1. Controller and contact details
The controller responsible for the processing described in this Privacy Policy is:
MNY GmbH
Birkenstrasse 47
6343 Rotkreuz
Switzerland
Email: admin@getplacesapp.com
You may contact us at this address about privacy, access, correction, objection, or deletion requests.
2. Scope
This Privacy Policy applies to registered Places users, private-alpha testers, website visitors, people who message @goplacesapp, and people who submit an Instagram link through the Service. It also covers data received through the Meta and Instagram platforms.
Meta and Instagram operate independently under their own terms and privacy policies. Places is not owned, sponsored, endorsed, or operated by Meta or Instagram.
3. Personal data we collect
Depending on how you use the Service, we may process the following categories of data.
3.1 Account and authentication data
- Your name, display name, email address, and internal account identifier.
- Authentication provider and provider-specific identifiers when you sign in with Apple, Google, email, or another supported method.
- Account status, language, settings, consent records, and the versions of policies you accepted.
- Security and authentication records required to protect your account.
We do not receive your Apple, Google, Meta, or Instagram password.
3.2 Instagram identity and messaging data
- Your Instagram-scoped sender identifier and, when available, Instagram username.
- The identifier of the Places Instagram Business account and the status and time of your Instagram connection.
- Meta message identifiers, event type, message and receipt timestamps, and processing status.
- Public Instagram post, Reel, or carousel links that you send to Places.
- Verification or account-claim messages used to connect your Instagram identity to a Places account.
- Limited technical information required to send processing, success, unresolved, duplicate, unsupported, or failure replies.
We use the Instagram-scoped identifier rather than relying only on a changeable username. We do not ask for or store your Instagram password, cookies, or login session.
3.3 Public Instagram content metadata
For a public Instagram item that you choose to submit, we may process:
- The original and normalized Instagram URL.
- Content type, such as Reel, post, or carousel.
- Creator username.
- Public caption text when accessible and permitted.
- Public location tag and related place identifiers when accessible.
- A permitted thumbnail URL, thumbnail reference, or limited cached thumbnail.
- Retrieval time, source, confidence, and field-level provider provenance.
We do not intentionally collect private Instagram content, Instagram Stories, complete profiles, or raw Reel or post video. Places processes one submitted public item at a time and does not crawl a creator's profile.
3.4 Saved-place and app data
- Saved place name, address, coordinates, geographic granularity, category, website, and description.
- Place-provider identifiers and legally required provider attribution.
- Instagram items attached to a saved place.
- Resolution candidates, confidence signals, corrections, unresolved status, and processing attempts.
- Favorite and visited status and other settings you choose to use.
- Data needed to prevent duplicate places or duplicate processing.
Saved places are private by default. Places does not provide a public profile or public social feed in its initial version.
3.5 Location data
If you grant permission, the mobile app may use your device's precise foreground location to center the map and provide location-relevant functions. Places does not collect background location. You may deny or withdraw location permission in your device settings; the core saved-place map remains usable without it.
3.6 Device, website, log, and security data
- IP address, browser or device type, operating system, app version, timestamps, and request identifiers.
- Crash, performance, queue, provider, security, and audit records.
- Cookie choices and website interactions where cookies or similar technologies are used.
- Name, email address, and message if you use a website contact form or contact support.
Operational analytics are designed not to include raw Instagram URLs, captions, exact private map contents, passwords, access tokens, or unnecessary personal identifiers.
3.7 Data we infer or generate
- A likely place name derived from a public location tag or caption.
- A Places category, place-resolution confidence, and duplicate assessment.
- A short place description generated from permitted source information.
- Internal fraud, abuse, reliability, and security signals.
Places does not use automated processing to make legal, employment, credit, insurance, or similarly significant decisions about you. Automated place results may be corrected by the user.
4. Sources of personal data
We obtain data:
- Directly from you when you create an account, contact us, use the app, paste a link, or message @goplacesapp.
- From Meta and Instagram when they deliver an authorized messaging event or public-content information.
- From public Instagram pages or permitted public embed representations for a link you submitted.
- From authentication providers you choose to use.
- From place, mapping, AI, hosting, security, and metadata providers used to operate the Service.
- Automatically from your device or browser when needed for operation, security, and diagnostics.
5. How and why we use personal data
We process personal data to:
- Create, authenticate, secure, and administer Places accounts.
- Link a Places account to the correct Instagram sender through a DM-based verification process.
- Receive and process public Instagram links submitted by DM or in the app.
- Identify, categorize, describe, deduplicate, and save places to a private map.
- Keep unresolved submissions so the user can correct them.
- Reply to Instagram messages initiated by the user.
- Synchronize data across the app and provide support.
- Prevent duplicate webhook events, fraud, misuse, unauthorized access, and security incidents.
- Diagnose failures, retry transient errors, monitor reliability, control provider costs, and improve the Service.
- Enforce our Terms of Service and comply with applicable law and valid legal requests.
- Send service communications and, only where permitted, optional marketing communications.
Where the GDPR or similar law applies, our legal bases are:
- Performance of a contract: providing the Service you requested, including account, Instagram-assistant, saved-place, and support functions.
- Legitimate interests: securing and improving the Service, preventing abuse, troubleshooting, maintaining audit records, and operating an efficient private alpha, provided those interests are not overridden by your rights.
- Consent: foreground location, optional cookies, marketing, or other processing where consent is required. You may withdraw consent at any time without affecting earlier lawful processing.
- Legal obligation: complying with tax, accounting, regulatory, security, and valid legal requirements.
6. How we use Meta and Instagram Platform Data
We process Meta and Instagram Platform Data only to provide and secure the Places functions described in this Privacy Policy. We do not sell Platform Data, use it for unrelated advertising, build unrelated user profiles, or disclose it to data brokers.
We request and retain only the fields reasonably needed for the submitted-link and messaging workflow. We provide all Places users, including Instagram-only or unregistered senders, with an accessible way to request deletion. We update or delete Platform Data when required by the user, Meta, applicable law, or when it is no longer needed for a legitimate disclosed purpose.
7. Service providers and recipients
We may disclose limited personal data to providers acting for us and under contractual confidentiality and data-protection obligations. Depending on the feature and environment, these may include:
- Meta and Instagram: inbound and outbound Instagram messaging, public-source links, permissions, and platform operation.
- Supabase: authentication, database, storage, edge functions, queues, and backend infrastructure. The current development project is hosted in the London, United Kingdom region.
- Apple: optional account authentication, mobile distribution, device services, and external directions when selected by the user.
- Google Maps Platform: Google map display, place-name resolution, Place IDs, addresses, coordinates, place types, and required attribution. A fully qualified place query and any available geographic bias may be sent to Google. Google may also receive technical request information such as an IP address. Google processes information under the Google Privacy Policy at https://policies.google.com/privacy.
- OpenAI: focused structured extraction, classification, contradiction checking, or short descriptions when AI enrichment is enabled. We minimize submitted fields and use business/API privacy controls where available.
- Approved public-content metadata providers: limited extraction of the specific public Instagram URL submitted by the user. During an expressly limited alpha evaluation, Bright Data may be evaluated for direct public URLs only; no Instagram credentials, cookies, private accounts, full profiles, or raw videos may be provided.
- Website, email, monitoring, security, and support providers: hosting, service communications, fraud prevention, diagnostics, and support.
We do not permit service providers to use Meta Platform Data for their own unrelated purposes. We remain responsible for selecting providers and limiting the data sent to them.
We may also disclose data when required by law, to protect rights or safety, in connection with a corporate transaction subject to appropriate safeguards, or with your specific direction or consent.
8. International transfers
MNY GmbH is located in Switzerland, and our providers may process data in Switzerland, the United Kingdom, the European Economic Area, the United States, or other countries. Where required, we rely on recognized adequacy decisions, contractual safeguards such as applicable standard contractual clauses, or another lawful transfer mechanism. You may contact us for information about the safeguards relevant to your data.
9. Retention
We keep personal data only for as long as reasonably necessary for the purposes described above, including the following rules:
- Unregistered Instagram senders: submissions and related extracted content are kept temporarily for up to seven days so the sender can create an account and claim them. If they remain unclaimed, the temporary submission data is deleted automatically. A warning may be sent approximately 24 hours before the earliest deletion deadline.
- Registered users: account, Instagram connection, saved places, and submitted items are retained while the account is active or until the user deletes the relevant item, disconnects a feature where deletion applies, or requests account deletion.
- Google Maps Platform place data: Google Place IDs may be retained. Google-derived coordinates are refreshed or removed within the permitted period, currently no more than 30 consecutive calendar days, unless the user independently confirms or corrects data in a manner that permits different treatment under applicable terms.
- Deleted unresolved submissions and places: removed promptly from active user-facing systems after confirmation.
- Account deletion: access is disabled promptly. A seven-day recovery period may apply; after it ends, permanent deletion begins and is completed as soon as reasonably possible.
- Security, audit, legal, and transaction records: retained only for the period reasonably required to protect the Service, meet legal obligations, resolve disputes, or enforce agreements. Where possible, remaining records are minimized, aggregated, or de-identified.
- Backups: residual data in protected backups is isolated from ordinary use and removed through the applicable backup-overwrite cycle unless retention is legally required.
If an original Instagram post later becomes private or is deleted, a saved place and limited metadata previously stored in Places may remain until the Places user deletes it or requests deletion.
10. Your choices and rights
Subject to applicable law, you may have the right to:
- Request information about and access to your personal data.
- Correct inaccurate or incomplete data.
- Request deletion of your data.
- Restrict or object to certain processing.
- Receive certain data in a portable format.
- Withdraw consent where processing relies on consent.
- Object to direct marketing at any time.
- Lodge a complaint with a competent data-protection authority.
In Switzerland, you may contact the Federal Data Protection and Information Commissioner. If you are in the EEA or United Kingdom, you may also contact the supervisory authority for your residence, work, or the alleged infringement.
To exercise a right, email admin@getplacesapp.com. We may request reasonable information to verify your identity and protect data from unauthorized disclosure. We will respond within the period required by applicable law.
Detailed deletion instructions are available at https://getplacesapp.com/data-deletion.
11. Account and Instagram disconnection
Disconnecting Instagram or revoking Places access in Instagram stops future authorized access but does not by itself delete data already saved in Places. To remove stored data, use the in-app deletion controls when available or follow the Data Deletion Instructions.
12. Security
We use technical and organizational safeguards appropriate to the private alpha, including encrypted transport, managed encryption at rest, access controls, server-side secret storage, signed-webhook verification, data minimization, private database schemas, Row Level Security for consumer-owned tables, idempotent processing, and administrative audit logging.
No service can guarantee absolute security. Please contact admin@getplacesapp.com if you believe your account or data has been compromised.
13. Children
The Service is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided data to Places, contact us so we can investigate and delete it where appropriate.
14. Cookies and website technologies
The website may use essential cookies or similar technologies for security, session management, preference storage, contact-form protection, and basic operation. Optional analytics or marketing cookies will be used only with any consent required by law. You can manage cookies through the website banner and browser settings.
15. Changes to this policy
We may update this Privacy Policy as the Service, providers, or legal requirements change. We will update the date above and provide additional notice when a change is material. The current version will remain publicly available at https://getplacesapp.com/privacy.
16. Contact
MNY GmbH
Birkenstrasse 47
6343 Rotkreuz
Switzerland
Email: admin@getplacesapp.com