This notice describes how MM4R collects and uses users' personal data, in
accordance with Regulation (EU) 2016/679 ("GDPR").
1. Data Controller
The Data Controller is Silvia Stecca,
with registered office at Viale Regina Margherita 13, VAT no. XXXXXXXXXXX, company register no. RO-12345,
reachable at privacy@meetme4real.com.
2. Data we collect
We collect the following categories of data:
- Identification and contact data: name and email address, received from the provider (Google or Meta) used to sign in.
- Social provider identifier: a unique code (Google ID or Facebook ID) linking your MM4R account to your social account, without which we could not recognise you on subsequent sign-ins.
- Declared age range: if the provider shares it at sign-in (for example "21 or older"), not your exact date of birth. This information is not certified: it is based on what the user declared to the social provider.
- Profile data: if you choose to fill it in, nickname, exact date of birth, sex, sexual preference, body type, height, biography and accommodation availability. These are optional data, processed only with your consent. Sex and sexual preference are special categories of data under Article 9 GDPR and require a separate explicit consent, collected when you fill in this information.
- Search preferences ("Looking for"): if you choose to fill them in, what you are looking for (sex, friendship, a relationship), the age range you are interested in, and which gender and which sexual preference you are looking for in others. These are optional. Stating that you are looking for sex, or which gender or sexual preference you are looking for, is data concerning sex life or sexual orientation under Art. 9 GDPR and requires its own explicit consent, separate from the one given for your own profile data: we ask for it when you fill in these fields. Stating only friendship, a relationship or an age range requires no further consent.
- Social life: if you turn this section on, the activities, interests, sports, cuisines, kinds of travel, music genres and occupation you pick from the lists offered, and five indications of how you describe yourself (sociability, life outside the house, tidiness, planning, jealousy), given on a scale from 1 to 5. These are optional. You can switch the section off at any time: the data stays saved but is no longer shown to other users.
- Religious or philosophical beliefs: if you choose to state them in the "Social life" section. These are a special category of data under Art. 9 GDPR — including when the choice is "none", "atheist" or "agnostic", which are beliefs too — and require their own explicit consent, which we ask for at the moment of the choice.
- Profile photos: the images you upload, stored with a cloud storage provider (Cloudflare) and delivered through its CDN.
- Private gallery photos and related shares: the images you choose not to publish and the list of users you have granted access to, together with any expiry of that authorisation.
- Geographic location: your device's coordinates, if you allow location access, or an estimate derived from your IP address; from these we determine your town and country. We store coordinates, town, country, the source of the data (device or IP address), the IP address used and the time of the reading. Location is required to use the service: without it, proximity search and geography-based content sorting do not work.
- Private messages: the text of the messages you exchange with other users, any attached images, the recipient, the time they were sent and the time they were read.
- Profile visits: when you open someone else's profile we record that you did and when, and we show it to them on their "Visits" page. The same applies in reverse: you can see who opened yours. We keep only the most recent visit per person, and entries are deleted after 1 day or, for users with an active subscription, after 15 days.
- Ratings, reactions and likes: the votes you cast on images under review, likes on photos and reactions to other users' profiles, together with your identifier. Ratings contribute in aggregate form to an image's score.
- Blocks and reports: the users you choose to block and the reports you submit or that concern you, with the stated reason, any note, the reported message and the outcome of the review.
- In-person meetups: the meetup proposal (chosen place, its coordinates and radius, date, time and time zone), the counterpart, acceptance of the specific rules and, at the moment of on-site validation, the position read from your device with its accuracy, the time of the attempt and its outcome.
- Payment data and account movements: the identifiers assigned by our payment provider (Stripe) to your customer profile, your subscription and individual payment authorisations, the status of meetup deposits and the history of movements (type, amount, currency and date). Your full card number is never transmitted to us and is not stored by us.
- Support requests: the subject and text of the requests you send us, the language used and the handling status.
- Consents given: confirmation of legal age, acceptance of the Terms of Use and of this notice, with the date, the version of the accepted text, the IP address and the browser user agent at the time of acceptance. We keep this data as evidence that consent was given.
- Preferences: the language and theme of the interface, and whether you want to be notified of new messages by email.
- Technical data: IP address, session identifiers and technical cookies necessary for the service to work. Your IP address and rounded coordinates are also kept for a short time in a technical cache (7 days for the IP address, 30 for the coordinates): this avoids asking external services again for a locality that has already been resolved, and it is deleted automatically when it expires.
- Sign-in log: for every successful sign-in we keep the date and time, the IP address, the country and town estimated from that address, the provider used and a description of the browser. They exist so you can recognise a sign-in that is not yours, and you will find them listed under "Sign-ins and security" in your account settings. These records are deleted automatically after 90 days.
The age range used for access and the date of birth entered in your
profile are processed separately: the former is used only to verify the
minimum age requirement at sign-in; the latter, if you provide it, stays
in your profile and is used solely to calculate and display your age to
other users — your exact date of birth is never shared with them.
We read nothing else from your Google or Meta account beyond what is
listed above: contacts, photos, posts and activity on your social profile
are not shared with us and are not stored.
3. Purposes and legal basis of processing
- Providing the service (account creation and management, authentication): performance of a contract (Art. 6.1.b GDPR).
- Verifying the minimum age requirement: legal obligation and/or legitimate interest in preventing access by minors (Art. 6.1.c and 6.1.f GDPR).
- Evidence of consent given (Terms and Privacy): legal obligation to be able to demonstrate the consent collected (Art. 6.1.c and Art. 7.1 GDPR).
- Profile management (personal details, preferences, photos): consent of the data subject (Art. 6.1.a GDPR).
- Processing of sex and sexual preference: explicit consent, as these are special categories of data (Art. 9.2.a GDPR).
- Processing of what you are looking for (looking for sex, gender and sexual preference sought): explicit consent, as this is data concerning sex life and sexual orientation (Art. 9.2.a GDPR).
- Processing of religious or philosophical beliefs: explicit consent, as this is a special category of data (Art. 9.2.a GDPR).
- Social life and personality description: consent of the data subject (Art. 6.1.a GDPR).
- Recording profile visits and showing them to the person visited: performance of a contract, this being a feature of the service requested (Art. 6.1.b GDPR).
- Access log, to let you recognise a sign-in that is not yours: legitimate interest in account security (Art. 6.1.f GDPR).
- Messaging between users (sending, receiving and storing conversations): performance of a contract (Art. 6.1.b GDPR).
- Proximity search and geography-based content sorting: performance of a contract, this being an essential function of the requested service (Art. 6.1.b GDPR); reading the position from your device only ever happens after you expressly allow it in your browser.
- Sharing your private gallery with users you authorise: consent of the data subject (Art. 6.1.a GDPR).
- Collaborative rating of images, to determine their visibility: legitimate interest in keeping public content within acceptable limits (Art. 6.1.f GDPR).
- Handling blocks, reports and moderation: legitimate interest in user safety and the prevention of abuse (Art. 6.1.f GDPR), as well as legal obligation where a report concerns unlawful content (Art. 6.1.c GDPR).
- Organising and validating in-person meetups, including verifying presence at the location through the device's position: performance of a contract (Art. 6.1.b GDPR).
- Managing subscriptions, deposits and the movement history: performance of a contract (Art. 6.1.b GDPR) and accounting and tax obligations (Art. 6.1.c GDPR).
- Sending service emails (new message, profile reactions, meetup outcome, support replies): performance of a contract (Art. 6.1.b GDPR); new-message notifications can be turned off at any time in your settings.
- Handling support requests: performance of a contract (Art. 6.1.b GDPR).
- Security and prevention of unlawful use, including protecting public forms from automated submissions: legitimate interest (Art. 6.1.f GDPR).
4. What other users can see
Other users of the platform can see your nickname, your age, your town and
an approximate distance from where they are, the information you chose to
enter in your profile, and the photos you published.
Not visible to other users: your email address, your name as received from
the social provider, your exact date of birth, the coordinates of your
position, your IP address, your payment data and your account movements.
Private gallery photos are visible only to the users you have expressly
authorised, for as long as that authorisation lasts. The votes you cast on
other users' images are not shown with your name: they only contribute to
the image's overall score.
Also visible are the "Looking for" and "Social life" sections of your
profile, the latter only if you have turned it on. Finally, the person
whose profile you open sees that you opened it and when: visits are
recorded both ways. With an active subscription you can browse profiles
incognito, in which case your visits are neither recorded nor shown to
anyone.
5. Moderation
To keep users safe and to act on reports, authorised staff may access
content on the platform, including private conversations, images exchanged
in chat and private gallery photos, and may remove them or make them no
longer visible. Such access takes place solely for moderation, safety and
report-handling purposes, and is limited to staff authorised to do so.
6. Who we share data with
Your data may be shared with:
- Google LLC and Meta Platforms, Inc., as authentication providers, to the extent needed to complete sign-in and obtain the age range;
- Google LLC, also as the provider of the map service used to choose a meetup location: searches and the point selected on the map panel are processed by Google;
- Stripe, Inc., for processing subscriptions and meetup deposits;
- Cloudflare, Inc., for storing uploaded photos and delivering them through its CDN, and for protecting the support form against automated submissions, which involves processing your IP address and technical browser data;
- OpenStreetMap Foundation, which receives approximate coordinates in order to return the corresponding town and country name;
- the IP-based geolocation service provider, when a precise position is not available, which receives your IP address;
- the outgoing email service provider, for delivering service communications;
- our hosting and technical infrastructure provider, which processes data on our behalf;
- other users of the platform, within the limits described in section 4;
- public authorities, when required by law.
We do not sell your personal data to third parties and do not use it for advertising purposes.
7. Data transfers outside the EU
Some of the providers listed in section 6 may process data outside the
European Economic Area. In such cases the transfer takes place on the
basis of the standard contractual clauses approved by the European
Commission or of other adequate safeguards provided for by the GDPR.
8. Retention period
We keep your account data for as long as the account remains active. In particular:
- private messages remain available for as long as the conversation exists and the account is active;
- location is overwritten at each new reading: on your profile we keep only the current value, not a history of your movements. The technical cache described above does remain, holding your IP address for 7 days and rounded coordinates for 30;
- meetup data, including validation attempts, is kept for as long as needed to handle any dispute over the deposit;
- account movements and accounting data are kept for the period required by tax law;
- reports and their outcomes are kept for as long as needed to prevent repeated abuse;
- profile visits are deleted after 1 day, or after 15 days if the person visited has an active subscription. We also keep the date on which you last looked at the list, used only to tell you how many visits have arrived since;
- the access log is deleted automatically after 90 days;
- the nickname of a closed account stays reserved indefinitely and no other user will be able to choose it: this prevents someone from presenting themselves, to people who knew them, under the name of a person who has left;
- data on consents given is kept even after the account is closed, for as long as needed to demonstrate, if required, that consent was actually collected.
When you ask for your account to be closed, it is suspended immediately and
is no longer reachable by other users; you have 30 days to change your mind
and reactivate it simply by signing in. After those 30 days your data is
deleted or anonymised: the messages you had sent stay in the conversations
of those who received them, but stripped of your name and of any link to
your account. The reserved nickname described above, the data on consents
given and any legal obligations requiring longer retention are unaffected.
9. Your rights
As a data subject, you have the right to:
- access your personal data and obtain a copy of it;
- request its rectification if inaccurate;
- request its erasure, within the limits provided by law;
- object to the processing or request its restriction;
- receive your data in a portable format;
- withdraw the consents you have given at any time, without affecting the lawfulness of processing already carried out;
- lodge a complaint with the competent data protection authority (in Italy, the Garante per la protezione dei dati personali, www.garanteprivacy.it).
To exercise these rights you can write to
privacy@meetme4real.com.
10. Cookies
We use a limited number of technical cookies, necessary for the service to function:
- a session cookie, to keep you signed in;
- a "remember me" cookie, if you choose to stay signed in between visits;
- a cookie storing your chosen interface language;
- the technical cookies set by Cloudflare on the support form, to tell human requests from automated ones.
We do not use profiling or advertising cookies. For this reason no cookie
consent banner is required: these are exclusively technical cookies
necessary to deliver the service you requested.
11. Data security
We take reasonable technical and organisational measures to protect your
data from unauthorised access, loss or improper disclosure. No system,
however, is 100% secure: we encourage you to protect the credentials of
your Google or Facebook account, which are the only means of accessing
MM4R.
Please also bear in mind that images shared in chat or through the private
gallery can be copied or photographed by the recipient: no technical
measure can fully prevent this. Consider carefully who you grant access
to.
12. Changes to this notice
We may update this notice over time. Substantial changes will be brought
to your attention through a new request for acceptance the next time you
sign in.
13. Contact and complaints
For any question about this notice or about the processing of your data,
write to privacy@meetme4real.com. You also
always have the right to lodge a complaint with the competent data
protection authority.