Student Compass VOF ("Student Compass", "we", "us" or "our") is the controller of the personal data described in this policy. We are registered in the Netherlands under KvK number 42011388 and VAT number NL869278071B01. Our address is Grote Gracht 60 E 01, 6211 SX Maastricht, the Netherlands.
You can contact our privacy contact and exercise your privacy rights at contact@studentcompass.nl. This policy is governed by the General Data Protection Regulation (GDPR) and the Dutch GDPR Implementation Act (UAVG).
This policy applies to the Student Compass mobile app and website, including our business directory and map, check-ins and rewards, connections, activities and stacked plans, group messaging, Pulse Check, Scout AI assistant, friendship-map features, user content, subscriptions and shareable activity links. It does not govern a partner's own website or service after you follow an external link; that organisation's own privacy notice applies.
| Category | What this includes | Why / source |
|---|---|---|
| Account and profile | Name, email address, optional profile photo, date of birth (used to derive age), gender if provided, university/programme, study stage, arrival date, language, housing status, household intent, 4-digit home postcode, budget band, interests, nationality or region. | You provide this when registering or completing onboarding. We use broad bands or zones where an exact value is not needed. |
| Check-ins and location | At a QR check-in, device GPS coordinates and accuracy are used momentarily to verify presence. We store the verified check-in, venue, timestamp and a dwell-time band, not the GPS coordinates. Optional passive visit detection occurs on the device; only venue identifier, dwell band and timestamp are uploaded. | You / your device. |
| Social and content | Connections and connection origin; activity/stacked-plan details, membership, attendance and group threads; messages, photos, voice notes, place cards and plan cards; "met in real life" responses, friendship-map records, pair/group streaks and availability; postcards, place notes, reviews and writeups; and reports/blocks. | You or other users using the service. |
| Scout, voice transcription and budget tips | Questions and conversation context submitted to Scout; where you use voice notes, the recording is transcribed; and saved budget/spending figures used for optional budget tips. Scout may also receive limited profile context needed to tailor its response. | You choose to use these features. |
| Pulse Check | Optional answers about studies, belonging, mood and confidence in continuing studies, and any optional comment. | You choose to complete Pulse. |
| Subscription, referral and rewards | Referral code and attribution; subscription status, store transaction IDs and limited billing metadata; rewards-programme opt-in, points balance and verified check-in events. We do not receive full card numbers. | App stores / RevenueCat / you. |
| Technical and service-security data | App and OS version, device class/platform, account/session identifiers, push token, and technical/security records needed to operate and secure the Service. We do not operate product analytics or session-replay tooling at launch. | Your device and use of the service. |
| Purpose | Data used | Legal basis |
|---|---|---|
| Provide and secure the service: account, directory/map, connections, activities, messaging, check-ins, Scout, subscriptions and support. | Relevant account, profile, social, content, check-in and technical data. | Performance of a contract (Art. 6(1)(b)); legitimate interests for security and abuse prevention (Art. 6(1)(f)). |
| Tailor app content and recommendations to your city, study and interests. | Profile, preferences and use data. | Performance of a contract; consent where the feature requires it. |
| Send push notifications and service messages. | Push token, lifecycle and notification settings. | Consent for promotional/re-engagement notifications; contract or legitimate interests for strictly necessary service messages. |
| Run optional Pulse Check and show the user their own private responses/trends. | Pulse answers. | Explicit consent (Arts. 6(1)(a) and 9(2)(a)). |
| Operate the optional check-in rewards programme. | Rewards opt-in record, verified check-ins and points balance. | Performance of a contract / consent, as described in the rewards terms. |
| Manage subscriptions, referrals, tax records and legal requests. | Subscription/referral records and necessary account data. | Contract, legal obligation (Art. 6(1)(b)/(c)) and legitimate interests where applicable. |
You may withdraw consent at any time in the relevant app setting or by contacting us. Withdrawal does not affect processing already carried out before it.
Pulse Check is the only feature through which we deliberately request special-category personal data. It is optional, free, and subject to separate explicit consent. We do not currently provide Pulse reporting to universities, faculties, municipalities, commercial partners or any other third party. We do not use Pulse answers for advertising, eligibility decisions, or university/faculty decision-making.
Do not include health, sexual-life, religious, political or other sensitive personal information in Scout, messages, voice notes, reviews or free-text fields. Those features are not designed to receive special-category data. If you choose to share it anyway, it may be included in the content processed to deliver the feature, including the providers identified in section 9. We minimise this processing and ask you not to submit it.
Interest categories that could reveal sensitive information (for example faith, LGBTQ+ spaces, mental-health support, disability access or addiction support) are not used for advertising or disclosed to businesses, universities, municipalities or other partners.
We do not make decisions with legal or similarly significant effects about you solely by automated means. At launch, content moderation is handled through human admin review of user reports and content held for review. We do not rely on automated text screening as a launch safeguard. Photo attachments are held in a pending moderation state; no automated image classifier or CSAM-detection service is currently integrated. Human reviewers, not automated tools, make content and account restriction decisions; you can request review and challenge a moderation outcome through the in-app reporting/support route.
We do not currently operate a business account, partner dashboard, institutional reporting surface, Pulse aggregation logic or k-anonymity/small-cell reporting layer. Accordingly, we do not currently disclose user-level or aggregate Pulse, wellbeing, needs, audience or performance information to businesses, universities or municipalities. If we later introduce a reporting product, we will update this policy and, where required, seek separate consent before that processing begins.
A public activity can have a shareable link. Signed-out visitors can see its title, venue, date, available places, and the first names and avatars of up to three attendees. Attendees who opt out are not shown; attendees under 18 are never shown. Links expire after the activity date. We record link click and install counts in aggregate, not per visitor. Public activities are created by users, not by business accounts.
Some app features create records visible to a defined audience. Direct messages are available only between connected users; activity group threads are visible to their members and can persist after an activity ends. A user who was ever a member of a persistent group may view that group's retained map and history. Place notes and template plans are visible only to the poster/creator's connections. Postcards are visible only to the poster's connections on the relevant venue page and in the poster's own moments view; under-18 postcards are excluded from venue pages. The personal friendship map is private by default. A recap card is created only when you request it and is handed to your device's share sheet; it contains aggregate counts only and no other person's name or image.
Met-in-real-life confirmations are recorded only when both people independently confirm. A one-sided response is not shown to either person and expires after seven days. Blocking hides prior met-confirmations and message history between the pair from both users; unblocking restores the met-confirmations. Pair and group streak data are visible only to the relevant pair or group. Weekly group availability is visible only to group members and is not retained beyond that week.
Profile visibility and location are private by default. We do not show a user's live or exact location to other users. Blocking and reporting controls are available to all users, not only users under 18; blocking prevents messaging and hides the pair's message history and met-confirmations from both sides while the block is in place.
Student Compass does not operate product analytics or session-replay tooling at launch. We therefore do not create analytics profiles or session recordings. If we introduce analytics or replay in the future, we will update this policy before activation, explain the data and retention period, and obtain consent where required.
We do not sell personal data and do not use personal data for third-party behavioural advertising.
The following table summarises the services and SDKs in the final technical inventory that can receive personal data off your device or from our server. Local-only libraries, including expo-asset, expo-file-system and expo-location, do not themselves transmit personal data. Where a file or location derived through one of those local tools is later uploaded or sent to an external service, that onward processing is described below.
| Provider / service | Role and data | Location / transfer safeguard |
|---|---|---|
| Supabase (including Auth, Realtime, Storage, PostgREST and Edge Functions) | Primary app backend, authentication, database, storage and real-time services. May process account, profile, app content, uploaded files, tokens and server logs. | Our project is hosted in AWS eu-west-3 (Paris, France). Supabase DPA and SCCs apply. |
| RevenueCat (react-native-purchases) | Subscription entitlement and App Store/Google Play purchase management. Processes purchase history, transaction IDs, subscription status, device/OS data, IP address and our account UUID used as the RevenueCat App User ID. | US-based provider; DPA and European Commission SCCs apply. |
| Expo Push API / Expo notifications | Push relay. Receives push token, notification title/body and deep-link data, which can contain personal content such as a display name or message preview. | US-based provider. The applicable Expo DPA is in place; we keep notification content minimised. |
| Apple APNs | Apple's infrastructure delivers push notifications to iOS devices. It receives a device token and notification payload. | Apple processes this flow under its applicable platform terms. We minimise notification content and do not place sensitive data in notifications. |
| Google Firebase Cloud Messaging (FCM) | Google's infrastructure delivers push notifications to Android devices. It receives the FCM/device token, notification content and technical request headers. | Google LLC / Google Ireland; global processing. Firebase Data Processing and Security Terms, including applicable SCCs, govern the service; retain acceptance evidence in the vendor register. |
| Google Gemini API | Provides Scout AI, voice-note transcription and optional budget tips. We send Scout conversations and limited profile context used to tailor answers; voice-note audio where you enable voice notes; and spending figures where you request budget tips. | Google LLC / Google Ireland; global processing. Scout uses a paid, billing-linked Google API project, with the applicable data-processing safeguards. The service is not EU-only; see section 10. |
| Google Cloud Natural Language API | Present in the technical configuration but not used to process user content at launch. If activated later, it may analyse user-generated text and voice-note transcripts for safety/moderation signals. | Google Cloud global infrastructure. Relevant Google Cloud data-processing terms apply before activation. |
| Google Cloud Vision API (SafeSearch) | Present in the technical configuration but not used to process user photos at launch. If activated later, it would receive a temporary signed URL to a photo stored in Supabase Storage and return fixed adult/violence/racy/medical/spoof safety-likelihood scores. It is designed not to send account identifiers, IP addresses or tokens to Google. | Google LLC / Google Ireland; global processing. Relevant Google Cloud data-processing terms apply before activation. |
| Google Maps SDK (react-native-maps) | Embeds Google Maps directly on iOS and Android. Google receives map-tile requests, IP address, device/OS information, visible map area and, where map location display is enabled, the device location needed to show the user's location dot. | Google acts as a separate controller under Google Maps Platform terms; processing may occur globally. The Maps Platform terms incorporate the relevant transfer safeguards. |
| Google Maps Places API | Our server queries Google for venue details such as name, address, coordinates, rating and opening hours. These requests do not include user profile information; Google receives our server IP rather than your device IP. | Google acts as a separate controller under Google Maps Platform terms; processing may occur globally. The Maps Platform terms incorporate the relevant transfer safeguards. |
| Expo platform services (only if enabled) | If over-the-air updates are enabled, Expo may receive OS/version, project ID and a random installation token. | US-based provider. We will document the enabled configuration and applicable safeguards before activation. |
| Apple App Store and Google Play | Operate the payment storefront and may process payment and account information under their own policies. Student Compass does not receive full card numbers. | Independent controllers under their own terms and privacy notices. |
We aim to host our core application data in the EEA. Some providers identified in section 9 are located in, or may remotely access data from, countries outside the EEA. Where required, we use an adequacy decision, the European Commission Standard Contractual Clauses (SCCs), and supplementary technical/organisational safeguards. Google and Expo processing is described in section 9. Before activation of a currently inactive Google moderation service, we will verify the relevant configuration, contractual safeguards and policy wording.
We keep personal data only for as long as necessary for the stated purpose, unless a longer period is required by law. The following schedule is the intended launch configuration and must match the live deletion/backup configuration before publication.
| Data | Retention |
|---|---|
| Account and profile | Until account deletion; then deleted or irreversibly anonymised under the verified deletion and backup schedule. |
| Check-ins and user-linked outbound clicks | User link retained for 13 months (one academic cycle), then removed; de-identified aggregates may remain. |
| Messages, photos, voice notes and other content | Until you delete it or delete your account, subject to the verified deletion/backup schedule and any lawful preservation need. Photo attachments may remain pending moderation until reviewed or deleted. |
| Pulse Check answers | Until you withdraw Pulse consent or delete your account, subject to the verified deletion/backup schedule. |
| Subscription, referral and tax records | For the required contractual period; financial/tax records are generally retained for seven years where Dutch law requires it. |
| Anonymous statistics | May be kept without a time limit once they no longer identify a person. |
Subject to the GDPR, you can request access, correction, deletion, restriction, portability or objection, and withdraw consent. You may delete your account in the app or use the public account-deletion page at https://student-compass-app.github.io/delete-account.html. The web page is publicly reachable and does not require an existing web-session login. Deletion covers associated account records and triggers deletion of linked content, subject to the retention table, legal obligations and the verified backup schedule. We normally respond within one month. Contact contact@studentcompass.nl.
You must be at least 16 years old to create or use a Student Compass account. We do not knowingly permit under-16 accounts. If you are 16 or 17, we use your date of birth to apply under-18 safeguards. Before a purchase, you must make the guardian-authorisation confirmation required by the purchase flow, confirming that your parent or legal guardian has reviewed and authorised the relevant agreement/use where applicable. We may ask for a reasonable confirmation of that authority. A parent or legal guardian may contact us at contact@studentcompass.nl about the account.
We use measures appropriate to the risks, including encryption in transit, access controls and row-level security, least-privilege staff access, technical and access controls for Pulse data, data minimisation, and vendor contractual safeguards. No system is completely secure; if a relevant personal-data breach occurs, we will handle it in accordance with applicable law.
The app uses local storage and identifiers necessary to operate the service. Non-essential analytics technologies are used only with your consent. An external site you open from Student Compass operates under its own privacy and cookie notice.
We may update this policy as our service or legal obligations change. We will post the updated version and effective date and, where a change is material, notify you in the app before it takes effect where required.
Contact us at contact@studentcompass.nl or Student Compass VOF, Grote Gracht 60 E 01, 6211 SX Maastricht, the Netherlands. You may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), Postbus 93374, 2509 AJ Den Haag, or via autoriteitpersoonsgegevens.nl.
Publication status. This policy is effective from 11 August 2026. It must remain aligned with the live release, the linked Terms/EULA and the store disclosures; update it before introducing a material new data flow, provider or feature.