Category of Data | What We
Collect
|
Purpose of
Use
|
Legal Basis (where applicable) |
Retention
|
Third-Party
Processors (examples) |
Account
Information
| - Name (first
and last)
-
Email address
-
Username (if
applicable)
-
Password
(hashed)
| - To create
and maintain
your account
- To communicate with you (service emails, updates)
- Age is used to enforce age-based restrictions and parental consent requirements
| Contract (to provide the Service) Legal Obligation (age verification laws) | -
Stored as long
as you have an
account.
-
If account is
deleted, we
delete or
anonymize this
data within 30
days, except as
needed for
legal
obligations (e.g.
proof of
consent) or
backup archives
(up to 90 days).
| -
Cloud hosting
provider (for
database
storage)
-
Email service (to
send
verification/notifications)
|
Profile
Information
| -
Profile photo
(optional)
- Bio or display
name (optional)
| -
To
personalize
your account/
profile in the
app (e.g.
show your
photo to
recipients if
you choose)
| -
Consent/
Contract (you
choose to
provide
optional info)
| -
Until you
remove or
update this info
or delete
account.
| -
Cloud storage
(for images)
|
Capsule Content
| - Videos you
upload (which
may include
your image,
voice, and
anything
captured in
video/audio)
- Attached
text messages
or captions
- Metadata
you provide
about the
capsule (title,
description of
event
| -
Primary: To
store and
later deliver
the capsule
to the
intended
recipient.
- To
allow you to
preview and
confirm the
content.
- For our
internal
operations:
to ensure the
content can
be played
(transcoding),
and to verify
it meets our
content
guidelines
(we may scan
for
prohibited
content).
| -
Contract: We
need to
process the
content to
perform the
service you
requested
(storing and
delivering
your
message).
- Legitimate
Interests:
Capsule Content- Videos you
upload (which
may include
your image,
voice, and
anything
captured in
video/audio)
- Protecting our
platform
(automated
scanning for
illegal
content).
- Consent: In
certain
jurisdictions,
we treat the
act of
uploading as
your consent
to process
that content
for delivery.
| -
Undelivered
capsules: stored
until delivery
trigger is
reached. This
could be years.
We conduct
periodic reviews
and rely on
fallback triggers
to ensure
eventual
delivery.
-
Delivered
capsules: we
retain the video
for the recipient
to access for
[90 days] after
delivery (unless
they request
deletion
sooner). After
that, we archive
or delete the
content.
-
If you delete a
capsule before
delivery, we
delete the
associated
content from
active storage
within 30 days.
(Backups may
persist a bit
longer but with
no intent to
restore unless
needed for
disaster
recovery).
| - Cloud storage provider encrypted
video storage)
- Video
processing/
transcoding
service (to
ensure
compatibility)
|
Recipient
Information
| -
Recipient’s
name (as
provided by
sender)
-
Recipient’s
email address
or contact info
-
Relationship
info (e.g. “my
daughter”, if
provided)
| -
To deliver
the capsule
to the
intended
recipient
(email
notifications
with links,
etc.).
-
To notify the
recipient and
facilitate
their access
to the
content
| -
Legitimate
Interests (of
sender and us
to deliver the
intended
message)
- Consent (if
required by
law, the
sender should
have consent
to provide this
third-party
data)
| -
Recipient
contact info is
stored until the
capsule is
delivered or
deleted.
-
If a capsule is
delivered, we
retain record of
the delivery and
recipient info
for legal record
keeping and so
the recipient
can have
continued
access (for the
retention
period noted
above, e.g. 90
days post
delivery).
-
If a capsule is
deleted before
delivery, we
delete the
recipient’s
contact info
along with it
| -
Email delivery
service (to send
capsule
notifications)
|
Parental
Consent Data
| -
Parent/
Guardian’s
name and
contact info
(email)
-
Child’s name (if
provided)
-
Consent
verification
records (e.g.
consent form,
transaction ID,
etc.)
| -
To obtain
and record
verifiable
parental
consent for
users under
required age
.
-
To allow the
parent to
manage the
child’s
account and
exercise
rights on the
child’s behalf
| -
Legal
Obligation
(COPPA, GDPR
Art.8, DPDP
Act, etc.)
- Consent (of
the parent on
behalf of
child)
| -
If consent is
not obtained
within a short
time, we delete
the child’s
attempted
account info.
- If
consent is
obtained, we
retain the
parental
consent record
as long as the
child’s account
is active (and
possibly for a
period after, as
required by law
to demonstrate
compliance).
| -
Identity
verification
service (if used
for age/consent
verification, e.g.
a service to
process credit
card consent
charge or ID
doc)
-
Cloud storage
(for storing
consent forms
or records)
|
Payment
Information
| -
Payment card
details or
account
(handled by our
paymentprocessor)
- Billing name
and address (if
required)
-
Transaction IDs
and history
| -
To process
your purchases or
subscription
payments.
- To
maintain
proper
business
records and
comply with
f
inancial
regulations
(receipts,
invoices).
| -
Contract
(payment is
part of the
service
contract)
- Legal
Obligation
(financial
record
keeping)
| -
We do not
store full card
numbers on
our servers. Our payment
processor (e.g.
Stripe) handles
that.
-
Transaction
records are
kept for at least
the legally
required period
(e.g. 7 years for
tax records in
some
jurisdictions).
| -
Payment
processor (e.g.
Stripe, PayPal)
for processing
payments (they
are PCI-DSS
compliant)
- Accounting
system (for
invoices/
receipts, which
may include
your name or
email)
|
Device and
Usage Data
| -
Device
information
(e.g. device
type, OS, app
version)
-
IP address
- Log of your
interactions
(pages or
screens visited,
button clicks,
error logs)
- Cookies and
similar tracking
data (see
Section 5)
| -
To operate
and improve
the Service
(ensure it
works on
your device,
debug issues,
analyze what
features are
used)
-
Security
monitoring
(protect
against
fraud, abuse,
unauthorized
access)
-
Optional
analytics to
understand
and enhance
user
experience (if
cookies/
analytics are
allowed by
user
| -
Legitimate
Interests:
Running a stable, secure service; understanding
usage.
- Consent: For
any non
essential
analytics or
tracking
cookies, we
will obtain
consent where
required (e.g.
EU cookie
banner).
| -
Raw logs are
kept for a short
period (e.g.
30-60 days) for
debugging and
security.
-
Aggregated or
anonymized
analytics may
be kept longer
for trends.
- Cookie data:
see Section 5
for specific
cookie
lifespans, but
non-essential
cookies only
persist as long
as you permit
or as per their
defined expiry
| -
Analytics
platform (e.g.
Google
Analytics, if
used – will be
configured with
IP
anonymization
where
applicable)
- Error tracking
service (to log
crashes or bugs
|
Communications
| -
Emails or
messages you
send to us
(support
queries,
feedback)
- Our
correspondence
with you
(responses,
chat logs)
| -
To address
your
inquiries,
provide
customer
support, and
improve our
services
based on
feedback.
- To
keep records
of support
interactions
(for training,
quality
assurance,
and liability
purposes).
| -
Legitimate
Interests:
Providing you
support and
improving our
service.
- Contract: If
your request
is about
performing
our
obligations to
you
| -
Support
emails and
tickets: retained
for as long as
needed to
resolve your
issue and as
required for
record-keeping.
- We typically
keep support
correspondence
for at least 1
year, and up to
3 years, in case
of follow-up
issues, unless
you ask us to
delete it and we
have no legal
need to keep it.
| -
Customer
support
ticketing system
(if we use a
third-party
helpdesk)
-
Email service
(since
communications
occur via email
|
Cookies &
Similar Tech (see
Section 5)
| -
Cookie
identifiers,
mobile ad IDs,
or similar
tracking tags.
-
Information
about your
browsing on
our site (pages
viewed, clicks)
tied to cookie
ID.
| -
Some
cookies are
necessary
for the site to function (login session
cookies,
preferences).
- Others
are for
analytics (to
understand
traffic and
usage
patterns).
- If
applicable,
cookies for
preferences
(like
remembering
your choices)
or
advertising
(though
currently we
do not host
third-party
ads on
PlayMeWhen,
so no
advertising
cookies as of
now).
| -
Consent: We
will obtain
consent for
any non
essential
cookies for
users in
jurisdictions
that require it
(e.g. EU, UK,
Brazil, etc.).
- Legitimate
Interests/
Contract: For
essential
cookies (like
keeping you
logged in),
which are
needed to
provide the
service you
requested.
| -
Session
cookies typically
last only during
your session or
a short time
after (e.g. 24
hours).
-
Preference
cookies might
last a few
months to a
year.
-
Analytics
cookies vary
(e.g. Google
Analytics
cookies often
6-24 months)
but we will
respect consent
and browser
settings.
- (More details in
Section 5.)
| -
Analytics
provider (if
used, e.g.
Google Analytics
or similar)
- Cookie
consent
management
tool (to store
your
preferences)
|