Last updated: 20 August 2026
Compliant with GDPR (EU 2016/679), CCPA & Google API Services User Data Policy
The Data Controller for personal data processed through the Halo application and platform ("Halo", "we", "us", "our") is Halo App. For any questions regarding the processing of your personal data or to exercise your rights under the General Data Protection Regulation (GDPR - EU Regulation 2016/679) and applicable privacy laws, you may contact our Data Protection Officer (DPO) at:
Halo is designed specifically for solo travelers around the Zero-Trust paradigm. Unlike conventional social networks, we have removed the root causes of social anxiety and invasive tracking: there are no public feeds, open indexed profiles, follower counts, or free-text review systems prone to retaliation or abuse. We process only the minimum technical data necessary to enable safe spontaneous meetups and safeguard the community from malicious or fraudulent behavior.
We process only the following categories of data strictly for purposes related to providing the service:
Unique user identifier (UID), email address, display name, and profile picture URL provided via secure Google OAuth. This data is processed to create your account, prevent impersonation, and allow confirmed event members to identify each other.
Real-time location retrieved from your device ONLY and EXCLUSIVELY in the foreground (while the app is open and actively in use), subject to your explicit consent. We perform no background location tracking. Location is used solely to discover and create nearby meetups.
Event title, activity category, scheduled meet time, optional destination link (screened via Google Web Risk API to prevent malware/phishing), introduction message for join requests, and ephemeral chat messages exchanged within the approved event room.
Confidential binary feedback signals (positive, no-show/ghost, flag) submitted asynchronously by verified participants after an event concludes, reliability multipliers, and interaction ledgers used to prevent vote manipulation and fake accounts (Anti-Sybil mechanism).
Pseudonymized crash reports and error monitoring (Sentry), performance telemetry (Firebase Performance), and anonymized usage analytics (Google Analytics for Firebase, activated only upon prior user consent via cookie banner).
Halo implements strict geospatial and algorithmic obfuscation mechanisms by design:
In public map discovery, event markers never expose exact GPS coordinates. The system encodes location into a 5-character Geohash (coarse area of ~±2.4 km) with randomized jitter. Exact coordinates reside in an isolated subcollection accessible ONLY to the host and approved participants.
Unapproved users see only an approximate time window (e.g., "This afternoon", "Tonight"). The exact meeting timestamp (meetAt) remains encrypted/restricted and is revealed only after the host explicitly accepts the join request.
Halo utilizes a deterministic reputation algorithm (Trust Gravity) to safeguard community members:
• Calculation Logic: Following each event, confirmed attendees may submit a confidential signal (positive, no-show/ghost, or conduct flag). The impact is weighted by the voter's trust tier and filtered through Anti-Sybil rules (repeated positive trades between identical pairs yield zero artificial score boost).
• Effects and Measures: The algorithm determines trust badge states ("Reliable", "Calibration phase", or "Suspended"). Accounts falling below safety thresholds due to chronic ghosting or misconduct flags are placed into automated Shadow Ban (events become invisible to others and join requests are suppressed).
• Right to Contest & Human Review: Under GDPR Art. 22, you have the right to request human review, state your viewpoint, and contest automated trust sanctions or restrictions by contacting privacy@joinhalo.it.
We enforce strict automatic data pruning using Cloud Firestore Time-To-Live (TTL) indices:
You may exercise your right to erasure (right to be forgotten) and permanently delete your account at any time. Account deletion can be triggered instantly from the profile settings inside the app or by emailing privacy@joinhalo.it. This permanently purges your user document from Firestore and your authentication record from Firebase Auth.
Halo's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We use only strictly necessary technical storage (session auth tokens, language preferences) and aggregated analytical cookies (Google Analytics for Firebase) with anonymized IP collection, active solely upon user consent via our Cookie Banner. Data is secured via end-to-end transport encryption (HTTPS/TLS 1.3) and encryption at rest (AES-256) hosted on Google Cloud / Firebase infrastructure.
Our primary database and server infrastructure are hosted within the European Union (Google Cloud region europe-west1). Whenever auxiliary technical transfers occur outside the European Economic Area (EEA), they are safeguarded under the EU-U.S. Data Privacy Framework and European Commission Standard Contractual Clauses (SCCs).
As a data subject, you hold comprehensive rights under GDPR and international privacy legislation:
To exercise any of these rights, contact us at: privacy@joinhalo.it