Privacy
Last update: 1 June 2022

1. Important introduction to our privacy policy
1A. What is a Privacy Policy
This Privacy Policy explains how Heartstring (“Heartstring,” “we”, “our”, or “us”) collects, uses, shares, and stores your information when you use the Heartstring website and/or the mobile applications that link to this Privacy Policy (“Services”).

1B. Why do I need to read and accept it?
When you use our Services, you are agreeing to our rules and policies, including this Privacy Policy and Terms of Use, and you consent to our collecting, processing and storing your information as described below. You must not access or use the Services if you do not agree with our Privacy Policy.

You should also read our Terms of Use because they also apply to your use of the Services. When during signup you tick the box to say you agree with this Privacy Policy, we keep a record of that consent.

1C. What company owns Heartstring?
Heartstring is a company incorporated in The Netherlands.

1D. What privacy law applies to Heartstring?
The personal information you provide to us that is collected through our Services is controlled by Heartstring in accordance with the laws of the country in which you live, meaning that not all parts of this policy will be relevant depending on where you live.

1E. How old do I have to be to consent to you using my data?
You can’t use Heartstring if you are younger than 16. In almost all countries, if you are 16 and over, you can allow us to use your data. But, since the law changed in Europe, in some European countries, we need to ask for your parent’s or guardian’s consent before we let you create an account if you are 16 years old.This is called the “age of consent”, and it means that if you are under a certain age, we need to get a parental consent. The age varies across different European countries, so it depends on where you live.

If you live in the UK, Ireland, Latvia, Czech Republic, Denmark, Poland, Spain or Sweden, we won’t need to ask for that extra consent from grownups.

If you live in Slovakia, Germany, Hungary, Lithuania, Luxembourg or Netherlands and are aged 16, you confirm that you have your parent’s consent to sign up to Heartstring and we will take all reasonable steps to verify this.

If you live in France and are aged 16, you confirm that you have your parent’s consent to sign up to Heartstring and we will take all reasonable steps to verify this.

If you live in Austria and are aged 16, you confirm that you have your parent’s consent to sign up to Heartstring and we will take all reasonable steps to verify this.

If you live anywhere outside of Europe you need to be at least 16 years of age as well to use the app. By creating an account and using the app you agree you are at least 16 years old at the time of doing so.

2. How do you collect my data?
How we collect, process and store information depends in part on how you use the Services. You may register to use the Services (“Registered User”). You can use some of the Services without creating an account (“Guest User”) or providing any information other than information that is automatically collected as explained below. The different categories of information we collect from you are described below.

3. What data do you collect about me?
We may collect information from you during your use of the Services, for things like your username, date of birth, payment information, location, and other information you provide or post on our Services or allow us to access when you do certain things, such as:
- Sign up and complete our registration form;
- Create or edit your user profile;
- Login to the Services;
- Location based on GPS enablement
- Submit questions or answer questions;
- Payment preferences for in-app purchases.
- Participate in voting or polling activities;
- Post user-generated content to or on our Services.

4. What data do you collect about my friends?
You can choose to invite your friends to join Heartstring so that you can stay in touch with them on the Services. To allow you to use this feature, we will ask your permission to access your personal contact list, which we will only access to store for your own use, to assist you with inviting friends to join you on the Services and to notify you when someone you know joins the Services.

5. Do you collect data about my computer/my phone?
We may automatically collect certain information about the computer or devices (including mobile devices) you use to access the Services, and about your use of the Services, even if you use the Services as a Guest User. We may collect information such as
(a) IP addresses, unique device identifiers (e.g. IDFA or other device IDs on Apple devices like the iPhone, iPad and iPod Touch), and other information about your mobile phone or other mobile device(s) browser types, browser language, operating system, the state or country from which you accessed the Services;  
(b) information related to the ways in which you interact with the Services, such as: referring and exit pages and URLs, platform type, the number of clicks, domain names, landing pages, pages viewed and the order of those pages, the amount of time spent on particular pages, the date and time you used the Services, error logs, and other similar information. As described further below, we may use third party analytics providers and technologies, including cookies and similar tools, to assist us in understanding how our Services are used. Such tools may collect and use your data, after we have depersonalized it, with other Heartstring users’ data.

6. Do you collect data about my location?
We may collect general information (e.g. IP address, zip code) about your location, and may use that information to customize the Services with location-based information, advertising, and features that need to know your location to work properly. By accessing and using the Services, you consent to this collection and processing of location information. If you choose to turn off location services on your device, some features may not be available to you.

7. I’ve heard about cookies, do you collect them too?
When you use the Services, we use persistent and session cookies and other similar technologies to:
(a) store your username and password;
(b) analyze the usage of our sites and Services by collecting the information discussed above;
(c) customize the Services to your preferences; and
(d) display advertising on the Services.

We may also use other Internet technologies, such as web beacons or pixel tags and other similar technologies, to deliver or communicate with cookies and analyze your use of the Services. We also may include web beacons in e-mail messages or newsletters to determine whether the message has been opened and for other analytics. Most browsers automatically accept cookies, but you can modify your browser setting to decline cookies by visiting your browser’s help page. If you choose to decline cookies, please note that you may not be able to sign in, customize, or use some features of the Services. By using our Services with your browser set to accept cookies you are consenting to our use of cookies in the manner described above.

8. Do you collect data about me from anyone else?
We may collect, process and store:
- your user ID associated with any social media account (such as your Gmail account) that you use to sign in to the Services or connect with or use with the Services. When you sign in to your account or mobile application with your social media account information, or otherwise connect to your social media account with the Services, you consent to our collection, storage, and use, in accordance with this Privacy Policy, of the information that you choose to make available to us through the social media interface. This could include, without limitation, any information that you have made public in connection with your social media account, information that the social media service shares with us, or information that is disclosed as being shared during the sign-in process. Please see your social media provider’s privacy policy for more information about how they share information when you choose to connect your account.


9. Do you anonymize my data so no-one knows its mine?
Generally we anonymize and/or de-identify information collected through the Services or via other means, including via the use of third-party web analytic tools so that the information no longer relates to you. Where we have appropriately anonymized and/or de-identified information it no longer constitutes your personal information (also known as personal data). As a result, our use and disclosure of aggregated and/or de-identified information is not subject to this Privacy Policy and may be disclosed to others on such basis.

10. If I create a post or comment, do you know who I am?
The fact that you can exchange information without other people knowing who you are is part of what makes Heartstring unique and so much fun. You can use a pseudonym. As a Registered User, even if you comment or share something anonymously, our Service will still have a record of the fact that you asked the question (even if we keep this private). This record will be encrypted and is only accessible by Heartstring in the case of a breach of 'TOU' by the user or by request of a 3rd party enabled by law. If you are a Guest User, we may not know who you are.

11. If I don’t register, do you still collect data on me?
If you are not a registered user, you must accept our terms of use and privacy policy prior to exchanging any information on Heartstring.

We collect information such as your IP address and possibly location. In certain countries you may be permitted to receive questions from unregistered users.

Any abuse of the unregistered user feature will result in a ban on such users, entirely at our discretion. As a user, you can also report offensive users and or content to us for a longer term ban to be imposed. You should exercise caution and apply common sense when using Heartstring.

We may assist the police or other law enforcement agencies with their requests, or produce information in response to legal process where we, in good faith, believe that such disclosure is required by law, or to protect our rights and property, or the safety of individual users or the public, or where otherwise permitted by this Privacy Policy.

12. Can law enforcement get my data from you?
We may assist the police or other law enforcement agencies with their requests, or produce information in response to legal process where we, in good faith, believe that such disclosure is required by law, or to protect our rights and property, or the safety of individual users or the public, or where otherwise permitted by this Privacy Policy.

13. What do you use my information for?
We use the information we receive from and about you for the following purposes:
- To provide the Services including any special features;
- To process and respond to your inquiries;
- To provide more relevant (user generated) content to you;
- To send you information about your relationship or transactions with us;
- To contact you if you have filed a complaint or report, or if someone has reported you;
- To make suggestions to you and other ysers, such as suggesting Registered Users’ profiles to follow;
- To notify you about new features of the Services, special events, or products, services etc.
- To moderate content and to keep the Services safe and secure and address any security issues;
- To generate advertising and promotional materials for our Services;
- To understand and assess the effectiveness of advertisements on the Services;
- To process payment for virtual goods that may be available from time to time;
- To generate and review reports and data about our user base and Service usage patterns;
- To generate data insights and overall data intelligence.
- To analyze the accuracy, effectiveness, usability, or popularity of the Services;
- To improve the content and features of the Services;
- To allow us to personalize the content and advertising that you see on the Services;
- To safeguard Heartstring’s and others’ rights or property;
- To investigate, prevent, or take action regarding illegal activities, involving potential threats to the physical safety of a person, prevention of fraud, and violations of our Terms of Use;
- To administer and troubleshoot the Services.

15. Does Heartstring share my information with other users?
15A. Sharing your profile information

If you are a Registered User, anyone who uses the Services is able to see your username and any information posted on your profile, including photos. Any space that you made can be seen by others until you delete them. This also applies to comments and replies.

While you have the ability to delete comments and spaces, you should be careful to only include information in your profile, including any questions and answers, or your location, that you would not mind making public.

15B. How can I protect myself?
In general, please be careful and responsible whenever you are online. Should you choose to voluntarily disclose information through the Services, such as by submitting a comment to another user or by creating a post, that information can be viewed publicly and people can copy content that is posted on the Internet.

It could also be collected and used by third parties without our or your knowledge, which may result in unsolicited messages from other individuals or third parties. You should not share personal information that might allow others to contact or locate you or other users. Think before you post.

16. Does Heartstring share my information with third parties?
16A. When and why we share your information with third parties

We may share your information in the following circumstances:

- To assist in providing the Services;
- To provide you with services or products that you have requested;
- With companies that perform services on our behalf (including both third parties and our affiliates), such as advertising providers, advertising networks/advertising exchanges, payment processors, providers of technical infrastructure (such as servers) or engineering or other support, order fulfillment companies, moderation companies, technical services and features developers, research and analytical companies, and e-mail service providers;
- With our affiliates for the collective benefit of our affiliates’ businesses and for operational purposes;
- Municipalities or governments requiring data insights in emerging trends.
- When we believe in good faith that such sharing is permitted by law or is reasonably necessary in order to investigate, prevent, or take action regarding possible illegal activities, suspected fraud, situations involving potential threats to the physical safety of any person, violations of this Privacy Policy or the Terms of Use;
- In order to respond to the claims of violation of the rights of third parties and/or to protect the rights, property, and safety of Heartstring, our employees, Registered and Guest Users, or the public. This may involve the sharing of your information with law enforcement, government agencies, courts, and/or other organizations;

As we continue to develop our business, we may sell, buy, merge or partner with other companies or businesses, or sell some or all of our assets. In such transactions, user information may be among the transferred assets;

We may share your information in any other circumstances where we have your consent or are otherwise permitted to share it by law.

16B. Do you use my data and content for research?
We or third parties we use may analyze your data and content for research purposes or commercial applications. This data is never connected directly to you as a user but serves as a general insight in content generated. When we use a third party to do this, we do not share any personal information with that party, we only provide anonymized data and user generated content and other non-personalised statistical data for analysis purposes.

16C. Tell me more about sharing my data for advertising purposes
(a) Anonymous Data
In order to understand our audience better and improve our service, such anonymous information is provided to third parties for their business purposes, including the creation of reports, market research, and trend analysis. This information does not contain information from which users can be identified and we will not provide additional information to such third parties that enable such third parties to identify you. Notwithstanding any other provision, we may also engage a third-party partner for the purpose of identifying users and delivering to them interest-based content and advertisements. We may share information about you with our partners such as your name, postal address, e-mail, or other identifier and may do so in non-human readable format to ensure the security of your information.

(b) Sometimes it’s personal data
Our partners also may collect information directly from your device, such as your IP address, device ID (which in some countries is considered as personal data) or similar information regarding the location of your mobile device; may combine our personal and non-personal information about you with information from other sources; and may place or recognize a unique cookie on your browser. If we are sharing ANY data that is considered to be personal data by the appropriate laws of the country in which you live, we will always ask your consent before we use your data in this way (and you can ask us to stop at any time).

16C. What does “profiling” mean and why do you need me to consent to it?
Profiling means we analyse your information and content (like your interests) so that we can tailor our advertising to you and what you’d like to see. Since the law changed in Europe in May 2018, we now need to ask your consent before we profile your information. That’s why, before we use your information in this way, you are asked to tick a box to allow us to profile your information and use it for tailored advertising.

16D. What is tailored advertising?
Third parties whose products or services are accessible or advertised via the Services may also use cookies or similar technologies to collect information about your use of the Services. This is done in order to help them
(i) inform, optimize, and serve ads based on past visits to our website and other sites
(ii) report how our ad impressions, other uses of ad services, and interactions with these ad impressions and ad services are related to visits to our website.

We also allow other third parties (e.g., ad networks/ad exchanges and ad servers such as Google Analytics, DoubleClick and others) to serve tailored ads to you on the Services, and to access their own cookies or similar technologies on your computer, mobile phone, or other device you use to access the Services. We neither have access to, nor does this Privacy Policy govern, the use of cookies or other tracking technologies that may be placed on your computer, mobile phone, or other device you use to access the Services by non-affiliated third-party ad technology, ad servers, ad networks, ad exchanges, or any other non-affiliated third parties. Those parties that use these technologies may permit you to opt out of ad targeting as described below. You may receive tailored advertising on your computer through a web browser.

When accessing the Services from a mobile application you may also receive tailored in-application advertisements. Each operating system: iOS, Android and Windows Phone provides its own instructions on how to prevent the delivery of tailored in-application advertisements. You may review the support materials and/or the privacy settings for the respective operating systems in order to opt out of tailored in-application advertisements. For any other devices and/or operating systems, please visit the privacy settings for the applicable device or operating system or contact the applicable platform operator.

17. What are online analytics?
To help us better understand your use of the Services, we may use third-party web analytics on our Services, such as Google Analytics. These service providers use the sort of technology that we’ve explained above for data that is automatically collected about your device, for example. The information collected by this technology will be disclosed to or collected directly by these service providers, who use the information to evaluate Heartstring users’ use of the Services. We also use Google Analytics as described more below. To prevent Google Analytics from collecting or using your information, you may install the Google Analytics Opt-Out Browser Add-on; to opt out of Flurry collecting or using your information, go to Google Analytics Opt-Out Browser Add-on.

18. How long do you keep my information for?
We keep your information and store it safely as long as you are using the Services. After you close your account we still keep some or all of your information for up to 3 months. It is important that we retain your data for this short period after cancellation to ensure that we can answer any payment or other account related queries, or provide information to third parties in line with our disclosure provisions outlined in this policy, e.g., assisting police investigations.

Even after you remove information from your profile or delete your account, copies of that information may still be viewable and/or accessed on the Internet to the extent such information has been previously shared with others, or copied or stored by other users or to the extent such information has been shared with search engines. We cannot control this, nor do we accept any liability for this. If you have given third party applications or websites access to your personal information, they may retain such information to the extent permitted under their terms of service or privacy policies. We also keep a record of some of your information like you IP address or e-mail address if you’ve broken the rules and we’ve added you to our block list: this helps to keep everyone safe on the Services.

19. Important notice about our Do Not Track Disclosure
We are committed to providing you with meaningful choices about the information collected on our Services for third-party purposes, and that is why we provide the above links to the NAI “Consumer Opt-out”, DAA opt-out, and Google opt-out. However, we do not currently recognize or respond to browser-initiated Do Not Track signals, as the Internet industry is still working on Do Not Track standards, implementations and solutions.

20. How can I report other users or comments?
You have the ability to report any user or space if you believe it violates our general terms of usage and service. You can report that space within the app or contact us: hello@heartstring.app

21. How does Heartstring protect my information?
We have put in place appropriate physical, electronic, and managerial procedures to safeguard and help prevent unauthorized access to your information and to maintain data security. These safeguards take into account the sensitivity of the information that we collect, process and store and the current state of technology. Although we take appropriate measures to safeguard against unauthorized disclosures of information, the internet and the Services are not 100% secure so we cannot assure you that personal information we collect or store will never be disclosed in a manner that is inconsistent with this Privacy Policy. We strongly urge you to take steps to keep your personal information safe (including your password) and to log out of your account after use. You should not tell anyone. If you lose your password or give it out to someone, your personal information will be at risk. If that happens, you should report it to us immediately. You must also change your password immediately via your “Settings” screen. We are not responsible for your failure to keep your password secure and failure to do so may breach our Terms of Use. We also strongly recommend that you change your password from time to time.

22. I want to delete Heartstring
You also have the right (in certain cases) to modify or delete the personal information we hold about you. You can generally exercise these rights by following the process described in the “Deleting Your Account” section of this Privacy Policy. However, you can also contact us using the details in Section 26 below, if you wish to modify information that cannot be amended or deleted through the Service.

23A. Leaving Heartstring
Should you choose to leave Heartstring, you may do so by notifying us accordingly via “Settings”, “Delete” screen. Once received, we will process your request to leave as soon as practicable. Once processed, your profile data will be removed from the Services and your questions to friends will be converted to anonymous questions (in other words, questions you have asked will remain visible but will appear to be from an anonymous user). You will be able to reactivate your account by logging back in for a period of 30 days after your request to leave Heartstring is processed. At the end of that period, your account will be deleted. We will delete your data as soon as reasonably practicable, but in certain cases limited types of data, including log files and backups, may take up to 90 days to be fully deleted. In order to enforce our Terms of Use and to prevent abuse of the Services, we may retain basic account information reasonably necessary to ensure a former user whose account has been terminated for breach of the Terms of Use does not open a new account and profile in further breach of our Terms of Use. We may also retain additional information where we reasonably believe that we are legally obligated to do so (such as where such information may be relevant to a law enforcement investigation).

Warning: After you have deactivated your account or left Heartstring, content you have previously transmitted through the Services may still appear on the Services, but will be anonymized and no longer associated with you directly.

Please also note that even after you remove information from your profile or deactivate your account, copies of such content may still be visible and/or accessed on the Internet to the extent such information has been previously shared with others, or to the extent such information has been shared with, indexed by or cached by search engines. Similarly, if you have given third-party applications or websites (e.g. other social networks) access to your personal information, they may keep that information. We cannot control this, nor do we accept any responsibility or liability for this.

24. Are my privacy rights different depending on where I live?
24A. Your rights if you live in Europe

Because you control your profile, you can see the personal information you’ve provided to us by accessing your “Profile” page, which gives you the option to correct or update your information at any time by just logging into the Services. Once you register, you will be able to change some of your personal information, including:
- your location;
- your profile picture;

You will not be able to change your birth date. You will also have the option to delete posts and comments posted by you at any time. You have a right to request a copy of the information we hold about you. Such a request must be in writing. You can do this via our “Feedback” screen. We will contact you to let you know what else we need from you before we send you a copy of your personal information. By law, in Europe we must respond to you within 30 days. You also have the right to be “forgotten” — that means, if you close your account and ask us to delete all your information, we need to do that. Although we are allowed to keep some of the information for security purposes in case we ever need to help the police with any criminal investigations.

24B. Your rights if you live in USA, Canada, or Australia
Law permits users located here  to request and obtain from us once a year, free of charge, a list of the third parties to whom we have disclosed their personal information (if any) for their direct marketing purposes in the prior calendar year, as well as the type of personal information disclosed to those parties. If you would like to request this information, please submit your request by “Feedback” form on “Settings” screen.

24C. Your rights if you live elsewhere
While the Service is provided from The Netherlands, it is a global website that operates and provides Services in various countries around the world. By giving us any personal information or by using the applications available on the Services, you agree that your personal information may be transferred to and stored and processed in our and our third-party vendors’ facilities in various countries around the globe, including the United States. These countries may have privacy laws that differ from the laws in your country or the laws of Ireland.

25. What are your rules on children’s data?
The Services are not intended for use by children under the age of 16. We do not knowingly collect (or knowingly allow any third party to collect) personal information from persons under the age of 16. If we become aware that personal information has been collected from a person under the age of 16, we will delete this information and terminate the person’s account as quickly as possible. If you believe that we may have personal information from or about a child under the age of 16, please contact us immediately: hello@heartstring.app

26. What about third-party links and services?
The Services may contain links to third-party websites, including other social media services. Your use of these features may result in the collection, processing or sharing of information about you by a third party, depending on the feature. Please be aware that we are not responsible for the content or privacy practices of other websites or services which may be linked to the Services. We do not endorse or make any representations about third-party websites or services. The personal information you choose to provide to or that is collected by these third parties is not covered by our Privacy Policy. We strongly encourage you to read such third parties’ privacy statements.

27. Can Heartstring make changes to this privacy policy?
We reserve the right to make changes to this Privacy Policy at any time to reflect changes in the law, our data collection and use practices, the features of our Services, or advances in technology. Please check this page periodically for changes. If we make any material changes to this Privacy Policy, we will post the updated Privacy Policy here and notify our Registered Users by e-mail or by means of a notice on the Services. Save for urgent changes (such as those required by law) we will post such a notice on our website prior to the changes becoming effective. Please review the changes carefully. Your continued use of the Services following the posting of changes to this policy will mean you consent to and accept those changes. If you do not consent to such changes, you can delete your account by following the process described in the “Deleting Heartstring" sections of this Privacy Policy.

28. What if I still have questions about this policy?
If you have any questions about the policy you can contact us at: hello@heartstring.app

heartstring