Privacy policy
Last updated: 13 September 2026
What we keep, why we keep it, and how to make us stop.
1. Who is responsible for your data
The controller of the personal data described here is Fieldfare OÜ ("Sipmate", "we", "us"), the maker of the Sipmate mobile app. You can reach us at support@fieldfare.cc.
Sipmate is a small independent project based in Estonia. This policy is written to meet the EU General Data Protection Regulation (GDPR) and the Estonian Personal Data Protection Act. It has not been reviewed by a lawyer; we will say so plainly rather than imply otherwise.
2. What we collect and why
- Email address. You sign in with a one-time code sent to your email. We use the address to authenticate you, to send those codes, and to answer you if you contact support.
- Date of birth. Used only to check you are old enough for the country you select and to work out your age. Your date of birth is never shown to anyone — other users see an age in years, nothing more.
- Country. Used to apply the right minimum age (21 in the United States, 20 in Japan and South Korea, 18 elsewhere).
- Profile content — display name, bio, photos, drink tags, vibe tags, intent. This is the part of Sipmate other people are meant to see. It is shown to other users nearby who meet the age rules, and to anyone you match with.
- Approximate location. When you allow it, the app sends your position to us and we store it as a single point, refreshed when you open the app. We use it only to work out who is nearby. Coordinates are never shown to other users — they see a distance rounded to about 100 m ("1.2 km", "<500 m"). You can use the app without location; you just won't get a useful list of people near you.
- Your tonight status. What you're drinking, an optional venue name (never an address), party size and time window. Shown to nearby users while it is active, then it expires by itself.
- Invites, passes, matches and messages. Needed to run the service: an invite is the cheers you send somebody and their answer to it, a pass decides who you see next, and messages are the conversation with your match.
- Blocks and reports. Who you blocked, and the reports you file (reason, optional details, who they concern). We use these to keep people safe and to act on patterns of abuse.
- Basic technical data. The usual server-side records that come with running an app: timestamps such as when you were last active, and short-lived request and error logs from our hosting provider.
We do not ask for your phone number, your address, your contacts, your photo library beyond the pictures you pick, or any identity document.
3. Legal bases
- Performance of a contract (GDPR Art. 6(1)(b)) — your account, profile, statuses, invites, passes, matches and messages. Without these there is no service to provide.
- Legal obligation (Art. 6(1)(c)) — age verification where local rules require it, and responding to lawful requests from authorities.
- Legitimate interests (Art. 6(1)(f)) — safety and abuse prevention (blocks, reports, hiding repeatedly reported profiles), keeping the service secure and working. We think these interests are ones you would expect and that they do not override your rights; you can object at any time (section 8).
- Consent (Art. 6(1)(a)) — location. You give it through the operating system's permission prompt and you can withdraw it at any time in your phone's settings, without affecting anything we did before you withdrew it.
4. What other people can see
Your display name, age, bio, photos, drink and vibe tags, intent, current status and a rounded distance. That is the whole list. Your email address, your date of birth, your exact location and your reports are never visible to other users. Blocking someone hides both of you from each other immediately, in both directions.
5. Who processes data for us
We keep the list of companies involved as short as we can. Today it is:
- Supabase — database, authentication and photo storage. This is where your account and content actually live.
- Expo — build and over-the-air update services for the app itself.
- Apple and Google — distribution of the app through the App Store and Google Play. They apply their own privacy policies to what they collect as distributors.
These providers act as processors on our instructions. Where a provider stores or accesses data outside the European Economic Area, that transfer relies on the European Commission's standard contractual clauses.
We do not sell your personal data, and we do not share it with advertisers. There is no advertising in Sipmate, and no third-party analytics or tracking SDK in the first release.
6. How long we keep things
- Your account and profile — for as long as your account exists.
- Messages — until you or the other person unmatches, or until either account is deleted, whichever comes first.
- Statuses — they expire on their own (a few hours to a few days).
- Reports — 12 months from the date of the report, so we can spot repeat behaviour. Reports about a deleted account are kept in a form that no longer identifies the person who filed them.
- Deletion requests — when you delete your account the data goes immediately from the live service, and within 30 days from backups.
7. Security
Everything travels over TLS. Data is stored in Postgres with row-level security, so the database itself enforces that you can only read your own row, the public parts of other people's profiles, and the messages in your own matches. Photos are held in a storage bucket where you can only write under your own prefix. Sign-in is a one-time code by email, so there is no password of yours for anyone to steal.
No service is perfectly secure. If a breach ever puts your rights at risk we will tell the Estonian Data Protection Inspectorate within 72 hours and tell you without undue delay.
8. Your rights
Under the GDPR you can ask us to:
- Access the personal data we hold about you, and get a copy.
- Correct anything wrong — most of it you can edit yourself in the app.
- Erase your data. Profile → Settings → Delete account does this yourself; see deleting your account.
- Restrict or object to processing based on legitimate interests.
- Port your data — receive what you gave us in a structured, machine-readable format.
- Withdraw consent for location, at any time, in your phone's settings.
Write to support@fieldfare.cc and we will answer within 30 days. There is no charge.
If you think we have got it wrong you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, www.aki.ee/en), or to the supervisory authority where you live.
9. Automated decisions
We do not make decisions about you by automated means with legal or similarly significant effects. One automated safety measure exists: a profile that receives three reports within 24 hours is hidden until a human looks at it. You can contest that by writing to us.
10. Children
Sipmate is for adults. You must be at least 18, and older where local law says so — 21 in the United States, 20 in Japan and South Korea. We do not knowingly collect data from anyone under those ages. If we learn that an account belongs to a minor we delete it. See our child safety standards, and tell us at support@fieldfare.cc if you believe a minor is using the app.
11. Changes to this policy
If we change this policy in a way that matters we will update the date at the top and tell you in the app before the change takes effect. The current version always lives at sipmate.fieldfare.cc/privacy.html.
12. Contact
Privacy questions, requests and complaints: support@fieldfare.cc.