ASAP Safety ("we", "our", or "us") is committed to protecting your privacy. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Dutch UAVG. We only collect data that is needed to provide the safety features of the app.
01
Who we are
ASAP Safety is a personal safety app founded by Yeline Hoogmans. The app helps users share their location with trusted contacts and trigger emergency alerts when they feel unsafe.
- Operating name: ASAP Safety
- Legal entity: ASAP Safety B.V. (in oprichting)
- Country of establishment: The Netherlands
- Email: contact@asapsafety.nl
- Website: asapsafety.nl
02
Data we collect
We apply data minimisation: we only collect information that is needed to make the app work safely and reliably.
Account and profile
- Phone number, used for authentication.
- Name and username, used to identify you to trusted contacts.
- Email address, used for account management and support.
- Gender, if provided, used only for in-app personalisation.
- Profile photo, if uploaded by you.
Location data
- Precise GPS location is used only during an active SOS session, check-in or location-sharing session.
- We do not continuously track your location outside active safety sessions.
- Location data is shared in real time with the contacts or circles you selected for that session.
Location consent: before location-based features are used, the app asks for permission and explains what is shared, with whom and for how long. You can revoke location permissions in your device settings.
Contacts and Safety Circles
- Contacts you add or invite, such as username, user ID and available profile details.
- Circle membership, pending invitations and accepted contact relationships.
- We do not sell your contact data and we do not use it for advertising.
Notifications and technical data
- Device push token, used to deliver SOS alerts, check-in updates and contact requests.
- Anonymised usage and crash information, used to improve stability and safety features.
03
Legal basis for processing
Under GDPR Article 13, we inform you of the legal basis for each processing activity.
| Processing activity | Data used | Legal basis |
|---|---|---|
| Creating and managing your account | Phone number, name, email | Contract - necessary to provide the service. |
| Sharing live location during SOS or check-in | Real-time GPS location | Consent - provided per session and via device permissions. |
| Managing contacts and Safety Circles | User IDs, usernames, contact relationships | Contract and legitimate interest - core safety functionality. |
| Sending push notifications | Device push token | Consent - via device permission prompt. |
| Improving the app | Anonymised usage and crash data | Legitimate interest - improving app stability and safety. |
| Responding to legal requests | Relevant account data | Legal obligation. |
Where we rely on consent, you can withdraw that consent at any time. Where we rely on legitimate interest, you have the right to object.
04
How we use your data
We use your personal data only for the purposes described here. We do not use your data for advertising or unrelated profiling.
| Purpose | Data used |
|---|---|
| Authenticate your account | Phone number and verification details. |
| Show your profile to trusted contacts | Name, username and profile photo. |
| Share your location during active sessions | GPS location for SOS, check-in and selected sharing sessions. |
| Send safety alerts | Push token, contact list, circle membership and alert metadata. |
| Provide support and handle requests | Account and contact details you provide to us. |
| Improve the app | Anonymised analytics and crash reports. |
05
Storage and security
ASAP Safety uses Google Firebase for authentication, database storage, push notifications and app analytics. Firestore data is stored in the European region europe-west1.
- Data is encrypted in transit using TLS.
- Data is encrypted at rest by Google Firebase.
- Access to production data is restricted to authorised personnel.
- Firebase Security Rules restrict access to data based on authenticated user relationships.
- Real-time location is used for active safety sessions and is minimised wherever possible.
06
Third-party processors
We use selected third-party services to operate the app. Each processor is used only for a specific purpose.
| Processor | Purpose | Data processed |
|---|---|---|
| Google Firebase | Authentication, database, push notifications, analytics and crash reporting. | Account data, push tokens, app events and technical logs. |
| Apple App Store | iOS app distribution and in-app platform services. | Apple account and device data handled by Apple. |
| Google Play | Android app distribution and platform services. | Google account and device data handled by Google. |
We do not sell, rent or trade personal data.
07
Data sharing
We share data only in limited situations:
- With your trusted contacts: when you start an SOS session, check-in or selected location-sharing session.
- With Firebase: to provide authentication, database storage and push notifications.
- If required by law: when required by applicable law, legal process or court order.
- Business transfer: if ASAP Safety is acquired or merged, data may transfer as part of that transaction, with notice where required.
08
Data retention
We retain personal data only for as long as needed to provide the app or meet legal obligations.
| Data type | Retention period | Reason |
|---|---|---|
| Account data | Until account deletion, then deleted within 30 days. | Service provision. |
| Real-time location | Only during active sessions, minimised after the session ends. | Safety functionality. |
| SOS and check-in history | Stored in your account until you delete it or your account. | User reference and safety history. |
| Push tokens | Until account deletion, token refresh or permission removal. | Notification delivery. |
| Anonymised analytics | Up to 14 months, unless configured otherwise. | App improvement. |
| Contact and circle data | Until removed, relationship ends, or account is deleted. | Service provision. |
09
Your rights under GDPR
If you are located in the EU or EEA, you have the following rights. We respond to GDPR requests within 30 days.
Access
Request a copy of the personal data we hold about you.
Rectification
Request correction of inaccurate or incomplete data.
Erasure
Request deletion of your account and associated data.
Restriction
Request restricted processing in certain circumstances.
Portability
Receive your data in a machine-readable format where applicable.
Object
Object to processing based on legitimate interest.
Withdraw consent
Withdraw location or notification consent in your device settings.
Complaint
Lodge a complaint with the Dutch Data Protection Authority.
To exercise your rights, contact us at contact@asapsafety.nl. We may ask you to verify your identity before processing your request.
10
Children's privacy
ASAP Safety is not intended for children under 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal information without appropriate consent, contact us and we will delete the relevant data.
For users between 13 and 16 in the Netherlands or other EEA countries where a higher minimum age applies, parental or guardian consent may be required.
11
Deleting your account
You can delete your account directly from the app or request deletion by email. See our Delete Account page for step-by-step instructions.
- Personal data associated with your account is permanently deleted within 30 days.
- Your profile and contact relationship data is removed from relevant contacts and circles.
- Anonymised analytics data that cannot identify you may be retained.
- Any legal retention obligation will be communicated where required.
12
Contact and complaints
If you have questions about this Privacy Policy or want to exercise your rights, contact us:
- Email: contact@asapsafety.nl
- Website: asapsafety.nl
- Response time: within 30 days for GDPR requests.
You also have the right to lodge a complaint with the Dutch Data Protection Authority: autoriteitpersoonsgegevens.nl.