Privacy Policy
Effective date: April 12, 2026
This policy describes how Sponti collects, uses, and protects your information. We believe privacy should be clear and readable — not buried in legalese.
1. Introduction
Sponti ("we", "our", or "us") operates a marketplace platform that connects local businesses offering last-minute deals with nearby customers (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and website.
By using Sponti, you agree to the practices described in this policy. If you do not agree, please discontinue use of our Service.
2. Information We Collect
2.1 Information You Provide
When you create an account or use our Service, we may collect:
Account information: Name, email address, phone number, and password (stored as a secure hash).
Business information (for business accounts): Business name, Instagram and TikTok handles, short description, support contact details, business category, logo and gallery images, venue location (address resolved via map pin), and payout/banking details submitted through our payment processor.
Profile information: Profile photo and any preferences or settings you configure in the app.
Communications: Messages or support requests you send to us.
2.2 Information We Collect Automatically
When you use the Service, we automatically collect:
Device information: Device type, operating system, unique device identifiers, IP address, and mobile network information.
Usage data: Pages visited, features used, deal categories browsed, search queries, tap and scroll interactions, session duration, and crash reports.
Location data: With your permission, we collect precise GPS location to show you nearby deals. You can revoke location permission at any time via your device settings, though this will affect core functionality.
Transaction data: Records of deals you viewed, saved, redeemed, or purchased through the platform.
2.3 Information From Third Parties
We may receive information from:
Analytics providers: Aggregated usage metrics to help us understand how the Service is used.
Payment processors: Transaction confirmation and limited payment metadata (we do not store full card numbers).
Social platforms: If you choose to connect your Instagram or TikTok account for business profile purposes.
3. How We Use Your Information
We use the information we collect to:
- Provide the Service: Match customers with relevant nearby deals, process bookings, and enable business-customer interactions.
- Personalise your experience: Surface deals based on your location, browsing history, and stated preferences.
- Process payments: Handle transactions, payouts to businesses, and associated record-keeping.
- Communicate with you: Send booking confirmations, deal alerts (if opted in), operational notices, and customer support responses.
- Maintain platform integrity: Detect fraud, verify business accounts, enforce our Terms of Service, and prevent abuse.
- Improve the Service: Analyse usage patterns, conduct A/B testing, fix bugs, and develop new features.
- Legal compliance: Meet our obligations under applicable laws and respond to lawful requests from authorities.
We do not sell your personal data to third parties for their own marketing purposes.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. When you delete your account:
- Your public profile information is removed within 30 days.
- Transaction and booking records may be retained for up to 7 years for legal and financial compliance purposes.
- Anonymised, aggregated analytics data derived from your usage may be retained indefinitely.
Business accounts that have processed payments through Stripe are subject to Stripe's data retention requirements as a regulated financial service provider.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your account and associated data, subject to legal retention requirements.
- Portability: Request your data in a structured, machine-readable format.
- Objection: Object to certain types of processing, such as direct marketing.
- Withdrawal of consent: Where processing is based on consent (e.g., location access), withdraw that consent at any time.
To exercise any of these rights, contact us at privacy@sponti.app. We will respond within 30 days. We may need to verify your identity before fulfilling a request.
If you are located in the European Economic Area, you also have the right to lodge a complaint with your local data protection authority.
8. Security
We implement industry-standard security measures including:
- Encryption in transit (TLS) and at rest for sensitive data
- Access controls restricting internal data access to authorised personnel
- Regular security reviews and vulnerability assessments
- Payment data handled exclusively by Stripe, a PCI DSS-compliant processor
No method of transmission over the internet is 100% secure. We cannot guarantee absolute security, but we take reasonable steps to protect your information and notify you promptly in the event of a breach that affects your data.
9. Children
Sponti is not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
10. Third-Party Links and Services
The Service may contain links to third-party websites or services (such as restaurant booking platforms, event ticketing systems, or social media pages). We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before sharing any personal information with them.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email or a prominent in-app notice at least 14 days before the changes take effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
We maintain a version history of this policy available upon request.
12. Contact Us
If you have questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact us at:
Sponti Email: privacy@sponti.app
We aim to respond to all privacy-related enquiries within 5 business days.
Questions about this policy? Email us at privacy@sponti.app