Effective date: 15 September 2026 · Last updated: 15 September 2026
Controller: The Factory FZE, a Free Zone Establishment registered in Sharjah Publishing City (SPC) Free Zone, United Arab Emirates (trade licence no. 4430363.01), registered office Sharjah Publishing City Free Zone, P.O. Box 3777, Sharjah, UAE ("BUDMO", "we", "us").
Distribution: BUDMO is operated by The Factory FZE and distributed on the Apple App Store and Google Play by OK Factory LLC on the operator's behalf.
EU representative (GDPR Art. 27) & UK representative (UK-GDPR Art. 27): being appointed; until appointment, EU/UK users may contact us at privacy@budmo.app. Data-protection contact: privacy@budmo.app.
This policy explains what personal data BUDMO collects, why, and your rights. It applies to everyone who uses BUDMO; for users in the EU and UK it is written to meet the EU GDPR and the UK GDPR.
1. Data we collect
Account & contact: phone number (one-time-code sign-in), name/handle, and — if you sign in with Apple or Google — your email address (Apple's private-relay address is supported).
Verification (biometric — special category): a selfie / liveness capture confirming you are a real, adult person, processed only with your explicit consent by our identity-verification provider. BUDMO does not store your selfie.
Profile: vibe/interests, availability, preferred setting, and your "not drinking tonight" flag.
Location: precise device location to find nearby tables and, during a meetup, live-location you switch on for safety.
Meetups & payments: tables joined, check-ins, deposits and venue credit. Card data is handled by our payment provider; we do not store full card numbers.
Device & usage: push token, app version, device identifiers, and usage/analytics. Our product analytics record the shape of events, not the content of your messages. On our website (budmo.app) we use Google Analytics 4 only if you accept the cookie notice; until then it receives only cookieless, aggregated pings. IP addresses are anonymised, Google Signals and advertising features are switched off, and you can withdraw consent at any time by clearing the site data in your browser.
2. How we use your data
To provide and match meetups; verify accounts and enforce the 18+ gate; keep the community safe (report/block, fraud and abuse prevention, women-only options); process deposits and venue credit; send the service notifications you enable; provide support; comply with law; and, only with your consent, send optional updates.
3. Lawful bases (GDPR / UK-GDPR)
Contract (Art. 6(1)(b)) — to provide the service you request.
Explicit consent (Art. 6(1)(a) + Art. 9(2)(a)) — biometric verification, precise location, and optional marketing; each withdrawable at any time.
Legitimate interests (Art. 6(1)(f)) — safety, security, fraud prevention and service improvement (balanced against your rights; balancing test available on request).
Legal obligation (Art. 6(1)(c)) — where we must retain or disclose data.
4. Who we share data with
We share personal data only with providers acting on our instructions under a data-processing agreement:
Faktorist Ukraine LLC — development and operations, as our processor under a Master Services Agreement.
Our SMS/OTP provider (phone verification) and payment provider (deposits and venue credit).
Apple (APNs) and Google (FCM) for push notifications, plus hosting and analytics providers.
Partner venues receive only the minimum needed to host your meetup.
We disclose data to authorities only where legally required or to protect people from harm. We do not sell personal data. A reporter's identity is never revealed to the person reported.
5. International transfers
The controller is in the UAE, which does not have an EU/UK adequacy decision. Where EU/UK users' personal data is transferred to the UAE or other non-adequate countries, we rely on appropriate safeguards — the EU Standard Contractual Clauses and the UK International Data Transfer Agreement / Addendum — together with a transfer risk assessment, and we aim to host EU/UK user data in the EU/EEA and to minimise transfers.
6. Retention
We keep personal data only as long as necessary or as legally required. Indicatively:
Account & profile — for the life of your account, then deleted within 90 days of account deletion (residual backups purged within a further 30 days).
Biometric verification — deleted immediately once the check completes; only the pass/fail outcome is kept.
Chat — time-limited by design (group chats expire shortly after the event).
Safety & report records — retained up to 24 months to protect the community.
Payment & transaction records — retained as required by applicable law.
7. Your rights
Under the GDPR/UK-GDPR you may access, rectify, erase, restrict, port, or object to the processing of your data, and withdraw consent at any time. You can delete your account in-app (Settings → Delete account). To exercise other rights, contact privacy@budmo.app; we respond within one month. You may also complain to a supervisory authority — in the EU, your local Data Protection Authority; in the UK, the Information Commissioner's Office (ICO).
8. Automated processing
Table matching uses automated logic to compose groups. This does not produce legal or similarly significant effects on you, and you can contact us about any match. We do not carry out solely-automated decisions of the kind in GDPR Art. 22 without the required safeguards.
9. Security
Our measures include encryption in transit, access controls and least privilege, isolation of reporter identity, and data-processing agreements with our vendors. We notify you and the relevant authority of qualifying personal-data breaches within the required timeframes.
10. Children
BUDMO is strictly for adults (18+). We do not knowingly process data of anyone under 18 and will delete it if discovered.
11. Biometric & location notices
Biometric: verification imagery confirms liveness and adulthood, is processed on your explicit consent by our verification provider, and is deleted on completion (see §6). You may decline, though verification may be required for certain features.
Location: precise location is used only for nearby discovery and the safety features you enable; you can switch it off in device settings at any time (some features then will not work).
12. Changes
We notify you of material changes and record your acceptance in-app (versioned consent).