Back to Vertigo

Privacy Policy

Vertigo proximity-based venue chat

Effective date: 3 September 2026

Last updated: 3 September 2026

Controller: Mapplin OÜ, registry code 17256092

Registered address:
Ahtri tn 12
Kesklinna linnaosa
15551 Tallinn
Harju maakond
Estonia

Privacy contact: support@mapplin.com

1. About this policy

This Privacy Policy explains how Mapplin OÜ ("Mapplin", "Vertigo", "we", "us" or "our") collects, uses, shares and protects personal data when you use the Vertigo mobile application, related websites and support services (together, the "Service").

Vertigo enables people who are physically near the same venue, event or defined area to join local conversations. Location is therefore central to the Service. This policy explains that processing directly.

Mapplin OÜ is the controller responsible for the processing described in this policy, unless another notice says otherwise.

2. Important points about location and anonymity

Location verification

Vertigo uses your device location to determine whether you are within the permitted radius of a venue, event or local chat. Depending on the implementation and device permission you grant, this may involve precise location. Other users are shown your participation in a room, not your precise coordinates.

Vertigo does not retain raw precise coordinates after venue eligibility is determined. Coordinates are used on the server to check whether you are inside, in a short grace window, or outside a room, and are not written to membership records or user accounts. We do not store a trail of user coordinates, and we do not show other users how far you are or where you are pointing.

Pseudonymous participation

Vertigo may allow you to participate using a temporary name, alias, generated identity or limited profile. This can conceal your real-world identity from other users, but it does not make you anonymous to Vertigo. We may still associate activity with your account, device, IP address, approximate or precise location, venue session and moderation records.

Public and private communications

Messages posted to a venue or event room can be seen by the users who have access to that room. Direct messages can be seen by their participants. Do not post information you do not want the relevant recipients to see or copy. Room access based on proximity reduces the audience; it does not guarantee confidentiality.

3. Personal data we collect

Information you provide

Account and profile data. Your email address, telephone number or social sign-in identifier; username, display name, alias, profile photo, age or date of birth if requested; and account settings.

User content. Venue-room posts, direct messages, replies, reactions, reports, photos, audio, profile text and other content you submit.

Support and safety data. Messages sent to support, reports about users or content, appeals, evidence, and records of moderation or enforcement actions.

Optional permissions and inputs. Information you choose to provide through camera, photo library, microphone, contacts or notification permissions. Vertigo will request only the permissions needed for the feature you choose to use.

Information collected through use of the Service

Location and venue-presence data. Device coordinates or approximate location are processed to complete a proximity check. We keep the selected or detected venue, proximity result (inside, grace period or outside), entry and exit from a venue session, and anti-spoofing or location-integrity signals where implemented. We do not keep the raw coordinates after that check.

Device and network data. IP address, device type, operating system, app version, language, time zone, mobile network, device or installation identifiers, and push-notification token.

Usage data. Rooms joined, features used, interaction times, messages viewed or acted on, blocks, mutes, reports, invite activity and other events needed to operate, secure and improve the Service.

Diagnostics. Crash reports, performance data, error logs and security events.

Information from other sources

We may receive limited information from sign-in providers, app stores, venues or event organisers, other users who report content, and security or fraud-prevention providers. The information depends on the service and your settings. We do not access more information from a sign-in provider than the permissions shown to you.

Required and optional data

Account identifiers and a successful location or proximity check are required to create an account and access location-restricted chats. If you do not provide them, those parts of the Service cannot operate. Profile details, media uploads, contacts access, marketing preferences and similar inputs are optional unless a specific feature states otherwise.

Cookies and similar technologies

Our app and websites may use local storage, cookies, software development kits, pixels and similar technologies for authentication, preferences, security, diagnostics and analytics. Where applicable law requires consent for a non-essential technology, we request it before use and provide a way to change the choice.

4. How and why we use personal data

Where the EU GDPR or UK GDPR applies, we rely on the legal bases described below. The correct basis depends on the particular processing.

PurposeWhat we doLegal basis
Provide the ServiceCreate and administer accounts; verify proximity; place users in the correct venue room; deliver posts, replies and direct messages; maintain preferences; and provide support.Performance of our contract with you.
Safety, moderation and integrityDetect spam, abuse, impersonation, harassment, unsafe conduct, location spoofing and security incidents; investigate reports; enforce our rules; and preserve evidence where necessary.Our legitimate interests in protecting users and the Service; compliance with legal obligations; and, in exceptional cases, protection of vital interests.
Improve and troubleshootDiagnose faults, measure reliability, understand feature usage and improve the Service.Our legitimate interests in operating and improving Vertigo. Where required, consent.
Communicate with youSend service notices, security alerts, policy updates, replies to support requests and optional product communications.Contract, legal obligation or legitimate interests. Consent where required for marketing.
Comply with lawRespond to lawful requests, exercise or defend legal claims, keep required records and comply with regulatory duties.Legal obligation or legitimate interests.

We do not use location, messages or other personal data for advertising unless this policy and the relevant in-app notice are updated and any consent required by law is obtained. We do not sell personal data or share it for cross-context behavioural advertising.

5. Automated systems and moderation

Vertigo may use automated systems to identify suspected spam, harmful content, fraudulent accounts, location manipulation or other rule violations, and to prioritise material for human review. Automated signals may also affect room access, rate limits or the visibility of content.

Vertigo does not make decisions based solely on automated processing that produce legal or similarly significant effects. Phrase filters and rate limits may reject or delay content or requests; reports and account restrictions are reviewed by people where they affect access to the Service.

Where required by law, you may request human review of a decision, express your point of view and contest the result by contacting us.

6. When we share personal data

We disclose personal data only as described below, as directed by you, or when required by law.

Other users. We share your chosen identity, profile elements, content, reactions and room participation with the audience for the feature you use. We do not intentionally reveal your precise coordinates to other users.

Service providers. We use processors for hosting, databases, content delivery, authentication, notifications, customer support, analytics, crash reporting, communications and security. They may process data only to provide services to us under contractual safeguards.

The processors we currently use include:

  • Salesforce, Inc. (Heroku) — application hosting and PostgreSQL database
  • Apple Inc. — Sign in with Apple
  • Google LLC — Google Sign-In

Vertigo does not currently use a separate analytics, crash-reporting, push-notification or customer-support platform. If we add one, we will update this list.

Venues and event organisers. We may provide aggregated or de-identified activity statistics. Identifiable information is shared only where you direct us, where the relevant feature clearly explains the sharing, or where needed for safety or legal compliance.

Professional advisers and authorities. We may disclose data to lawyers, auditors, insurers, regulators, courts and law-enforcement bodies when reasonably necessary and legally permitted.

Corporate transactions. If Vertigo or Mapplin is involved in a merger, acquisition, financing, restructuring, insolvency or sale of assets, data may be disclosed under appropriate confidentiality and transferred as part of the transaction.

7. International transfers

Vertigo may use providers or personnel located outside the country where you live. When EU, EEA or UK personal data is transferred to a country that is not recognised as providing adequate protection, we use an approved safeguard, such as the European Commission Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, together with supplementary measures where required. You may contact us for information about the safeguard relevant to your data.

Primary production data is hosted on Heroku (Salesforce) with Heroku Postgres. Depending on the region assigned to the production application, that infrastructure may be in the European Union (typically Ireland) or the United States. Apple and Google may process sign-in data in the United States and other countries where they operate.

8. Data retention

We retain personal data only for as long as necessary for the purposes described in this policy, including safety, dispute resolution, legal claims and statutory obligations. Retention can vary if data is subject to a report, investigation, legal hold or backup cycle.

Data categoryRetention rule
Account and profile dataWhile the account is active, then removed from active systems when you delete the account, subject to the backup and safety exceptions below.
Raw precise locationNot retained after the eligibility check. Coordinates are not stored on membership or user records.
Venue-presence or proximity recordsRoom membership (without coordinates) is kept for the related venue session, including a short grace period after you leave, and is discarded when the room expires.
Venue-room messages24 hours, or when the venue session ends, whichever is sooner, unless reported or legally preserved.
Direct messagesWhile the conversation exists and your account remains active. Deleted when you delete your account, unless a participant reports the conversation or we must preserve it for safety or legal reasons.
Reports and moderation recordsFor as long as needed for safety, repeat-offender detection or legal claims, then deleted or anonymised.
Security and server logsA limited operational period on the hosting platform, typically up to 30 days unless a security incident requires longer review.
BackupsDeleted or overwritten within the Heroku Postgres backup cycle, currently up to 4 days for the production plan in use.

We may keep aggregated or genuinely de-identified information that no longer identifies you.

9. Your choices and controls

Location permissions. You can change location permissions in your device settings. If location is disabled or reduced below the accuracy needed for a proximity check, venue-room access may not work.

Profile and audience. Use the in-app controls to choose the identity and profile information shown to other users, where the feature supports these choices.

Block and report. You can block users and report messages, content, profiles or accounts through the Service, in the same way as on our other apps. Reporting and blocking are available so people can flag objectionable content and abusive users.

Notifications and marketing. Manage push notifications in the app or device settings. Use the unsubscribe mechanism in marketing emails. Service and security communications may still be sent.

Account deletion. Delete your account in the app by going to Settings → Account → Delete Account, or contact support@mapplin.com. Deletion is permanent and cannot be undone. Account deletion does not necessarily remove content already received or copied by other users, and limited records may be retained as described above.

10. Your data-protection rights

Depending on where you live and subject to legal conditions and exceptions, you may have the right to: obtain access to your personal data; correct inaccurate data; request deletion; restrict processing; object to processing based on legitimate interests; receive data you provided in a portable format; withdraw consent; and complain to a supervisory authority.

To exercise a right, contact us using the details in section 16. We may need to verify your identity. We will not discriminate against you for exercising a legal right. A request can be limited or refused where permitted by law, including to protect other users’ rights and safety.

If you are in the EEA, you may complain to your local data-protection authority or the Estonian Data Protection Inspectorate. If you are in the United Kingdom, you may complain to the UK Information Commissioner’s Office.

Estonian authority: www.aki.ee UK authority: www.ico.org.uk

11. Security

We use technical and organisational measures designed to protect personal data, including access controls, encryption in transit (HTTPS), database connections over TLS, hashed credentials and device identifiers, restricted administrative access to the hosting platform, monitoring of application logs, and backups provided by Heroku Postgres, as appropriate to the risk. No system is completely secure. Protect your account credentials, use device security controls and report suspected unauthorised access promptly.

12. Children

Vertigo is not intended for anyone under 18, and we do not knowingly collect personal data from children under 18. If you believe a child has provided personal data, contact us so we can investigate and delete it where appropriate.

13. Sensitive information

Do not post special-category or highly sensitive information in public or venue-room messages unless it is necessary and you understand the audience. Free-form content may reveal health, political, religious, sexual-orientation or other sensitive information. We do not ask users to provide such information for ordinary use of Vertigo. If moderation requires us to process sensitive information contained in a report, we do so only where permitted by applicable law.

14. Third-party services

The Service may link to third-party sites or services. Their privacy practices are governed by their own notices. Sign-in providers, app stores, device operating systems and venues may independently process data under their own terms.

15. Changes to this policy

We may update this policy to reflect changes to the Service, our practices or applicable law. We will post the updated version and revise the “Last updated” date. If a change materially affects your rights or how we use personal data, we will provide additional notice where required, such as an in-app notice or email.

16. Contact us

For privacy questions, rights requests or complaints, contact:

Controller: Mapplin OÜ, registry code 17256092

Registered address:
Ahtri tn 12
Kesklinna linnaosa
15551 Tallinn
Harju maakond
Estonia

Email: support@mapplin.com