1. Who we are
The Access operates the website at the-access-app.com and the Access mobile application for iOS and Android (together, the “Services”). The Services help hospitality venues find vetted creators and help creators review invitations, confirm attendance and submit agreed content.
The Access is the controller of personal information processed through the Services. Questions about this policy or your information can be sent to privacy@theaccess.app.
2. Information we collect
We collect the information below when you create an account, use the app, or contact us. We do not sell personal information and we do not use advertising or analytics SDKs in the app.
Account and profile
- Email address and password, or the email and name provided by Sign in with Apple or Google Sign-In.
- Display name and creator type.
- City you select for events (for example Dubai or Madrid).
- Interest tags you choose.
- Profile photo and up to four gallery photos.
- Instagram username, a one-time validation token, and the Instagram sender identifier we receive when you send that token as a direct message to @theaccessapp.
- Account status, such as whether your Instagram is validated, whether your application is approved, and whether the account is suspended.
- A last-active timestamp used to understand who is using the app.
Collaborations and attendance
- Event applications, approvals, confirmations, cancellations and no-shows.
- QR check-in records when you confirm attendance at a venue.
- Deliverable files you upload as proof of agreed content, such as photos or short videos.
- In-app notifications about invitations, attendance and deliverables.
Device and technical data
- Push-notification device tokens (Firebase Cloud Messaging) and the device platform, if you allow notifications.
- Approximate location, only if you grant permission, used once to suggest the closest city. We store the city you choose, not a continuous GPS track.
- Language preference stored on the device.
- Standard server logs such as IP address, browser or app version, and request times, generated when you use the website or our backends.
Website enquiries
When you submit a website form, we receive that enquiry. A venue enquiry may include venue or brand name, launch city, work email and a website or Instagram handle. A creator enquiry may include email, Instagram handle and launch city.
3. App permissions
The iOS and Android app may ask for the following permissions. You can refuse them and still use most of the app, with the matching feature turned off.
- Approximate location. Used once to select the closest launch city. You can change city later from the home header.
- Photo library. Used to set a profile picture and to upload event proof.
- Camera. Used to take a profile photo or capture event proof.
- Microphone. Used only when you record video for event proof, such as a Reel or Story.
- Notifications. Used to send updates about invitations, attendance and deliverables.
4. How we use information
- Create and secure your account, including password reset and Sign in with Apple or Google.
- Review creator applications and operate an exclusive network.
- Match creators and venues, show profiles, and keep a shared record of each brief.
- Confirm attendance at the door and collect agreed content afterwards.
- Send transactional messages in the app and, if you allow it, as push notifications.
- Respond to enquiries from the website.
- Maintain safety, prevent abuse, enforce our rules and meet legal obligations.
- Improve reliability, such as requiring a minimum app version.
We do not use your information to show third-party advertising in the app, and we do not sell or rent personal information.
6. Service providers
We use the following third parties to operate the Services. Each processes information under its own terms as well as ours:
- Supabase. Authentication, database and file storage for accounts, profiles, events and deliverables.
- Google Firebase Cloud Messaging. Push notification delivery. We do not use Firebase Analytics or advertising products in the app.
- Google Sign-In. Optional sign-in. We receive your email and basic profile if you choose this method.
- Apple. Sign in with Apple, App Store distribution and, on iOS, system push delivery. Apple may provide your name and an email address, which can be a Hide My Email relay.
- Meta / Instagram. We receive the Instagram sender ID, username and message content when you DM a validation token to @theaccessapp. We do not post to Instagram on your behalf.
- CARTO and OpenStreetMap. Map tiles used to show a venue location in the app. Tile requests can include an IP address.
- Website hosting and fonts. The website is hosted on Netlify. Pages load the Figtree font from Google Fonts.
- n8n. Routes website form submissions to our team and stores a copy of each enquiry.
- Postmark. Sends us an email when someone submits a website form.
7. Retention and deletion
We keep account and collaboration records for as long as your account is open and as long as we need them to operate the network, resolve disputes or meet legal requirements.
You can delete your account in the app. Deletion removes your login, email, name, photos, Instagram details, notifications and device tokens, and cancels upcoming event spots. Anonymized attendance counts for past events may remain so venues can run their calendar. Deletion cannot be undone. You will need a new account to use the app again.
If you cannot open the app, email privacy@theaccess.app from the address on the account and we will handle the request.
8. Your choices and rights
Depending on where you live, including the European Economic Area, the United Kingdom, Spain and the United Arab Emirates, you may have the right to access, correct, delete, restrict or object to certain processing, and to receive a copy of your information. You may also withdraw consent where processing is based on consent, such as optional location or notifications. Withdrawal does not affect processing already carried out.
You can update most profile information in the app, turn notifications off in device settings, and delete your account as described above. To exercise other rights, email privacy@theaccess.app. You may also complain to your local data-protection authority. In Spain that is the Agencia Española de Protección de Datos (AEPD).
9. Children
The Services are intended for adults. Do not create an account if you are under 18. We do not knowingly collect personal information from children. If we learn that we have collected information from someone under 18, we will delete the account.
10. International transfers
The Access is used in more than one country, including Spain and the United Arab Emirates. Our providers may process information in the European Union, the United States or other countries. Where required, we rely on appropriate safeguards such as the provider’s standard contractual clauses or an adequacy decision.
11. Security
We use industry-standard measures to protect personal information, including encrypted transport, access controls and least-privilege access to production systems. No method of transmission or storage is completely secure. Please use a strong unique password and keep your devices up to date.
13. Changes
We may update this policy when the Services change. The “Last updated” date at the top will change when we do. The current version will always be published at the-access-app.com/privacy/.
14. Contact
Privacy requests: privacy@theaccess.app
Website: the-access-app.com
Instagram: @theaccessapp