Pinglow logoPINGLOW
Legal

Privacy Policy

Last updated

September 3, 2026 · Effective September 3, 2026

Pinglow Konnect Limited (“Pinglow”, “we”, “our”, or “us”) operates the Pinglow mobile application (iOS and Android) and website at pinglow.app (together, the “Platform”). This Privacy Policy explains what personal information we collect, why we collect it, how we use and share it, and the rights you have over your data.

By creating an account, accessing, or using the Platform, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Platform.

This Policy applies to all users of the Platform, including attendees, event organizers, and visitors. Pinglow is based in and operated from Nigeria, and we process personal data in accordance with the Nigeria Data Protection Act 2023 (“NDPA”) and applicable Nigerian data-protection regulations. The Platform is intended for users in Nigeria; if you access it from outside Nigeria, you do so on your own initiative and are responsible for compliance with the laws of your location.


1.Information We Collect

We collect information you provide directly, information generated by your use of the Platform, and limited information from third-party services.

1.1 Account and Identity Information

  • Personal accounts: first name, last name, email address, country of residence, and a password (stored as a salted cryptographic hash - we never store your plaintext password).
  • Organizer accounts: all of the above plus business name, and optionally a website URL, Instagram handle, Twitter/X handle, and a short public biography.
  • OAuth sign-in (Google): if you sign in with Google, we receive your name, email address, and profile photo URL. We do not receive your Google password.

1.2 Profile Information

You may voluntarily add a profile photo, display name, and username. Profile photos are stored on secure cloud storage and may be visible to other authenticated users.

1.3 Precise Location Data

  • Mobile (iOS/Android): we request foreground location permission only. We do not request background location access.
  • Web: we request the browser’s Geolocation API each session when you open the map.
  • What we transmit: latitude and longitude are sent to our backend to compute nearby results. Each location query is ephemeral - we do not build a continuous location history.
  • If you deny location access: you may still browse the Platform but nearby filtering and map centering will be unavailable.

1.4 Event Activity and Transactions

  • Check-ins: when an organizer scans your ticket at an event (admission), we record a check-in - your user ID, the event ID, and the timestamp - which we use to compute live crowd levels.
  • Ticket purchases: we record the order ID, event ID, ticket tier, quantity, total amount paid, checkout contact information (name, email, phone), and an HMAC cryptographic signature for offline verification.
  • Ticket validation: when a QR code is scanned at admission, we record the scan timestamp and mark the ticket as used.
  • Search queries: recent search terms are stored locally on your device in AsyncStorage and are never transmitted to our servers.
  • Friend connections: if you send, accept, decline, or remove a friend request, or block another user, we record that connection and its status between the two accounts involved.

1.5 Payment Information

Pinglow does not store card numbers, CVVs, or bank account numbers. All payment processing is handled by our third-party payment processor (PCI-DSS compliant). The specific provider is named in our Sub-processor List. We store only the payment reference, status, and amount - not card details. Our payment processor’s privacy policy governs how they handle your financial data.

1.6 Device and Technical Information

  • Device type, operating system and version, browser type and version.
  • App version and build number (mobile only).
  • IP address at the time of authentication.
  • Session tokens stored securely via our auth provider; mobile tokens persist in encrypted device storage.
  • Crash reports and performance traces collected by our error monitoring service, which may include device state, stack traces, and breadcrumbs. No plaintext passwords or payment data are included.
  • Push notification token (mobile only): if you enable notifications, we store a device push token used to deliver event reminders and the alerts you’ve opted into in Settings. Disabling notifications or deleting your account removes the stored token.

1.7 Analytics and Usage Data

We use a third-party product analytics platform to understand how users interact with the Platform. It collects page views, feature interactions, session recordings (web only), and performance metrics. Data is associated with an anonymous identifier. We have configured our analytics platform to respect Do Not Track signals where supported. The specific provider is named in our Sub-processor List.

1.8 Communications

We send transactional emails through a third-party email delivery provider, including: order confirmation emails after a successful ticket purchase, event reminder emails approximately one hour before events you have tickets for, and account-related emails (e.g. email verification, password reset). We do not currently send marketing emails. The specific provider is named in our Sub-processor List.


2.How We Use Your Information

We use the information we collect for the following purposes:

PurposeData UsedLegal Basis (NDPA)
Provide and operate the PlatformAccount info, location, event activityPerformance of a contract
Authenticate identity and maintain sessionsEmail, password hash, device info, IPPerformance of a contract
Show nearby events and placesPrecise location (ephemeral)Performance of a contract
Compute real-time crowd levelsCheck-in recordsLegitimate interests
Process ticket purchases and deliver ticketsPurchase info, contact info, payment referencePerformance of a contract
Send order confirmations and event remindersEmail address, ticket/event dataPerformance of a contract
Enable organizer event management and analyticsTicket data, attendee contact info, revenue dataPerformance of a contract
Validate tickets via QR scanTicket ID, HMAC signaturePerformance of a contract
Manage friend connections and share event presence with friendsFriend connection records, check-in records, Ghost Mode / Show Location settingsConsent
Send push notifications (event reminders, friend activity, alerts)Push token, notification preferencesConsent
Detect and prevent fraud and abuseAccount info, device info, IP, activity logsLegitimate interests
Debug errors and improve reliabilityCrash reports, device infoLegitimate interests
Analyze product usage and improve featuresUsage data (anonymous)Legitimate interests / Consent
Comply with legal obligationsAny relevant dataLegal obligation
Enforce Terms of ServiceAccount info, activity logsLegitimate interests

3.How We Share Your Information

We do not sell, rent, or trade your personal information to third parties. We share your data only as described below.

3.1 Event Organizers

When you purchase a ticket, the organizer receives your checkout contact information (name, email, phone) for event management purposes only. Organizers are bound by our Terms of Service and may not use your data for unrelated purposes or share it with third parties.

3.2 Public Profile Information and Friends

Your username, display name, and profile photo (if set) are visible to any user you send or receive a friend request from, and to your accepted friends. Whether your check-in at an event is visible to friends attending the same event is controlled by the Ghost Mode and Show Location toggles in Settings (Show Location is on and Ghost Mode is off by default; enabling Ghost Mode or turning off Show Location stops friend presence-sharing immediately). You can remove a friend connection or block another user at any time from the Friends section of the app. You can update or remove your profile photo, display name, and username at any time in your profile settings.

3.3 Service Providers (Sub-processors)

We engage third-party sub-processors who process personal data on our behalf under contractual obligations to protect it. For the full named list of specific companies, including their locations and the data shared with each, see our Sub-processor List, maintained separately so provider changes can be reflected without a full policy revision. The categories of sub-processors we use are:

CategoryPurposeData Types
Cloud infrastructure, database & authDatabase hosting, authentication, file storage, real-time subscriptionsAll Platform data
Interactive mapping & geocodingMap rendering, location search, reverse geocodingMap requests, geocoding queries
Payment processingTicket payment collection and webhook verificationPayment reference and status only
Transactional email deliveryOrder confirmations, event reminders, account emailsEmail address, name, order/event details
Error monitoringDetecting and diagnosing application errorsDevice info, stack traces, user ID
Product analyticsUnderstanding feature usage and product performanceUsage events, anonymous identifier
Mobile app distributionApp delivery to iOS/Android, over-the-air updatesApp usage metadata
App store platformsiOS/Android distribution; Google Sign-In OAuthOAuth token, basic Google profile

3.4 Legal and Safety Disclosures

We may disclose your information to law enforcement or other parties when necessary to: comply with applicable law or legal process; protect the safety, rights, or property of Pinglow, our users, or the public; detect or prevent fraud or security issues; or enforce our Terms of Service.

3.5 Business Transfers

If Pinglow is involved in a merger, acquisition, or asset sale, your personal data may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.


4.Data Retention

We retain personal data as long as necessary to fulfil the purposes described in this Policy, unless a longer retention period is required by law.

Data TypeRetention Period
Account and profile dataUntil you delete your account, plus 30 days for recovery
Check-in records24 months from the date of check-in
Friend connection recordsUntil you remove the friend, decline/cancel the request, or delete your account
Push notification tokensUntil you disable notifications or delete your account
Ticket and order records7 years (financial/legal compliance)
Payment references7 years (financial/legal compliance)
Transactional email delivery logs30 days
Crash reports90 days
Product analytics12 months, then anonymized
Authentication logs90 days
Deleted account dataPurged within 30 days, except where legally required

Anonymized or aggregated data that cannot reasonably be re-identified may be retained indefinitely for statistical purposes.


5.Your Rights and Choices

Depending on your jurisdiction, you have some or all of the following rights. We respond to all verified requests within 30 days.

5.1

Right of Access

Request a copy of all personal data we hold about you and how it is processed.

5.2

Right to Rectification

Request correction of inaccurate or incomplete data. You can update most profile information directly in the app at any time.

5.3

Right to Erasure

Request deletion of your account and associated personal data by emailing privacy@pinglow.app. We process deletions within 30 days. Certain data (e.g. financial records) may be retained to comply with legal obligations.

5.4

Right to Restriction

Request that we restrict processing of your personal data in certain circumstances (e.g. while you contest data accuracy).

5.5

Right to Portability

Receive your data in a structured, machine-readable format (JSON or CSV) and transmit it to another controller where processing is based on consent or contract.

5.6

Right to Object

Object to processing based on legitimate interests. We will cease unless we can demonstrate compelling grounds that override your interests.

5.7

Right to Withdraw Consent

Withdraw consent at any time (e.g. location access, analytics, push notifications) without affecting prior lawful processing. Revoke location or notification permission in your device settings, or stop sharing your event presence with friends at any time via Ghost Mode / Show Location in the app’s Settings.

5.8

Opt-Out of Analytics

Opt out of analytics collection by contacting privacy@pinglow.app. On web, you may also use a browser-level Do Not Track signal.

Right to Lodge a Complaint

If you believe we have not handled your personal data in accordance with the NDPA, you may lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpb.gov.ng. We encourage you to contact us first at privacy@pinglow.app so we can try to resolve it.


6.International Data Transfers

Our infrastructure relies on service providers (listed in our Sub-processor List) that are primarily located in the United States. When we transfer personal data outside Nigeria, we rely on the cross-border transfer mechanisms permitted under the NDPA - including transfers to jurisdictions recognised as providing adequate protection and contractual data-protection safeguards with our providers. You may request details of the relevant safeguards by contacting privacy@pinglow.app.


7.Data Security

We implement appropriate technical and organizational security measures including:

  • Encryption in transit: all data between your device and our servers is encrypted using TLS 1.2 or higher.
  • Encryption at rest: our database and storage infrastructure encrypts data at rest using AES-256.
  • Password security: user passwords are never stored in plaintext - bcrypt hashing with a per-user salt is applied.
  • Ticket signing: each ticket carries an HMAC-SHA256 cryptographic signature generated at purchase. The secret key is stored exclusively server-side.
  • Row-level security: database RLS policies prevent any authenticated user from accessing data belonging to another user unless explicitly authorized.
  • Session management: authentication tokens are short-lived and rotated on each refresh. Mobile tokens are stored in encrypted AsyncStorage.
  • Access controls: internal access to production data is restricted to authorized personnel on a need-to-know basis.

No transmission over the internet or electronic storage is 100% secure. If you believe your account has been compromised, contact support@pinglow.app immediately.


8.Children’s Privacy

The Platform is not directed to individuals under 16. We do not knowingly collect personal data from children under 16. If you believe your child has provided us with personal data, contact privacy@pinglow.app and we will promptly delete it. In jurisdictions where digital consent age is higher (e.g., 18), that higher threshold applies. Minors under applicable law may only use the Platform with parental or guardian consent and supervision.


9.Cookies and Tracking Technologies

9.1 What We Use

  • Strictly necessary: authentication session tokens stored in HTTP-only cookies. Required for the Platform to function.
  • Analytics cookies: first-party cookies set by our analytics provider to understand usage patterns. Set only with your consent where required by law.
  • LocalStorage (web): used to persist UI preferences such as filter settings.

9.2 Cookie Consent

Where required by law, we display a cookie consent banner on your first visit. You may accept or decline non-essential cookies. Change preferences anytime by clearing browser cookies or adjusting browser settings.

9.3 Mobile

The mobile app does not use browser cookies. Analytics events are sent to our analytics provider via an in-app SDK with an anonymous device identifier. Session tokens are stored in Expo SecureStore (iOS Keychain / Android Keystore).


10.Organizer-Specific Privacy Obligations

If you use Pinglow as an event organizer, you access attendee personal data (names, emails, phone numbers) through the organizer dashboard. In this capacity, you act as an independent data controller with respect to attendees’ data and must:

  • Process attendee data only for purposes related to the management and execution of your Pinglow events.
  • Not share, sell, or use attendee data for marketing without obtaining separate informed consent from each attendee.
  • Implement appropriate security measures to protect any attendee data you export or download.
  • Comply with all applicable data protection laws in your jurisdiction.
  • Delete or return attendee data upon request or when no longer needed.

Pinglow acts as a data processor on behalf of organizers with respect to attendee data. We process it strictly as instructed and have implemented technical controls (Row-Level Security, role-based access) to ensure organizers can only access data for their own events.


11.Third-Party Links and Services

The Platform may display links to third-party websites or event venue pages. Such links are provided for convenience and do not constitute an endorsement. This Policy applies only to information collected by Pinglow.


12.Changes to This Privacy Policy

When we make material changes, we will: update the “Last updated” date at the top of this page; send an email notification to registered users; and display a prominent notice on the Platform for at least 14 days. Your continued use after the effective date constitutes acceptance of the changes.


13.Contact Us

For questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Privacy team:

Pinglow Konnect Limited

Lagos, Nigeria

Privacy: privacy@pinglow.app

Support: support@pinglow.app

We aim to respond to privacy inquiries within 5 business days and resolve all valid rights requests within 30 calendar days.

← HomeSub-processor ListTerms of Service →