Privacy Policy
Effective: 2026-09-24 · Version 1.1
This Privacy Policy explains how Jive ("we", "us") collects, uses and protects personal data of users of the Jive mobile app and website ("Jive"). We process personal data under the EU General Data Protection Regulation (GDPR, in Dutch the AVG) and the Dutch GDPR Implementation Act (UAVG).
1. Who we are
Controller: Antek Marek (operating as Jive), the Netherlands. Contact for privacy inquiries: privacy@parallelcohesion.com. We have not appointed a Data Protection Officer; we are not required to.
2. What we collect
Guests
- Email address — for your account and transactional messages.
- Date of birth — to check you are 18 or older.
- Display name — shown in the app. (A profile photo, if you add one, stays on your phone and is never uploaded.)
- Home city — to show relevant parties.
- Claims, saved parties and tickets — which discounts you claimed and when.
- Scan events — when your code was scanned at a venue door.
- Push token — if you allow notifications, so we can send event reminders.
- Crash and diagnostic data — app stability data with personal data removed.
Friends invited with a +1 link
No account is created. We store the single-use +1 code and whether and when it was scanned — no name, email or phone number.
Venue staff and venue contacts
- Dashboard users — email address and the venue you administer.
- Door scanner phones — a random device identifier, the shift it was enrolled for and the scans it made. No personal account is needed.
- Venue referrals — the name and contact details you enter on the referral form.
Security logs
IP addresses and browser/app identifiers are stored only as salted hashes, for abuse and fraud detection.
We do not collect contacts, advertising identifiers or your precise location. If you allow location access, it is used only on your phone to sort parties by distance and is never sent to us. Face ID / fingerprint checks happen entirely on your device; we never receive biometric data. The door scanner uses the camera only to read QR codes; no images are stored or sent.
Your email address and date of birth are needed to create an account; without them we cannot provide the service. Everything else is optional or generated by using Jive.
3. Why we process it (lawful bases, GDPR Art. 6)
- Performance of a contract (Art. 6(1)(b)) — to provide the service: your account, claims, QR codes, +1 links, and the venue dashboard and scanner.
- Performance of a contract — the 18+ check. Jive is only offered to adults; checking ID and age at the door (Alcoholwet) remains the venue's legal duty.
- Legal obligation (Art. 6(1)(c)) — keeping billing records for the statutory period (see section 6).
- Legitimate interest (Art. 6(1)(f)) — security, fraud and abuse prevention, and aggregated statistics. You may object (section 7).
- Consent (Art. 6(1)(a)) — push notifications and any marketing email about new parties. Opt-in only; withdraw at any time.
4. Who we share it with
Venues see the scans at their own door (that a valid code was used, and when) and aggregate numbers — not your profile, history or other nights out.
We use service providers (processors) under Data Processing Agreements. The current list, with purpose and region, is at jive.parallelcohesion.com/legal/subprocessors. Each is contractually bound to protect personal data to at least the standard in this policy and may use it only to provide its service to Jive. We never sell personal data.
5. International transfers
Your account data is stored in the EU (Frankfurt). Some providers are US companies (for example Supabase, Vercel, Google, Apple and Expo) and may access limited data from the United States. Such transfers rely on the EU-US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses.
6. How long we keep it
- Account and profile data — until you delete your account. Deletion takes effect immediately; residual copies in encrypted backups expire within 30 days.
- Claim history — anonymised on account deletion; only aggregate counts are kept for billing reconciliation.
- Billing records toward venues — 7 years, as required by Dutch law (art. 2:10 Burgerlijk Wetboek and art. 52 Algemene wet inzake rijksbelastingen). These contain no guest identity after anonymisation.
- Hashed IP and device identifiers in security logs — up to 18 months.
- +1 codes — expire when the event ends; scan records follow the billing rule above.
- Consent-based data (push token, marketing) — until you withdraw consent.
7. Your rights
Under the GDPR you have the right to:
- Access and portability — in-app "Download my data", or email us.
- Rectification — edit your profile in the app.
- Erasure — in-app "Delete account", or see jive.parallelcohesion.com/delete-account.
- Restriction and objection — to processing based on legitimate interest.
- Withdraw consent — turn notifications off in the app or your phone settings, and use the unsubscribe link in any marketing email.
- Complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens: autoriteitpersoonsgegevens.nl.
We respond to requests within one month (GDPR Art. 12). Email privacy@parallelcohesion.com.
8. Cookies
The website uses only strictly necessary cookies: a sign-in session cookie for the venue dashboard. There are no analytics, advertising or tracking cookies, so no consent banner is required (Telecommunicatiewet art. 11.7a). The app contains no advertising or tracking SDKs.
9. Children
Jive is only for people aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe we have, contact privacy@parallelcohesion.com and we will delete it promptly.
10. Automated decision-making
We do not use profiling or automated decisions with legal or similarly significant effects. The only automatic check is the 18+ age check at sign-up.
11. Security
We use TLS in transit, encryption at rest, row-level access control in our database, hardware-backed storage for sign-in tokens on your phone, and optional biometric locking of your QR code. Full posture: jive.parallelcohesion.com/security.
12. Data breaches
We report personal-data breaches to the Autoriteit Persoonsgegevens within 72 hours of becoming aware of them, and inform affected users without undue delay when there is a high risk to their rights and freedoms.
13. Changes to this policy
Material changes are announced in the app at least 30 days before they take effect. The version date is shown at the top of this page.
This page is the canonical privacy policy referenced in the App Store and Google Play listings.