Last updated: May 9, 2026
Effective: 9 May 2026
Which version of the Black Planet app do you have?
- Version 2.0 or newer (the rebuilt app, available from May 2026): the policy below applies to you.
- Version 1.x (the previous app): see our previous Mobile App Privacy Policy.
If you’re not sure which version you have, check on your phone:
- iPhone: Settings → General → iPhone Storage → Black Planet. The version number is shown at the top of the app’s storage page.
- Android: long-press the Black Planet app icon → App info → scroll to the bottom (the version is shown under “App details” or similar, depending on your phone manufacturer).
This policy applies to version 2.0 and later of the Black Planet mobile app for iOS and Android. For data practices on our website (blackplanet.se), see our main privacy policy. For cookies set on the website, see our cookie policy.
Some of these website cookies may also be set inside the app whenever you open an event detail page, the in-app online community page, the privacy or terms pages, or use the “Go to blackplanet.se” link, these are the same cookies described in the website cookie policy.
The two privacy policies are consistent; this one focuses on data handled inside the mobile app specifically.
You can read the privacy policy of version
Data controller
Black Planet, represented by Reza Iranpour Mobarakeh, is the responsible party (controller) for the data we collect and process through the Black Planet mobile app.
Reza Iranpour Mobarakeh
Duvholmsgränd 16, Skärholmen, 127 41
Email: [email protected]
Application permissions
The app requests the following permissions on your phone. You can review or revoke any of them in your phone’s system settings at any time.
- Internet access (essential): required for the app to talk to our servers, fetch your membership profile, your tickets, and resale data.
- Notifications (recommended, can be disabled): required only if you want to be notified when someone replies to your Resale conversation, when crew responds in Emergency chat, or for occasional event announcements relevant to clubs you’ve marked as interesting. The app works without this permission; you simply won’t receive pushes.
- Storage / photo access (when used): requested only at the moment you choose to attach a photo to a Resale or Emergency chat message. The app does not browse, scan, or read other files on your device.
The app does not request access to your camera, microphone, contacts, calendar, precise location, health data, or any other system permission.
What this app does
The Black Planet app is the official member companion app for Black Planet, a community around alternative club nights. Membership is free. Through the app you can:
- Show your membership QR code at the door
- Browse upcoming events and pick up tickets on blackplanet.se in a browser tab.
- View tickets you have purchased, with QR codes ready to scan
- Resell tickets you cannot use, or buy sold-out tickets from other members
- Reach Black Planet crew during events through Emergency chat
- Manage your profile and preferences.
- Sign up for new membership and account
Data we collect through the app
When you sign up for membership, the app collects:
- Your email address (used to send sign-in magic links and to identify your account)
- Your name (used on your membership card and shown to crew)
- Your date of birth (used to verify you are 18 or older — required for Black Planet membership)
- The Black Planet clubs you say you are interested in (used to send you relevant event announcements)
When you use the app day-to-day, we additionally process:
- A push-notification token (a random identifier from OneSignal that lets us notify your device, never your real name or email)
- Your ticket history and resale activity (managed on our portal at my.blackplanet.se)
- Messages and any photos you upload in Resale or Emergency chat conversations
- Approximate device type (iOS / Android) and app version, for diagnostic purposes only
- A log of important actions you take (signing in, updating your profile, listing or buying a ticket on Resale, requesting account deletion). Used for security investigations and dispute resolution. Kept for 2 years from the date of the action, then permanently deleted.
We do not collect:
- Your phone’s contacts, photos library, microphone, camera, or precise location
- Tracking data for advertising purposes
- Any content from messages or attachments for purposes other than delivering them in the conversation you sent them in
Information collected automatically
In addition to the data you provide, the app and our servers process some technical information automatically when you use the app:
- Your device type (iOS or Android)
- Your phone’s operating system version
- The version of the Black Planet app you’re running
- Your IP address (used for transit and connection only — we do not log it for analytics or attempt to map it to a precise location)
- Aggregated, anonymous usage information that helps us diagnose crashes and slowdowns (e.g. which screen had a problem, not what you typed on it)
This information is used solely to keep the app working, fix bugs, and plan improvements. It is not used for behavioral advertising or shared with marketing partners.
How we sign you in
The app does not use passwords. To sign in, you enter your email address and we send you a single-use magic link via email (delivered through Postmark). Clicking that link signs you in.
If you used Apple Hide My Email or another email-relay service, the magic link is delivered to that relay address and forwarded to your real email by the relay provider. If you later deactivate the relay, you will be unable to sign in until the email address is updated — contact [email protected] for assistance.
Member-to-member ticket resale
Through the Resale tab, you can list event tickets you cannot use for sale to other members, or browse what other members are selling.
What other members can see when you list a ticket:
- Your member display name (names are editable in your profile)
- The event, ticket tier and price
- The status of your listing (open, in discussion, sold)
What other members cannot see:
- Your phone number or Swish details
- Your date of birth
When a buyer contacts a seller, the messages exchanged are stored on our portal servers (my.blackplanet.se) for the lifetime of the listing plus 12 months after the listing closes (sold, withdrawn or expired), then permanently deleted.
You can attach photos or files to messages in Resale chat. Attachments are visible only to participants of the conversation and are automatically and permanently deleted 30 days after upload, regardless of whether the conversation is still active.
Resale payments are made directly between buyer and seller using Swish or another peer-to-peer service. Black Planet does not process, hold, or store payment information for resale transactions and is not a party to the payment exchange.
Emergency chat
The Emergency chat feature in the More tab connects you to Black Planet crew during events. The chat itself runs on our self-hosted Chatwoot instance at livechat.blackplanet.se.
When you start a chat, the app automatically sends Chatwoot:
- Your member identifier (a stable internal account ID)
- Your email address
- Your display name
This is so crew can identify you and respond without you having to retype your details mid-conversation.
Conversation transcripts are stored on our own servers and retained for 24 months from the close of the conversation, after which they are permanently deleted. We may retain transcripts longer in exceptional cases (active investigation of a safer-spaces incident, ongoing legal matter, regulatory request).
You can attach photos or files to messages in Emergency chat. Attachments follow the same retention as the conversation transcript.
For genuine life-threatening emergencies, always dial 112 (or the local emergency number where you are). Emergency chat in the app is for non-life-threatening contact with our crew during events.
Push notifications
If you grant notification permission, the app uses OneSignal to send you pushes for:
- New messages in Resale conversations you are part of
- Replies in Emergency chat conversations you opened
- Status changes on a Resale listing (interest expressed, payment marked, ticket transferred, conversation closed)
- Occasional event announcements relevant to the clubs you have marked as interesting
Lock-screen notification text is intentionally vague. We never include the content of a message, the name of an event, the name of another member, or any payment detail on the lock screen. Specifics are visible only after you open the app.
You can disable push notifications at any time:
- In your phone’s system settings: revoke notification permission for Black Planet
OneSignal receives a randomly generated push token (used to target your device) and the canonical names of clubs you said you were interested in (used to send you relevant event-specific pushes without revealing who you are). It does not receive your real name, email or any chat content.
How we use your personal data
We process your personal data only for the following purposes:
- To authenticate you via magic link, so you can sign in without a password.
- To display your membership card and QR code at events, so door staff can confirm your membership without a paper card.
- To show your purchased tickets with QR codes for entry to events.
- To run the Resale feature — listing tickets you can’t use, browsing tickets others have listed, conversing with the other party, and transferring a ticket once a sale closes.
- To run Emergency chat — connecting you to Black Planet crew during events without you having to retype your details mid-conversation.
- To send you relevant push notifications — chat replies, listing updates, and occasional event announcements for clubs you’ve said you’re interested in.
- To investigate security incidents and resolve disputes — for example when a Resale transaction goes wrong or a member reports a safer-spaces concern.
- To comply with legal obligations, including Swedish accounting law that requires us to keep ticket-purchase records for seven years.
- To improve the app via aggregated, non-identifying diagnostic data.
In-app web browser
Several features, Resale listing browsing, Emergency chat, the in-app links to our website and policies, open content from blackplanet.se, my.blackplanet.se or livechat.blackplanet.se inside an in-app web browser. The native screens of the app do not use cookies, but these in-app browser views handle cookies the same way a normal web browser would, including:
- Session cookies that keep you signed in across in-app browser windows
- Functional cookies set by Chatwoot for the live-chat experience
- Cookies set by blackplanet.se for site analytics
You can clear cookies for the in-app browser at any time using your phone’s app settings:
- iOS: Settings → Black Planet → Reset / Clear app data
- Android: long-press the app icon → App info → Storage → Clear cache
We do not place advertising or tracking cookies inside the native mobile app screens..
Third-party processors used by the app
We use the following service providers to operate the app. Each processes only the minimum data needed for its function and is bound by contractual data-protection terms:
- Supabase (Supabase Inc., USA, with data hosted in the EU region) — authentication and account database. Stores your email address and account identifier; does not see payment data. Privacy policy
- Postmark (ActiveCampaign LLC, USA) — transactional email delivery, including the magic-link emails that sign you in. Privacy policy
- OneSignal (OneSignal Inc., USA) — push notification delivery to your device. Receives only your push token and a few non-personal tags (interested clubs, app version). Privacy policy
- Chatwoot — self-hosted on our own servers at livechat.blackplanet.se. Powers Emergency chat. Because we host Chatwoot ourselves, your chat data is not transferred to a third-party operator. Software project
- IDrive e2 (IDrive Inc., USA, data hosted in the EU region) — S3-compatible object storage. Holds photo attachments uploaded in Resale chat for 30 days, after which files are permanently deleted. Files are accessed only via our portal with re-authentication of the requester on every request; the bucket itself is private. Privacy policy
- Vercel (Vercel Inc., USA) — application hosting and edge delivery for the my.blackplanet.se portal that the app talks to. Vercel processes requests in transit; it does not have access to our stored database or your messages. Edge points of presence may serve static assets from EU regions when geographically closer. Privacy policy
- Swedbank Pay — payment processing for primary ticket purchases on our website. Note: Resale payments between members are NOT processed through Swedbank Pay; those go directly between buyer and seller via Swish. Privacy policy
- Google Play Services (Google LLC, USA / Google Ireland Ltd) — Android operating-system services that the app uses passively for app distribution, automatic updates from the Play Store, and Android-level integrity checks. Receives device-level diagnostic signals collected by the Android OS, not application content. Privacy policy
When and with whom we share your data
We share your personal data only in the following situations:
- With our service providers — the third parties listed in the previous section, each contractually bound to use your data only for the function we engaged them for.
- With other Black Planet members, in Resale conversations — only your member display name is visible to the other party. Your real name (unless you set it as your display name), email, phone number and Swish details are never exposed by Resale.
- With Black Planet crew, in Emergency chat — when you start a chat, crew sees your member display name and email so they can identify and respond to you. Crew members are bound by Black Planet’s confidentiality and safer-spaces policies.
- For legal compliance — see the next section.
- For business transfers — if Black Planet ever merges with, is acquired by, or sells assets to another entity, your data may be transferred as part of that transaction. The acquiring entity would be bound to the same privacy commitments described in this policy.
- With your explicit consent — for any other purpose, only after we ask you and you say yes.
We do not sell your personal data, exchange it with data brokers, or use it for cross-context behavioral advertising.
Disclosure when required by law
We may disclose your personal data when we believe in good faith that doing so is necessary to:
- Comply with a court order, subpoena, lawful police request, or other legal process
- Investigate suspected fraud or harm to Black Planet, our members, or third parties
- Protect the safety of any person — for example, in response to a credible threat
- Enforce our community guidelines or terms of use
Where we are not legally prohibited from doing so, we will notify you if your data is being requested by an authority before we disclose it.
Security
We take reasonable technical and organizational measures to protect your personal data against unauthorized access, loss, alteration or disclosure:
- All connections between the app and our servers use HTTPS / TLS encryption in transit.
- Account data in our Supabase database is encrypted at rest in the EU region.
- Resale chat photo attachments are stored in a private, access-controlled S3 bucket and are never exposed via direct URLs — every download requires a fresh re-authenticated request from our portal.
- Only a small number of authorized Black Planet crew members have administrative access to member data, and that access is logged.
- Magic-link sign-in tokens are single-use and expire on a short timer.
No system can guarantee absolute security against a determined attacker. If we ever discover a breach affecting your personal data, we will notify you and the Swedish Data Protection Authority (IMY) within 72 hours of becoming aware of it, in accordance with GDPR Article 33.
Where your data is stored
Your data is stored in different locations depending on which feature it relates to:
- Main blackplanet.se website + the WordPress members database — on a Netcup VPS in Germany.
- Our self-hosted Chatwoot instance (Emergency chat) — on the same Netcup VPS in Germany.
- The my.blackplanet.se portal application (Resale conversations, ticket data, account session management) — hosted on Vercel. Vercel’s edge points of presence may serve static content from EU regions for faster delivery.
- Authentication accounts and profile data — Supabase EU region.
- Resale chat photo attachments — IDrive e2 S3 storage (US company, data hosted in Ireland region).
- Push tokens and notification delivery — OneSignal (United States).
- Email transit for magic-link sign-in — Postmark (United States).
The international transfer safeguards we apply are described in the next section.
International data transfers
Some of our service providers (Postmark, OneSignal, IDrive e2, Vercel) are based in the United States. Where personal data is transferred from the EU to the US, the transfer is protected by Standard Contractual Clauses adopted by the European Commission, and where the provider is certified, the EU-US Data Privacy Framework. You can request copies of these safeguards by emailing [email protected].
Legal basis under GDPR
We process your personal data on the following legal bases:
- Performance of contract (Art 6.1.b) — to provide the membership, ticket and resale services you signed up for
- Legal obligation (Art 6.1.c) — Swedish accounting law requires us to keep purchase records for 7 years
- Legitimate interests (Art 6.1.f) — to protect the service from abuse, investigate security incidents, and resolve disputes; the scope of this processing is minimised to what’s necessary
- Your consent (Art 6.1.a) — for push notifications. You can withdraw by turning notifications off in your phone’s system settings
Automated decision-making
We do not subject you to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects. Membership status, event entry, ticket transfers and resale outcomes always involve human review where any judgment is required.
Users under 18
Black Planet membership is restricted to users 18 and older. We do not knowingly collect personal data from anyone under 18.
We verify age at signup (your date of birth is required, and the app rejects sign-ups under 18) and at events (door staff may check ID).
If we discover that an account belongs to someone under 18, we will close the account and delete the associated personal data. If you believe a child has shared data with us, please contact [email protected] so we can take action quickly.
How to download your data
You can download your data in the app: More / Settings / Download my data
You can also download your data via portal on web: my.blackplanet.se/dashboard/settings → “Download my data”
How to delete your account
You can permanently delete your Black Planet account at any time:
- In the app: More → Settings → “Delete account”
- On the website: my.blackplanet.se/dashboard/settings → “Cancel membership”
- By email: [email protected] with the subject “Delete my account”, sent from the email address on file
Deletion immediately removes the following from our active systems:
- Your name, email address and date of birth
- Your interested-club preferences
- Your push-notification token (you stop receiving notifications)
Some data is retained for the retention windows stated above:
- Resale conversation transcripts: 12 months from listing close, even after account deletion, so the other party still has dispute-resolution access if needed
- Emergency chat transcripts: 24 months from conversation close, for safer-spaces incident review
- Backups: a rolling 30-day window during which deleted data still exists in encrypted backups before being purged
- Orders and tickets data: kept for 7 years for bookkeeping purposes.
If you used Apple Hide My Email or another relay service, deleting your account does not deactivate the relay, that’s done in your Apple ID settings separately.
Your rights
You have the right to:
- Access the personal data we hold about you
- Correct any inaccurate data
- Delete your data (see above)
- Object to or restrict certain processing
- Data portability — receive your data in a machine-readable format
- Lodge a complaint with the Swedish data protection authority (Integritetsskyddsmyndigheten — IMY, imy.se) if you believe we have mishandled your data
To exercise any of these rights, email [email protected] from the address on your account.
If you believe we have mishandled your personal data, please first contact us at [email protected] so we can try to resolve the matter directly.
You also have the right at any time to lodge a complaint with the Swedish Data Protection Authority (Integritetsskyddsmyndigheten — IMY), the supervisory authority for data protection in Sweden:
- Website: imy.se
- Email: [email protected]
- Postal address: Integritetsskyddsmyndigheten, Box 8114, 104 20 Stockholm, Sweden
Your consent
By installing and using the Black Planet mobile app, you consent to the processing of your personal data as described in this privacy policy. Where the legal basis for a specific processing activity is your consent (for example, push notifications), you can withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal:
- For push notifications: revoke notification permission in your phone’s system settings, or open the app → More → Settings → toggle “Push notifications” off.
- For all other consent-based processing: email [email protected] stating what you wish to withdraw consent for.
If you no longer agree with this policy, you can stop using the app at any time and delete your account using the methods described under “How to delete your account”.
Changes to this policy
We may update this policy as the app evolves.
The “Last updated” date at the top reflects the most recent revision.
Contact us
Questions about this policy or your data:
- Email: [email protected]
- Subject line for fastest routing: “Privacy” or “Data request”
For our main privacy policy covering use of blackplanet.se in a web browser, see blackplanet.se/privacy.
