1. Overview
MapleMatch+ Inc. ("MapleMatch+", "we", "us", or "our") operates the MapleMatch+ mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our App.
We are committed to complying with applicable data protection laws, including the General Data Protection Regulation (GDPR) for users in the European Union and European Economic Area, the Personal Information Protection and Electronic Documents Act (PIPEDA) for users in Canada, the California Consumer Privacy Act (CCPA/CPRA) for users in California, and other applicable privacy laws worldwide.
By creating an account and using our App, you consent to the collection, use, and disclosure of your information as described in this Privacy Policy.
2. Data We Collect
2.1 Information You Provide Directly
- Account information: Name, email address, password (hashed), phone number, date of birth, gender, country, and city.
- Profile data: Bio, interests, values, relationship intent, profile photos, voice prompts.
- Verification data: Government-issued ID document images and selfie photos for identity verification. This data is processed for the sole purpose of identity verification and is deleted after verification is completed or rejected.
- Event data: Events you create or attend, ticket purchases, event staff assignments, fundraiser contributions.
- Communication data: Messages you send to other users, match form submissions, close-loop requests.
- Payment data: Transaction records for subscriptions, event tickets, boosts, and donations. We do not store full credit card numbers — payment processing is handled by Stripe.
2.2 Information Collected Automatically
- Device information: Device type, operating system version, and push notification token (APNS token).
- Location data: Approximate location based on your profile settings (country and city) for showing nearby events. We do not track precise GPS coordinates unless you explicitly grant location permission.
- Usage data: App interactions such as events viewed, matches made, and feature usage. This data is used to improve the App's functionality.
- Camera and microphone access: Used only for identity verification (ID scan and selfie capture), profile photo uploads, and video prompts. Media is processed for the stated purpose and is not accessed without your explicit permission.
- Push notification tokens: Apple Push Notification service (APNS) tokens for sending you notifications about events, matches, messages, and platform announcements.
2.3 Information Collected by Third-Party Services
- Stripe: Payment processing — Stripe collects payment method details independently under their own privacy policy.
- Apple Push Notification service (APNS): Delivers push notifications to your device.
- Google Maps: Map display and location search — Google may collect usage data under their privacy policy.
- Sentry: Crash reporting and error tracking — Sentry receives anonymized crash data.
3. How We Collect Data
We collect data through:
- Direct input: Information you provide when registering, creating a profile, or using App features.
- Automated collection: Device tokens, usage patterns, and technical data collected during normal App operation.
- Permissions: Data accessed through device permissions you grant (camera, microphone, location, notifications).
- Third-party services: Data processed by Stripe, APNS, Google Maps, and Sentry as described above.
4. How We Use Your Data
We use your personal information for the following purposes:
- Account management: Creating and managing your account, authentication, and profile.
- Matching: Facilitating connections between users based on shared interests, values, and location.
- Events: Creating, managing, and attending events; ticket purchases; event promotion (boosts).
- Communication: Enabling in-app messaging, match notifications, and close-loop requests.
- Verification: Identity verification to enhance trust and safety on the platform.
- Push notifications: Sending notifications about events, matches, messages, and platform announcements.
- Payments: Processing subscriptions, ticket sales, boosts, and donations.
- Safety and security: Detecting fraud, preventing abuse, and enforcing our Terms of Service.
- App improvement: Analyzing usage patterns to improve features and user experience.
- Legal compliance: Meeting obligations under applicable laws and regulations.
5. Legal Basis for Processing (GDPR)
For users in the European Union and European Economic Area, we process your personal data under the following legal bases as defined in Article 6 of the GDPR:
- Consent (Article 6(1)(a)): For collecting and processing profile photos, voice prompts, camera/microphone data, and push notification tokens. You can withdraw consent at any time.
- Contract (Article 6(1)(b)): For processing necessary to provide the App's core functionality — account creation, matching, messaging, event management, and ticket purchases.
- Legal obligation (Article 6(1)(c)): For retaining transaction records and complying with tax and regulatory requirements.
- Legitimate interest (Article 6(1)(f)): For fraud prevention, safety measures, analytics, and improving the App. Our legitimate interests do not override your fundamental rights and freedoms.
6. Third-Party Services
We share data with the following third-party service providers, each of whom processes data under their own privacy policy:
Stripe Inc.
Purpose: Payment processing for subscriptions, tickets, boosts, and donations.
Data shared: Payment method details (processed directly by Stripe via Stripe PaymentSheet), transaction metadata (event ID, amount, currency).
Privacy policy: stripe.com/privacy
Apple Push Notification service (APNS)
Purpose: Delivering push notifications to your device.
Data shared: Device push notification token, notification payload (title, body, data).
Privacy policy: apple.com/legal/privacy
Google Maps Platform
Purpose: Map display, location search, and address autocomplete.
Data shared: Search queries, approximate location coordinates.
Privacy policy: policies.google.com/privacy
Sentry (Functional Software, Inc.)
Purpose: Crash reporting and error monitoring.
Data shared: Anonymized crash logs, device model, OS version, app version. No personal identifiers are sent.
Privacy policy: sentry.io/privacy
We do not sell your personal information to any third party. We do not share your data with advertising networks or data brokers.
7. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the App's services. Specific retention periods:
- Account data: Retained until you delete your account. Account deletion is available within the App under Settings → Delete Account.
- Verification data (ID documents and selfies): Deleted after verification is completed or rejected, typically within 30 days.
- Payment records: Retained for 7 years as required by Canadian tax law and applicable financial regulations.
- Messages: Retained for the duration of the conversation. Conversations may be deleted by users.
- Device tokens: Deleted when you log out, uninstall the App, or when the token becomes invalid.
- Event data: Retained while events are active and for a reasonable period after for analytics and record-keeping.
When you delete your account, we remove your profile, photos, messages, device tokens, and verification data. Some data may be retained in backup systems for up to 90 days before permanent deletion. Payment records are retained as required by law.
8. Data Security
We implement appropriate technical and organizational measures to protect your personal information:
- Encryption: All data in transit is encrypted using TLS/SSL. Passwords are hashed using bcrypt.
- Access control: Access to personal data is restricted to authorized personnel only.
- Authentication: API access requires Bearer token authentication via Laravel Sanctum.
- Secure storage: APNS authentication keys and sensitive credentials are stored securely on the server.
- Regular audits: We periodically review our security practices and update them as needed.
Despite these measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but strive to use commercially acceptable means to protect your personal information.
9. International Data Transfers
Your personal information may be transferred to and processed in countries other than your country of residence, including Canada (where our servers are located) and the United States (where some third-party services operate).
For users in the European Union and European Economic Area, we ensure appropriate safeguards are in place for international data transfers, including:
- Standard Contractual Clauses (SCCs) as approved by the European Commission.
- Binding corporate rules where applicable.
- Adequacy decisions for specific countries.
You have the right to receive a copy of the safeguards we rely upon by contacting us at the email provided in Section 14.
10. Your Rights
10.1 GDPR Rights (EU/EEA Users)
Under the GDPR, you have the following rights:
- Right of access (Article 15): Request a copy of your personal data.
- Right to rectification (Article 16): Correct inaccurate or incomplete data.
- Right to erasure (Article 17): Request deletion of your personal data ("right to be forgotten").
- Right to restriction (Article 18): Limit the processing of your data.
- Right to data portability (Article 20): Receive your data in a structured, machine-readable format.
- Right to object (Article 21): Object to processing based on legitimate interest.
- Right to withdraw consent (Article 7): Withdraw consent for data processing based on consent at any time.
- Right to lodge a complaint: You can lodge a complaint with your local Data Protection Authority.
10.2 PIPEDA Rights (Canadian Users)
Under PIPEDA and Quebec's Law 25, you have the right to:
- Access: Request access to your personal information held by us.
- Correction: Request correction of inaccurate personal information.
- Deletion: Request deletion of your personal data by deleting your account.
- Withdrawal of consent: Withdraw consent for data collection and processing.
- Complaint: File a complaint with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca.
10.3 CCPA/CPRA Rights (California Users)
Under the CCPA/CPRA, California residents have the right to:
- Know: Request disclosure of categories and specific pieces of personal information collected.
- Delete: Request deletion of personal information.
- Opt out: We do not sell or share personal information, so no opt-out is necessary.
- Non-discrimination: We will not discriminate against you for exercising your privacy rights.
10.4 How to Exercise Your Rights
To exercise any of these rights:
- In-App: Go to Settings → Delete Account to delete your account and associated data.
- Email: Contact us at privacy@elloria.ca with your request.
- Response time: We will respond to your request within 30 days (GDPR) or 45 days (CCPA).
11. Children's Privacy
Our App is not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you believe we have collected information from a child under 18, please contact us immediately at privacy@elloria.ca, and we will take steps to delete such information.
Age verification is performed during the registration process through date of birth. Users must confirm they are at least 18 years old to create an account.
12. Cookies and Local Storage
The MapleMatch+ mobile App does not use cookies. We use local device storage (UserDefaults) to store:
- User preferences (language, notification settings).
- Authentication state (securely stored in the device Keychain).
- Onboarding completion status.
- Verification status.
This data is stored locally on your device and is not transmitted to our servers unless explicitly required for App functionality. Deleting the App removes all locally stored data.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will:
- Update the "Last updated" date at the top of this page.
- Notify you of material changes through the App or via email.
- Continue using the App after changes constitutes acceptance of the updated policy.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
For EU/EEA users, you may also contact your local Data Protection Authority. A list of EU Data Protection Authorities is available at edpb.europa.eu.
For Canadian users, you may contact the Office of the Privacy Commissioner of Canada at priv.gc.ca.