Privacy Policy
Last updated
September 3, 2026 · Effective September 3, 2026
Pinglow Konnect Limited (“Pinglow”, “we”, “our”, or “us”) operates the Pinglow mobile application (iOS and Android) and website at pinglow.app (together, the “Platform”). This Privacy Policy explains what personal information we collect, why we collect it, how we use and share it, and the rights you have over your data.
By creating an account, accessing, or using the Platform, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Platform.
This Policy applies to all users of the Platform, including attendees, event organizers, and visitors. Pinglow is based in and operated from Nigeria, and we process personal data in accordance with the Nigeria Data Protection Act 2023 (“NDPA”) and applicable Nigerian data-protection regulations. The Platform is intended for users in Nigeria; if you access it from outside Nigeria, you do so on your own initiative and are responsible for compliance with the laws of your location.
1.Information We Collect
We collect information you provide directly, information generated by your use of the Platform, and limited information from third-party services.
1.1 Account and Identity Information
- Personal accounts: first name, last name, email address, country of residence, and a password (stored as a salted cryptographic hash - we never store your plaintext password).
- Organizer accounts: all of the above plus business name, and optionally a website URL, Instagram handle, Twitter/X handle, and a short public biography.
- OAuth sign-in (Google): if you sign in with Google, we receive your name, email address, and profile photo URL. We do not receive your Google password.
1.2 Profile Information
You may voluntarily add a profile photo, display name, and username. Profile photos are stored on secure cloud storage and may be visible to other authenticated users.
1.3 Precise Location Data
- Mobile (iOS/Android): we request foreground location permission only. We do not request background location access.
- Web: we request the browser’s Geolocation API each session when you open the map.
- What we transmit: latitude and longitude are sent to our backend to compute nearby results. Each location query is ephemeral - we do not build a continuous location history.
- If you deny location access: you may still browse the Platform but nearby filtering and map centering will be unavailable.
1.4 Event Activity and Transactions
- Check-ins: when an organizer scans your ticket at an event (admission), we record a check-in - your user ID, the event ID, and the timestamp - which we use to compute live crowd levels.
- Ticket purchases: we record the order ID, event ID, ticket tier, quantity, total amount paid, checkout contact information (name, email, phone), and an HMAC cryptographic signature for offline verification.
- Ticket validation: when a QR code is scanned at admission, we record the scan timestamp and mark the ticket as used.
- Search queries: recent search terms are stored locally on your device in AsyncStorage and are never transmitted to our servers.
- Friend connections: if you send, accept, decline, or remove a friend request, or block another user, we record that connection and its status between the two accounts involved.
1.5 Payment Information
Pinglow does not store card numbers, CVVs, or bank account numbers. All payment processing is handled by our third-party payment processor (PCI-DSS compliant). The specific provider is named in our Sub-processor List. We store only the payment reference, status, and amount - not card details. Our payment processor’s privacy policy governs how they handle your financial data.
1.6 Device and Technical Information
- Device type, operating system and version, browser type and version.
- App version and build number (mobile only).
- IP address at the time of authentication.
- Session tokens stored securely via our auth provider; mobile tokens persist in encrypted device storage.
- Crash reports and performance traces collected by our error monitoring service, which may include device state, stack traces, and breadcrumbs. No plaintext passwords or payment data are included.
- Push notification token (mobile only): if you enable notifications, we store a device push token used to deliver event reminders and the alerts you’ve opted into in Settings. Disabling notifications or deleting your account removes the stored token.
1.7 Analytics and Usage Data
We use a third-party product analytics platform to understand how users interact with the Platform. It collects page views, feature interactions, session recordings (web only), and performance metrics. Data is associated with an anonymous identifier. We have configured our analytics platform to respect Do Not Track signals where supported. The specific provider is named in our Sub-processor List.
1.8 Communications
We send transactional emails through a third-party email delivery provider, including: order confirmation emails after a successful ticket purchase, event reminder emails approximately one hour before events you have tickets for, and account-related emails (e.g. email verification, password reset). We do not currently send marketing emails. The specific provider is named in our Sub-processor List.
2.How We Use Your Information
We use the information we collect for the following purposes:
| Purpose | Data Used | Legal Basis (NDPA) |
|---|---|---|
| Provide and operate the Platform | Account info, location, event activity | Performance of a contract |
| Authenticate identity and maintain sessions | Email, password hash, device info, IP | Performance of a contract |
| Show nearby events and places | Precise location (ephemeral) | Performance of a contract |
| Compute real-time crowd levels | Check-in records | Legitimate interests |
| Process ticket purchases and deliver tickets | Purchase info, contact info, payment reference | Performance of a contract |
| Send order confirmations and event reminders | Email address, ticket/event data | Performance of a contract |
| Enable organizer event management and analytics | Ticket data, attendee contact info, revenue data | Performance of a contract |
| Validate tickets via QR scan | Ticket ID, HMAC signature | Performance of a contract |
| Manage friend connections and share event presence with friends | Friend connection records, check-in records, Ghost Mode / Show Location settings | Consent |
| Send push notifications (event reminders, friend activity, alerts) | Push token, notification preferences | Consent |
| Detect and prevent fraud and abuse | Account info, device info, IP, activity logs | Legitimate interests |
| Debug errors and improve reliability | Crash reports, device info | Legitimate interests |
| Analyze product usage and improve features | Usage data (anonymous) | Legitimate interests / Consent |
| Comply with legal obligations | Any relevant data | Legal obligation |
| Enforce Terms of Service | Account info, activity logs | Legitimate interests |
3.How We Share Your Information
We do not sell, rent, or trade your personal information to third parties. We share your data only as described below.
3.1 Event Organizers
When you purchase a ticket, the organizer receives your checkout contact information (name, email, phone) for event management purposes only. Organizers are bound by our Terms of Service and may not use your data for unrelated purposes or share it with third parties.
3.2 Public Profile Information and Friends
Your username, display name, and profile photo (if set) are visible to any user you send or receive a friend request from, and to your accepted friends. Whether your check-in at an event is visible to friends attending the same event is controlled by the Ghost Mode and Show Location toggles in Settings (Show Location is on and Ghost Mode is off by default; enabling Ghost Mode or turning off Show Location stops friend presence-sharing immediately). You can remove a friend connection or block another user at any time from the Friends section of the app. You can update or remove your profile photo, display name, and username at any time in your profile settings.
3.3 Service Providers (Sub-processors)
We engage third-party sub-processors who process personal data on our behalf under contractual obligations to protect it. For the full named list of specific companies, including their locations and the data shared with each, see our Sub-processor List, maintained separately so provider changes can be reflected without a full policy revision. The categories of sub-processors we use are:
| Category | Purpose | Data Types |
|---|---|---|
| Cloud infrastructure, database & auth | Database hosting, authentication, file storage, real-time subscriptions | All Platform data |
| Interactive mapping & geocoding | Map rendering, location search, reverse geocoding | Map requests, geocoding queries |
| Payment processing | Ticket payment collection and webhook verification | Payment reference and status only |
| Transactional email delivery | Order confirmations, event reminders, account emails | Email address, name, order/event details |
| Error monitoring | Detecting and diagnosing application errors | Device info, stack traces, user ID |
| Product analytics | Understanding feature usage and product performance | Usage events, anonymous identifier |
| Mobile app distribution | App delivery to iOS/Android, over-the-air updates | App usage metadata |
| App store platforms | iOS/Android distribution; Google Sign-In OAuth | OAuth token, basic Google profile |
3.4 Legal and Safety Disclosures
We may disclose your information to law enforcement or other parties when necessary to: comply with applicable law or legal process; protect the safety, rights, or property of Pinglow, our users, or the public; detect or prevent fraud or security issues; or enforce our Terms of Service.
3.5 Business Transfers
If Pinglow is involved in a merger, acquisition, or asset sale, your personal data may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.
4.Data Retention
We retain personal data as long as necessary to fulfil the purposes described in this Policy, unless a longer retention period is required by law.
| Data Type | Retention Period |
|---|---|
| Account and profile data | Until you delete your account, plus 30 days for recovery |
| Check-in records | 24 months from the date of check-in |
| Friend connection records | Until you remove the friend, decline/cancel the request, or delete your account |
| Push notification tokens | Until you disable notifications or delete your account |
| Ticket and order records | 7 years (financial/legal compliance) |
| Payment references | 7 years (financial/legal compliance) |
| Transactional email delivery logs | 30 days |
| Crash reports | 90 days |
| Product analytics | 12 months, then anonymized |
| Authentication logs | 90 days |
| Deleted account data | Purged within 30 days, except where legally required |
Anonymized or aggregated data that cannot reasonably be re-identified may be retained indefinitely for statistical purposes.
5.Your Rights and Choices
Depending on your jurisdiction, you have some or all of the following rights. We respond to all verified requests within 30 days.
Right of Access
Request a copy of all personal data we hold about you and how it is processed.
Right to Rectification
Request correction of inaccurate or incomplete data. You can update most profile information directly in the app at any time.
Right to Erasure
Request deletion of your account and associated personal data by emailing privacy@pinglow.app. We process deletions within 30 days. Certain data (e.g. financial records) may be retained to comply with legal obligations.
Right to Restriction
Request that we restrict processing of your personal data in certain circumstances (e.g. while you contest data accuracy).
Right to Portability
Receive your data in a structured, machine-readable format (JSON or CSV) and transmit it to another controller where processing is based on consent or contract.
Right to Object
Object to processing based on legitimate interests. We will cease unless we can demonstrate compelling grounds that override your interests.
Right to Withdraw Consent
Withdraw consent at any time (e.g. location access, analytics, push notifications) without affecting prior lawful processing. Revoke location or notification permission in your device settings, or stop sharing your event presence with friends at any time via Ghost Mode / Show Location in the app’s Settings.
Opt-Out of Analytics
Opt out of analytics collection by contacting privacy@pinglow.app. On web, you may also use a browser-level Do Not Track signal.
Right to Lodge a Complaint
If you believe we have not handled your personal data in accordance with the NDPA, you may lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpb.gov.ng. We encourage you to contact us first at privacy@pinglow.app so we can try to resolve it.
6.International Data Transfers
Our infrastructure relies on service providers (listed in our Sub-processor List) that are primarily located in the United States. When we transfer personal data outside Nigeria, we rely on the cross-border transfer mechanisms permitted under the NDPA - including transfers to jurisdictions recognised as providing adequate protection and contractual data-protection safeguards with our providers. You may request details of the relevant safeguards by contacting privacy@pinglow.app.
7.Data Security
We implement appropriate technical and organizational security measures including:
- Encryption in transit: all data between your device and our servers is encrypted using TLS 1.2 or higher.
- Encryption at rest: our database and storage infrastructure encrypts data at rest using AES-256.
- Password security: user passwords are never stored in plaintext - bcrypt hashing with a per-user salt is applied.
- Ticket signing: each ticket carries an HMAC-SHA256 cryptographic signature generated at purchase. The secret key is stored exclusively server-side.
- Row-level security: database RLS policies prevent any authenticated user from accessing data belonging to another user unless explicitly authorized.
- Session management: authentication tokens are short-lived and rotated on each refresh. Mobile tokens are stored in encrypted AsyncStorage.
- Access controls: internal access to production data is restricted to authorized personnel on a need-to-know basis.
No transmission over the internet or electronic storage is 100% secure. If you believe your account has been compromised, contact support@pinglow.app immediately.
8.Children’s Privacy
The Platform is not directed to individuals under 16. We do not knowingly collect personal data from children under 16. If you believe your child has provided us with personal data, contact privacy@pinglow.app and we will promptly delete it. In jurisdictions where digital consent age is higher (e.g., 18), that higher threshold applies. Minors under applicable law may only use the Platform with parental or guardian consent and supervision.
9.Cookies and Tracking Technologies
9.1 What We Use
- Strictly necessary: authentication session tokens stored in HTTP-only cookies. Required for the Platform to function.
- Analytics cookies: first-party cookies set by our analytics provider to understand usage patterns. Set only with your consent where required by law.
- LocalStorage (web): used to persist UI preferences such as filter settings.
9.2 Cookie Consent
Where required by law, we display a cookie consent banner on your first visit. You may accept or decline non-essential cookies. Change preferences anytime by clearing browser cookies or adjusting browser settings.
9.3 Mobile
The mobile app does not use browser cookies. Analytics events are sent to our analytics provider via an in-app SDK with an anonymous device identifier. Session tokens are stored in Expo SecureStore (iOS Keychain / Android Keystore).
10.Organizer-Specific Privacy Obligations
If you use Pinglow as an event organizer, you access attendee personal data (names, emails, phone numbers) through the organizer dashboard. In this capacity, you act as an independent data controller with respect to attendees’ data and must:
- Process attendee data only for purposes related to the management and execution of your Pinglow events.
- Not share, sell, or use attendee data for marketing without obtaining separate informed consent from each attendee.
- Implement appropriate security measures to protect any attendee data you export or download.
- Comply with all applicable data protection laws in your jurisdiction.
- Delete or return attendee data upon request or when no longer needed.
Pinglow acts as a data processor on behalf of organizers with respect to attendee data. We process it strictly as instructed and have implemented technical controls (Row-Level Security, role-based access) to ensure organizers can only access data for their own events.
11.Third-Party Links and Services
The Platform may display links to third-party websites or event venue pages. Such links are provided for convenience and do not constitute an endorsement. This Policy applies only to information collected by Pinglow.
12.Changes to This Privacy Policy
When we make material changes, we will: update the “Last updated” date at the top of this page; send an email notification to registered users; and display a prominent notice on the Platform for at least 14 days. Your continued use after the effective date constitutes acceptance of the changes.
13.Contact Us
For questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Privacy team:
We aim to respond to privacy inquiries within 5 business days and resolve all valid rights requests within 30 calendar days.
