Last updated: August 2026
Vicinto is a live map of events near you. Privacy isn't a checkbox for us — it's the core design constraint of a product that puts people on a map. This policy explains what we collect, what we deliberately don't, and what we do with it.
Account: your email address or phone number (used for sign-in; verification codes are delivered by our SMS provider, Twilio), or the identifier shared when you sign in with Apple or Google, plus the profile information you choose to add — name, bio, Instagram or Snapchat handle, and an optional photo. If you have Vicinto Pro, a Pro badge and a featured map pin are shown to others.
Location — approximate only. When you set your map location, your device's coordinates are blurred on your device to a random point within the radius you choose (about a block to a neighborhood) before anything is sent to us. Your exact coordinates are never transmitted to or stored on our servers. You are invisible on the map by default and appear only while your visibility toggle is on.
Content & media: messages, and any photos or images you upload, in community chat, group chats, event chats, and direct messages; events you create and RSVP to. Direct messages are access-controlled so only the participants can read them. A message from someone you haven't added arrives as a message request and stays separate from your direct messages until you accept it. Don't upload media you don't have the rights to.
Profile views: we record when a signed-in member opens your profile so we can show you who viewed you (a paid feature). You can't be viewed anonymously by other members through this feature.
Connected contacts (optional): if you connect Apple Contacts, we access your contacts only to match them against Vicinto members and show you who's nearby. We never post, message, or take any action on those accounts, we don't share your contact list with other users, and you can disconnect a source at any time to stop the matching.
Purchases & tickets: when you buy an event ticket, a paid plan, or promotion for an event you host (a boost or sponsor slot), we record the transaction — what you bought, the amount, the date, and an order/ticket reference. We do not collect or store your full card number; card details are entered directly with our payment processors (see below) and never touch our servers. For event tickets we generate a unique QR code tied to your ticket; when an event organizer scans it at the door, we record that the ticket was checked in (and when), which is visible to that event's organizer for entry management.
Push notifications: if you allow notifications, we store a device push token so Apple can deliver them (new messages, friend requests, event updates). You can turn notifications off any time in iOS Settings, and we delete the token when you sign out or delete your account.
Camera (event hosts): the check-in scanner uses your camera solely to read guest ticket QR codes, live on your device. No photos or video are recorded, stored, or sent to us — only the result of a valid scan (that a ticket was checked in) is saved.
Apple Wallet passes: if you add a ticket to Apple Wallet, we generate a pass containing your event details and ticket QR code; it's stored on your device and managed by Apple Wallet.
On-device caching: the app keeps a local copy of content you've recently viewed (your inbox, chats, events, tickets) on your device so it works offline and loads instantly. This cache stays on your device and is cleared when you sign out or delete the app.
We don't sell your data. We don't share it with advertisers. We don't track your location in the background — there is no background tracking at all. Your location updates only while you're using the app — it refreshes to your current, blurred location when you open it, and never when the app is closed. We ask only for the location permission needed to place you on the map while you're using the app, nothing more.
Your approximate pin appears on the map only while your visibility toggle is on. When your profile is visible, it can also be opened by anyone with a direct link to it — for example when you or another member shares your profile — including people who don't have a Vicinto account; shared links show a preview (your name, bio, and photo) in messaging apps. Turning your visibility off removes you from the map and from shared-link previews. Event pages and their link previews (title, date, cover photo) are public. Your profile also shows the upcoming events you're attending or hosting; for any single event you can choose not to appear on its public guest list. If a chat owner gives you a role badge (like Promoter or Support), that badge is visible to that chat's members. Community chat is visible to members. Group messages are visible to that group's members. DMs are visible only to you and the recipient.
If you give us your phone number we text you two things and nothing else: a one-time sign-in code, and a link to a ticket or guest pass you asked for. We never send marketing texts, and we never sell or share your number, or your consent to be texted, with third parties for their own marketing. Message frequency varies with your own activity. Message and data rates may apply. Reply STOP to any message to opt out, HELP for help. Full detail, including exactly how each opt-in works, is on our SMS terms page.
Data is stored with Supabase (database and authentication) and served via Vercel, both with industry-standard encryption in transit and at rest. Phone-number verification codes are delivered by Twilio. These providers act as our service providers (sub-processors).
Vicinto uses two separate payment paths, and we share only the information each one needs to process your purchase:
Event tickets are processed by Stripe. When you buy a ticket, your payment details go directly to Stripe, who acts as our payment processor and the organizer's payout provider. We receive a confirmation, the amount, and a transaction reference — not your card number. Stripe handles your payment data under its own privacy policy.
Paid plans and boosts are processed through the app store you installed Vicinto from — Apple In-App Purchase on iOS — and managed with RevenueCat, which records your subscription status so we can unlock features. Apple processes the payment under its own privacy policy; we receive your subscription status, not your card details.
These processors act as our service providers (sub-processors). We don't sell or share this information with advertisers.
We use only a small number of strictly-necessary cookies to keep you signed in and remember your settings (these can't be turned off without breaking the app). We do not use advertising or cross-site tracking cookies, and we don't track you across other apps or websites. See our Cookie Policy for details.
To understand how Vicinto is used and to fix problems, we record a small set of in-app actions against your account — for example creating an event, sending a message, RSVPing, starting a checkout, or sharing a referral code — along with basic error reports when something breaks. This is first-party only: it stays in our own database, it is never sold or shared with advertisers, and it is not used to track you across other apps or websites. It is deleted when you delete your account.
Depending on where you live (including the EU/UK under GDPR and California under the CCPA/CPRA), you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can correct your data any time in Edit profile and delete your account and its data in Settings → Delete account. For access, export, objection or restriction, email privacy@vicinto.com and we'll respond within the time the law requires (within 45 days for CCPA/CPRA requests and one month for GDPR requests, unless we tell you we need an extension). We don't sell your personal information.
We keep your data only while your account is active. When you delete your account we remove your profile, map pin, messages, events, RSVPs, tickets, friends, uploaded photos, push tokens and product-analytics records. Two narrow exceptions: reports other people have filed about your account are kept for safety purposes with your identifier removed, and we retain limited records where the law requires it. Encrypted backups are retained for up to 30 days and then overwritten on a rolling schedule.
You can edit or clear any profile field, turn visibility off at any time, choose whether you appear on event attendee lists, and change your location radius. You can delete your account and its data yourself, at any time, in Settings → Delete account — no email required. If you'd rather we did it for you, email privacy@vicinto.com. See Data retention above for exactly what deletion removes.
Phone numbers collected for entry passes and sign-in codes are used only to send those transactional messages. We do not share your phone number or SMS opt-in consent with third parties or affiliates for their marketing purposes. Reply STOP to any message to opt out.
Vicinto is for people 18 and older.
If this policy changes materially, we'll notify members by email before the change takes effect.