Last updated: March 2026
For a simplified overview, see our user-friendly privacy summary.
This Privacy Policy explains how Beacon ("we," "us," or "our") collects, uses, discloses, and protects your personal data when you use our mobile application and website (collectively, the "Service").
Data Controller:
Beacon
Email: security@usebeacon.social
We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and other applicable data protection laws.
| Category | Data Elements | Purpose |
|---|---|---|
| Account Identifiers | Email address, username | Account creation, authentication, communication |
| Profile Information | Display name, bio, profile photo (optional) | Personalization, display to friends |
| User Content | Beacons (title, description, location name), comments, friend groups | Core service functionality |
| Social Connections | Friend relationships, group memberships | Friend-based beacon visibility |
| Category | Data Elements | Purpose |
|---|---|---|
| Authentication Data | Session tokens, passkey public keys, OAuth tokens | Secure authentication |
| Device Information | User agent string (browser/OS type) | Service optimization, security |
| Push Notification Data | Push subscription endpoint, encryption keys | Delivering notifications you opt into |
| Usage Analytics | Feature usage events (e.g., beacon created, friend added) | Service improvement |
| Error Logs | Crash reports, error messages (no PII included) | Bug fixes, stability |
If you sign in via Google or Apple:
We do not receive or store your password from these providers.
Under the GDPR, we process your personal data based on the following legal grounds:
| Legal Basis | Processing Activities |
|---|---|
| Contract Performance (Art. 6(1)(b)) | Account creation, authentication, beacon functionality, friend connections, displaying your content to friends |
| Consent (Art. 6(1)(a)) | Push notifications, optional profile information (bio, photo), marketing communications (if any) |
| Legitimate Interests (Art. 6(1)(f)) | Service security, fraud prevention, aggregated analytics for improvement, error logging for stability |
| Legal Obligation (Art. 6(1)(c)) | Compliance with applicable laws, responding to lawful requests |
Your profile information, beacons, and activity are visible to your accepted friends. This is the core functionality of Beacon. You control your friend list and can remove friends or block users at any time.
We use the following third-party service providers:
| Provider | Purpose | Data Processed |
|---|---|---|
| Cloudflare | Hosting, CDN, database (D1) | All service data |
| Sentry | Error monitoring | Error logs (PII excluded) |
| Google (OAuth) | Authentication | Auth tokens during sign-in |
| Apple (OAuth) | Authentication | Auth tokens during sign-in |
These providers process data on our behalf under data processing agreements that ensure appropriate safeguards.
We do not sell, rent, or trade your personal data to third parties for their marketing purposes. We do not share data for cross-context behavioral advertising.
For California residents: Under the CCPA/CPRA, we confirm that we do not "sell" or "share" (as those terms are defined under California law) your personal information.
We may disclose your data if required by law, court order, or governmental authority, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
Your data may be processed in countries outside your country of residence, including the United States and other countries where our service providers operate.
For transfers from the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on:
| Data Type | Retention Period |
|---|---|
| Account data | Until account deletion + 30 days |
| Beacons | Visible for 12 hours; stored until account deletion |
| Email OTP codes | 10 minutes or until verified (whichever is first) |
| Session data | Until logout or 30 days of inactivity |
| Analytics events | 12 months (aggregated/anonymized thereafter) |
| Error logs | 90 days |
Residents of Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws have similar rights to access, delete, correct, and port their data. We honor these requests consistent with applicable law.
You can exercise most rights directly in the app:
For other requests, contact us at security@usebeacon.social. We will respond within 30 days (or as required by applicable law). We may need to verify your identity before processing requests.
We implement appropriate technical and organizational measures including:
No system is 100% secure. If you discover a security vulnerability, please report it to security@usebeacon.social.
Beacon is not intended for children under 13 years of age. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal data, please contact us at security@usebeacon.social and we will delete it.
For users in the EEA, the age threshold may be higher (up to 16) depending on your country's implementation of the GDPR.
We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on you. Beacon matching is based solely on mutual friend connections and explicit beacon activity, not algorithmic profiling.
We use minimal, essential cookies and local storage for:
We do not use tracking cookies, advertising cookies, or third-party analytics cookies. We do not participate in cross-site tracking.
We may update this Privacy Policy from time to time. We will notify you of material changes by:
Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.
This Privacy Policy is governed by the laws of the Republic of Estonia, without regard to conflict of law principles. For EU residents, this does not affect your rights under mandatory consumer protection laws in your country of residence.
For privacy-related inquiries:
Email:security@usebeacon.social
General inquiries:team@usebeacon.social
For EEA residents, you have the right to lodge a complaint with your local supervisory authority. A list of EU data protection authorities is available at edpb.europa.eu.