Skip to content

Privacy Policy

Effective date: 16 July 2026

This Privacy Policy explains how The Corner Factory SA (Up4it, we, us, or our) processes personal data when you use our websites, applications, Help Center, and related services (together, the Platform) or otherwise interact with us.

The Platform is designed around private, real-world social coordination. This Policy applies to current features. A roadmap item is not a current data practice.

The controller responsible for the processing described in this Policy is:

The Corner Factory SA, Rue de St-Guérin 6, 1950 Sion, Switzerland. UID: CHE-271.016.257. Email: support@the-corner.io.

The data we process depends on the features you use and the choices you make.

  • Account and contact data: email address, login information, account identifiers, age or date of birth where needed to confirm eligibility, and account preferences.
  • Profile data: display name, profile photo, biography, language, and other optional profile fields.
  • Mood and Moment data: titles, descriptions, images, dates, times, approximate or precise locations, requirements, invitations, participation responses, and Organizer instructions.
  • Social and audience data: friend connections, Circle membership, invitations, blocks, and audience choices for shared Content.
  • Communications: messages and other information you send through communication features that are available in your version of the Platform.
  • Support, safety, and legal data: correspondence, reports, appeals, evidence you choose to provide, and information needed to investigate abuse, protect safety, or respond to legal requests.

Do not include sensitive personal data in a Mood, Moment, profile, or message unless it is necessary and appropriate for the selected audience.

2.2 Data collected when you use the Platform

Section titled “2.2 Data collected when you use the Platform”
  • Device and network data: IP address, device and app type, operating system, language, time zone, and identifiers needed for authentication, security, or reliable delivery.
  • Usage and log data: access times, pages or screens viewed, feature interactions, invitations and responses, error logs, crash data, and security events.
  • Location data: approximate location derived from an IP address and, only where the feature requires it and device permission is granted, location from your device. You can control device location through operating-system settings, but some location-based features may then be unavailable.
  • Cookies and local technologies: data described in our Cookie Policy.
  • Sign-in providers: if you choose a third-party sign-in method, we receive the identifiers and profile fields shown during that sign-in flow.
  • Other Members and reporters: another person may invite you, include information about you in Content, or submit a report concerning an interaction.
  • Public authorities and security sources: where lawful and necessary to protect the Platform, comply with law, or investigate abuse.

Up4it does not currently process payment-card, bank-account, payout, or payment-transaction data because it does not offer a payment service.

Where the GDPR or another law requires a legal basis, we rely on the bases below as applicable. Swiss data-protection principles, including transparency, proportionality, purpose limitation, and security, apply independently.

We do not require health, biometric, religious, political, sexual-orientation, or other legally sensitive data as a standard account condition. If a released feature asks for sensitive data, we will identify the purpose and use explicit consent where required, or rely on another specific basis permitted by law, such as protecting vital interests or establishing legal claims. An Organizer who independently requests or uses sensitive data has separate responsibilities under the Participant Privacy Standards.

Purpose Typical data Legal basis where required
Create and secure an account; provide requested features Account, profile, social, Mood, Moment, communication, device data Performance of our contract with you
Show Content to the audience you select and coordinate participation Profile, social, location, Mood, Moment, communication data Performance of our contract with you
Authenticate users, prevent fraud, debug, and maintain service security Account, device, usage, report data Contract; legitimate interests in a secure and reliable service; legal obligations
Enforce policies, review reports and appeals, and protect Members Content, communications where relevant to a report, account, usage, and report data Legitimate interests in safety and enforcement; contract; legal obligations; vital interests in an emergency
Respond to support and data-rights requests Account, contact, support, verification data Contract; legal obligations; legitimate interests in handling requests correctly
Send service notices and requested notifications Contact, preference, Mood, and Moment data Contract; legitimate interests for essential service notices
Send optional marketing Contact and preference data Consent where required, or another basis permitted by applicable law; you may opt out at any time
Improve the Platform using aggregated or limited usage information Usage, device, and feedback data Legitimate interests in improving the service; consent where required for optional analytics technologies
Establish, exercise, or defend legal claims and comply with valid requests Account, Content, usage, support, report, and legal-request data Legal obligations; legitimate interests; establishment or defence of legal claims

We do not use Content from private Moods, Moments, or communications for advertising. We do not make decisions that produce legal or similarly significant effects based solely on automated processing. If that changes, we will provide the legally required information and review rights before the processing begins.

We may share personal data with the following recipients only for the stated purposes:

  • Members you select: according to the audience, invitation, participation, and privacy settings for the relevant feature. For safety, an Organizer and confirmed Participants may receive information reasonably needed to coordinate a Moment.
  • Service providers: companies that provide hosting, authentication, communications delivery, security, error monitoring, support, or other infrastructure under contractual restrictions.
  • Professional advisers and insurers: where reasonably necessary for legal advice, audits, claims, security, or risk management.
  • Authorities and affected persons: where required or permitted by law, valid legal process, or a good-faith response to an emergency or serious threat. See Law Enforcement Requests.
  • A successor organization: as part of a merger, financing, reorganization, insolvency, or transfer of all or part of the Platform, subject to confidentiality and applicable notice requirements.

We do not sell personal data. We do not share personal data with third parties for cross-context behavioural advertising.

Members who receive another person’s information must follow the Participant Privacy Standards.

The Platform is operated from Switzerland. Service providers may process personal data in Switzerland, the European Economic Area, the United States, or another country identified in the relevant feature or consent notice.

Before disclosing personal data to a country without legally recognized adequate protection, we use an available safeguard, such as approved standard contractual clauses with any required Swiss or European supplements, or a specific legal exception. You may request information about the applicable destination and safeguard by contacting us.

Information you choose to share with a Member may be accessed from the country where that Member is located.

We retain personal data only for as long as reasonably necessary for the purpose described, taking account of legal obligations, safety, security, disputes, and technical backup cycles.

  • Account and profile data: retained while the account is active, then deleted or anonymized after a valid deletion request unless continued retention is necessary.
  • Moods and Moments: designed to stop being visible after their selected expiry or end. Expiry is not the same as immediate deletion from every system. Limited copies may remain temporarily in backups, security logs, reports, or legal records.
  • Social and participation data: retained while needed to operate Friends, Circles, invitations, blocks, and participation history, or until the account or relevant relationship is deleted, subject to safety and legal exceptions.
  • Support, report, and appeal records: retained for the time needed to resolve the matter, prevent repeated abuse, demonstrate fair enforcement, comply with law, and establish or defend claims.
  • Technical and security logs: retained for a limited period based on security, reliability, and incident-investigation needs, then deleted or aggregated unless an incident requires longer preservation.
  • Legal records: retained for the period required by law or reasonably necessary for a legal claim or valid preservation request.

Where an exact period cannot be stated in advance, we use the shortest period consistent with the purpose, sensitivity, risk, and applicable limitation or retention periods. We periodically review retained data.

We use appropriate technical and organizational measures designed to protect personal data, including access controls, data minimization, secure transmission where appropriate, logging, backup controls, and incident response. No service can guarantee absolute security.

If a personal-data breach occurs, we will assess it and notify the competent authority and affected people where applicable law requires.

Depending on applicable law, you may have rights to:

  • ask whether we process your personal data and obtain access to it;
  • correct inaccurate or incomplete data;
  • request deletion, restriction, or cessation of processing;
  • object to processing based on legitimate interests or for direct marketing;
  • receive certain data in a portable format;
  • withdraw consent at any time, without affecting earlier lawful processing;
  • express your view and request human review of an automated individual decision, if we introduce one; and
  • complain to a competent data-protection authority.

These rights may be subject to lawful exceptions, including the rights and safety of others, legal privilege, security, and record-retention duties. Instructions are available in How to Exercise Your Data Subject Rights.

The Platform is intended for Members aged 13 and older. People under 13 may not create or use an independent account. If we learn that an under-13 account was created, we will restrict or close it and delete or limit the associated data, subject to child-safety, security, rights-request, and legal-preservation duties.

Members aged 13 to 17 are Young Members. We apply privacy-protective defaults, provide age-appropriate information, and do not use a Young Member’s personal data for profiling-based advertising. The Young Members Policy explains the additional design, contact, location, reporting, and guardian safeguards that apply.

Where the GDPR applies and we rely on consent to process a child’s personal data in connection with an online service offered directly to the child, a parent or guardian must authorize that consent if the child is below the age set by the child’s EU or EEA country. That age varies by country between 13 and 16. This rule concerns consent-based data processing; other legal bases and national rules may apply to other processing. We will make reasonable and proportionate efforts to verify parental authorization where it is required.

We use proportionate, privacy-preserving age-assurance measures and collect no more age information than reasonably necessary for eligibility and safety. A parent or guardian may contact us about a child’s data. We may verify the requester’s identity and authority, and we will also consider the Young Member’s privacy, safety, and applicable rights.

Third-party sites and services have their own privacy practices. Review the information shown before linking an account, enabling a device permission, or following an external link. Up4it’s Policy does not govern a third party’s independent processing.

You may contact us first so we can address a privacy concern. You also have the right to contact the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, where the GDPR applies, the data-protection authority in the country where you live, work, or believe an infringement occurred.

We may update this Policy to reflect changes in law, technology, or the Platform. We will update the lastUpdate date and provide reasonable notice of material changes. If a new purpose requires consent, we will request it before using data for that purpose.

For privacy questions, complaints, or rights requests, email support@the-corner.io with the subject Privacy request, or write to the controller address in Section 1.