Privacy Policy

Last updated: September 21, 2026

Our Commitment

This policy describes how Proximal Coast LLC collects, uses, discloses, and retains personal information when you use Proximatic. Proximatic does not sell personal information for money or use personal information for targeted advertising.

1. Information We Collect

Organizer inquiries

When you contact us with organizer intent, we store your email, message, explicit reply permission, submitted source when supplied, receipt time, an exact-submission deduplication key, and owner-notification attempt status. We use these records to review and answer your request. Reply permission applies only to this request, not a marketing subscription. Older inquiries without this signal are marked as permission not recorded. Inquiries are not completed signups.

Account and identity data

Name, email address, optional phone number and profile image, verification status, authentication accounts, and session records.

Organization and event data

Memberships, roles, teams, invitations, availability, event details, shifts, assignments, and scheduling rules provided by users and organizers.

Attendance and communications

Check-in and check-out timestamps, accepted terms version, QR verification records, device push registration identifiers, and messages submitted through the Service.

Payments, donations, and content

Payment identifiers, amounts, statuses, donation attribution, donor-provided contact details, posts, and uploaded images. Proximatic does not store full payment-card numbers.

Event Location Data

Organizers may save an event address and coordinates so participants can view a map and directions. The event editor can use an organizer's browser location, with browser permission, to populate those event coordinates. The iOS event editor uses Apple Maps for searches and maps and can request the organizer's device location once, in the foreground, after they choose Use current location and grant permission. The chosen meeting point is saved only when the organizer saves the event and is visible to event viewers. Search terms and map requests go to the map provider. For confirmed shifts whose organizer enables a check-in area, volunteers may separately opt into automatic arrival check-in in the iOS app. With Always Allow and Precise Location permission, iOS monitors the event area in the background and Proximatic requests one precise fix on arrival. The server uses that fix to validate the area and shift window without saving the coordinates, accuracy sample, or travel history. Proximatic saves the selected consent terms, policy revision, and minimal attendance receipt. Volunteers can pause this phone or revoke an individual shift’s consent. Choosing an event pin or signing up does not enable monitoring. QR attendance remains available; background arrival delivery is not guaranteed and departure does not automatically check a volunteer out.

2. How We Use Information

  • Authenticate users and maintain account security.
  • Provide organization, event, team, scheduling, and attendance workflows.
  • Send transactional email, phone-verification codes, organizer email broadcasts, and push notifications.
  • Process platform billing and organization donations through Stripe.
  • Respond to support requests, prevent abuse, and investigate service failures.
  • Measure site usage when analytics consent has been granted.

3. Visibility and Disclosure

Organization data is scoped to the relevant organization. Owners and administrators can access member contact details, roles, assignments, attendance, and operational records needed to manage that organization.

Organizer inquiries are separate from organization data. Their counts and messages are available in the product only to the configured Proximatic product owner, not to organization owners, administrators or public visitors. We do not verify the submitted email address or treat an inquiry as permission for unrelated marketing.

Published event pages are public and may display event details, team names, aggregate participation, fundraising totals, and donation amounts without donor identity. Users should not post sensitive information in public event content.

We disclose information to service providers only as needed to operate the Service, process payments, deliver communications, store data, monitor errors, and comply with lawful requests.

4. Retention and Security

We retain account and operational records while they are needed to provide the Service. Payment, donation, security, and dispute records may be retained longer for accounting, fraud prevention, and legal obligations. Uploaded content is not subject to an automatic 30-day deletion policy.

Organizer inquiries are retained while needed to handle the request and reviewed for deletion when no longer needed. There is no automatic inquiry expiry. You can request access or deletion through hello@proximatic.app; related notification copies and backups have separate retention and must also be considered.

We use tenant access controls, secure transport, restricted provider credentials, and authenticated one-time QR claims. No internet service can guarantee absolute security, and organizers remain responsible for granting appropriate access within their organizations.

5. Cookies and Analytics

Essential cookies support authentication and security. The browser also stores your consent preference and push-registration state locally. Google Analytics or Google Tag Manager loads only after analytics consent is granted. You can change analytics consent through Cookie Preferences.

When analytics consent is granted and you are signed in, Google Analytics receives a pseudonymous Proximatic account identifier so activity from the same account can be recognized across browsers and devices. We do not send your email address or name as the analytics user identifier. Anonymous visits remain measured with Google's normal browser or device identifier.

With analytics consent, eligible campaign entries on the volunteer guide and organizer signup page may also contribute to first-party daily campaign landing counts. These store shared campaign labels, entry type, UTC day and count, without IP addresses, browser identifiers, account details or individual visit records. They do not measure unique visitors or email opens. Daily aggregates are retained for up to 90 UTC days while collection is active; dormant collection requires removal of expired aggregates before reactivation. Rejecting analytics does not disable account, event, payment, or attendance functionality.

Shared campaign links may also pass through a first-party redirect that counts requests by UTC day, shared campaign labels and destination type. This server counter operates independently of browser analytics consent and does not use tracking pixels, cookies, browser storage, IP addresses, user agents, referrers, recipient codes or individual request records. Automated email scanners and repeated requests can contribute; these counts do not identify human clicks or email opens. Only the volunteer guide and organizer signup are supported destinations. Reports exclude aggregates older than 90 UTC days; expired rows are removed on successful collection, with maintenance required during periods without collection. Ordinary account and event processing at the destination remains separate.

6. Service Providers

  • Telegram and the configured email provider: contact-form notifications to the product owner, including submitted email and message.
  • Stripe: platform billing, connected payment accounts, donations, and payouts.
  • Resend: transactional and organizer-sent email.
  • Twilio: user-requested phone verification codes when this optional feature is available.
  • Google and Firebase: Google sign-in, consent-gated analytics, and web push delivery.
  • Vercel and database providers: application hosting, image storage, and operational data storage.
  • Sentry: application error and performance monitoring.
  • Scheduling solver service: team membership, availability, shifts, and staffing rules needed to generate schedules.
  • OpenStreetMap and Photon: website event maps and organizer location search.
  • Apple Maps: map display and organizer-initiated place searches in the iOS event editor.

7. Your Choices and Requests

You can update profile information and communication permissions in the Service. Depending on where you live, you may also have rights to request access, correction, deletion, portability, or limits on certain processing, and to receive equal service when exercising those rights.

Submit a request through the contact form or email hello@proximatic.app. We may need to verify your identity and may retain information where permitted or required by law.