Privacy
sidebop Privacy Policy
Effective September 9, 2026
sidebop helps people discover events and build plans around them. This policy explains how the sidebop website and iOS app handle information.
Using sidebop without an account
You can browse events without creating an account. Guest saves, taste choices, and draft Boops may be kept on your device. The iOS app creates a random installation identifier so it can operate reliably and prevent duplicate interaction records; it is not an advertising identifier.
Information you choose to provide
- Account information: email address, password credential stored as a one-way hash, the identifier and relay email Apple provides when you use Sign in with Apple, or the identifier and verified email address Google provides when you use Continue with Google.
- Phone information, when those features are offered: the US mobile number you provide for phone sign-in or sidebop texts; after successful verification, the number is linked to your account as an authentication identifier. We also process verification state, your separate text-consent record, text preferences, and message delivery status.
- Your activity: saved events, taste preferences, private Boop prompts and workflow settings, generated plans, and inbox state.
- Support messages: information you include when you contact us.
- Shared-boop participation: the name, comments, RSVPs, and reactions you add on a shared boop page. These are visible to anyone with the link.
- Waitlist information: the email address you give us and the entry point where you joined.
A shared boop link carries the plan in the URL itself: the boop title, stop identifiers, roles, and any restrictions or settings the plan was built with. Anyone who has the link can read that information, so treat the link like the plan it contains.
Product and technical information
The iOS app may send foreground sessions and event interactions such as impressions, detail opens, saves, shares, and source-link opens, together with the event, time, broad category, selected intent, daypart, and coarse sidebop area. Those records may be associated with the random installation identifier and, after sign-in, your account. We use them to operate saves and Boops, personalize recommendations, understand aggregate product use, prevent abuse, and improve sidebop.
Our hosting and security systems may process ordinary request information such as IP address, device or browser type, timestamps, requested URLs, and error details. We use it to deliver and protect the service, diagnose failures, and enforce rate limits.
Location
Location is optional. In the iOS app, choosing “Use where I am” lets sidebop use device location on-device for nearby sorting; Apple Maps processes it for ETAs and directions. For ordinary reachability, the app sends sidebop only a starting point rounded to an approximately 150 m grid; exact device coordinates are not sent to Sidebop for those requests. sidebop keeps that rounded starting point only in an unlinked, in-memory routing cache for up to five minutes; a later movement, permission change, or travel-option change may create a new rounded request. You can always choose an LA area manually.
A separate, optional, account-linked text alert ring works differently. The recurring-text product surface is currently unavailable and disabled (“DARK”), so no one can preview or save a text-alert ring today. When recurring sidebop texts are available in an eligible app build, you can explicitly choose and save one current 15- or 30-minute walk, bike, transit, or drive ring. To preview it, sidebop receives the selected origin and creates the travel-time boundary on its servers. If you save it, sidebop normalizes the origin to three decimal places and keeps an encrypted ring definition—including that normalized origin and the server-derived boundary—linked to your account. We use it only for app functionality: remembering the ring and matching eligible new events so an alert can be prepared if you have separately turned recurring texts on. We do not use it for advertising or tracking, send it to Plausible, collect your location continuously, or monitor location in the background. Because the saved origin and boundary are account-linked, sidebop treats them as precise location in its App Store privacy disclosure.
On the website, your browser may provide an approximate device location after you grant permission so the page can estimate nearby events. The website may also use a coarse network-derived hint for local ranking. sidebop does not send precise coordinates or a manually chosen neighborhood to Plausible Analytics.
Website analytics
The website uses Plausible Analytics for aggregate page and product-use measurement. We configure it without form-submission capture. Analytics can include pageviews and actions such as choosing an intent, changing a filter, viewing results, or opening an event source. The iOS interaction service described above is separate from Plausible.
The app download page no longer assigns visitors to different page designs. A version cookie from the earlier comparison is ignored and expires within 30 days of being set; it contains no unique identifier.
Optional Meta ad measurement on /get
For recognized Meta ad and sidebop Instagram-profile visits, the sidebop app landing page also uses a dedicated Meta Pixel to understand whether the visit led to a landing-page view or an App Store-link tap. The pixel does not load for direct or QR-code visits. Meta may receive ordinary browser and network information, the page URL and referrer, Meta pixel cookies, a PageView event, and an AppStoreClick event with an allowlisted acquisition-channel token, browser-context, and button-placement fields. An AppStoreClick means only that someone tapped a Store link; it is not an install, registration, or first open.
We run this pixel in Meta’s Limited Data Use mode and disable automatic event discovery. We do not use advanced matching or send Meta a sidebop account identifier, phone number, email address, form value, Boop content, precise location, or iOS installation identifier. Meta processes pixel information under its Business Tools Terms, State-Specific Terms, and US Regional Privacy Notice; those terms state that event data may be retained for up to two years.
Meta measurement does not load when your browser sends a Global Privacy Control signal or when you turn it off through Your Privacy Choices on /get. Turning it off stores the choice in that browser, stops future Sidebop-triggered Meta events, and clears Sidebop’s first-party Meta pixel cookies where the browser permits it. You can return to Your Privacy Choices to allow measurement again; Global Privacy Control always takes priority.
Optional Meta ad measurement in the iOS app
In app versions that offer Ad measurement in Profile, this setting is off until you turn it on and allow tracking through iOS. With both permissions, sidebop uses Meta’s iOS SDK to measure which advertisements bring people to the app and whether they create an account, use the map, or open a detail. Meta can receive app installation and activation signals, eligible new-account creation events, coarse map-use and detail-open activity, advertising and SDK device identifiers, and standard app, device, network and diagnostic information. These signals do not establish every download or registration, and a first measured activation can occur after installation. This measurement is disabled in TestFlight and other test builds.
We do not include your sidebop account identifier, email address, phone number, location coordinates, search text, Boop content, or the identity of events you view in the activity events we add. The random installation identifier used by sidebop’s own interaction service remains separate and is not passed to Meta. Meta’s own identifiers and network information are distinct from that first-party identifier.
Your choice is stored on this iPhone. Turning Ad measurement off stops new sidebop activity events. You can also withdraw iOS tracking permission in Settings. This does not recall information already sent or requests already in flight. Activity queued while you allowed measurement may be sent if you allow it again. New-account events require your measurement choice to be active before account creation begins; signing into an existing account or enabling measurement later does not count as a new registration. Pending local registration events are cleared if you withdraw this choice or change accounts. The device keeps a hashed account reference to avoid duplicate registration dispatch attempts; this reference is not sent to Meta and is removed when you delete your account. Every sidebop feature remains available with measurement off. We configure the SDK with Meta’s Limited Data Use setting and regional auto-detection, and enable its restriction of app-event data to analytics and conversions. Meta processes information under its Business Tools Terms and applicable regional privacy terms.
Phone verification and sidebop texts
As of August 22, 2026, sidebop’s US carrier registration for recurring texts is verified, but the recurring-text product surface is currently unavailable and disabled (“DARK”). The current service cannot accept recurring-SMS consent or save a text-alert ring; no alert can be enqueued and no recurring SMS can be sent. Posting this policy, creating an account, connecting a phone, or requesting a verification code does not enroll anyone.
If phone-number sign-in is offered, sidebop may send a one-time verification code that you request. Requesting a code or providing a number does not enroll you in recurring texts. If the recurring-text surface is separately activated for your app and account, you will receive saved-event reminders or chosen-ring alerts only after you check a distinct SMS-only checkbox that starts blank and then submit the enabled Turn on texts action. Closing or declining the sheet leaves texts off. Message frequency varies, and message and data rates may apply. Reply STOP to unsubscribe. Reply START only to remove a carrier-level delivery block; START does not restore sidebop consent, so you must opt in again in the app. Reply HELP for help. See the sidebop texts opt-in page for the built in-app consent flow and current program status, or the sidebop texts terms for the full program rules.
Twilio processes the phone number and verification status as sidebop’s phone-verification provider and, before recurring texts can be enabled, may process it to confirm mobile-line eligibility. If sidebop texts later send an alert, Twilio also processes the destination number, message, and delivery information needed to transmit it. A geographic-ring alert can state the number of new matching events and the selected travel mode and time, but it does not include the saved ring origin or boundary. Twilio may monitor US and Canadian message content for spam, fraud, and compliance as described in its own privacy and service notices.
sidebop stores a verified phone number using authenticated encryption, with a separately keyed lookup digest and a last-four display hint. sidebop’s application database does not store the raw E.164 number in plaintext. Verification challenges are short-lived and bounded; the app does not persist the one-time code or send a raw phone number to analytics or application logs.
sidebop does not sell mobile information or share mobile numbers, text opt-in data, or consent with third parties or affiliates for marketing or promotional purposes. Twilio and any other messaging or authentication provider may process this information only as needed to verify your number, deliver messages, provide support, protect the service, and comply with law.
How information is shared
We do not sell personal information. We do not send advertising providers sidebop account identifiers, mobile numbers, precise location, Boop content, or sidebop’s first-party iOS installation identifier. If you allow Meta measurement on /get, Meta receives the limited web information described above under its own terms and the Limited Data Use setting. If you separately allow optional iOS ad measurement and iOS tracking, Meta receives the app activity and SDK advertising, device, network and technical information described above under the Limited Data Use setting. We otherwise disclose information only as needed to service providers that help host, secure, analyze, and communicate for sidebop; to comply with law or protect people and the service; or as part of a business transfer subject to appropriate safeguards.
Current service categories include cloud and website hosting, transactional email, website analytics, limited advertising measurement, and Apple and Google authentication. Twilio also provides phone verification and, if a person later separately opts in after the recurring-text surface becomes available, messaging. Event and ticket links open third-party sites governed by their own privacy practices.
Retention and deletion
We keep account and product information while needed to provide sidebop, maintain security, meet legal obligations, and resolve disputes. Raw interaction records are automatically deleted after 90 days, and privacy-protected hourly activity summaries are automatically deleted after 180 days. Other record types follow their operational or legal purpose, and backups expire on their normal cycle.
When phone verification is enabled, we keep the encrypted phone identifier while it remains linked to an active account. If recurring texts become available, we will keep text-consent and opt-out records as needed to provide the program, prove consent, honor your preference, and meet legal requirements. Replying STOP will disable recurring sidebop texts; it will not delete the account or prevent a one-time verification code you separately request.
If the recurring-text surface becomes available, sidebop will keep a saved text-alert ring’s encrypted origin and boundary only while that ring and its associated recurring-text consent are active. Removing the ring deletes the active encrypted definition and cancels pending alerts for it. Turning texts off in Profile or replying STOP withdraws recurring-message consent, removes active text-alert rings, and cancels pending recurring messages. Replacing the verified number also withdraws that consent and requires a fresh opt-in. We may retain limited consent, opt-out, delivery, and non-coordinate security records as needed to prove choices, honor suppression, prevent unsafe retries, protect the service, or comply with law; backups expire on their normal cycle.
Shared-boop participation (names, comments, RSVPs, and reactions) is kept until the thread closes, 30 days after the boop's reference date. A waitlist email address is kept until the purpose it was collected for ends or you ask us to delete it.
You can delete a signed-in account inside the iOS app from Profile → Delete account. Deletion removes the account and linked saves, taste, Boops, sessions, devices, interaction records, and active text-alert ring definitions from the active service. If phone features were used, deletion also removes the encrypted number, its ownership lookup material, active verification state, pending delivery state, and consent records unless retention is legally required. A minimal suppression record may remain only when needed to honor an opt-out; it cannot be used to recover the number. Device-only guest state remains on that device unless you remove it or uninstall the app. You can also contact hello@sidebop.com for access, correction, or deletion help.
Security
We use administrative, technical, and organizational safeguards intended to protect information. No online service can guarantee absolute security, so please use a unique password and tell us if you believe your account has been compromised.
Children
sidebop is not directed to children under 13. Some linked events or venues may have their own age restrictions; always check the source listing.
Changes
We may update this policy as sidebop changes. We will post the new effective date here and provide additional notice when a material change requires it.
Contact
Questions or privacy requests can be sent to hello@sidebop.com. See the Terms of Service or sidebop Support for account and event help.