Privacy Policy, Gutsy Ltd

Effective Date: April 6, 2026 ยท Version 1.0

1. Introduction

Welcome to Just Gutsy. This Privacy Policy explains how GUTSY LTD ("Company", "we", "us", "our") collects, uses, and protects your personal data when you use our mobile application (the "App") and related services (the "Services").

Your privacy is important to us. We are committed to protecting your personal data and being transparent about how we handle it. This policy is designed to comply with the UK General Data Protection Regulation (UK GDPR).

Where applicable, this policy also addresses our obligations under the Privacy and Electronic Communications Regulations 2003 (PECR), which governs our use of push notifications, marketing communications, and analytics technologies such as Firebase and Google Analytics.

2. Who is the Data Controller?

For the purposes of the UK GDPR, the data controller is:

GUTSY LTD A company incorporated in England and Wales.

Company Number: 16761444

Registered Address: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ

If you have any questions about this Privacy Policy or our data protection practices, please contact us at:

Email: hello@justgutsy.com

You have the right to lodge a complaint with the UK's data protection regulator, the Information Commissioner's Office (ICO), at any time. You can find their contact details at www.ico.org.uk.

3. What Personal Data Do We Collect?

We collect data that you provide to us directly, data generated through your use of the App, and data from third parties. This is necessary to provide and improve our Services.

Data Category Examples of Data Collected
Account & Profile Data Your phone number, email address, name, profile photos, bio, age, and any other information you add to your profile.
Special Category Data Some information you voluntarily provide may constitute special category data under Article 9 of the UK GDPR. This includes information that may reveal your racial or ethnic origin, religious or philosophical beliefs, sexual orientation, or health status for example, through photographs, your bio, or descriptions of trips and activities you share on your profile. We do not ask you to provide this information and we do not use it for any profiling or targeting purpose. Where you choose to share such information publicly on your profile, we process it on the basis of your explicit consent, which you give by voluntarily adding it to your profile. You may remove this information at any time by editing your profile.
User-Generated Content Information you provide when you create Meetups or trips, including descriptions and photos.
Communications Data The content of messages you send and receive through the App, and any communications with our support team.
Location Data Real-time information about your device's location (if you grant permission) to enable features like discovering nearby users. We display your approximate location within a 25km by 25km grid to other users (not precise location). If you are close to another user, we won't display exact location but a minimum of 2km. You may enable "Snooze Mode" in the app settings to hide your location.
Technical & Usage Data Your IP address, device type, operating system, crash reports, and usage patterns within the App (e.g., features used, time spent). This is collected via Firebase and Google Analytics.
Verification Data (Optional) If you choose to get a "Verified Badge", we will collect a copy of your government-issued ID (e.g., passport or driving licence), which is manually reviewed by our team solely for the purpose of confirming your identity and age. The document is securely deleted once verification is complete. We only retain a log of your verified status, not the document itself. Please note that a government-issued ID may reveal information such as nationality or date of birth, which may constitute special category data in certain contexts. This data is processed solely for identity and age verification purposes, on the basis of your explicit consent given at the point of submission. You may withdraw this consent at any time by contacting us, which will result in removal of your verified status.
Transaction Data We do not process payments directly, but we receive confirmation of your subscription status from Apple or Google.
Affiliate Interaction Data Click activity on third-party booking links.

4. How We Use Your Data and Our Legal Bases

We only process your personal data when we have a valid legal reason to do so. Under UK GDPR, these reasons are known as "legal bases." The table below explains the purposes for which we use your data and the legal basis we rely on for each.

Purpose of Processing Personal Data Used Legal Basis
To provide and operate the App (e.g., create your account, display your profile, facilitate connections) Account & Profile Data, Technical & Usage Data Performance of a Contract with you.
To process any special category data you choose to share in your profile or content. Profile photos, bio text, trip descriptions, and any other content you voluntarily add to your profile that may reveal sensitive characteristics. Explicit Consent (Article 9(2)(a) UK GDPR). You may withdraw your consent at any time by removing the relevant content from your profile or by contacting us to delete your verification data.
To enable user-to-user communication and the creation of Meetups Communications Data, User-Generated Content Performance of a Contract with you.
To provide location-based features, including displaying your approximate location to nearby users and enabling you to discover other users in your area. Your precise location is never displayed; we cluster users within a small area so that individual positions cannot be determined, with a minimum display distance of 2km. You may activate Snooze Mode at any time to hide your location entirely. Location Data Consent (Article 6(1)(a) UK GDPR). Location access is requested at the point of use and can be withdrawn at any time via your device settings. Withdrawing consent will disable location-based features but will not affect your ability to use the rest of the App.
To ensure the safety and security of our platform (e.g., investigating fraud, abuse, and violations of our terms) All categories, as relevant Legitimate Interests (to protect our platform and users) and Legal Obligation.
To provide optional identity verification Verification Data Consent. You may withdraw your consent at any time by contacting us. Withdrawal may result in removal of your verified status.
To improve our Services (e.g., analysing usage patterns to fix bugs and develop new features) Technical & Usage Data Legitimate Interests (to improve and develop our App).
To comply with legal and regulatory requirements (e.g., responding to law enforcement requests) All categories, as required Legal Obligation.
To manage subscriptions and provide access to paid features Transaction Data (subscription status, product type, purchase confirmation from app stores), Account Data Performance of a Contract.

We do not use automated decision-making that produces legal or similarly significant effects. While we use algorithms to recommend connections, these are not binding and the user retains full control over who they interact with.

A Note on Our Legitimate Interests

Where we rely on "legitimate interests" as a legal basis, we have conducted a balancing test to ensure that our interests do not override your fundamental rights and freedoms. Our legitimate interests include:

  • Protecting our community: Keeping our platform safe from fraud, harassment, and other harmful activities.
  • Improving our service: Understanding how our users interact with the App so we can enhance their experience and develop new features.
  • Growing a safe and engaged community: Ensuring our platform attracts and retains genuine users through organic growth and community-building activities, in a manner that respects your privacy and does not override your rights.

You have the right to object to processing based on legitimate interests. Please see Section 7 for more information on how to exercise your rights.

5. Data Sharing and International Transfers

We do not sell your personal data. However, we share it with trusted third parties to provide our Services.

Recipient Category Purpose of Sharing
Infrastructure & Analytics Providers We use Firebase and Google Analytics (both part of Google) for hosting our backend, storing data, and analysing app usage to improve our service.
Payment Processors We use Apple and Google to process in-app subscriptions. We do not receive your payment card details.
Law Enforcement & Regulators We may disclose your data where required by law, to comply with a valid legal request, or to protect the safety and rights of our users.

Data Processor Agreements

We have entered into legally binding data processing agreements with all our third-party service providers, including Google (Firebase), as required by Article 28 of the UK GDPR. These agreements ensure that our processors are obligated to protect your data to the same high standards as we do.

Business Transfers

If we are involved in a merger, acquisition, financing, or sale of all or part of our assets, your personal data may be transferred to the relevant third party as part of that transaction. In such cases, we will require any successor entity to treat your personal data in a manner consistent with this Privacy Policy and applicable law. We will notify you of any such change by posting a notice on the App or sending an email where required.

Third-Party Websites

The App may contain links to third-party websites or services. These third parties operate independently and have their own terms and privacy policies.

We are not responsible for the availability, accuracy, or content of such third-party services, nor for any products or services offered through them.

The inclusion of links to third-party services does not imply any endorsement or recommendation by us. Your use of such services is at your own risk.

International Data Transfers

Our primary servers are located in the European Union (EU). However, some of our service providers, such as Google (Firebase), are based in the United States. This means that your personal data may be transferred to, stored, or processed in the US.

When we transfer your data outside the UK/EU, we ensure it is protected by implementing appropriate safeguards. For transfers to the US, we rely on:

  • The UK Extension to the EU-US Data Privacy Framework, for transfers to US companies that are certified under the framework.
  • The UK's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU's Standard Contractual Clauses (SCCs).

These are legal mechanisms designed to ensure your data receives a level of protection equivalent to that provided under UK law.

6. How Long We Keep Your Data

We only retain your personal data for as long as necessary to fulfil the purposes we collected it for. Our retention periods are as follows:

  • Account & Profile Data: Retained for as long as your account is active.
  • Communications & Usage Data: Retained for as long as your account is active.
  • Verification Documents: Securely deleted after your identity has been verified. We only retain a log of the verification status, not the document itself.
  • Legal & Safety Records: Certain information may be retained for longer periods after account deletion where we have a legal obligation or legitimate interest to do so.
Record Type Retention Period Legal Basis
Harassment and abuse reports (including evidence submitted, correspondence, and outcome) 6 years from resolution Legitimate Interests (protecting platform safety; defending potential legal claims)
Fraud investigation records 6 years from conclusion of investigation Legal Obligation (potential civil liability); Legitimate Interests
Account ban and suspension records (including the reason for and date of action) 6 years from the date of action Legitimate Interests (preventing re-registration; defending appeals or legal claims)
ID verification audit logs (confirmation that verification occurred, date, and outcome, not the document itself) 6 years from account deletion Legitimate Interests (demonstrating compliance with age and identity verification obligations)
Law enforcement communications (records of requests received and responses provided) 6 years from the date of communication Legal Obligation (UK GDPR Article 6(1)(c); potential statutory obligations)
Dispute documentation (records of formal complaints and their resolution) 6 years from resolution Legitimate Interests (consistent with the UK Limitation Act 1980, which sets a 6-year limitation period for contract claims)

The 6-year retention period across these categories is consistent with the standard limitation period for contractual claims under the Limitation Act 1980. Records are deleted or fully anonymised at the end of the applicable retention period. Where anonymisation is not possible, records are securely destroyed.

Data is deleted or anonymised when no longer necessary.

When your account is deleted, your profile and other personal data are permanently and irreversibly removed from our public-facing systems. Please note that because we implement measures to protect data from accidental or malicious loss, residual copies of your personal data may remain in our backup systems for a limited period following deletion before being purged in accordance with our standard backup rotation schedule. We reserve the right to delete accounts and associated data after a period of inactivity (24 months) to comply with data minimisation principles.

7. Your Data Protection Rights

Under the UK GDPR, you have the following rights in relation to your personal data:

  • Right to Access: You can request a copy of the personal data we hold about you.
  • Right to Rectification: You can ask us to correct any inaccurate information we hold about you.
  • Right to Erasure ("Right to be Forgotten"): You can ask us to delete your personal data.
  • Right to Restrict Processing: You can ask us to temporarily stop processing your data in certain circumstances.
  • Right to Data Portability: You can request your data in a structured, machine-readable format.
  • Right to Object: You can object to our processing of your data where we rely on legitimate interests as our legal basis. Where you object to processing for direct marketing purposes, we will stop such processing immediately and unconditionally, without requiring you to demonstrate particular grounds.
  • Right to Withdraw Consent: Where we process your personal data on the basis of your consent, you have the right to withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing carried out before you withdrew consent. To withdraw consent, please contact us at hello@justgutsy.com or, where applicable, adjust your settings within the App.
  • Right Not to Be Subject to Solely Automated Decision-Making: You have the right not to be subject to a decision based solely on automated processing including profiling that produces legal or similarly significant effects on you. As noted in Section 4, while we use algorithms to suggest connections within the App, these suggestions are not binding and no decision with legal or significant effect is made about you without human involvement.

To exercise any of these rights, please contact us at hello@justgutsy.com. We will respond to your request within one month. We may request additional information to verify your identity before responding to your request.

You may also designate an authorised representative to submit a request on your behalf. We may require reasonable verification that the representative is authorised to act for you, such as written confirmation of authorisation, before processing the request.

8. Security

We have implemented appropriate technical and organisational security measures to protect your personal data from accidental loss, unauthorised access, use, alteration, or disclosure. No method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security. However, we take our obligations seriously and continually review our security practices.

Our security measures include:

  • Encryption of data in transit: All data transmitted between your device and our servers is encrypted using TLS (Transport Layer Security). This is enforced by default across our infrastructure, including Firebase, which implements HTTPS/TLS for all client-server communications.
  • Secure authentication mechanisms: Account access is protected by phone number verification and secure session management. We do not store plaintext passwords.
  • Restricted access controls: Access to personal data within our systems is limited to personnel who require it to perform their role. Administrative access to backend systems requires authentication.
  • Monitoring and logging of system activity: Our infrastructure provider Firebase maintains server-side logs of system activity, including access logs and error reporting, which we use to detect and investigate anomalies. We review these logs as part of our security monitoring practices.
  • Secure cloud infrastructure: Our data is hosted on Firebase (Google Cloud), which maintains its own extensive security certifications and controls, including ISO 27001 and SOC 2 compliance.

We will notify the ICO within 72 hours of becoming aware of a personal data breach that is likely to result in a risk to individuals' rights and freedoms, as required by Article 33 of the UK GDPR. Where the breach is likely to result in a high risk to affected individuals, we will also notify those individuals directly without undue delay.

9. Age Restriction

The App is strictly for users aged 18 and over. We do not knowingly collect data from anyone under 18. We require age declaration and reserve the right to request proof of age.

As a secondary age assurance mechanism, users who choose to obtain a Verified Badge are required to submit a government-issued ID, which is manually reviewed by our team. This process also serves to confirm that the user meets the minimum age requirement of 18 years.

If we become aware that a minor has provided us with personal data, we will terminate their account and delete their information.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes by email or through an in-app notification. Your continued use of the App after such a notification constitutes your acceptance of the new policy. Previous versions of this Privacy Policy are available upon request by contacting us at hello@justgutsy.com

11. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

GUTSY LTD

Email: hello@justgutsy.com

Address: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at any time:

ICO Website: www.ico.org.uk

ICO Helpline: 0303 123 1113