Privacy Policy — AlgarveFlow
Last updated: 2026-02-17
AlgarveFlow (“AlgarveFlow”, “we”, “our”) provides an events discovery and community application (the “App”) and related website (the “Website”). This Privacy Policy explains what data we collect, how we use it, and your rights.
If you do not agree with this policy, please do not use the App or Website.
1) Scope and Controller
This policy applies to personal data processed through the Service. AlgarveFlow is the data controller for the processing described in this policy.
2) Information we collect
A) Information you provide
- Account details: email address and password (if email sign-in is used), and/or phone number (if account confirmation by SMS is used).
- Profile details: display name/username, city, bio, and other profile information you choose to provide.
- User content: event, venue, and organizer content; support requests; and images you upload (if enabled).
B) Information collected automatically
- Usage and diagnostics: app activity metadata, crash information, device/OS/app version, timestamps, and technical logs for reliability and troubleshooting.
- Security signals: fraud/abuse prevention data, suspicious login indicators, and service integrity telemetry.
C) Information from third parties
If you sign in with a third-party identity provider (e.g., Google Sign-In), we receive basic profile data required to authenticate you (typically name, email, and profile photo if available).
D) Optional permissions and notifications
Where applicable, the App may request operating system permissions (for example, notifications). You can manage these permissions in device settings at any time.
3) How we use your information
- Create and manage accounts
- Authenticate users and secure the Service
- Provide requested features (saved events, follows, notifications, moderation flows)
- Operate, maintain, debug, and improve the Service
- Communicate service and security updates
- Comply with legal obligations and enforce legal terms
4) Legal bases (EEA/UK)
- Contract: providing account and app functionality
- Legitimate interests: security, fraud prevention, service operation, and improvement
- Consent: where required (for example, optional communications)
- Legal obligation: compliance with applicable law
5) How we share information
We do not sell personal information.
We may share data only as follows:
- Service providers: authentication, hosting, infrastructure, analytics/crash tools, notifications, and support providers acting under our instructions.
- Legal and safety: where required to comply with law, enforce rights, prevent fraud, or protect users and systems.
- Business transfers: in a merger, acquisition, or asset transfer, subject to applicable notice obligations.
6) Google user data (if applicable)
If Google Sign-In is offered, we request only the minimum Google account data necessary for authentication. We do not access restricted/sensitive Google APIs unless explicitly disclosed and required for a specific feature.
7) Data retention
We retain personal data only for as long as necessary for legitimate purposes, including:
- maintaining active accounts and requested features
- security monitoring and fraud prevention
- dispute resolution, legal compliance, and contract enforcement
Backup copies may persist for a limited period according to operational retention schedules before secure deletion or anonymization.
8) Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal data. No method of transmission or storage is completely secure.
9) Your rights and choices
Depending on your location, you may have rights to:
- access, correct, or update personal data
- request deletion of account and associated personal data
- object to or restrict specific processing
- request portability (where legally applicable)
- withdraw consent for consent-based processing
You may also have rights under local laws (including GDPR/UK GDPR and, where applicable, U.S. state privacy laws). We do not sell personal information and do not process personal information for cross-context behavioral advertising.
10) Account deletion
You can request deletion by:
- using Settings → Delete Account in the App (if available), or
- emailing info@algarveflow.pt from your registered account address.
We may need to verify account ownership before processing a deletion request. Some records may be retained where legally required or necessary for security/fraud prevention.
11) Children’s privacy
The Service is not directed to children under 13 (or higher minimum age where required by local law). We do not knowingly collect personal data from children.
12) International transfers
Personal data may be processed in countries other than your country of residence. Where required, we apply appropriate safeguards for international transfers.
13) Third-party links and services
The Service may contain links to third-party websites or integrate third-party services. Their privacy practices are governed by their own policies.
14) App Store / Google Play disclosures
Privacy disclosures presented in Apple App Store and Google Play listings are provided in summary form. This policy is the complete statement for the Service. If there is any inconsistency, this policy governs to the extent permitted by law.
15) Changes to this policy
We may update this policy from time to time. We will revise the “Last updated” date and, where required, provide additional notice in-app or on the Website.
16) Contact
For privacy requests or questions:
Email: info@algarveflow.pt
Website: https://algarveflow.pt
See also: Terms of Service · Account Deletion