Privacy notice for the official mobile app
Privacy Policy - Time in Jazz App
This notice describes the processing of personal data carried out
through the official Time in Jazz mobile app, the backend, support web
pages and connected technical tools. It covers accounts, email, Google
and Apple sign-in, programme browsing, saved items, reviews,
notifications, maps, calendar actions, external links, aggregate usage
statistics and the administrative area.
1. Data Controller
The Data Controller is Associazione culturale Time in Jazz, Via
Umberto I, 37 - 07022 Berchidda (SS), Italy, Tax Code 90004730900,
VAT 01812780904.
Privacy requests can be sent to
segreteria@timeinjazz.it.
2. Covered services
The app lets users browse the festival programme, days, artists,
venues, hospitality, food, ticket resources and announcements; search
content; create an account; save items to their personal festival;
leave post-event reviews; receive notifications; open maps and
directions; add events to the calendar; open external links; and use
account deletion pages. The connected administrative area manages
content, push campaigns, aggregate statistics and users with marketing
consent.
3. Data processed
- account and profile data: name, email, role, marketing-consent status, notification status, password stored only as a hash, app tokens/sessions and related expiry dates;
- federated sign-in data: Google or Apple provider, provider identifier, provider email and Firebase token used to verify identity during sign-in;
- privacy acceptance evidence: accepted version, date, acceptance flow and marketing preferences;
- saved items: item type, item identifier and saving date;
- reviews: event, rating, optional comment, creation and update date;
- push notifications: random device identifier generated by the app, FCM/APNs token, platform, language, app version and last token update;
- app usage statistics: random visitor and session identifiers, event type, screen, content type and identifier, language, platform, app version, date and time;
- local device data: content cache, preferences, random analytics and push identifiers, store-review reminder counters, guest consents and access tokens stored in the system secure storage;
- current location, only when authorised by the device, used in the app to calculate local distances and sorting without storing it on the Time in Jazz backend;
- technical and security logs: IP address, user agent, timestamps, requested endpoints, errors, diagnostics, access attempts and administrative audit logs;
- administrative-area data: admin accounts, admin sessions, content changes, push campaigns, analytics exclusions and possible exports of users with marketing consent.
4. Purposes and legal bases
- delivering the app, displaying content, managing search, accounts, sign-in, saved items, reviews, profile and account deletion: performance of the requested service;
- verifying identity through email/password, Google, Apple and Firebase Authentication: performance of the service and technical steps required by the sign-in method chosen by the user;
- sending operational or editorial push notifications enabled by the user: consent, device settings and requested service;
- sending marketing emails: separate, optional and revocable consent;
- displaying maps, directions, distances, system-calendar actions, external links and store-review requests: service requested by the user and device or provider settings;
- producing aggregate and anonymous usage statistics, improving content, stability and features: legitimate interest of the Controller, with minimisation and without individual commercial profiling;
- protecting accounts, backend, administrative area and infrastructure, preventing abuse and documenting relevant operations: legitimate interest and, where applicable, legal obligations.
Marketing consent is optional and separate from acceptance of this
Privacy Policy.
5. Analytics and statistics
The app collects minimal interaction events, such as app opens, screen
views, successful login or registration, adding or removing favourites,
and submitting or deleting reviews. Events are used only for app usage
statistics and to understand which sections and features are used most.
New analytics events do not store the user's name, email or account
identifier. If the user is authenticated, the token may be read by the
backend only to exclude already configured internal or test accounts
from analytics; the identity is not then stored on the event. The
internal dashboard shows aggregate counts and rankings, not raw
individual navigation logs.
Interaction data is not used for behavioural advertising, is not
resold to third parties and is not disclosed for individual commercial
profiling.
6. Features, plugins and device services
- Google Sign-In, Sign in with Apple and Firebase Authentication may provide identity and contact data needed for the sign-in method chosen by the user;
- Firebase Cloud Messaging, Firebase Admin and Apple Push Notification service deliver push notifications and manage technical delivery tokens;
- Google Maps Platform and the Google Maps or Apple Maps apps may receive technical requests when the user displays maps or opens directions;
- the location feature uses operating-system permissions and calculates distances on the device; Time in Jazz does not store current location on its backend;
- the calendar plugin passes the event title, description, location and time to the system calendar only when the user chooses to add it; the app does not read or export the user's personal calendar;
- the store-review reminder uses local counters and, if the user accepts, opens App Store or Google Play; Time in Jazz does not receive the text or rating of reviews published in the stores;
- WebView and URL Launcher are used to show the Privacy Policy and to open websites, tickets, maps, email or other external links requested by the user;
- Shared Preferences, secure storage and local cache store settings, tokens and technical data needed for the app to work on the device.
7. Third-party services and recipients
Personal data may be processed by technical suppliers acting on behalf
of the Controller as processors, or in some cases as independent
controllers for their own ecosystem services. Depending on the actual
configuration, the app and backend may use Heroku or equivalent
platforms for hosting, PostgreSQL for databases, Firebase and Google
for authentication and push, Apple for sign-in, APNs and store
services, Google Maps Platform for maps, AWS S3 or equivalent services
for media and storage, Apple App Store and Google Play for
distribution, updates and reviews, and email providers if marketing
communications are activated.
Time in Jazz does not sell or resell personal data to third parties.
8. International transfers
Some technology providers may involve data processing or access outside
the European Economic Area. In those cases, the Controller adopts or
relies on safeguards required by applicable law, including adequacy
decisions, standard contractual clauses or equivalent mechanisms made
available by the providers involved.
9. Retention and deletion
- account, federated sign-in, saved-item, review and settings data: for the duration of the account and until deletion or user request, unless obligations or service-protection needs require otherwise;
- sessions, refresh tokens and push tokens: until expiry, logout, notification disabling, technical invalidation or account deletion;
- privacy acceptance evidence, marketing consent and administrative audits: for as long as needed to document choices, security and Controller accountability;
- analytics events not linked to the account and aggregate statistics: for the period needed for technical and organisational app analysis, then deleted or kept only in aggregate or anonymised form;
- technical and security logs: for periods proportionate to security, diagnostics, abuse prevention and service continuity;
- local device data: until the app is deleted, local data is cleared or the app technically replaces it.
Users may delete their account from the app or through the dedicated
account deletion web pages. Deletion removes data linked to the account
according to the technical database relations; statistics already
aggregated or anonymised do not identify the user.
10. Data subject rights
Users may exercise the rights provided by Articles 15 and following of
the GDPR, including access, rectification, deletion, restriction,
objection, portability and consent withdrawal, where applicable.
Consent withdrawal does not affect the lawfulness of processing
carried out before withdrawal.
Requests may be sent to
segreteria@timeinjazz.it.
Users may also lodge a complaint with the competent supervisory
authority.
11. Automated decisions
The app does not make decisions based solely on automated processing
that produce legal or similarly significant effects on the user. Usage
statistics are used for aggregate service analysis, not individual
decisions or commercial profiling.
12. Policy updates
This notice may be updated over time to reflect legal, organisational
or technical changes affecting the app. In case of relevant changes,
the Controller may require users to review and, where necessary, accept
the privacy version applicable to their user profile.