Privacy Policy
What data Strobe holds, why, on what legal basis, and every right you have over it.
1. Who we are
In plain language
The company behind Strobe, and how to reach it.
This summary is for reading convenience and does not form part of the agreement. The text below governs.
The data controller for the Strobe platform is Tancredi Tsui, Milan, Italy, acting as a natural person. Strobe is not yet incorporated; when a company is registered it will replace the controller named here and this policy will be reissued under a new version. You can reach us about anything in this policy at strobesocial@gmail.com.
Data Protection Officer: none appointed. Art. 37 GDPR requires one only for public authorities, for large-scale regular and systematic monitoring, or for large-scale processing of special-category data. None of which applies at this stage. The determination is reviewed before launch and again at incorporation.
2. Who is responsible for what
In plain language
Strobe and each venue are controllers for different things. Your booking record at a venue belongs, in law, to that venue.
This summary is for reading convenience and does not form part of the agreement. The text below governs.
Strobe is the data controller for your account and any social features you turn on. It will also be the controller for the cross-venue reputation record described in section 6, which is planned and not yet built.
Each venue is the data controller for its own guests’ booking records (the nights, tables and parties at its own room) on a contract-performance basis. Strobe processes those records on the venue’s instructions under the data processing terms at /legal/dpa.
This split is deliberate: it is what makes “your guest data is yours” a true statement for a venue, and it is why a venue can never see another venue’s records.
3. What we collect
In plain language
Only what the product uses. No field exists without a purpose.
This summary is for reading convenience and does not form part of the agreement. The text below governs.
Identity and contact: name, email, phone, date-of-birth affirmation (18+).
Booking data: venue, night, table, party members, minimum spend, cart contents, deposit and balance status.
Payment data: processed by our regulated payment provider. Full card details never reach Strobe; we hold the provider’s token and the transaction state.
Party members added by an organiser: name and phone, provided by the person who booked the table (see section 12).
Door check-in and attendance: that you arrived, when, and with how many.
Profile photo: optional. Purpose: identity matching at the door only. Never an input to any approval decision.
Reputation signals: what you committed to and whether you showed up. Held today only as the booking and attendance records above. The band derived from them, and the cross-venue record, are planned and not yet built: see section 6.
Device and technical data: logs, error reports, coarse device metadata.
Communication preferences and consents: including the exact wording you agreed to, the timestamp, and the policy version in force.
Support correspondence.
4. Why, and on what legal basis
In plain language
Contract, legal obligation, legitimate interest, or consent: one row per purpose.
This summary is for reading convenience and does not form part of the agreement. The text below governs.
Performing the booking contract (Art. 6(1)(b) GDPR): holding your table, splitting payments, refunding you if the pool fails.
Legal obligations (Art. 6(1)(c)): fiscal records, safety and capacity records.
Legitimate interests (Art. 6(1)(f)): fraud prevention, platform security, and service improvement. Each interest named and assessed; you may object.
Consent (Art. 6(1)(a)): marketing, social features, non-essential cookies. Withdrawable at any time, without affecting processing already done.
5. Special-category caution
In plain language
Where you go out can say things about you. We treat that as sensitive by default.
This summary is for reading convenience and does not form part of the agreement. The text below governs.
Attendance at particular venues can imply special-category information under Article 9 GDPR. Social and presence features are therefore treated as sensitive by design: explicit opt-in, off unless you enable them, mutual-accept only, venue-level granularity only, auto-expiring, with a short deletion schedule for raw records.
Presence is derived from door check-in, never from GPS. There is no geofencing, no background location, no continuous tracking.
6. Automated decision-making
In plain language
Not in use today. Described here because it is planned, and because there is never automated rejection.
This summary is for reading convenience and does not form part of the agreement. The text below governs.
No automated decision-making is in operation today. The reputation system described below is planned and not yet built; this section states in advance how it will work, so nothing about it arrives unannounced.
Once live, a venue will be able to configure an approval policy evaluated against your reputation band. The logic is: requests above the configured band are confirmed; others are queued for human review.
There is no automated rejection: an unapproved request simply lapses. A human review path is always available through the venue or through us.
You have the rights described in Article 13(2)(f) GDPR: to know this happens, to know the logic involved, and to know its significance.
7. Who receives data
In plain language
Named categories, in named roles.
This summary is for reading convenience and does not form part of the agreement. The text below governs.
The payment processor (controller in its own right for the payment).
Email delivery (processors), for receipts and account mail. Strobe operates no WhatsApp or SMS channel: booking links are generated in the app and shared by the organiser.
Hosting and database infrastructure (processors), EU-hosted.
Error monitoring and product analytics (processors), EU-hosted, IP-anonymised.
Venues and event brands (controllers for their own records).
Approved channel partners (controllers for the bookings they place).
Professional advisers, and authorities where the law requires.
8. Transfers outside the EEA
In plain language
EU-first. Where a transfer exists, it is contracted.
This summary is for reading convenience and does not form part of the agreement. The text below governs.
Hosting is EU-first. Where a provider processes data outside the EEA, the transfer is governed by standard contractual clauses plus a transfer impact assessment. You can obtain a copy of the safeguards by writing to strobesocial@gmail.com.
9. How long we keep things
In plain language
A table, not a sentence.
This summary is for reading convenience and does not form part of the agreement. The text below governs.
Booking and fiscal records: 10 years (art. 2220 of the Italian Civil Code; to be confirmed with a commercialista once trading begins).
Names on lists and tables: the night, plus the liability window.
Door counts: retained; they are numbers, not people.
Document images, none. An age check records that it happened and who did it, never a scan. No biometrics, no facial recognition: absent by design, not disabled by setting.
Marketing consent, until you withdraw it.
Account data, until you delete your account. Fiscal-record entries are anonymised rather than deleted, and we tell you that at the moment you ask.
10. Your rights
In plain language
Access, correct, erase, restrict, port, object, withdraw.
This summary is for reading convenience and does not form part of the agreement. The text below governs.
You have the rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent at any time.
Exercise them from your account settings or by writing to strobesocial@gmail.com. We answer within one month.
11. Complaints
In plain language
You can complain to the Garante, or to your own authority.
This summary is for reading convenience and does not form part of the agreement. The text below governs.
You have the right to lodge a complaint with the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Roma: www.garanteprivacy.it), or with the supervisory authority of your own member state.
12. People added by someone else
In plain language
If a friend adds you to a table, this is what we hold and what you can do.
This summary is for reading convenience and does not form part of the agreement. The text below governs.
When an organiser adds you to a table, we hold your name and phone number, provided by them, to send you your share link and to place you on the door record. This is the Article 14 notice for that data.
The legal basis is the performance of the booking the organiser made, and the venue’s safety obligations. You may exercise every right in section 10 over this data (access, correction, deletion) by writing to strobesocial@gmail.com.
13. Minors
In plain language
18+. No exceptions.
This summary is for reading convenience and does not form part of the agreement. The text below governs.
The service is for adults only. We do not knowingly collect data from anyone under 18. If we discover we have, the account is closed and the data deleted.
15. Changes to this policy
In plain language
Versioned, with notice.
This summary is for reading convenience and does not form part of the agreement. The text below governs.
If this policy changes materially, we notify account holders before the change takes effect. Every version is numbered and dated; previous versions remain available.