AT A GLANCE

Who we are: I'm Here, a venue-based social layer operating in the United Kingdom. I'm Here is currently run on an unincorporated basis. A registered company will be incorporated once the platform has been trading for approximately 6 to 12 months, and this Policy will be updated with the incorporated entity's details at that time.

I'm Here ('we', 'us', 'our') is a web-based social layer for venues, event spaces, and events. We are committed to protecting your personal data and handling it transparently and responsibly. This Privacy Policy explains what data we collect, why we collect it, how we use it, who we share it with, and what your rights are. This policy applies to all users of im-here.co.uk (our marketing website) and im-here.live (our web app, accessed via venue QR codes), as well as venue partner portals. Where practices differ between the website and the app, we make this clear. We are the data controller for personal data collected through the services. For all privacy-related enquiries, contact us at support@im-here.live.

  1. INFORMATION WE COLLECT

Information You Provide to Us

When you create a session profile or register an account, we collect the following:

  1. Email address

  2. Date of birth (used to verify you are 18 or over; your age is displayed on your profile, not your full date of birth)

  3. Gender

  4. Profile photograph

  5. Connection preference (open to meeting: men, women, or everyone). This information, combined with your gender, may indicate your sexual orientation. See Section 3 for how we handle this.

  6. Intentions (the connection type you have selected: Serious, Casual, or Social)

  7. Vibe tags (selected from our provided options)

  8. Information Collected Automatically

When you use our services, we automatically collect the following technical and usage data:

  1. IP address (stored in hashed, anonymised form and automatically deleted after 90 days)

  2. Device type and operating system

  3. Browser type and version

  4. Session identifiers

  5. Location data. When you access a venue session, we check your real-time GPS location solely to verify you are physically within approximately 150 metres of a participating venue. Your GPS coordinates are never saved to our database. Only a yes or no venue presence flag is recorded. Once your session ends, no location information is retained.

  6. QR code scan events and session activity (waves sent, matches made, session duration)

Information from Third Parties

If you make a payment through our services, payment data is processed by Stripe. We receive confirmation of payment status but do not store your full card details. Please review Stripe's Privacy Policy at stripe.com/gb/privacy. When you access the services, Cloudflare Turnstile is used to perform a bot and fraud detection check. This processes a token and your IP address to verify you are a human user. No personal data is retained by us from this process beyond what is described in this policy.

  1. HOW WE USE YOUR INFORMATION

We use the information we collect for the following purposes:

  1. To provide the services: creating and displaying your session profile, enabling waves and mutual matches, facilitating in-session chat, and managing your session and account.

  2. Venue presence verification: using your real-time location to confirm you are physically within range of a participating venue or event. Location data is not stored and is not used for any purpose beyond this check.

  3. Safety and moderation: investigating reports of misconduct, enforcing our community guidelines, issuing warnings and bans, and escalating serious incidents to relevant authorities where required. Reported messages are retained as evidence.

  4. Payments and subscriptions: processing purchases and managing subscription billing through Stripe.

  5. Transactional communications: sending account confirmations, one-time sign-in codes, payment receipts, and safety notices via Resend, our email delivery provider.

  6. Marketing communications: where you have given consent, we may send marketing emails via MailerLite. You can withdraw consent and unsubscribe at any time.

  7. Fraud and bot prevention: using Cloudflare Turnstile to protect the platform against automated abuse.

  8. Website analytics: understanding how visitors use our marketing website, im-here.co.uk, in aggregate, using Google Analytics. This applies to the marketing website only, not the app.

  9. Website advertising: serving and measuring advertising campaigns via Google Ads, Meta Ads (Facebook and Instagram), and Meta Pixel. These operate on the marketing website only and are subject to cookie consent. See Section 7 (Cookies and Tracking) for full detail.

  10. Legal compliance: meeting our obligations under applicable law, including the UK Online Safety Act 2023, UK GDPR, and the Data Protection Act 2018.

  1. LEGAL BASIS FOR PROCESSING

We process your personal data on the following legal bases under UK GDPR:

  1. Contract: processing necessary to provide the services you have signed up for, including profile creation, session management, and payment processing.

  2. Legitimate interests: fraud prevention, platform security, bot detection, service improvement, and moderation, where these do not override your rights and freedoms

  3. Legal obligation: where we are required to process or retain data to comply with applicable law, including safety reporting obligations under the UK Online Safety Act 2023.

  4. Consent: for marketing communications and non-essential cookies on the marketing website. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

  5. Explicit consent for special category data: your gender and connection preference may, in combination, reveal information about your sexual orientation. This is special category data under Article 9 UK GDPR. We rely on your explicit consent under Article 9(2)(a) UK GDPR to process this data, obtained separately from your general acceptance of this Policy at the point you create your session profile. You may withdraw this consent at any time by contacting support@im-here.live or deleting your account.

  1. HOW WE SHARE YOUR INFORMATION

With Other Users

Your profile, including your first name, age, photo, intentions, vibe tags, and connection preference, is visible to other users present at the same venue during an active session. Your email address, date of birth, GPS location, IP address, and device information are never shared with other users. Once your session expires or you leave the venue's proximity, your profile becomes invisible to other users. See our Terms and Conditions for full details on session and visibility rules.

With Venue Partners and Event Organisers

Venue partners and event organisers have access to limited, privacy-safe operational data to manage their venue or event, including aggregate attendance figures, live session status, and safety-relevant information in the event of a reported incident. Partners cannot access your email address, date of birth, messages, GPS data, or IP address. We share this information with Partners on the basis of our legitimate interests in protecting user safety and the integrity of the platform.

With Third-Party Service Providers

We share data with the following trusted third-party providers, who process data on our behalf:

  1. Stripe: payment processing. Data shared: transaction data necessary to process and record payments.

  2. Resend: transactional email delivery (sign-in codes, receipts, safety notices). Data shared: email address and email content.

  3. Cloudflare Turnstile: bot and fraud detection. Data shared: a verification token and IP address at the point of access.

  4. MailerLite: marketing email communications. Data shared: email address and communication preferences, where consent has been given.

  5. Google Analytics: website usage analytics, marketing website only. Data shared: anonymised usage and behaviour data.

  6. Google Ads: website advertising, marketing website only, with cookie consent. Data shared: anonymised conversion and audience data.

  7. Meta Ads and Meta Pixel: website advertising on Facebook and Instagram, marketing website only, with cookie consent. Data shared: anonymised conversion and audience data.

All third-party providers are required to handle your data in accordance with applicable law and our instructions. We will update this policy if additional providers are engaged.

With Authorities

We may disclose personal data to law enforcement, regulatory authorities, or emergency services where we are legally required to do so, or where we believe disclosure is necessary to protect the safety of any person, prevent fraud, or comply with a legal obligation.

With Our Developer

Our development partner is based in India. They may have access to platform data for the purposes of maintaining, testing, and improving the services, subject to your authorisation as the data controller. Before any access to live user data is granted, this will be governed by a Data Processing Agreement in accordance with UK GDPR Article 28. Because our developer is based in India, a country which does not currently benefit from UK adequacy regulations, any such access is also subject to an appropriate transfer safeguard under UK GDPR, specifically the ICO's International Data Transfer Agreement, supported by a transfer risk assessment. Both the Data Processing Agreement and the transfer safeguard will be put in place before the developer is given access to live user data.

Business Transfers

If I'm Here is involved in a merger, acquisition, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you before your data is transferred and becomes subject to a different privacy policy.

  1. DATA RETENTION

We retain your personal data only for as long as necessary for the purposes set out in this policy, or as required by law. Our retention periods are as follows:

  1. Session messages: automatically deleted 30 days after the match (mutual wave) to which they belong has ended. Messages that have been reported are retained as evidence for the duration of any active moderation or legal process.

  2. Profile and account data: profiles with no activity for 12 months are automatically anonymised, meaning personal details are stripped from the record. Deletion requests are processed within 30 days.

  3. Location data: GPS coordinates are never stored. The venue presence flag (yes or no) is not retained after session end.

  4. IP addresses and device logs: stored in hashed, anonymised form and automatically deleted after 90 days.

  5. Payment records: retained for 6 years from the date of transaction in accordance with HMRC requirements and UK financial regulations. Deletion of records no longer required is carried out manually and is reviewed at least annually to ensure timely removal.

  6. Moderation and ban records: retained for up to 6 years from the date of the relevant incident for legal compliance and safety purposes, and reviewed at least annually to ensure records are not kept longer than necessary.

  7. Serious incident and safety logs: retained for up to 6 years or as required by law enforcement or regulatory guidance, and reviewed at least annually to ensure records are not kept longer than necessary.

  8. Backups: a full server backup is performed weekly by Hostinger. Backup frequency will be reviewed as the platform grows.

  1. DATA SECURITY

We take the security of your personal data seriously. Our services are hosted on a UK-based Hostinger VPS server. We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss, destruction, or disclosure. Chat messages are individually encrypted using AES-256 encryption, meaning their contents cannot be read even by someone with raw database access. IP addresses are stored in hashed, anonymised form. Profile and account data is accessible only to authorised personnel and third-party providers under appropriate agreements. Despite these measures, no method of transmission over the internet or electronic storage is entirely secure. If you believe your account has been compromised, contact us immediately at support@im-here.live.

  1. COOKIES AND TRACKING TECHNOLOGIES

Our use of cookies differs between the marketing website and the web app. We set out both below.

The Web App (accessed via venue QR code)

The app uses essential cookies only. These are required for the platform to function and cannot be disabled:

  1. Session cookie, short-lived, 15 minutes: keeps you signed in during an active session.

  2. Session cookie, long-lived, 30 days: keeps you signed in if you choose to stay signed in across visits.

  3. Security cookie: helps prevent fraud and unauthorised access.

The app also stores a small non-sensitive item in your browser, your cookie consent flag. No advertising, analytics, or third-party tracking cookies are set within the app. Because the app uses only essential cookies, a full consent-based cookie banner is not required for app access. An acknowledgement notice is displayed at the point of QR code scan.

The Marketing Website (im-here.co.uk)

The marketing website uses additional cookies for analytics and advertising, subject to your consent:

  1. Essential cookies: required for the website to function.

  2. Analytics cookies (Google Analytics): collect anonymised information about how visitors use the website to help us improve it.

  3. Advertising cookies (Google Ads, Meta Ads, Meta Pixel): used to deliver relevant advertising and measure campaign effectiveness. These may track activity across other websites.

A cookie consent banner is displayed on the marketing website. Non-essential cookies are not set until you have given your consent. You can update your cookie preferences at any time via the cookie settings link on the website. You can also control cookies through your browser settings. Disabling cookies may affect the functionality of certain parts of the website.

  1. YOUR RIGHTS

Under UK GDPR and the Data Protection Act 2018, you have the following rights in relation to your personal data:

  1. Right of access: you may request a copy of the personal data we hold about you.

  2. Right to rectification: you may request that we correct inaccurate or incomplete personal data.

  3. Right to erasure: you may request that we delete your personal data where there is no compelling reason for its continued processing. Some data may be retained for legal compliance purposes as set out in Section 5.

  4. Right to restriction: you may request that we restrict the processing of your personal data in certain circumstances.

  5. Right to object: you may object to processing where we rely on legitimate interests as our legal basis.

  6. Right to withdraw consent: where we process your data on the basis of consent, including explicit consent for special category data, you may withdraw that consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at support@im-here.live. We will respond within one month. We may need to verify your identity before processing your request. If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office at ico.org.uk or by calling 0303 123 1113.

  1. CHILDREN AND AGE VERIFICATION

Our services are strictly for users aged 18 and over. We operate in licensed venue environments and do not permit access to minors. At the point of profile creation, you are required to enter your date of birth. We use this to calculate your age and confirm eligibility. Your full date of birth is not displayed to other users, only your age is shown on your profile.

Age verification is currently self-declared. At present, we only onboard venues and events that independently operate their own over-18s admissions policy, which provides an additional layer of protection alongside self-declaration. By entering your date of birth and accessing the services, you confirm that you are 18 or over and that the information you have provided is accurate. If we become aware that a user is under the age of 18, we will immediately suspend or permanently remove that account and delete their personal data.

Because the services are accessed online, by scanning a QR code, self-declaration together with venue-level admissions policies may not, on their own, satisfy the "highly effective age assurance" standard that Ofcom applies to user-to-user services under the Online Safety Act 2023. This is because the online access point, the QR code and web app, is not itself age-gated, even where the physical venue is. We are keeping our approach to age assurance under active review as the platform grows, and this section will be updated if the verification method changes.

  1. LOCATION DATA

We collect your real-time GPS location when you access a venue session to verify that you are physically within approximately 150 metres of a participating venue or event. This is a core integrity feature of the platform ensuring that only people genuinely present at a venue can appear in that venue's session. Your GPS coordinates are never saved to our database. Only a yes or no venue presence confirmation is recorded. Location data is not used for advertising, profiling, or any purpose other than real-time venue access verification, and no location information is retained after your session ends. Your device will prompt you to grant location permission when you access a venue session. If you decline, you will not be able to join the session.

  1. INTERNATIONAL DATA TRANSFERS

Your personal data is stored and processed in the United Kingdom on our Hostinger VPS server. Some of our third-party service providers may transfer or process data outside the UK. Specifically:

  1. Stripe: may process payment data in the United States and other jurisdictions. Stripe maintains appropriate safeguards including standard contractual clauses.

  2. Google (Analytics and Ads): may process data outside the UK. Google maintains appropriate safeguards under the UK GDPR international transfer framework.

  3. Meta (Ads and Pixel): may process data outside the UK. Meta maintains appropriate safeguards under the UK GDPR international transfer framework.

  4. Resend: may process email data outside the UK. Appropriate safeguards are maintained.

  5. Cloudflare: may process verification data outside the UK. Cloudflare maintains appropriate safeguards.

  6. Our developer: based in India. India does not currently benefit from UK adequacy regulations. Any processing by our developer is subject to an appropriate safeguard under UK GDPR, specifically the ICO's International Data Transfer Agreement, supported by a transfer risk assessment, both of which will be completed before access to live user data is granted.

Where data is transferred outside the UK, we ensure that appropriate safeguards are in place in accordance with UK GDPR, including standard contractual clauses, the International Data Transfer Agreement, or adequacy decisions, as applicable.

If we begin to actively offer or direct our services to users based in the European Union, we will appoint an EU representative in accordance with Article 27 of the EU GDPR and update this Policy accordingly.

  1. THIRD-PARTY LINKS

Our services may contain links to third-party websites, including venue partner websites. We are not responsible for the privacy practices of those third parties and encourage you to review their privacy policies before providing any personal data to them.

  1. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. We will update the 'Last updated' date at the top of this policy and, where changes are material, we will notify you by email or by a prominent notice on the services. Your continued use of the services after any changes constitutes your acceptance of the updated policy.

  1. CONTACT US

For any questions, concerns, or requests relating to this Privacy Policy or how we handle your personal data, please contact us:

I'm Here

United Kingdom

support@im-here.live

I'm Here is currently operated on an unincorporated basis while the service is in its early trading phase. We intend to incorporate a registered company within approximately 6 to 12 months of the platform going live, and this Policy will be updated with the incorporated entity's name, company number, and registered office address at that time.

Data protection registration: I'm Here has not yet registered with the ICO's data protection fee register. We will complete this registration before the services begin live processing of user personal data.

Data Protection Officer: I'm Here has not appointed a Data Protection Officer. Our development partner will be engaged under a Data Processing Agreement in accordance with UK GDPR Article 28, and whether a Data Protection Officer is required will be kept under review as the platform grows.

To complain to the regulator:

Information Commissioner's Office (ICO), ico.org.uk, 0303 123 1113

Last updated: 23 June 2026.