Privacy Policy

What we keep, and what we don't.

This policy explains what data Radar Nocturno processes, on what legal basis and, above all, what data we never collect.

1 · Data controller

ConceptValue
ControllerHumberto Franco Díaz de León (natural person, self-employed)
NIE (Spanish foreign-resident ID number)X6230664X
Address for notification purposesP.O. Box 21001, 28080 Madrid (Spain)
Emailhola@radarnocturno.com
Data Protection Officer (DPO)Mandatory appointment does not apply under art. 37 GDPR. The controller directly handles data subject rights requests. If the volume and categories of processing require it in the future, a DPO will be formally appointed.

2 · Data we process

2.1 · Data we ask for directly

DataWhenMandatoryWhy
EmailRegistrationYesAuthentication
Date of birthOnboardingYesConfirmation of legal age (self-declaration)
Public aliasOnboardingNoSo other users can identify you socially
Short bioProfileNoOptional personalization
AvatarProfileNoOptional personalization. You choose the image: if you upload one you can be recognized in, that's your decision. You can change or remove it whenever you want, and doing so deletes the previous one (see §2.3)
Gender, orientation, role and interest tagsProfile (optional)NoDeclared social affinity within the niche. Closed set, no free text. Art. 9.2.a (see §3.2)

2.2 · Data we collect from use

DataWhenRetention
Active visit (venue + start time)When confirmed by geolocationUntil manual checkout or expiry at 120 min (renewable with a tap)
Confirmed-visit counterWhen confirmed by geolocationWhile the account is active; it's an aggregated integer, with no breakdown by venue or date (see §2.3)
Friend requests and confirmationsWhen using the social featureUntil account closure
Private messagesWhen sentUntil account closure or manual deletion
Stripe subscription dataWhen you subscribe6 years (tax obligation)
GeolocationWith your consent: map, sorting by distance and visit confirmation, after explicit information (see §11)Not stored (the one calculated on the device does not leave it; the visit's is discarded after the check)
Technical logs (IP, user agent, requested URL)Any HTTP request30-90 days on Cloudflare

2.3 · Data we NEVER collect

  • Full legal name, surname.
  • National ID, passport or other identity documents.
  • A face photo or ID document photo for identification or verification purposes: we never ask you for an image to check who you are. The avatar is free and optional (see §2.1).
  • Health data, including HIV/STI status or any data about your sexual health.
  • Racial or ethnic origin.
  • Religious or ideological beliefs, political or trade-union affiliation.
  • Genetic or biometric data.
  • Free text in profile tags (the set of tags is closed; see §2.1 and §3.2).
  • A history of visits by venue or date on any screen of the product: you only see a total counter of verified check-ins, with no breakdown.
  • Continuous geolocation on our servers or in the background (the position used by the map does not leave your device, see §11).
  • Card data (handled entirely by Stripe).
  • Phone or social-media contacts.

2.4 · Special category data under art. 9 GDPR

Processing of art. 9 GDPR data (sex life, orientation and identity) can have two origins: (i) inferred from your activity (the fact that a venue belongs to a category such as BDSM, swinger, sauna, LGBTQ+ or mixed makes it possible to infer information about the user's sex life when they check in) and (ii) declared voluntarily through the optional profile tags (gender, orientation, role and interests), from a closed set with no free text. We treat both scenarios as art. 9 GDPR data and therefore apply reinforced safeguards:

  • Anonymity by design (we do not publicly associate individual check-ins with visible users).
  • No breakdown by venue or date: only an aggregated counter, never a list of visits.
  • Messaging only between mutually confirmed friends.
  • Declared tags are optional, private by default, and their visibility is controllable by the user tag by tag.
  • Reinforced legal basis: explicit consent (art. 9.2.a) obtained through a separate checkbox, independent from acceptance of the Terms. Details in §3.

Anti-discrimination guarantees (LO 4/2023, Spain's trans and LGTBI equality law). No tag conditions the service: (1) no access to the Application depends on declaring any tag; (2) no social feature is mandatory; (3) no venue can filter or segment users by tag in its dashboard. Tags exist so you can present yourself as you choose, not to classify or exclude you.

3 · Purposes and legal bases

3.1 · Table of purposes

PurposePrimary basisSecondary basis
Creating and maintaining your accountArt. 6.1.b GDPR (performance of the contract)—
Showing venue occupancyArt. 6.1.b (contracted service)Art. 9.2.a (explicit consent for data inferable under art. 9)
Showing your declared affinity tagsArt. 9.2.a (explicit consent)—
Social features (friendships)Art. 6.1.bArt. 9.2.a
Private messaging between friendsArt. 6.1.b (contracted service)Art. 9.2.a (consent already obtained during onboarding)
Managing your subscription and billingArt. 6.1.bArt. 6.1.c (tax obligations)
Confirming legal ageArt. 6.1.b (the contract can only be entered into with adults; a pre-contractual check is necessary)—
Use of location (map, nearby venues and visit confirmation)Art. 6.1.a (informed consent, see §11)—
Moderating the community and applying sanctionsArt. 6.1.f (legitimate interest: protecting other users and the service)—
Keeping an email hash after a permanent account closureArt. 6.1.f (overriding legitimate interest: preventing re-openings after a serious sanction)Art. 17.3.b GDPR for level 4
Transactional email (operational notices)Art. 6.1.b—
Technical logsArt. 6.1.f—

The balancing test for the legitimate interest underlying the purposes based on art. 6.1.f is documented internally. Contact the controller to request a copy of the assessment.

3.2 · Explicit consent under art. 9.2.a (granularity)

Processing of art. 9 GDPR data is based on the explicit consent of the data subject under art. 9.2.a, obtained through a separate checkbox, independent from acceptance of the Terms and Conditions. This data can be inferred from your activity or declared by you through the optional profile tags. It is a single-layer consent: it covers both origins with one checkbox; it is not split by category or by tag.

The primary purpose of the processing is to provide the real-time occupancy information service and to enable socializing between like-minded people. Identifying, classifying or segmenting the user's sexual orientation or gender identity is not a purpose of the processing. Declaring tags is optional and does not condition access or any feature.

You have a per-tag visibility control, the veil, with three states, and your choice does not affect the lawfulness of the processing. Hidden is the default: every tag you declare is born hidden and no one but you can see it. Friends: seen by people you have a confirmed friendship with. Public: seen by any other user with an active Premium subscription. You choose the veil tag by tag, you can change it whenever you want, and moving to the public state asks for explicit confirmation because it's the one that exposes you the most.

Even if you've opened the veil, your tags are not shown to anyone you've blocked or who has blocked you, to sanctioned accounts, to anyone if you've withdrawn consent for sensitive data, or to visitors without a signed-in session. Your tags never leave your profile: they do not appear on the map, on the radar, in the directory, on any venue's dashboard, or in any aggregated data, and they are never cross-referenced in any search or matching between users. Searching for people remains alias-only.

Change of 4 September 2026. Until that date, tags were visible only to their owner and the veil had no effect: this Policy committed to activating any visibility opening only after a prior review of the impact assessment, and to communicating it. That review has now taken place (DPIA version 2.2, of 4 September 2026, which reassesses the exposure risk of these tags and the measures that limit it), and this section is that communication. The legal basis does not change: the consent you gave already contemplated that you can choose who each tag is shown to.

Consent is revocable at any time from /ajustes/privacidad. Withdrawal takes immediate effect: all your declared tags are deleted, and check-in and messaging, which depend on this consent, are suspended. Your account stays active and you can keep using the rest of the Application, or request full account closure at any time. Selective deletion of tags is available without needing to withdraw consent.

Text of the checkboxes shown during onboarding (literal transcription):

  • I have read and accept the Terms and Conditions, the Privacy Policy and the Acceptable Use Policy. I understand that harassment, doxxing, fraud or contact with minors are grounds for immediate account closure.
  • Special category data. I explicitly consent to Radar Nocturno processing data about my sex life, orientation and identity (special category data under art. 9 GDPR), inferred from my use of the app or declared by me on my profile, for the purpose of providing the occupancy information service and social features. Declaring profile tags is optional and I can choose who each one is shown to. I can withdraw this consent at any time from Settings → Privacy; withdrawal entails deletion of my declared tags and suspension of the features that depend on it.

Both checkboxes are recorded in a consent event system (consent_events) with a timestamp, the version, and the full text shown to the user, with support for withdrawal.

4 · Retention periods

4.1 · General table

DataRetention
Active accountAs long as you keep it
Check-inWhile active
Private messagesUntil account closure or deletion by the user
Subscription data6 years from the last transaction (Spanish Tax Agency, AEAT)
Technical logs30-90 days
Sanctions and appeals2 years from resolution
Data from the /contacto form and support emails (including non-user senders)1 year from ticket closure
Email hash after permanent closureEscalated by sanction level (see §4.2)
Technical database backups30 rolling days (Supabase)

4.2 · Email hash after permanent closure

The email hash after a permanent account closure is kept for periods that differ depending on the severity of the sanction that caused the closure. The justification and proportionality are aligned with the limitation periods of the Spanish Criminal Code and of art. 17.3.b GDPR.

Sanction levelHash retention periodLegal basis
Level 3 (fraud, doxxing, non-criminal coercion)10 years from the sanctionOverriding legitimate interest (art. 6.1.f) and data minimization (art. 5.1.e), aligned with the limitation period under art. 187 of the Spanish Criminal Code.
Level 4 (harm to minors, unlawful content, criminal threats)Indefinite, with a mandatory review every 5 yearsOverriding legitimate interest (art. 6.1.f) and art. 17.3.b GDPR: protection of minors and the integrity of the service. Proportionality based on the criminal limitation period for the relevant offences (up to 35 years from the age of majority under LO 8/2021).

In every case, the hash is deleted:

  • Automatically once the period expires (level 3).
  • If the sanction is overturned following an appeal under the Acceptable Use Policy procedure.
  • If the controller's five-yearly review concludes that the legitimate interest no longer applies (level 4).

The hash is pseudonymized data: it incorporates a global salt (pepper) kept server-side. The AEPD has held in recent rulings that a hash with a pepper is still personal data while the salt exists, which is why we apply a retention period with proactive review instead of treating the data as anonymized.

5 · Recipients (processors)

To provide the service we use the following core processors, all with a data processing agreement (DPA) under art. 28 GDPR:

ProviderFunctionLocationSafeguard
Supabase Inc.Database, authentication, edge functionsEU (Paris, eu-west-3)Supabase standard DPA
Stripe Payments Europe, Ltd.Subscriptions and paymentsEU (Ireland)Stripe standard DPA
Cloudflare, Inc.App hostingUSAEU-US Data Privacy Framework
Resend, Inc.Transactional emailUSAEU-US Data Privacy Framework

Stripe offers only its standard DPA, with no bilateral negotiation, aligned with art. 28 GDPR. The controller accepts the risk, residual and common to the whole industry, of a unilateral change to Stripe's terms, mitigated through a documented six-monthly review and an internal alert for substantial changes.

Domain email: Zoho Mail EU (receiving); the routing of the support inbox through the controller's email providers is being brought into contractual order.

We do not share data with third parties for purposes other than providing the service. We never sell personal data.

6 · International transfers

Cloudflare and Resend are in the USA. The transfer is carried out under the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023). Both entities are listed as adherents to the framework as of this Policy's last update.

If a transfer must be carried out without an adequacy framework, Standard Contractual Clauses approved by the Commission will be used, subject to a prior transfer impact assessment (TIA).

7 · Your rights

As a data subject, you can exercise the following at any time:

RightHow
AccessEmail hola@radarnocturno.com requesting a copy of your data
RectificationDirectly in Settings → Profile, or by email
ErasureSettings → Delete my account, or by email
PortabilityEmail requesting an export. We send you structured JSON
ObjectionEmail stating the processing you object to
RestrictionEmail stating which processing you want restricted
Withdrawal of art. 9.2.a consentToggle in /ajustes/privacidad. Immediate effect: all declared tags are deleted, and check-in and messaging are suspended. The account stays active; you can keep using the rest of the Application or request full closure at any time
Deletion of declared tags“Delete my tags” toggle in /ajustes/privacidad (all at once), or removing them one by one from your profile. Selective deletion without withdrawing consent or closing the account
Not being subject to automated decisionsWe do not apply automated decisions with legal effects. Moderation always has human review

Response time: we will respond to you within the maximum period set out in art. 12.3 GDPR: one month from receipt of the request, extendable up to three months with justification when the complexity or number of requests warrants it. We will notify you of the extension, if necessary, within the first month.

Complaint to the AEPD: if you believe your rights have not been properly addressed, you can file a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD):

8 · Security

We apply reasonable technical and organizational measures to protect your data:

  • Encryption in transit: TLS 1.3 across all communications.
  • Encryption at rest: AES-256 at disk level in Supabase.
  • Row-level authorization (RLS): enabled on every table. Each user can only access their own data and what has been expressly shared.
  • Messaging: only between mutually confirmed friends, with an additional is_user_active() guard that blocks sanctioned accounts.
  • Visit confirmation: server-side validation of the actual distance to the venue before creating the record; the client's word is never accepted without checking the coordinate.
  • We never handle card data: Stripe manages the entire PCI DSS flow.
  • Administrator access: logged (access log) and justified by a sanction.

Security breaches: in the event of a breach affecting your rights, we will notify you without undue delay and, if applicable, will also notify the AEPD within 72h under art. 33 GDPR.

9 · Cookies and similar technologies

The Application uses:

  • Strictly necessary cookies for authentication (Supabase Auth) and session management. They do not require consent (art. 22.2 LSSI, Spain's information-society services act).
  • Local browser storage for app state (language, preferences). It does not require consent.

We do not use advertising tracking cookies or third-party cookies for analytics purposes. If we activate usage analytics in the future, it will be done with tools that do not install tracker cookies (Plausible or Umami are the alternatives under evaluation), with no need for an additional consent banner.

If the controller ever decides to add analytics tools that do require consent cookies, a banner will be shown in line with current AEPD guidelines, and a specific Cookie Policy will be published, linked from the footer of every page.

10 · Minors

The Application is not directed at anyone under 18 and its use by minors is expressly prohibited. We do not knowingly process minors' data. If we become aware that a minor has created an account:

  1. The account will be closed immediately.
  2. Their guardians will be notified when possible.
  3. A report will be filed with the competent authorities where applicable under art. 450 of the Spanish Criminal Code.
  4. The minor's data will be anonymized immediately, except where a legal retention obligation applies.

11 · Geolocation and informed consent

With your consent, the Application uses your location only while you have it open and for two purposes: showing your position on the map and sorting venues by distance, and confirming your visit to a venue (since 20 August 2026, instead of scanning a QR code). It never checks your location in the background or with the app closed.

Map and nearby venues. While you have the map open, the Application follows your position to place you on it; the directory and the visit screen use it to sort venues by distance and detect the nearest one. That calculation happens on your device: that position is not sent to our servers or stored. To draw the map, the Application requests the map tiles for the area you are viewing through our server, which obtains them from CARTO, our map provider. Those requests do not include your coordinates, but they do include the area the map shows, which, when it follows you, is centred near you with an accuracy of a few hundred metres. CARTO does not receive your IP address. Like any request to the Application, these requests are kept in the technical logs described in sections 2.2 and 4.

Visit confirmation. When you tap “Confirm I am here”, the Application sends your location once to check that you are near the venue. The coordinate is discarded after the check.

While your visit is active (up to 120 minutes, renewable with a tap if you're still inside) it is shown according to the privacy level you choose (Invisible, Friends or Public). When it expires or you close it yourself by tapping “Leave the venue”, no record is kept of which venue you visited or when: only one unit is added to your total confirmed-visits counter, which does not identify venue or date and counts toward your badges. This is the case even in Invisible mode.

Before requesting the browser's technical permission, the Application shows an interstitial screen that informs the user of:

  • Foreground use: geolocation is only used with the app open. The map follows it while you have it open; to confirm a visit it is sent once.
  • What is kept and what is not: the position used by the map, the directory and the visit screen does not leave your device; the coordinate sent when confirming a visit is discarded after the check; the venue and time of the visit are not kept after it expires; only the aggregate counter, with no breakdown, is kept.
  • Revocability: consent can be withdrawn at any time from /ajustes/privacidad. Withdrawing it means the map stops showing your position, the directory cannot be sorted by distance and you cannot confirm new visits; it does not delete the counter already accumulated, which, having no breakdown, does not identify any venue or date.
  • Granularity: this consent is independent from the art. 9.2.a consent and from the Terms acceptance bundle. Anyone who had accepted its earlier version (auto-checkout, until 20 August 2026) must accept it again: the scope of processing changed. Since 24 September 2026 it also covers the map and sorting by distance: anyone who accepted it only to confirm visits can keep doing so, and the map will invite them to extend it the next time they open it.

The consent record is added to the same event system (consent_events) that records the data subject's other consents. The interstitial screen comes before the browser's native prompt. The technical permission granted by the operating system is not, on its own, considered informed consent for the purposes of art. 7 GDPR.

Change of 24 September 2026. Until that date, this section said that location was checked only once and never continuously, but the map already showed your position while you had it open, calculated on your device, with the browser's permission but without asking for this consent. From this version on, the map only uses your location if you have granted it, and this section describes both uses.

12 · Data shared with venues (B2B)

Venues that join the service have access to an analytics dashboard showing aggregated and anonymized data about occupancy on their own premises. The dashboard:

  • Never identifies individual users, under any circumstances.
  • Applies a minimum threshold of N≥3 people in every sampling time window. Below that threshold, the dashboard does not show numeric data but rather an undifferentiated status (“low occupancy”).
  • Does not allow downloading or exporting raw per-user data.

The public map available to B2C Users applies the same N≥3 threshold before showing a numeric presence indicator.

The aggregation safeguard is threefold: a minimum threshold of N≥3, k-anonymity of k≥5 in demographic breakdowns, and 15-minute time truncation in the series, so that no combination of views can isolate a specific person.

Under this architecture, the venue does not receive personal data. It is not a recipient within the meaning of art. 4.9 GDPR, nor a joint controller under art. 26 GDPR. The relationship between the controller and the venue is governed by the B2B Terms and Conditions, with no need for an additional joint-controller agreement.

If in the future a feature were added that involved disclosing personal data to a venue (for example, identifiable user data by express consent for a loyalty programme), this Policy will be amended and the data subject's specific consent will be obtained.

13 · Changes to this Policy

We may update this Policy to reflect legal or operational changes. Material changes will be communicated by email with at least 30 days' notice. Previous versions are archived internally and available on request.

14 · Impact Assessment (DPIA)

Under art. 35 GDPR, we have carried out a Data Protection Impact Assessment given that the processing may affect art. 9 data. The DPIA's executive summary is available on reasoned request to hola@radarnocturno.com.

15 · Contact

For any matter related to this Policy or to your personal data:

We will respond to you within the maximum period set out in art. 12.3 GDPR: one month from receipt of the request, extendable to three months with justification when the complexity or number of requests warrants it.

Privacy Policy · Version 1.3.0 · 24 September 2026 · Radar Nocturno · Madrid