SYP ← Back

Legal · Indonesia & European Union Operations

Privacy Policy

Effective Date: September 2026  |  Share Your Plans SRL · BCE No. BE1034.288.729  |  Prepared in accordance with UU PDP No. 27/2022 & GDPR (Regulation (EU) 2016/679)

1. Identity of the Data Controller

The entity responsible for processing your personal data in connection with the SYP application is:

Share Your Plans SRL
Incorporated under Belgian law  |  BCE No. BE1034.288.729

Share Your Plans SRL acts as the sole data controller for all personal data collected through the Platform. There is no subsidiary or local entity involved in data processing at this stage of operations.

Data Protection Contact: SYP has designated a contact responsible for handling personal data inquiries and requests. This function can be reached at privacy@syp-app.com.

2. Scope of This Policy

This Privacy Policy applies to all Users who access or use the SYP mobile application within the territory of Indonesia and the European Union. It describes how we collect, use, store, share, and protect your personal data, and how you may exercise your rights under applicable law.

This Policy is governed by the Indonesian Personal Data Protection Law (UU PDP No. 27/2022), the Electronic Information and Transactions Law (UU ITE No. 11/2008 as amended), and Government Regulation No. 71/2019 on Electronic System and Transaction Operations (GR 71). In addition, as Share Your Plans SRL is incorporated under Belgian law and acts as an EU data controller, the processing of personal data in connection with the Platform is also governed by the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679), regardless of where you are located — see Section 9 for the provisions specific to GDPR.

This Policy applies to users accessing the Platform from Indonesia, the European Economic Area, and other jurisdictions. Where both UU PDP and the GDPR apply, SYP complies with each applicable data protection law to the extent required. In case of inconsistency between this Privacy Policy and any applicable mandatory law, the mandatory provisions of that law shall prevail.

3. Personal Data We Collect

We collect only the personal data necessary to operate and deliver the Platform's features.

3.1 Account and Profile Data

When you register for a SYP account, we collect the following:

  • First name and last name (mandatory — only your first name is displayed to other users in the Explorer mode. After Double Acceptance or an accepted request to join, your last name will be displayed)
  • Email address (mandatory)
  • Date of birth (mandatory — used to verify the minimum age requirement of 18 years and age displayed on the user profile — visibility in these two scenarios before mutual acceptance: (1) visible to the Plan owner when reviewing a request to join; (2) visible to both users before Double Acceptance in algorithmic matching)
  • City of residence (optional — for internal statistical analysis; displayed on the user profile — visibility in these two scenarios before mutual acceptance: (1) visible to the Plan owner when reviewing a request to join; (2) visible to both users before Double Acceptance in algorithmic matching)
  • Preferred match distance and time margin (mandatory — used exclusively by the matching algorithm; never triggers device location permissions)
  • Language(s) spoken (mandatory — used to determine your app interface language)
  • Profile photo (optional — visibility in these two scenarios before mutual acceptance: (1) visible to the Plan owner when reviewing a request to join; (2) visible to both users before Double Acceptance in algorithmic matching)
  • Brief bio (optional — displayed on the user profile — visibility in these two scenarios before mutual acceptance: (1) visible to the Plan owner when reviewing a request to join; (2) visible to both users before Double Acceptance in algorithmic matching)
  • Password (stored in hashed, non-reversible form — never accessible in plain text)

3.2 Plan Data

When you create or publish a Plan on the Platform, we collect: title of the activity, category (one of five fixed options: Sport, Culture, Food, Travel, Social), specific address of the planned activity as entered by you via the integrated mapping service used by the Platform, date and time, and an optional description.

The activity address is a fixed, user-entered property of the Plan. It is never derived from your device location, and its collection does not constitute user geolocation in any form.

3.3 Location Data — Permanent Policy

SYP does not collect any GPS coordinates or real-time device location data. This is an architectural and product commitment. The application does not request, access, or process device location permissions at any point.

Location information in SYP is limited exclusively to two manually entered data points: the city you provide at registration, and the specific address you enter when creating a Plan via the integrated mapping service used by the Platform.

3.4 Usage and Technical Data

We automatically collect: device type and operating system version, app version, session timestamps and duration, log data (errors, crash reports), and IP address (used for security and fraud prevention only — not used for location tracking).

This data may be collected in part through Grafana and Loki, our infrastructure monitoring and log aggregation tools. These tools collect device identifiers and usage data solely for the purpose of monitoring app stability and performance. This data is not used for advertising or cross-application tracking. At launch, this collection is enabled by default so that we can monitor the stability and use of the Platform during its first months, on the basis of our legitimate interest described in Sections 4 and 9.2. You may object at any time by writing to privacy@syp-app.com, in which case usage analytics will be disabled for your account. A future update of the App will ask you to confirm whether you agree to the continued collection of usage analytics.

Where you choose to upload a photo to a Plan, the app will request access to your device camera or photo library. This permission is requested only at the time of the action and solely for the purpose of uploading the selected image. It is entirely optional and does not affect core Platform functionality if declined.

3.5 Communication Data

Once a Match or a request to join is accepted, Users may exchange messages through the Platform's in-app Chat Thread. Messages are stored to ensure service continuity and enable moderation where required. Messages are not monitored proactively — access is restricted to authorised personnel for safety, legal compliance, and moderation purposes only.

Users may also exchange messages in group chats available within confirmed Activities. Users may delete conversations from their interface. However, copies of messages may be retained for a limited period where necessary for safety, moderation, fraud prevention, or compliance with legal obligations — see Section 6.3 for the specific retention period.

3.6 Payment Data

If you subscribe to a payment plan:

  • On Android devices, payments are processed via Google Play Billing
  • On iOS devices, payments are processed via Apple StoreKit

SYP does not store full payment card numbers or sensitive financial credentials. We retain only the data necessary to manage your subscription (subscription tier, billing status, transaction reference).

3.7 Matching Logic

The Platform operates two distinct connection mechanisms, each generating different types of data:

  • Algorithmic Matching: The Platform automatically identifies compatible Plans based solely on user-defined criteria (category, title, location, distance preference, date and time margin). A Match is, and will always remain, based exclusively on these declared criteria — it is never influenced by your past activity or behaviour on the Platform.
  • Request to Join (Explorer Mode — see Section 3.1 for access conditions): Users may browse existing Plans and send a request to join. The Plan owner independently decides to accept or decline each request. This mechanism does not use the Algorithmic Matching described above — it is driven entirely by user initiative.

In both mechanisms above, Matches result solely from user-defined criteria and independent user decisions. SYP does not currently build behavioural profiles of its users for matching purposes.

4. Legal Basis for Processing

Under UU PDP No. 27/2022, we process your personal data on the following legal bases:

  • Performance of a Contract — for account data, Plan data, communication data, necessary to provide the service.
  • Consent — for optional profile information (such as your bio) that you choose to provide to personalise your profile. You may withdraw this consent at any time by deleting the information from your profile.
  • Legitimate Interest (where permitted under applicable Indonesian law) — for technical and usage data to maintain security, stability, and performance.
  • Legal Obligation — where required by Indonesian law, including UU ITE and GR 71.

See Section 9.2 for the corresponding legal bases under GDPR Article 6.

5. Purposes of Processing

We use your personal data strictly for the following purposes: creating and managing your user account and profile; operating the Plan publication and Matching features; delivering Match notifications and enabling in-app messaging after acceptance of a Match or a request to join; ensuring platform security and preventing fraud; responding to user support requests; complying with legal obligations; and improving Platform performance through aggregated, anonymised analytics.

SYP does not use personal data for targeted advertising or cross-application tracking. We do not sell personal data to advertisers.

For information regarding user interactions, safety, and liability, please refer to our Terms of Service.

6. Data Storage and Infrastructure

6.1 Storage Location

All personal data is stored on secure cloud infrastructure and database hosting services operated by third-party providers acting as data processors under our instruction. These providers implement appropriate technical and organisational measures to ensure the security and integrity of personal data in accordance with industry standards and do not use your data for their own purposes.

Certain real-time and messaging functionalities rely on secure third-party infrastructure under strict access control and security standards. Third-party providers include Grafana and Loki (infrastructure monitoring and log aggregation), push notification services, and payment providers (the latter acting as independent data controllers).

In addition, we use the following named providers whose processing is directly relevant to the services you receive:

  • Railway (Singapore) — application backend hosting.
  • Railway Object Storage (Singapore) — S3-compatible object storage for profile and activity images.
  • Neon (a Databricks company; database hosted in Singapore) — PostgreSQL database hosting.
  • Google Firebase (United States) — in-app messaging (Chat Thread and group chat) and push notifications.
  • Resend (United States) — transactional emails (account verification, password reset). Not retained by SYP for marketing purposes; limited delivery and security logs may be retained by the provider in accordance with its documented retention practices.
  • Grafana & Loki (United States) — infrastructure monitoring, log aggregation and crash/error monitoring (app usage, session stability). Technical data including IP addresses and session identifiers; not used for advertising. Retained for a maximum of 14 calendar days.
  • Google Play Billing (United States) — subscription management and in-app purchases (Android). Acts as an independent data controller for payment data.
  • Apple StoreKit (United States) — subscription management and in-app purchases (iOS). Acts as an independent data controller for payment data.

Each infrastructure and technology provider listed above (other than Google Play Billing and Apple StoreKit, which act as independent controllers) is bound by a Data Processing Agreement requiring it to process personal data only on our instructions and to implement appropriate security measures. See Section 6.8 for the safeguards applicable to transfers outside the EEA and Indonesia.

6.2 Security Measures

We implement appropriate technical and organisational measures to protect your personal data, including: encryption of data in transit (TLS 1.2 or higher), encryption of data at rest on our database infrastructure, access controls and role-based permissions, token-based authentication and session management, and rate limiting to mitigate abuse.

6.3 Data Retention

  • Account and profile data: retained for the duration of the account, including a 30-day grace period after a deletion request during which the account may be reactivated; after this period the data is permanently deleted
  • Plan data and Match history: retained for the duration of the account
  • In-app messages (Chat Thread and group chat): retained for the duration of the account. Following voluntary account closure, messages may be retained for up to 90 calendar days, unless a longer retention period is necessary in connection with a reported incident, legal claim, fraud investigation, or legal obligation. In the case of a permanent ban, relevant messages and evidence may be retained for up to 12 months, in accordance with UU PDP Article 20.
  • Technical logs: retained for a maximum of 14 calendar days
  • Billing records: retained for 7 years in accordance with Belgian accounting and tax obligations

You may delete your account even if a subscription remains active, but we recommend cancelling it first to avoid further charges. Deleting your account does not automatically cancel an active subscription.

6.4 Inactive Accounts

If your account has been inactive for a continuous period of 2 years (no login or activity), we reserve the right to close it automatically. You will be notified by email at least 30 calendar days before any automatic closure.

6.5 Post-Closure Safety Retention Window

Following account closure, we retain a limited subset of your data in accordance with the following schedule:

  • Voluntary account closure (user-initiated deletion): 90 calendar days. This short safety window enables investigation of any violations that may come to our attention after closure, consistent with the data minimisation principle under UU PDP Article 20.
  • Permanent ban: 12 months. This extended window is necessary to support any review request, preserve evidence for potential legal proceedings, and detect repeat violations or attempts to circumvent a ban (e.g. re-registration under a new account), in accordance with UU PDP Article 20(2)(f).

At the end of the applicable retention period, all retained data is permanently deleted or anonymised. See Section 9.2 for the corresponding GDPR legal bases (Articles 5(1)(e) and 6(1)(f)).

6.6 Suspended vs. Deleted Accounts

If your account is suspended, your profile will no longer be visible to other users on the Platform. However, your data will be retained for the duration of the suspension period, as your account may be reinstated at the end of that period. Deletion of your account and associated data may be requested at any time during suspension by contacting privacy@syp-app.com.

Once your account is closed — including if you do not log back in within 2 years following the end of a suspension period — your data is deleted in accordance with the retention schedule set out above.

6.7 Data Breach Notification

In the event of a personal data breach that is likely to affect your rights or security, we will notify the competent authority and affected users in accordance with applicable law, including notification to the competent Indonesian authority within 3 × 24 hours of becoming aware of the breach under UU PDP No. 27/2022 (Article 46). See Section 9.5 for the additional GDPR breach notification obligations, which apply regardless of your location.

6.8 International Data Transfers

Personal data may be processed and stored outside the territory of Indonesia, including in jurisdictions where our infrastructure and technology providers operate — currently Railway, Neon (a Databricks company), Google Firebase and Resend. Where such transfers occur, SYP ensures appropriate safeguards, including contractual protections and adherence to recognised data protection standards, in accordance with applicable Indonesian data protection laws. By using the Platform, you acknowledge and are informed of such cross-border data transfers as necessary for the operation of the service.

See Section 9.4 for the transfer mechanism required under GDPR Chapter V for these same transfers.

7. Sharing of Personal Data

We do not sell, rent, or commercially exploit your personal data. We share personal data only in the following limited circumstances:

  • With Other Users — certain profile information is visible after acceptance of a Match or a request to join. In Explorer Mode, only first name and Plan details are visible.
  • User Reports and Moderation — data may be reviewed internally by authorised personnel to ensure platform safety.
  • Infrastructure and Database Hosting Providers — technical data for application hosting and database storage. These providers act as data processors under our instruction.
  • Infrastructure Monitoring Providers (Grafana & Loki) — technical data for app stability monitoring and log aggregation.
  • Payment Providers (Google Play Billing, Apple StoreKit) — subscription status and billing processing.
  • With Authorities — where required by Indonesian, Belgian or EU law, court order, or governmental authority.
  • In Corporate Restructuring — in the event of a merger or acquisition, with equivalent privacy protections and prior user notification.

We only share the minimum data necessary for each purpose.

8. Your Rights

As a data subject under UU PDP No. 27/2022, you have the right to: access your data, correct inaccuracies, request deletion, restrict processing, object to processing based on legitimate interest, withdraw consent, and request data portability. See Section 9.6 for the additional rights available to you under GDPR, which applies to our processing of your data regardless of your location.

Account deletion: You may delete your account directly from within the app at any time via the Settings menu. This will initiate the deletion of your account and associated personal data. You may also submit a deletion request by email.

To exercise any of your rights, submit a written request to privacy@syp-app.com. Account deletion requests are processed after a 30-day grace period, during which the account may be reactivated. All other rights requests will be responded to within 14 calendar days where possible and, in any event, within one month of receipt. In complex cases, this period may be extended by up to two further months (see Section 9.6), in which case we will notify you of the extension. Users in Indonesia also have the right to lodge a complaint with the competent Indonesian supervisory authority responsible for personal data protection, namely the Kementerian Komunikasi dan Digital (Komdigi), or any successor authority designated under UU PDP No. 27/2022.

9. GDPR (Regulation (EU) 2016/679) — Additional Provisions

This section sets out, in one place, the provisions of this Policy that are specific to GDPR. It supplements — and does not replace — the rest of this Policy.

9.1 Applicability

Share Your Plans SRL is incorporated under Belgian law and acts as an EU data controller. Accordingly, GDPR governs our processing of your personal data regardless of where you are located, in addition to any other applicable law described in Section 2 — this Section 9 is therefore not limited to users in the European Economic Area. Where both UU PDP and the GDPR apply, SYP complies with each applicable data protection law to the extent required.

9.2 Legal Basis for Processing (Article 6)

Under GDPR, we process your personal data on the following legal bases:

  • Performance of a Contract (Article 6(1)(b)) — for account data, Plan data, communication data, and core matching based on your declared criteria (see Section 3.7), necessary to provide the service.
  • Consent (Article 6(1)(a)) — for optional profile information (such as your bio) that you choose to provide to personalise your profile; you may withdraw this consent at any time by deleting the information, without affecting the lawfulness of processing before withdrawal.
  • Legitimate Interests (Article 6(1)(f)) — for (i) technical and usage data to maintain security, stability, and performance, and (ii) the extended 12-month post-ban retention window described in Section 6.5. We have assessed that these interests do not, in the general case, override your data protection rights; you may nonetheless object to any of them at any time on grounds relating to your particular situation (see Section 9.6).
  • Legal Obligation (Article 6(1)(c)) — where required by applicable EU or Belgian law.

The storage-limitation principle underlying the retention periods in Section 6.3 and 6.5 corresponds to GDPR Article 5(1)(e).

9.3 Automated Matching (Article 13(2)(f) / Article 22)

In accordance with GDPR Article 13(2)(f), we inform you that the Algorithmic Matching mechanism described in Section 3.7 involves automated processing of your personal data. Matching is based solely on your declared criteria (category, location, distance, date and time) and is necessary to provide this core feature of the Platform (Article 6(1)(b)); it does not use your past activity or behaviour on the Platform. In our assessment, this processing does not produce legal effects or similarly significantly affect you within the meaning of Article 22, as all Match suggestions remain subject to your acceptance or decline.

9.4 International Data Transfers (Chapter V)

As Share Your Plans SRL is incorporated in Belgium and acts as an EU data controller, transfers of the personal data described in Section 6.8 to processors located outside the European Economic Area (EEA) are subject to GDPR Chapter V (Articles 44–50). Singapore does not currently benefit from an EU adequacy decision. Transfers to the United States may rely on the EU–US Data Privacy Framework where the recipient is duly certified; otherwise, SYP relies on Standard Contractual Clauses or another valid transfer mechanism under GDPR Chapter V. Copies of the applicable transfer safeguards are available upon request at privacy@syp-app.com.

9.5 Data Breach Notification (Articles 33–34)

In addition to the notification described in Section 6.7, under GDPR Article 33 we will notify the Belgian Data Protection Authority (APD) without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay in accordance with GDPR Article 34.

9.6 Your Rights Under GDPR (Articles 15–22)

Because your data is processed by an EU-incorporated controller, you have the following rights under GDPR in addition to the rights described in Section 8 — regardless of where you are located:

  • Right of access (Article 15) — to obtain a copy of your personal data
  • Right to rectification (Article 16) — to correct inaccurate data
  • Right to erasure (Article 17) — to request deletion of your data
  • Right to restriction of processing (Article 18)
  • Right to data portability (Article 20)
  • Right to object (Article 21) — to processing based on our legitimate interest, as described in Section 9.2
  • Rights related to automated decision-making (Article 22)

To exercise any GDPR right, contact privacy@syp-app.com. Requests will be responded to within one month of receipt, extendable by one additional period of up to two months for complex requests; we will notify you of any such extension. You also have the right to lodge a complaint with the Belgian Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit — APD/GBA) at www.dataprotectionauthority.be, or with the supervisory authority of your own EEA country of residence.

10. Protection of Minors

The SYP Platform is strictly intended for users aged 18 and over. We do not knowingly collect personal data from individuals under the age of 18. If we become aware that a minor has registered on the Platform, we will immediately ban the account and delete the associated personal data.

To report a minor on the Platform, please use the in-app reporting feature available on any user profile, or contact us directly at privacy@syp-app.com.

11. Cookies and Similar Technologies

The SYP mobile application does not use traditional browser cookies. However, we may use the following technologies strictly necessary for the operation of the Platform:

  • Session tokens — to maintain your authenticated session and keep you logged in securely.
  • Local device storage (such as device-native storage mechanisms) — to remember your in-app preferences and settings. This may involve the use of device identifiers as required by the operating system.
  • Camera and photo library access (optional) — requested only if you choose to upload a photo to a Plan. This permission is never requested at app launch and can be revoked at any time from your device settings.

None of these technologies are used for advertising, cross-application tracking, or any purpose beyond the operation of the Platform. Device identifiers accessed through local storage are used solely for session management and app functionality, and are not shared with third parties for commercial purposes.

If a web-based version of the Platform is made available in future, a separate cookies notice will be provided at that time.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, applicable law, or the Platform's features. In the event of material changes, we will notify you via in-app notification or email at least 14 calendar days before the updated Policy takes effect.

The date of the most recent version is indicated at the top of this document. Your continued use of the Platform after the effective date of any revision constitutes your acceptance of the updated Policy.

13. Language

This Privacy Policy is drafted in English. In the event of any inconsistency between the English version and any translated version, the English version shall prevail to the extent permitted by the mandatory law applicable to you. An Indonesian (Bahasa Indonesia) version of this Privacy Policy is available on request at privacy@syp-app.com.

14. Contact — Data Protection

For any questions, requests, or concerns relating to this Privacy Policy or the processing of your personal data, please contact:

Share Your Plans SRL
BCE No. BE1034.288.729  |  Incorporated under Belgian law
Email: privacy@syp-app.com

We aim to respond to all privacy-related inquiries within 14 calendar days of receipt and, in any event, within the timelines set out in Sections 8 and 9.6. In complex cases, this period may be extended, and we will notify you of any such extension.

© 2026 Share Your Plans SRL  ·  BCE No. BE1034.288.729
Terms of Service Privacy Policy Contact

Last Updated: September 2026  ·  Prepared in accordance with UU PDP No. 27/2022 & GDPR (Regulation (EU) 2016/679)