← Pastime
Updated 30 August 2026

Privacy Policy

This policy explains the personal information used by Pastime, why it is used, who helps process it, and the choices available to you.

Who operates Pastime and how to contact us

Pastime is operated by MASIKA LTD. For privacy questions or requests, email joshuapl1998@gmail.com, or use our public contact page. Signed-in members can also use Support for an account-specific thread.

Personal information we use

  • Account details, including your Clerk account identifier, email address, name and profile photo.
  • Profile details, hobby interests, privacy choices, friends, blocks and invitations.
  • Your approximate home area and place searches. When you choose device location, the app accesses the precise coordinate temporarily, rounds it to an approximate home area before sending it, and the API rounds it again. Your precise device location is not stored by Pastime.
  • Events, attendance, waitlists, posts, comments, reactions, messages, reports, support requests and other activity you create.
  • Payment, refund and organiser-payout references and transaction status where paid events are enabled. Pastime does not store full payment-card details.
  • Technical information used for security and reliability, such as IP address, request and device information, authentication events, cookies or device-stored authentication and preference data, service logs and error diagnostics.

Why we use it

  • To create and secure accounts.
  • To provide profiles, nearby discovery, events, social features and conversations.
  • To process paid events, refunds and organiser payouts where payments are enabled.
  • To investigate reports, enforce blocks, prevent abuse and protect the service.
  • To answer support requests and send service or event messages.
  • To diagnose failures, measure reliability and comply with legal obligations.

Cookies and device storage

Current first-party web code uses browser local storage to remember your theme, notification sound choice and custom hobby labels. It uses session storage temporarily to avoid repeating a stale-code recovery reload. The mobile app uses device storage for the notification sound choice. Clerk uses authentication cookies or related browser storage on the web, and its mobile token cache uses secure device storage for authentication tokens.

Service providers

Pastime currently relies on the following providers or configured alternatives:

  • Clerk for authentication and account identity.
  • Supabase-hosted Postgres for the application database.
  • Google Cloud Run for the API and Google Cloud Storage for media when GCS is configured.
  • Cloudflare for DNS/CDN delivery and Cloudflare R2 for media when R2 is configured.
  • Vercel for the public website and web application.
  • Mapbox when configured, or OpenStreetMap Nominatim as the place-search fallback, for map and location features.
  • Stripe for checkout, refunds and organiser payouts where payments are enabled.
  • Upstash Redis for shared rate limits and live-message delivery where Redis is enabled.
  • Sentry for error monitoring only when Sentry is enabled.
  • The configured SMTP provider for reminder email only when SMTP email is enabled, and Google's Gmail service when you email the published contact address.
  • Expo is the app framework. If EAS cloud builds are configured and used, Expo Application Services may process source, build configuration and developer/build metadata for that build. Using Expo as the app framework does not by itself show that EAS cloud processing is active, or that an Expo-hosted update or push-notification service is enabled.

We require service providers that process personal information for Pastime to protect it consistently with this policy and Apple's privacy requirements. App Store privacy labels include Pastime's practices and the practices of integrated third-party code.

Sharing and visibility

Information you post or add to an event may be visible to other members. Messages are shared with their conversation participants. We may disclose information when legally required or when necessary to protect users and the service.

Retention and account deletion

Paid bookings retain restricted booking snapshots, payment and refund history, and relevant dispute evidence, including after account deletion. Evidence is scheduled for removal 540 days after capture or the event end, whichever is later. Open disputes and cases updated in the last 180 days extend retention. Access is limited to authorised staff handling payments and disputes.

We keep information only while it is needed for the purposes described above, subject to security, dispute, financial, tax, accounting, fraud-prevention, reconciliation and legal retention needs.

You can request account deletion from Settings. Access is disabled and deletion is queued as durable background work. Owned media, identity-provider data and provider records are removed or detached only after the relevant work succeeds. Direct media links, CDN caches and backups may remain for a period governed by cache expiry, backup rotation and verified provider processes. Financial or dispute records may be retained or de-identified where required. We do not promise immediate erasure when the request is submitted.

Your data protection rights

Depending on the circumstances and any legal exemptions, you may ask for access, correction or rectification, deletion, restriction, or portability of your information. You may also object to some processing and withdraw consent where processing relies on consent. Use the public contact details above to make a request.

You can complain to the UK Information Commissioner's Office (ICO). The ICO recommends giving the organisation a chance to resolve the concern first. See the ICO's complaint guidance.