SideQuest Privacy Policy

Effective Date: September 12 2025 | 12.09.2025

Last Updated: September 12 2025 | 12.09.2025

Table of Contents

1. Introduction

Welcome to SideQuest ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and related services (collectively, the "Service").

SideQuest is a social challenge application that allows users to create and participate in group challenges, share media content, vote on submissions, and engage with friends through various interactive features.

By using our Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use our Service.

2. Information We Collect

2.1 Information You Provide Directly

Account Information:

  • Email address (required for registration)
  • Username (unique identifier)
  • Password (stored as encrypted hash)
  • Display name
  • Profile biography
  • Profile picture

Profile Information:

  • First and last name (optional)
  • Bio/description
  • Profile picture/avatar
  • User preferences and settings

Content and Communications:

  • Challenge submissions and descriptions
  • Photos and videos uploaded to the platform
  • Group chat messages
  • Comments and interactions
  • Voting activity on submissions

2.2 Information Collected Automatically

Device and Technical Information:

  • Device type, model, and operating system
  • Unique device identifiers
  • IP address and general location information
  • App version and build information
  • Device settings and preferences

Usage Information:

  • Features used within the app
  • Time spent in the application
  • Challenge participation and completion data
  • Voting patterns and preferences
  • Group membership and activity

Push Notification Data:

  • Firebase Cloud Messaging (FCM) tokens for Android devices
  • Apple Push Notification Service (APNs) tokens for iOS devices
  • Device registration information
  • Notification preferences and settings

2.3 Information from Third Parties

We may receive information about you from third-party services integrated with our platform, including but not limited to authentication providers and notification services.

3. How We Use Your Information

We use the information we collect for the following purposes:

3.1 Service Provision

  • Create and manage your user account
  • Authenticate your identity and secure your account
  • Enable participation in challenges and group activities
  • Process and display your content submissions
  • Facilitate voting and scoring systems
  • Provide group chat and communication features

3.2 Communication

  • Send push notifications about app activity
  • Notify you of challenge updates and group activities
  • Respond to your inquiries and support requests
  • Send important service announcements

3.3 Platform Improvement

  • Analyze usage patterns to improve our services
  • Develop new features and functionality
  • Monitor and maintain system performance
  • Ensure platform security and prevent abuse

3.4 Legal and Safety

  • Comply with legal obligations
  • Protect against fraud and abuse
  • Enforce our Terms of Service
  • Resolve disputes and investigate violations

4. Information Sharing and Disclosure

4.1 Public Information

The following information may be visible to other users:

  • Username and display name
  • Profile picture and biography
  • Challenge submissions (photos, videos, descriptions)
  • Voting activity (in aggregate form)
  • Group memberships (to other group members)
  • Scoring and leaderboard information

4.2 Limited Sharing

We may share your information in the following circumstances:

With Other Users:

  • Group members can see your participation in shared challenges
  • Your submissions may be visible to group members for voting
  • Chat messages are shared with group participants

Service Providers:

  • Cloud storage providers for media content
  • Push notification services (Firebase, Apple)
  • Authentication and security services
  • Analytics and performance monitoring tools

Legal Requirements:

  • When required by law or legal process
  • To protect our rights and property
  • To ensure user safety and platform security
  • In connection with business transfers or acquisitions

4.3 No Sale of Personal Information

We do not sell, rent, or trade your personal information to third parties for commercial purposes.

5. Data Storage and Security

5.1 Data Storage

  • User account data is stored in Redis databases with encryption
  • Media files are stored on secure file systems
  • Session data is managed through encrypted JWT tokens
  • All data transmission uses HTTPS encryption

5.2 Security Measures

  • Password hashing using industry-standard algorithms
  • Account lockout protection after failed login attempts
  • Regular security audits and monitoring
  • Access controls and authentication requirements
  • Data backup and recovery procedures

5.3 Data Breach Response

In the event of a data breach, we will:

  • Investigate and contain the incident promptly
  • Notify affected users within 72 hours when required by law
  • Cooperate with relevant authorities
  • Take steps to prevent future incidents

6. Third-Party Services

6.1 Firebase Cloud Messaging (FCM)

We use Google's Firebase Cloud Messaging to deliver push notifications to Android devices. This service:

  • Collects device tokens for notification delivery
  • Processes notification content and delivery status
  • May collect device and usage information
  • Is governed by Google's Privacy Policy

6.2 Apple Push Notification Service (APNs)

We use Apple's Push Notification Service for iOS devices. This service:

  • Collects device tokens for notification delivery
  • Processes notification content through Apple's servers
  • Is governed by Apple's Privacy Policy

6.3 Other Third-Party Services

We may integrate with additional third-party services for:

  • Analytics and performance monitoring
  • Cloud storage and content delivery
  • Authentication and security services

Each third-party service has its own privacy policy governing the collection and use of your information.

7. Your Rights and Choices

7.1 Account Management

  • Access and update your profile information
  • Change your password and security settings
  • Manage notification preferences
  • Delete your account and associated data

7.2 GDPR Rights (EU Users)

If you are located in the European Union, you have the following rights:

Right of Access: Request a copy of your personal data

Right to Rectification: Correct inaccurate or incomplete data

Right to Erasure: Request deletion of your personal data

Right to Restrict Processing: Limit how we process your data

Right to Data Portability: Receive your data in a portable format

Right to Object: Object to certain types of data processing

Right to Withdraw Consent: Withdraw consent for data processing

7.3 California Privacy Rights (CCPA)

California residents have additional rights including:

  • Right to know what personal information is collected
  • Right to delete personal information
  • Right to opt-out of the sale of personal information
  • Right to non-discrimination for exercising privacy rights

7.4 Exercising Your Rights

To exercise any of these rights, please contact us using the information provided in Section 12. We will respond to your request within the timeframes required by applicable law.

8. Data Retention

We retain your information for as long as necessary to provide our services and fulfill the purposes outlined in this Privacy Policy:

Account Information: Retained while your account is active and for up to 30 days after deletion

Media Content: Retained while your account is active and for up to 90 days after deletion

Chat Messages: Retained for up to 1 year or until group deletion

Usage Data: Retained for up to 2 years for analytics purposes

Legal Requirements: Some data may be retained longer to comply with legal obligations

You may request earlier deletion of your data by contacting us directly.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws than your country.

When we transfer your information internationally, we ensure appropriate safeguards are in place, including:

  • Standard contractual clauses approved by relevant authorities
  • Adequacy decisions by competent authorities
  • Other legally recognized transfer mechanisms

10. Children's Privacy

Our Service is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information promptly.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will notify you of any material changes by:

  • Posting the updated Privacy Policy in the app
  • Sending a notification through the app or email
  • Updating the "Last Updated" date at the top of this policy

Your continued use of the Service after any changes constitutes acceptance of the updated Privacy Policy.

12. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: contact@sidequest.cards

Address: contact@sidequest.cards