (user-initiated) | App functionality (profile display) | Yes — Firebase Storage | Optional | Yes (TLS 1.3) | Yes — user can remove or modify in-app |
| Messages (Chat) | Yes | App functionality (direct messaging) | Yes — Firebase (for delivery) | Required to use chat | Yes (TLS 1.3 + encrypted at rest) | Yes — auto-permanently deleted after 7 days |
| Crash Logs & Diagnostics | Yes | Analytics (Firebase Crashlytics) | Yes — Google LLC (Crashlytics) | Automatic (required for stability) | Yes | Opt-out available in App Settings → Privacy & Security |
| App Performance Data | Yes | Analytics (Firebase Performance) | Yes — Google LLC (Firebase) | Automatic (can be disabled) | Yes | Opt-out available in App Settings → Privacy & Security |
| Push Notification Token | Yes | App functionality (alerts/chat) | Yes — Firebase Cloud Messaging | Optional (revocable in OS settings) | Yes | Yes — revoke notification permission in OS settings |
| Device Identifiers | Yes | Security, fraud prevention & analytics | Yes — Firebase | Automatic (required for security) | Yes | Deleted on account deletion |
Data Sale: Downtown does not sell, rent, or trade any personal data to third parties for advertising or any other commercial purpose.
9. Data Retention
- Messages & Map Markers: Automatically deleted after 7 days.
- Account & Profile Data: Retained for the duration of your account. Deleted within 30 days of account deletion request.
- Aggregated Analytics: Retained in anonymized form for up to 2 years for product research.
- Security Logs: Retained for up to 90 days for fraud detection and investigation.
- Legal Hold: Data subject to active legal proceedings may be retained beyond the above periods as required by law.
10. Children's Privacy
The Downtown App and website are not directed at children under the age of 13 (or 16 in certain EU jurisdictions). We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal data, please contact us immediately at support@downtownsocial.in and we will take steps to delete such information.
11. Advertising & Marketing
Downtown may show personalized content or "Sponsored" social markers on the live map based on your pseudonymized location and profile interests. We do not sell your data to third-party advertisers. All personalized advertising is handled within our own infrastructure to preserve your privacy.
- Personalized Ads: We use your city, general location, and in-app activity to show you relevant local events or business promotions. You can opt out of personalized ads in App Settings → Privacy & Security → Personalization.
- Marketing Communications: If you have opted in, we may send you occasional emails or push notifications about new city launches or premium features. You can unsubscribe at any time.
12. Security
We implement administrative, technical, and physical safeguards designed to protect your data against unauthorized access, disclosure, alteration, and destruction. These include end-to-end transport encryption (TLS 1.3), server-side database encryption at rest, internal access controls on a need-to-know basis, and regular security audits. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
13. Your Rights Under GDPR (EU/EEA/UK Users)
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Correct inaccurate or incomplete data.
- Right to Erasure ("Right to Be Forgotten"): Request permanent deletion of your personal data.
- Right to Portability: Receive your personal data in a structured, machine-readable format.
- Right to Restrict Processing: Object to or restrict certain data processing activities, including profiling for personalized ads.
- Right to Withdraw Consent: Withdraw previously granted consent at any time (e.g., location access) without affecting prior lawful processing.
- Right to Lodge a Complaint: File a complaint with your national Data Protection Authority (e.g., ICO in the UK, CNIL in France).
14. Your Rights Under CCPA/CPRA (California Users)
- Right to Know: Request disclosure of the categories and specific pieces of personal data collected about you in the past 12 months.
- Right to Delete: Request deletion of personal data we have collected, subject to certain exceptions.
- Right to Opt-Out of Sale/Sharing: Downtown does not sell or share personal data for cross-context behavioral advertising. We only show internal personalized ads within our own platform.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.
15. Indian User Rights (DPDPA 2023)
If you are located in India, you have the right to access, correct, and erase your personal data under the Digital Personal Data Protection Act 2023. You may nominate another individual to exercise your rights on your behalf. To exercise your rights, contact our Data Protection Officer via support@downtownsocial.in.
16. How to Exercise Your Rights
To exercise any of the rights above, or to submit a data deletion request, please visit our Data Rights Portal or email us at support@downtownsocial.in. We will respond within:
- 30 days for GDPR requests (extendable by 60 days for complex requests with notice).
- 45 days for CCPA requests (extendable by 45 days with notice).
17. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Effective Date" at the top of this page and, where feasible, by sending notice through the App. Continued use of the App after changes constitutes acceptance of the revised Policy.
18. Data Protection Officer & Contact
- Data Protection Officer: support@downtownsocial.in
- General Support: support@downtownsocial.in
- Registered Entity: Downtown Social Pvt. Ltd., India.