Privacy Policy
ShowApp lets a guest share their location with the host of an event they joined, starting one hour before it begins. This policy explains exactly what we collect, why, how long we keep it, and what you can ask us to do about it. It covers the ShowApp website and the ShowApp iPhone and Android apps.
Two things worth stating up front, because they are unusual: we run no advertising trackers or analytics SDKs of any kind, and we never sell or share your personal information.
Information we collect
- Account info — your name, and an email address or phone number. We sign you in with a one-time code, or with Sign in with Google or Apple. We never ask for or store a password.
- Event data — event names, dates, locations, guest lists, RSVP answers, and any note you send the host.
- Location data — GPS positions from your device, only if you opt in as a guest, and only in the window from one hour before the event.
- Messages — event group chat and direct messages between guests, where the host has enabled them.
- Photos — a cover image, if a host uploads one.
- Push tokens — an anonymous device identifier so we can send notifications. It identifies a device, not you.
- Technical data — IP address and timestamps in server logs, used to prevent abuse and to record consent.
Your phone contacts stay on your phone
If you use the app to pick guests from your contacts, that list is read on your device and never uploaded. We receive only the specific people you choose to invite. We do not store, scan, or index your address book.
Location data
Location sharing is opt-in and activates one hour before your event. While it is active we store the positions your device reports, so the host can see your progress and estimated arrival. We keep nothing beyond the event: every stored position is deleted automatically within 12 hours of the event's start time. You can turn sharing off at any moment from the app, and we never track you outside an event you joined.
Text messages
We text you only if you ticked the SMS consent box when joining an event. We keep a record of that consent — when you gave it and the exact wording you agreed to — because the law requires us to be able to show it. Expect at most three messages per event. Reply STOP to any message to stop them permanently, or HELP for help. Message and data rates may apply.
We email event confirmations, reminders, and invitations. Every one carries an unsubscribe link that works without signing in.
How we use your information, and why we are allowed to
- To run the event you joined — show your location and ETA to the host and guests, send confirmations and reminders. This is necessary to provide the service you asked for (GDPR Art. 6(1)(b)).
- To send you texts, where you have ticked the consent box (GDPR Art. 6(1)(a) — consent, which you may withdraw at any time).
- To send you a host's newsletters and event invites, only where you ticked "Get news & invites from this host" (GDPR Art. 6(1)(a) — consent; unsubscribe any time).
- To detect and prevent fraud, spam, and abuse, and to keep the service secure (GDPR Art. 6(1)(f) — our legitimate interest in a service that is not overrun by abuse).
- To respond when you contact support (GDPR Art. 6(1)(b) and (f)).
Who we share it with
We do not sell your personal information, and we do not share it for advertising. We share it only with:
- The host and guests of your event — your name, RSVP, and (if you opted in) your live location and ETA.
- A host's community — only if you tick "Get news & invites from this host" when you RSVP. That adds your name and email to that host's audience so they can send you newsletters and event invitations through ShowApp. It's entirely optional, every message has a one-click unsubscribe, and hosts can message you but can't export or download your contact details.
- Twilio — to deliver text messages.
- SendGrid (Twilio) — to deliver email.
- Google — Maps for geocoding and map display; Firebase for push notifications and chat delivery.
- Our hosting provider — which stores the database on our behalf.
- Law enforcement — only where we are legally required to, and we will tell you unless we are legally barred from doing so.
Each of these acts as our processor under contract and may use your data only to provide that service to us.
How long we keep it
- Location positions — deleted automatically within 12 hours of the event's start time.
- Event and guest records — kept while your account exists, so you and your hosts can see your history. Deleted when you delete your account.
- Messages — kept for the life of the event.
- Community membership — kept until you unsubscribe from that host or delete your account. Unsubscribing stops all further messages from that host.
- Consent records and abuse logs — kept up to 4 years, because we may need them to demonstrate we had permission to contact you.
Deleting your account
You can delete your account and everything in it from the app, under Profile, or on the web at showapp.app/delete-data.php. Deletion is permanent and immediate — we do not keep a shadow copy.
Your rights
Wherever you live, you may ask us to give you a copy of your data, correct it, or delete it. Email support@showapp.app and we will respond within 30 days. We will never charge you or degrade your service for exercising a right.
If you are in the EU or UK, you also have the right to object to or restrict processing, to data portability, to withdraw consent at any time, and to complain to your national data protection authority.
If you are in California, you have the right to know what we collect, to delete it, to correct it, and to be free from discrimination for asking. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we have not done so in the past 12 months — so there is no "Do Not Sell or Share My Personal Information" action for you to take.
Where your data is held
Our servers are in the United States. If you use ShowApp from outside the US, your information is transferred there. For transfers from the EU, UK, or Switzerland we rely on the European Commission's Standard Contractual Clauses.
Children
ShowApp is not directed to children. You must be at least 13 to use it, and at least 16 in countries where that is the minimum age for consent to online services. We do not knowingly collect information from anyone below that age. If you believe a child has given us their information, email support@showapp.app and we will delete it.
Security
Traffic is encrypted in transit with TLS. Access to the database is limited to the people who operate the service. No system is perfectly secure, but if a breach ever affects your personal data we will notify you and the relevant regulator as required by law — within 72 hours where GDPR applies.
Cookies
We set a single session cookie so the site can remember you are signed in. We use no advertising, analytics, or tracking cookies, which is why you have never seen a cookie banner here.
How to reach us
ShowApp is the controller of the information described here. For any privacy question, or to exercise any right above:
Email support@showapp.app. We are based in the United States and will respond within 30 days.
We may update this policy. If a change materially affects your rights we will email you before it takes effect. The date at the top always reflects the current version.