← Metvas

Privacy Policy

Last updated: 2026-06-12

This privacy policy explains which personal data we process when you use Metvas (web app and mobile app, together “the platform”), for which purposes, and which rights you have. The Swiss Federal Act on Data Protection (FADP) applies.

1. Controller

The controller responsible for data processing is the operator of Metvas:

Metvas Email: kontakt@metvas.ch Switzerland

For any privacy matter, contact us at the email address above.

2. Data we process

We only process data needed to run the platform:

  • Account data: email address, username (handle), display name, date of birth (for age verification, never shown publicly), password (stored encrypted), chosen language and appearance.
  • Profile data (optional): profile photo, bio, interests.
  • Event data: events you create incl. title, description, location (map pin, optionally rounded to ~100 m), time, capacity, cover and place photos.
  • Participation data: RSVPs, waitlists, and details you submit for events with attendance requirements (e.g. legal name, age — visible only to that event's host).
  • Location data (optional, opt-in): your approximate location to sort the feed by distance. You can disable this anytime; no movement profile is created.
  • Communication: messages in event chats and direct messages, comments, reactions.
  • Payment data: Venue subscriptions are processed by Payrexx (cards & TWINT). We never receive or store card details — only your subscription status.
  • Push tokens: device tokens for notifications in the mobile app.
  • View statistics (Metvas Plus only): we count profile and event views per day to show Plus members aggregate numbers — never who specifically viewed you.
  • Technical data: server logs (IP address, timestamp, requested resource) and anonymous error reports to keep the platform stable.

3. Purposes

  • Providing the platform: account, map, events, participation, chat, notifications.
  • Safety and abuse prevention: reports, blocks, moderation, age checks.
  • Processing paid Venue subscriptions.
  • Improving the platform through aggregated, cookieless usage statistics.
  • Complying with legal obligations.

4. Processors and cross-border transfers

We use carefully selected service providers that process data on our behalf, all under data processing agreements. For US providers we rely on their certification under the Swiss–U.S. Data Privacy Framework (DPF):

  • Supabase (database, login, file storage) — servers in Frankfurt, EU.
  • Vercel (web hosting) — USA, DPF-certified.
  • Payrexx AG (Venue subscription payments, cards & TWINT) — Switzerland.
  • Sentry (error reporting) — USA, DPF-certified.
  • PostHog (usage statistics) — EU cloud, operated cookieless (see section 7).
  • CARTO (map tiles) and Photon/komoot (address search) — receive only map viewports or search queries with coordinates, never account data.
  • Resend (transactional email) — planned; will be added here before activation.

5. Retention and deletion

  • Events are automatically hidden everywhere 7 days after they end.
  • Account data is kept until you delete your account; profile, events, photos and messages are then deleted.
  • Push tokens are removed after 90 days of inactivity.
  • Server logs rotate automatically after a short period.

6. Your rights (Art. 25 et seq. FADP)

You can request access to your data, its correction or deletion, and a copy in a common format (data portability) at any time via the email address in section 1. We respond within 30 days.

The competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner (FDPIC), www.edoeb.admin.ch.

7. Cookies and local storage (Art. 45c TCA)

Metvas uses only strictly necessary and functional cookies / local storage — no advertising or tracking cookies. That is why we show no cookie banner:

  • Login cookies (Supabase): keep you signed in. Strictly necessary.
  • NEXT_LOCALE: remembers your language. Functional.
  • theme (localStorage): remembers light/dark mode. Functional.

Our usage statistics (PostHog) deliberately run without cookies and without storing anything on your device. You can also block or delete cookies in your browser settings at any time; apart from staying logged in, the platform remains usable.

8. Data security

All connections are TLS-encrypted. Database-level access rules (Row Level Security) restrict access to what is necessary; passwords are stored only as hashes.

9. Changes

We may update this policy, for example when new features or providers are added. The version published here applies; the date above shows the last revision.

Privacy Policy · Metvas