LetsPlay Privacy Policy
This policy explains what information LetsPlay Inc. (“LetsPlay”, “we”, “us”) collects when you use the LetsPlay app, how we use it, who we share it with, and the choices you have. We are a Canadian service and handle personal information in accordance with Canada’s federal privacy law (PIPEDA) and, for residents of Quebec, Quebec’s Law 25.
The short version: we collect what’s needed to run a sports-meetup app — your profile, your events, and your payments — plus basic usage and crash data so we can see what’s working and fix what isn’t. We don’t sell your data, we don’t show ads, we don’t use advertising or cross-app tracking SDKs, we never record your screen, and your device’s GPS location is never sent to our servers.
1. Information we collect
Account and profile information (you provide it):
- Name, email address, phone number, date of birth, and gender (collected at signup);
- Optional profile details: favourite sports, an “about me” bio, and a profile photo.
Event information (you provide it):
- Events you create: title, sport, date and time, location, description, participant limit, and price (for paid events);
- Events you join, leave, or cancel, and when.
Location information:
- Your device’s GPS location is used only on your phone. If you enable the “Nearest” sort and grant location permission, your coordinates are used locally to order the event list — they are never sent to or stored on our servers, and they’re discarded when the app restarts.
- When you type an event location while creating an event, your search text is sent to Google Places to show address suggestions (see Section 3). The address and map coordinates of the event venue you pick are stored with the event.
- Separately, our analytics and crash-reporting providers derive a coarse location (roughly city or region) from your IP address, as almost all internet services do. That is not your GPS location and is far less precise.
Payment information (paid events):
- Payments are processed by Stripe. Your card number goes directly to Stripe — we never see or store it.
- You can also pay with Apple Pay or Google Pay. In that case your card details stay with Apple or Google, who pass Stripe a one-time payment token; we never see your card either way.
- We store payment records: the event, the amounts (price, fees, total), the payment status (paid, refunded, paid out), and Stripe reference IDs.
- If you host paid events, Stripe collects identity and banking information directly from you to verify your account and send payouts. That collection is governed by Stripe’s privacy policy.
Notification information (if you enable push notifications):
- A push token — an identifier your device’s operating system issues so we can deliver notifications to it. It holds no personal details, and it’s deleted when you sign out or delete your account. Turning off notification categories in the app changes what we send you, not whether your device stays registered — to stop delivery entirely, turn notifications off for LetsPlay in your device settings.
- Your notification preferences — the in-app toggles for event reminders and event activity, stored on your profile.
Safety and support information:
- Reports you submit about other users (reason and any details you add), users you block, and feedback you send us (with your app version and platform, so we can reproduce bugs).
Usage analytics (collected automatically):
We use PostHog to understand how the app is used — which features people reach, and where they get stuck. We record a fixed, limited list of actions, for example: signing up and completing your profile, opening the app, viewing or creating an event, joining an event, opening and completing (or failing) a payment, cancelling a spot or an event, tapping share on an event, inviting friends to the app, running a search, and submitting feedback.
Each of these carries only identifiers, categories, numbers, and yes/no values — for example an event ID, a sport, whether an event was paid, a price, or the number of search results. By design we never attach free text to an analytics event: your search terms, event titles, descriptions, bios, names, and email addresses are never sent to PostHog. For searches we record only how many characters you typed and how many results came back — not what you typed.
PostHog also records standard technical details with each event (device model, operating system version, app version, locale, timezone, and an IP-derived approximate location) and a device identifier. Once you sign in, these events are linked to your LetsPlay user ID — never to your email or name. When you sign out, the link is cleared.
Crash and error diagnostics (collected automatically):
We use Sentry to capture crashes and errors. A crash report includes the error and its stack trace, the device model, operating system, app version, and a short trail of the actions leading up to the crash. Sentry is configured not to attach your email address or username to reports.
What we don’t collect: advertising identifiers, cross-app tracking data, contacts, background location, screen or session recordings, the text of your searches, or anything from your camera roll beyond the single photo you pick as your avatar.
2. How we use your information
- To operate the Service: show events, manage joins and cancellations, process payments and refunds, and send hosts their payouts;
- To show your public profile to other users (see Section 4);
- To keep the community safe: reviewing reports, enforcing blocks, investigating fraud and Terms violations;
- To communicate with you about your account and transactions (e.g. confirming your email address when you sign up, payment receipts, password resets);
- To send you the push notifications you’ve enabled — about your events (someone joining or leaving, a host cancelling, reminders 24 hours and 2 hours before an event, and a check-in afterward) and, for hosts, your payouts and any payment issues;
- To improve the app based on feedback you send us;
- To understand how the app is used in aggregate — which features get used, and where people drop out of a flow — so we can prioritize what to build and fix;
- To detect, diagnose, and fix crashes and errors;
- To comply with legal obligations (e.g. tax and financial record-keeping for payments).
We do not sell or rent your personal information, and we don’t use it for third-party advertising.
3. Who we share information with
We share personal information only with the service providers needed to run LetsPlay:
| Provider | What they process | Why |
|---|---|---|
| Supabase | Account, profile, event, and payment-record data; your profile photo |
Hosts our database, login system, and file storage. Data is stored
in the United States (AWS us-east-2,
Ohio) — see
“Where your information is
stored” below.
|
| Stripe | Payment details, and identity/banking details for hosts | Payment processing, refunds, payouts, and fraud prevention |
| Google (Places API) | The location text you type when creating an event | Address autocomplete suggestions |
| Apple & Google (push delivery) | Your device’s push token, and each notification’s title and body (which may include a first name and an event title) | Delivering the push notifications you’ve enabled to your device, via Expo’s push service and Apple’s (APNs) / Google’s (FCM) systems |
| Apple & Google (wallet payments) | A one-time payment token, if you choose Apple Pay or Google Pay | Letting you pay without entering card details |
| PostHog | Usage events (identifiers, categories, and numbers only), your LetsPlay user ID, device/OS/app version, and IP-derived approximate location | Product analytics — understanding feature usage and drop-off. Processed in PostHog’s United States cloud region — see “Where your information is stored” below. |
| Sentry | Crash reports: error and stack trace, device model, OS, app version, and pre-crash breadcrumbs | Crash and error monitoring. Processed in Sentry’s United States region — see “Where your information is stored” below. |
We may also disclose information if required by law (e.g. a court order), or to protect the rights and safety of our users or the public. If LetsPlay is ever acquired or merged, user information may transfer as part of that transaction; we’d notify you before it becomes subject to a different privacy policy.
Where your information is stored
LetsPlay is a Canadian service, but your information is stored and processed in the United States. Specifically:
-
Our database, login system, and file storage (Supabase)
are hosted in the AWS
us-east-2region in Ohio, USA; - Our product analytics (PostHog) and crash reporting (Sentry) both use their United States regions;
- Stripe, Google, and Apple process information in the United States and in other countries where they operate.
This means your personal information is subject to the laws of the United States, and may be accessible to US courts, law enforcement, and government authorities under those laws — including through lawful access requests that would not require your consent or notice to you. We use reputable providers that are contractually bound to protect your information, but we cannot exempt them from the legal obligations of the country they operate in.
By using the Service, you acknowledge that your information is transferred to and stored in the United States. If you have questions about this, contact us (Section 10).
4. What other users can see
LetsPlay is a social app, so parts of your profile are visible to other users:
- Your name, profile photo, bio, favourite sports, and your counts of events joined and hosted are visible on your public profile;
- When you join an event, your name and photo appear in that event’s participant list;
- When you host an event, your name and photo appear on the event page, and the event itself (including its location) is visible to users of the app and to anyone a participant shares the event link with.
Your email, phone number, date of birth, gender, and payment details are never shown to other users.
5. Retention and deleting your account
- We keep your information for as long as your account exists.
- You can permanently delete your account in the app (Profile → Delete Account). This immediately erases your name, email, phone number, date of birth, gender, bio, and profile photo; destroys your login credentials so the account can never be used again; and removes your participation history, your notification history, your saved devices, and any blocks you had set.
- Events you hosted are never deleted. Upcoming ones are cancelled and their participants refunded before your account is removed; all of them — past and cancelled alike — stay visible to the people who joined them, listed as hosted by “Deleted user”, so those participants don’t lose their own event history.
- Your own upcoming paid spots are refunded, unless the event starts within 12 hours. In that case the spot is forfeited under the same rule that applies when you cancel a spot normally — see the Cancellation Policy.
- Refunds are for the full amount you paid. We can’t refund a payment you’ve already disputed with your bank, because the bank’s chargeback process controls that money. If a refund fails at our payment provider we record it and complete it manually.
- Records of payments you made or received are retained for 7 years after the transaction, as required by Canadian tax and financial regulations. After deletion they are no longer linked to your name or contact details.
- If money is still owed to you as a host when you delete, we keep only what’s needed to send it to your payout account, and remove that once the transfer completes.
- Reports involving you — whether you filed them or they were filed about you — are retained where needed for safety and legal purposes. A deleted account does not erase reports made about it.
- Blocks other people placed on you are kept — that’s their protection, not yours to remove. The entry no longer appears in their blocked list, since there is no longer an account to unblock.
- Feedback you sent us is kept with the link to you removed, so we don’t lose the bug reports.
- We keep an anonymized record of the account itself, so that the events, payments, and reports connected to it stay intact. It holds no personal information and appears throughout the app only as “Deleted user”.
- Notifications other people already received may still contain the first name you used at the time — for example “Alex left your event”. Those sit in other users’ own notification history, and we don’t alter them.
- Usage analytics and crash reports are retained for 30 days and then deleted. Deleting your account does not remove analytics or crash data already collected — it remains for the rest of that 30-day window. It is never linked to your name or email address.
6. Your rights and choices
- Access and correction: You can view and edit your profile in the app at any time. For a copy of the personal information we hold about you, or to correct something you can’t edit yourself, contact us (Section 10).
- Location permission: entirely optional — the app works fully without it (you just lose the “Nearest” sort). You can revoke it any time in your device settings.
- Photo access: only requested when you choose to set a profile photo. You can also remove a profile photo you’ve already set, at any time.
- Notifications: you choose whether to allow push notifications at all (in your device settings), and you can turn off event reminders and event activity separately in the app (Settings → Notifications). Important alerts — an event being cancelled, a refund, or a payout problem — are always sent, since they affect your money or your plans.
- Analytics: analytics and crash reporting cannot currently be turned off inside the app. If you’d rather we didn’t hold usage data about you, contact us (Section 10) and we’ll delete what we have.
- Blocking: you control who can see and join your events via in-app blocking. Blocking works both ways and takes effect immediately — it also removes you and the other person from each other’s upcoming events. If a host blocks you, any paid spots you held in their upcoming events are refunded in full; if you block a host, you give up those spots without a refund. The Cancellation Policy sets out the full rules.
- Complaints: if you believe we’ve mishandled your information, contact us first; you also have the right to complain to the Office of the Privacy Commissioner of Canada and, if you live in Quebec, to the Commission d’accès à l’information.
7. Security
We protect your information with industry-standard measures: encrypted connections (TLS) for all traffic, row-level access controls on our database so users can only read data they’re entitled to, and payment handling delegated entirely to Stripe (a PCI-DSS Level 1 provider). No system is perfectly secure, but we design so that a single mistake doesn’t expose your data. If a breach affecting you occurs, we’ll notify you as required by law.
8. Children
The Service is intended solely for adults 18 and older. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If we learn that we have collected information from a person under 18, we will delete that account and the personal information associated with it, subject to the retention exceptions in Section 5. If you believe a minor is using the Service, contact us at support@letsplayapp.ca and we will remove the account.
9. Changes to this policy
We may update this policy as the app evolves (for example, if we add a new payment method or a new service provider). Material changes will be announced in the app before they take effect, and the effective date above will be updated.
10. Contact us
Questions, access requests, or privacy complaints:
Privacy Officer, LetsPlay Inc.support@letsplayapp.ca
2520 Eglinton Ave W
Mississauga, ON L5M 0Y4
Canada