Indabeez is a Swiss-based platform. We comply with both the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (nLPD, in force since September 2023). This page explains what data we collect, why, how long we keep it, and what your rights are.
1. Data controller
The controller responsible for processing your personal data is:
J&V Global, C. Zilocchi
Route du Lac 5
1026 Denges, Switzerland Commercial register : CHE-116.029.820
For any question regarding the protection of your data, use our contact form.
Hosting provider : Infomaniak Network SA, Rue Eugène-Marziano 25, 1227 Genève, Suisse.
2. What data we collect
We collect only the data needed to run the platform:
Technical data: IP address, browser, device type (logged temporarily for security and to enforce rate limits).
Consent log: when you give or withdraw consent (e.g. map visibility), we record the choice, your IP, browser, and timestamp — this is required by law to prove consent was obtained.
Country detection: when you sign up, the country is pre-selected from the language your browser announces (for example fr-CH). That information already travels with every page; no external service is consulted and nothing is passed on. You can pick another country.
3. Legal basis (GDPR art. 6)
Performance of the contract (art. 6(1)(b)): to provide the services requested when creating and using the account.
Consent (art. 6(1)(a)): for certain optional features (for example public visibility on the map) or where the law requires consent.
Legitimate interest (art. 6(1)(f)): to ensure platform security, prevent fraud, detect abuse, keep the services running properly and improve them.
Legal obligation (art. 6(1)(c)): where processing is necessary to comply with an applicable legal obligation.
4. Who can see your data
Other users: only the data you choose to make public (your profile, posts, etc.). Email, password, payment data and IP address are never shown to other users.
Indabeez team: only when strictly necessary (technical support, abuse handling, account verification).
Subprocessors: our hosting provider (Infomaniak Network SA, Switzerland) and, when a paid service is active, the payment provider. These providers are bound by data protection agreements.
Authorities: only when legally compelled (court order, judicial requisition).
Profile visits: when you visit someone else's profile, your name and avatar may be shown to them in their dashboard. This feature is limited to certain paid plans. You can opt out at any time by enabling private browsing in Settings, Privacy tab: your visits will then appear as anonymous.
When you view someone profile, that visit may be shown to them, with your name, if they have the corresponding feature. You can opt out at any time by turning on private browsing in your settings: your visits then remain anonymous.
We do not sell your data. We do not share it with advertisers. We do not use it for behavioral advertising.
5. How long we keep your data
Active accounts: as long as your account exists.
Deleted accounts: when you request deletion, your personal data is erased or anonymized within 30 days. Minimal records are kept where the law requires it (e.g. invoices for 10 years under Swiss tax law).
Inactive accounts: after 24 months of no login, you receive a notice. After 36 months total inactivity, the account is deactivated and personal data anonymized.
Server logs: 90 days maximum, then automatically deleted.
Safety and disputes: moderation and sanction records (reports, warnings, bans) may be retained after account deletion, for as long as necessary for platform safety and for the establishment, exercise or defense of legal claims.
6. Your rights
Under GDPR and nLPD, you have the right to:
Access: ask us what data we hold about you (we respond within 30 days).
Rectification: correct inaccurate data. Most fields are editable directly from your profile.
Erasure ("right to be forgotten"): you can delete your account and associated personal data via Settings → Status → Delete my account. Deletion takes effect after a 30-day grace period, during which you can cancel it by logging back in; after that, your data is irreversibly anonymized.
Portability: receive your data in a machine-readable format (JSON export), to transfer it elsewhere.
Restriction: request that the processing of your data be restricted in the cases provided for by law.
Objection: object to processing based on legitimate interest.
Withdraw consent: any consent you gave can be withdrawn at any time (Settings → Privacy).
Complaint: you may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC), or with the competent data protection authority of your place of residence, where applicable law allows it.
To exercise these rights, use our contact form. We respond within one month at most.
7. Security
We protect your data with HTTPS encryption for all traffic, password hashing (bcrypt), strict access controls, rate limiting, regular backups stored in Switzerland and security monitoring. No system is entirely secure. Appropriate security measures are implemented to protect the data and limit the risks.
8. Cookies
We use only essential cookies: a session cookie to keep you logged in, a CSRF token for security, and a language preference cookie. We use no third-party trackers, no advertising networks, and we do not sell any data. Audience measurement: we count page views and visits to know what is useful. An anonymous token, kept for thirty minutes in a cookie, lets us recognise that a single visit opened several pages. This token is randomly generated: it says nothing about you, is linked to no account, and does not follow you from one site to another. Your IP address is used to determine the country, then forgotten — it is never stored. These figures are shared with no one and serve only to improve the platform.
9. International transfers
Data is hosted in Switzerland, on Infomaniak Network SA infrastructure, in their Swiss data centres. Switzerland benefits from an adequacy decision by the European Commission: transfers between the European Union and Switzerland are therefore recognised as offering an adequate level of protection.
Third-party services
Some features rely on external services. None is triggered without an action from you: reading a page, browsing the feed or viewing a profile sends nothing to anyone. Fonts and map backgrounds are served from our own servers.
GIPHY — only if you search for a GIF while composing a story. Receives your IP address and the words you type. Not using that search is enough to send nothing.
Google and Apple — for notifications, if you enabled them. They receive your device's technical address and the signal that a message awaits you, never its content: your device fetches that from us. Notifications are off by default.
Nominatim (OpenStreetMap) — to turn a city name into coordinates, once per city. The request comes from our servers, never from your browser: your IP address is not passed on. The result is stored with us.
Paddle — for paid subscriptions. Acts as merchant of record: it collects payment, invoices and handles VAT. Receives the data needed for payment. We never see your card number.
10. Minors
Indabeez is intended for people aged 18 and over. We do not knowingly collect data from minors. If you become aware that an account was created by someone under 18, report it to us: it will be deleted.
11. Changes to this policy
We may update this policy when our practices change or when the law requires it. Any change affecting the data we collect, how we use it or with whom we share it will be notified by email and by a banner in the application. Wording corrections are signalled only by an updated date and version number at the top of this page.
Disclaimer: This is a plain-language summary of our practices. For the legally binding text, contact us. For independent guidance on your rights, see edoeb.admin.ch (Switzerland) or your national data protection authority.