Privacy policy
Deep Connect Solutions GmbH ("we", "us", "our") operates the Abbs mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our App. We are committed to protecting your privacy and complying with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.
By using Abbs, you acknowledge that you have read and understood this Privacy Policy.
1. Information We Collect
1.1 Information You Provide
- Account information: When you use Sign in with Apple, we receive your Apple user identifier and, when Apple provides them, your name and email address. We store those details as part of your Abbs account. If you verify your phone number, we collect that number for additional account security and abuse prevention.
- Profile information: Your username, date of birth, calculated age, gender, ethnicity, height, weight, body type, tribe, relationship status, positions, looking-for preferences, profile status, and any free-text "about me" description you enter.
- Photos and videos: Images and videos you upload to your profile or share in chats, including album content.
- Messages: Text messages, photos, and videos sent through the in-app chat feature.
- Location data: Your precise GPS coordinates (latitude and longitude) and derived city name, used to show you nearby users and display your approximate distance to others. We also retain a limited history of your location updates for service operation, security, troubleshooting, and improvement.
- Subscription and purchase data: Details of any in-app purchases (Gold or Platin subscriptions), processed through Apple's App Store.
- Safety and moderation information: Blocks and reports you submit, including the reported account, reason, optional details, review status, and any moderation or enforcement records associated with the report.
- QR pass information: If you create a QR pass, we store its destination (chat or profile), selected validity, creation and expiry times, and a one-way hash of the pass token. We do not store the raw bearer token on our servers.
1.2 Information Collected Automatically
- Device information: We maintain a record of the devices you use to access the App, which is updated each time you open the App and is associated with your account. This record includes your device model, platform, operating system name and version, app version and build number, language, locale, time zone, a per-vendor device identifier (Apple's identifierForVendor), basic display characteristics (screen dimensions and scale), low-power-mode status, and push notification tokens. The per-vendor device identifier is not an advertising identifier (we do not collect Apple's IDFA) and is not used for cross-app tracking; accordingly, no App Tracking Transparency prompt is presented.
- Device-integrity information: On supported devices, Apple App Attest helps us verify that protected actions come from a genuine instance of Abbs. We process App Attest key identifiers, public keys, attestation receipts, assertion counters, timestamps, and validation results for this purpose.
- Usage data: Interactions within the App such as viewing or opening profiles, likes, favorites, and starting chats. These records are used to operate and improve the discovery experience and to understand feature use.
- Location history: A record of your location updates over time, retained for service operation, security, troubleshooting, and improvement. Location history is retained for no more than 90 days and then automatically deleted.
- Log and connection data: IP addresses, access times, API and feature errors, and related diagnostic information. When you open the App, we record the IP address of your connection (determined on our servers from your network request) together with the device record described above, to help secure your account and prevent fraud and abuse.
- Online status: Whether you are currently active in the App, based on your WebSocket connection state.
1.3 Information from Third Parties
- Sign in with Apple: Authentication tokens and, when provided by Apple, your name and email address.
- Apple App Store: Subscription status and transaction identifiers for in-app purchases.
- Apple device services: App Attest integrity information and push-notification delivery services where those features are used.
2. How We Use Your Information
We process your personal data for the following purposes:
- Providing the service: Creating your account, displaying your profile to other users, enabling chat and messaging, facilitating discovery of other users based on location and preferences.
- Personalisation: Tailoring the profiles shown to you based on your stated preferences (filters), location, and interaction history.
- Content moderation: Automatically evaluating uploaded photos and videos, recording user reports, and enforcing our community guidelines and applicable laws.
- Safety and security: Detecting and preventing fraud, abuse, harassment, and other harmful activities. Enforcing our Terms of Service and blocking users who violate them. We use device information, device-integrity information, and connection data (including device identifiers and IP addresses) to identify suspicious activity and protect accounts.
- Push notifications: Sending you messages, likes, visit notifications, and other relevant updates via Apple Push Notification Service (APNs).
- Subscriptions: Processing and verifying in-app purchases, managing your subscription tier (Free, Gold, or Platin), and providing tier-appropriate features.
- QR passes: Creating time-limited QR links and resolving them to the chat or profile destination you selected.
- App compatibility and support: Recording the app version and build you are running so we can ensure compatibility, deliver and prompt required updates, and provide technical support and diagnostics.
- Analytics and improvement: Understanding how users interact with the App to improve features, fix bugs, and enhance the user experience. We may use aggregated, de-identified data for this purpose.
- Legal compliance: Responding to legal requests, enforcing our agreements, and complying with applicable laws and regulations.
3. Legal Basis for Processing (GDPR)
Under the GDPR, we rely on the following legal bases:
- Contract performance (Art. 6(1)(b)): Processing necessary to provide you with the App's services, including account creation, profile display, messaging, and discovery.
- Legitimate interests (Art. 6(1)(f)): Processing for fraud prevention, security, analytics, and service improvement, where our interests do not override your fundamental rights.
- Consent (Art. 6(1)(a)): For processing your precise location data and sending push notifications. You may withdraw consent at any time through your device settings.
- Legal obligation (Art. 6(1)(c)): Where we are required to process data to comply with applicable law.
4. How We Share Your Information
4.1 With Other Users
Your profile information (username, calculated age, photos, profile status, approximate distance, and other profile fields) is visible to other Abbs users in accordance with your privacy settings. Messages and media you send are visible to their recipients subject to the sharing controls you select.
4.2 Service Providers
We use the following infrastructure providers to operate the App:
- Amazon Web Services (AWS): Our core backend, database, and media-storage systems are hosted in the European Union (Germany). A global content delivery network may process network information and deliver requested media from locations closer to users.
- Apple: For Sign in with Apple, App Attest, Apple Push Notification Service, and App Store subscription processing. Apple services may process data outside the European Union in accordance with Apple's applicable terms and privacy policies.
Where a service provider processes personal data on our behalf, we require contractual, organisational, and technical protections consistent with this Privacy Policy and applicable law, providing the same or an equivalent level of data protection.
4.3 We Do Not Sell Your Data
We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We do not share your data with advertisers.
4.4 Legal Requirements
We may disclose your information if required by law, court order, or governmental request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
5. Data Storage and Security
- Core account data, databases, and media storage are hosted on AWS infrastructure in the European Union (Germany). Requested media may be delivered through global content-delivery edge locations.
- Media files (photos and videos) are delivered through a content delivery network with signed, time-limited URLs that expire automatically.
- Passwords are not stored; authentication is handled through Sign in with Apple and secure token-based sessions.
- Verified phone numbers are encrypted at rest and are not displayed to other users. On our servers, QR pass bearer tokens are stored only as one-way hashes.
- We implement industry-standard security measures including encryption in transit (TLS), encrypted storage, and access controls. However, no method of transmission or storage is completely secure.
6. Data Retention
- Active accounts: Your data is retained for as long as your account is active.
- Account deletion: When you delete your account, we initiate a 30-day grace period during which the account is deactivated and may be restored only after your confirmation. After the grace period, the account and its associated profile, messages, conversations, media, locations, interactions, and other user-linked records are permanently deleted from our active production systems. Limited records may be retained where required by law, to establish or defend legal claims, or to meet financial and security-audit obligations. Residual copies may remain temporarily in protected backups until they are overwritten under our normal backup cycle.
- Location history: Your location history is retained for a maximum of 90 days. Older entries are automatically and permanently deleted on a regular schedule.
- Chat messages: Messages are retained for the duration of the conversation. When a conversation or account is permanently deleted, its associated messages are removed from active systems.
- Interaction data: User-linked interaction records are retained for a maximum of 90 days. Aggregated or de-identified statistics that no longer identify an individual may be retained for service analytics.
- QR passes: A QR pass expires after the validity period you select, which is no longer than 30 days. Expired pass records are deleted by our cleanup process.
- Safety records: User-linked blocks, reports, profile status, and moderation records are removed during permanent account deletion unless limited retention is required for a legal or security reason.
- Legal holds: We may retain data longer if required by law or ongoing legal proceedings.
7. Your Rights
7.1 GDPR Rights (EU/EEA Users)
You have the right to:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate personal data.
- Erasure ("Right to be Forgotten"): Request deletion of your personal data, subject to legal retention requirements.
- Restriction of processing: Request that we limit how we use your data in certain circumstances.
- Data portability: Receive your personal data in a structured, machine-readable format and transmit it to another controller.
- Object: Object to processing based on legitimate interests.
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Lodge a complaint: File a complaint with your local data protection authority.
7.2 CCPA Rights (California Residents)
You have the right to:
- Know: Request disclosure of the categories and specific pieces of personal information we have collected about you.
- Delete: Request deletion of your personal information.
- Opt-out of sale: We do not sell personal information, so this right does not apply.
- Non-discrimination: We will not discriminate against you for exercising your CCPA rights.
To exercise any of these rights, please contact us using the information in Section 11 or use the account deletion feature within the App (Settings > Account > Delete Account).
8. Children and Age Restriction
Abbs is strictly for users aged 18 and older. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected data from a person under 18, we will delete that data immediately. If you believe a minor has provided us with personal information, please contact us.
9. International Data Transfers
Our core backend, database, and media-storage systems process data in the European Union. If you use Abbs outside the EU, your data is transferred to the EU. Global content delivery and Apple services may process limited data in other countries. Where personal data is transferred outside the EU/EEA, we use safeguards required by applicable law, such as an adequacy decision or standard contractual clauses where appropriate, and require processors acting on our behalf to provide the same or an equivalent level of protection.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you through the App (for example, by requiring re-acceptance) and update the "Last Updated" date above. Your continued use of the App after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy, wish to exercise your data protection rights, or have concerns about how we handle your data, please contact us at:
Deep Connect Solutions GmbH
Represented by: Cenk Türkeli
Address: Konsul-Smidt-Str. 8q, 28217 Bremen, Germany
Email: privacy@abbsapp.com
For GDPR-related inquiries, you may also contact your local data protection authority. The lead supervisory authority for Abbs is Die Landesbeauftragte fuer Datenschutz und Informationsfreiheit der Freien Hansestadt Bremen.
Website visitors
This section applies only to visitors of the abbsapp.com website. The controller is Deep Connect Solutions GmbH, represented by Cenk Türkeli, Konsul-Smidt-Str. 8q, 28217 Bremen, Germany (contact: privacy@abbsapp.com).
This website is a set of static pages hosted in the European Union and delivered through a content delivery network. It sets no cookies, runs no analytics, performs no tracking, and keeps no logs of your visit. It loads no resources from third parties and sends no data to anyone.
If you follow the links on this site to install or open the Abbs app, the privacy policy above governs your use of the app itself.