TwøDay Privacy Policy

Last Updated: September 2, 2026

TwøDay is operated by Social Maps Inc. ("we," "us," or "our"). This Privacy Policy explains what information the TwøDay mobile application ("TwøDay" or the "App") collects, why we collect it, who we share it with, how long we keep it, and what you can do about it.

By creating an account or using the App, you agree to the practices described here. If you do not agree, please do not use the App.

1. Age Requirement

TwøDay is intended for people aged 16 and over, and is rated 16+ on the App Store. The App shows real-world events and venues — including concerts, nightlife and other venues intended for older teenagers and adults — and lets users find and message one another nearby. We ask you to confirm you meet the minimum age when you sign up.

We do not knowingly collect personal information from anyone under 16. If we learn that an account belongs to someone under 16 — from a date of birth, a report, or any other source — we will close it and delete its data within 30 days, without waiting for a request. We do not knowingly collect personal information from anyone under 13, and we would delete any such information immediately on becoming aware of it. If you believe someone under 16 has given us personal information, email us at usercare@twoday.live.

If you are in the European Economic Area or the United Kingdom, the age at which you can consent to an online service on your own varies between 13 and 16 depending on where you live. If you are below that age in your country, you need a parent or guardian's permission to use TwøDay.

2. Information We Collect

a) Information you give us

  • Account details: your username, display name, email address, and password (stored only as a salted hash — we never store it in readable form).
  • Optional profile details: profile photo, bio, recovery email address, and date of birth. These fields are optional; leaving them blank does not limit the App.
  • Sign-in with Apple or Google: if you use one of these, we receive a provider account identifier and basic profile information (name, email address, and — where the provider supplies it — a profile photo). We never receive or store your Apple or Google password. If you use Apple's Hide My Email, we only ever see the relay address Apple gives us.
  • Things you create in the App: activities and group events you post, chat messages, photos you upload, comments, and your joins, saves and RSVPs.
  • Reports and support requests: reports you file about other users, groups or content, blocks you apply, and bug reports or messages you send us.

b) Location information

TwøDay is a map. Location is the core of how it works, so we want to be precise about what happens to it rather than vague.

  • What we collect: your device's approximate or precise GPS coordinates (latitude and longitude), and cities you search for manually.
  • What we do with it in the moment: we send your coordinates to our servers and to our event data partners to find events, activities and recreation near you, and to draw the map around you.
  • What we store: we store your most recent coordinates on your account record, so the App can open on the right part of the map and so nearby-user features work. We also record dated location entries — coordinates plus the city and country they resolve to — as part of the usage log described in Section 2(c). Taken together, these entries form a history of the general places you have opened the App. Earlier versions of this policy said we did not keep a location history. That was inaccurate, and this section corrects it.
  • What we do not do: we do not track you in the background when the App is closed, we do not sell location data, and we do not share your individual location with advertisers or data brokers.
  • What other users see: other users can see that you are nearby, and can see the location of activities and groups you choose to post. They do not see your stored coordinate history.
  • Your control: you can turn location access off at any time in your device settings. The App will not be able to show you nearby events without it, and you can still browse by searching a city by name.
  • How long we keep it: at 90 days old, each dated location entry is automatically replaced by a daily tally — how many times the App was used in a city, and for what. No coordinates. No IP address. Nothing showing where in the city you were. We delete those tallies 12 months after the day they cover. The single most-recent coordinate on your account is deleted with the rest of your account data when you ask us to delete your account (see Section 7).

c) Information collected automatically

  • Usage and diagnostic events: we record a dated log of app activity — installs, sign-ins (successful and failed), session starts and heartbeats, profile completion, city searches, and activity creation. Each entry may include the coordinates, city and country described above, the provider or source involved, and a one-way hash of your IP address. We hash the IP so that we can spot abuse and duplicate accounts without keeping a record of the actual address.
  • Signup context: the city and country you first signed up from, and the source that brought you to the App (for example, an app store or a referral link).
  • Device information: device model, operating system version, app version, and device identifiers supplied by the platform.
  • Push notification token: if you allow notifications, we store the token Firebase Cloud Messaging issues to your device so we can deliver alerts.

d) Your device's calendar

If you tap "Add to Calendar" on an event, the App hands the event's title, time and venue to your device's own calendar app, which asks you to confirm before saving. We never read your calendar, and no calendar information is sent to our servers.

e) Information we do not collect

  • We do not ask for or store your phone number.
  • We do not read, upload or match your device's contacts or address book.
  • We do not collect payment card details, billing addresses or financial information. TwøDay is free and has no purchases or subscriptions.
  • We do not collect health, fitness, biometric or precise-advertising data.
  • We do not use third-party advertising networks, and we do not run ads.

3. How We Use Your Information

  • To run the service: show you events, activities and recreation near you; draw the map; power search, groups and chat.
  • To manage your account: create and authenticate your account, keep you signed in, and let you edit your profile.
  • To notify you: send push notifications you have opted into — group invites and join requests, messages, and event updates.
  • To keep TwøDay safe: investigate reports, enforce blocks, detect spam, fraud and duplicate accounts, and act on violations of our Terms.
  • To fix and improve the App: diagnose crashes and errors, measure whether features work, and understand which areas need better event coverage.
  • To meet legal obligations: respond to lawful requests and enforce our agreements.

We do not use your information to build advertising profiles, and we do not make automated decisions that produce legal or similarly significant effects about you.

4. Legal Bases (for users in the EEA and UK)

  • Performance of a contract: account creation, showing you the map, delivering messages and groups.
  • Consent: location access, push notifications, and optional profile fields such as your date of birth. You can withdraw consent at any time through your device settings or by clearing the field.
  • Legitimate interests: keeping the service secure, preventing abuse, and diagnosing faults — balanced against your privacy, which is why we hash IP addresses and delete usage logs on a schedule.
  • Legal obligation: responding to valid legal process.

5. Third-Party Services

TwøDay relies on the following providers. Each has its own privacy policy.

  • Google Maps Platform — draws the interactive map and resolves places. Coordinates and map requests are sent to Google. See Google's Privacy Policy.
  • Firebase (Google) — push notification delivery and basic app analytics. See the Firebase Privacy Policy.
  • Sign in with Apple — optional authentication. See Apple's Privacy Policy.
  • Google Sign-In — optional authentication. See Google's Privacy Policy.
  • Event data providers — including SeatGeek, Ticketmaster and other public event sources. We send approximate coordinates and a search radius to retrieve nearby events. We do not send your name, email address, account identifier or any other personal information to these providers.
  • Amazon Web Services (AWS) — hosting, database and file storage, located in the United States. See the AWS Privacy Notice.

We previously offered Facebook Login. It has been removed, and we no longer receive any information from Meta.

6. Sharing and Disclosure

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We share information only as follows:

  • With other users: your display name, username, profile photo, bio, and anything you post in groups or chat are visible to the users who can see that content. Your friend and mutual-friend connections are visible to people who can see your profile.
  • With service providers: the providers listed in Section 5, who process data on our instructions and are bound by confidentiality obligations.
  • For legal reasons: when required by law, subpoena, or valid government request, or to establish or defend legal claims.
  • For safety: when we believe disclosure is necessary to prevent imminent harm to a person, or to protect the rights, safety or property of Social Maps Inc., our users or the public.
  • In a business transfer: if Social Maps Inc. is involved in a merger, acquisition or sale of assets, your information may transfer as part of that transaction. We will tell you before your information becomes subject to a materially different privacy policy.

Protection by third parties. Every third party with whom we share user data — including the providers named in Section 5, any analytics tool, advertising network or third-party SDK, and any parent, subsidiary or other related entity that has access to user data — is contractually required to provide the same or equal protection of your data as this policy describes. They may process your information only on our instructions and for the purposes set out here, and may not use it for their own purposes.

7. How Long We Keep Information

  • Account and profile data: kept while your account is active, and deleted within 30 days of a deletion request.
  • Usage, diagnostic and dated location entries: at 90 days old, each detailed row — coordinates, hashed IP, provider and device context — is automatically replaced by a daily count per city and activity type. That count is deleted 12 months after the day it covers. Both steps are automated and run on a fixed schedule.
  • Event and activity pins: transient by design; they leave the map shortly after the event ends and are pruned from our systems on a rolling basis.
  • Chat messages: kept while the group or conversation exists, and removed when it is deleted or when the account that created it is deleted.
  • Reports, blocks and moderation records: kept for up to 24 months after the account is closed, so that we can enforce bans and respond to repeat abuse. These records are minimised to what safety requires.
  • Encrypted backups: deleted data may persist in backups for up to 30 days before being overwritten.

8. Security

We protect your information with encrypted transport (HTTPS/TLS), hashed passwords, signed authentication tokens stored in your device's secure keychain, hashed IP addresses, and access controls on our AWS infrastructure. No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities as required by law.

9. Your Rights and Choices

  • Access and correct: view and edit your profile at any time in the App.
  • Delete your account: use Profile → Settings → Delete Account in the App, or email us. Deletion removes your profile, posts, messages and stored location data within 30 days, except the minimised safety records described in Section 7.
  • Export your data: email us and we will provide a copy of the personal information associated with your account.
  • Turn off location: at any time in your device settings.
  • Turn off notifications: in the App or in your device settings.
  • Withdraw consent: where we rely on consent, you may withdraw it at any time; this does not affect processing already carried out.
  • Object or restrict: where you are in the EEA or UK, you may object to or ask us to restrict certain processing, and you may complain to your local supervisory authority.
  • California residents: you have the right to know, delete, and correct your personal information, and the right not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA/CPRA. To exercise a right, email us at the address below.

We will not charge you for exercising these rights, and we will not degrade your experience because you did.

10. International Transfers

Our servers are located in the United States. If you use TwøDay from outside the United States, your information will be transferred to and processed there. Where required, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses for these transfers.

11. Contact Us

Questions, requests, or concerns about this policy or your data:

Social Maps Inc.

Support: help@twoday.live
Privacy, data requests, safety and user care: usercare@twoday.live
Commercial and events: admin@twoday.live

See also our Terms of Service, which govern your use of the App.

12. Changes to This Policy

We may update this policy. When we make a material change, we will update the "Last Updated" date above and, where the change meaningfully affects how we use your information, notify you in the App before it takes effect. Continuing to use TwøDay after a change means you accept the revised policy.