Privacy Policy
What we collect
To provide BeatMeThere, we collect and store your email address and display name; optional profile details you choose to add (profession, bio, and a profile photo); the work check-ins you create, including the location and visibility you set for each one; messages you exchange with your connections; recommendations you leave for professionals; and records of tips you send or receive (amount, fee, status, and the counterparty). If you receive tips, we store the identifier of your Stripe payout account, but never your bank or card details. We store an Expo push token when you enable notifications so we can deliver them. We collect technical logs (IP address, device type, timestamps) needed to keep the service secure and reliable.
Location
Location is used only in the foreground, and only when you intentionally create a check-in or center the map. We never collect your location in the background, and we never track your movements. A check-in captures the location and visibility you set at the moment you create it, and it expires on its own — it does not follow you and it is not shared beyond the visibility you chose.
Contacts
Contacts are never saved, shared, or used by BeatMeThere. If you let the app read the contacts on your phone, the list is used on the device to show you names you could invite, and nothing about it is uploaded to us or to anyone else.
Messages, photos, and recommendations
Messages exist only inside accepted connections and are visible to you and the person you are messaging. Profile photos are visible according to your discoverability setting and to your connections. Recommendations are positive-only — there are no public ratings or reviews to leave, so there is no way to post a negative rating about a professional.
Tips and payments
Tips are processed by Stripe. When you send a tip, your payment goes directly to the professional's own Stripe account; the app receives only a payment confirmation. We do not see, store, or process your card number — that stays with Stripe. We keep a record of each tip (amount, platform fee, status, sender, and recipient) so both parties have an accurate history.
How we use it
We use this information solely to operate the app: to place your check-ins on the map for the people you allow, to connect and message people, to deliver notifications you have enabled, and to process tips. We do not sell personal information. We do not use your data for advertising, and we do not use third-party advertising or analytics SDKs.
Who can see it
Access is enforced by row-level security in our database, scoped to each user and their connections. Your discoverability setting (hidden, connections, or professional) controls who can find you. Blocking a person severs visibility and messaging in both directions. Our staff access data only for support and operations, and that access is logged.
Links you share outside the app
A personal invitation link opens a page showing your photo, your first name, and your last initial. Nothing else: not a check-in, not a destination, not a status, not a location, and nobody else’s details. You choose whether your photo appears, before the link is created, and the switch is on by default. The link carries at least 128 bits of randomness, stops working after seven days, and you can turn it off at any time. We store a one-way hash of it, never the link itself.
Turning a link off takes effect on the next request, including the photo, which is fetched through our own server and re-checked every single time it is loaded rather than handed out as a reusable address. What somebody has already seen or screenshotted cannot be recalled, and no setting can change that.
If you have professional discovery switched on, you also have a stable public page showing your approved photo, your name, your profession, how many people recommend you, and the places you work. It never shows who recommended you or what they wrote, and never a check-in or a schedule. That page is public and cannot tell who is reading it, so blocking someone removes them from your app entirely but does not hide it from them. Turning professional discovery off takes it down everywhere.
These pages ask search engines not to index, archive, or excerpt them. They carry no third-party analytics. They send no referrer to anywhere you click through to, and the addresses are not written into the logs we keep — only the name of the route and a one-way fingerprint.
Processors
We rely on Supabase (database, authentication, storage), Vercel (hosting), Stripe (tip payments and professional payouts), and Expo (push notification delivery). Each processes data on our behalf under their own security commitments. Stripe is the only party that handles card and bank details.
Account deletion, retention, and what is kept
You can delete your account at any time from inside the app. When you do, we remove your profile, profile photo, messages you sent, push token, and check-ins, and we delete your login. We retain the tip and payment records tied to your account because the other party to each tip needs an accurate history of a completed transaction and we may be required to keep financial records; on your side, personal identifiers on those records are cleared. You can also email support@cre84ever.com to request deletion; we complete requests within 30 days, except records we must keep for legal or financial compliance.
Security
Data is encrypted in transit (TLS) and at rest. Every table is protected by row-level security. Sensitive actions are audit-logged, and payout and payment data is handled by Stripe.
Your rights
You can access, correct, export, or delete your personal information. Use in-app deletion, or contact support@cre84ever.com and we will respond within 30 days.
Changes
If this policy changes materially, we will notify you in the app or by email before the change takes effect. Questions: support@cre84ever.com.