Privacy
Privacy Policy.
Last updated: October 2026 · How the FOMO Social app and brand console handle your data.
01 · Who we are
Who we are
This policy explains how Dealide Inc., a Delaware corporation ("FOMO Social", "we", "us", "our"), collects, uses and shares personal data in the FOMO Social mobile app for Android and iOS, on our website, thefomosocial.com, and in the FOMO Social brand console. Dealide Inc. is the controller of this data.
In the app, people discover events, buy tickets, share photos and videos as memories, Forts and stories, message friends and, through the FOMO Partner program, earn rewards from brands. In the brand console, brands and event organizers sell tickets, run events and campaigns, and buy FOMO points (100 points = $1) to reward people in the app.
Some services you can reach from FOMO Social, such as Ticketmaster checkout, Instagram and Stripe, have their own privacy policies, which apply to what you do there.
02 · What we collect
What we collect
What we collect depends on how you use FOMO Social. For each kind of data below, you'll find what it is, why we use it and, where laws such as the GDPR require one, the legal basis we rely on (explained in How we use it).
From people who use the app:
Account and profile
When you sign up: your name, email address, phone number, password, date of birth and gender. Later: your username, profile photo, bio, app language and privacy settings. We store your password only as a secure hash.
Why: To create and secure your account, sign you in, check that you're old enough to use FOMO Social, show your profile, and email you sign-in codes, tickets, event reminders and service notices.
Legal basis: Contract; legitimate interests (account security and age checks).
Your posts and content
Memories, Forts and stories you post, with their photos and videos and the sound recorded with them; captions and place tags; comments, likes, bookmarks, shares and reactions; and events you create in the app.
Why: To publish your content, show it to the people your settings allow, and let others interact with it.
Legal basis: Contract.
Messages
Direct messages, group chats (including event group chats) and the reactions and content you share in them. Messages are stored on our servers so they reach the people you're talking to; they are not end-to-end encrypted.
Why: To deliver your conversations.
Legal basis: Contract.
Friends and followers
Who you follow, who follows you, friends, follow requests, and the people you block or restrict.
Why: To build your feed, apply your privacy settings and blocks, and suggest people you may know from mutual follows.
Legal basis: Contract.
Events and activity
Events you RSVP to or hide your attendance from, reminders, organizer announcements you've read, and the people, events and places you search for. Searches are used to answer them and aren't saved to your account.
Why: To run these features, send reminders and suggest events and people you may like.
Legal basis: Contract; legitimate interests (relevant suggestions).
Location
If you allow it, the app uses your device's precise location while you're using it, never in the background: to show events and places near you and on the map, to suggest nearby places when you tag a memory, and to work out the city you're in. We use your position to answer each request and don't save it to your account, though like any request it can appear briefly in our server logs. We save only the city with your sign-in history, so you can spot a sign-in that isn't yours. A place you tag on a memory is saved with it and seen by whoever can see that memory.
Why: To show you what's around you, tag memories and help protect your account.
Legal basis: Your consent, given through the location permission, which you can withdraw at any time; legitimate interests for the sign-in city (account security).
Camera, microphone and photos
The app uses the camera only when you take a photo, record a Fort or story, take a ticket selfie or, as an organizer, scan tickets at the door; tickets are read on the device and only the ticket code is sent. It uses the microphone only while you record a Fort or story, so the video has sound. When you add photos or videos from your library, you pick them in your phone's photo picker and the app receives only what you pick. We upload only what you choose to post or send.
Why: To let you create and share photos and videos, and to admit guests at the door.
Legal basis: Your consent through the camera and microphone permissions; contract for what you post.
Tickets and payments
Tickets you buy, receive or claim, with the order details, ticket codes and check-in status, and the names and emails of any attendees you enter. When you pay, your card details go straight from the app to Stripe: we never see or store your card number. If the organizer requires it, we also collect a selfie for the door check and, if they ask for photo consent, a record of your consent (the wording, your name, email address, IP address, device details and the time).
Why: To sell and deliver your tickets, let organizers admit you, handle refunds and chargebacks, prevent fraud and keep financial records.
Legal basis: Contract; legal obligation (tax and accounting records); legitimate interests (fraud prevention, and letting organizers prove photo consent).
Ticket resale
Where ticket resale is available: your listings, offers, purchases, reviews, saved searches and watchlist. Sellers set up payouts with Stripe, which collects the identity and bank details it needs; we keep only a reference to your Stripe account and its status.
Why: To run resale, pay sellers and resolve disputes.
Legal basis: Contract; legal obligation (financial records).
FOMO Partner program
If you join Partner and connect Instagram, Instagram (Meta) shares with us, with your permission: your Instagram account ID, username, account type, follower and following counts, number of posts, your recent posts' captions, links, dates and like and comment counts, and insights such as reach and saves. We work out your engagement from these, and keep your Partner profile, points balances, the points you earn and the rewards you claim. Your Instagram access tokens are stored encrypted.
Why: To check campaign posts, credit points and rewards, show brands your creator stats and stop fake engagement.
Legal basis: Your consent when you connect Instagram (you can disconnect it at any time); contract for points and rewards; legitimate interests (fraud prevention).
Device, usage and crash data
Your device's name and ID, saved with your sign-in history; your push notification token; and the IP address and requests our servers log. Through Google Firebase, the app also sends analytics and crash reports. Firebase Analytics collects an app-instance ID, app opens, sessions, screen views and updates, your device model, operating system and app version, and an approximate location (country, region and city) that Google works out from your IP address. Crashlytics collects crash and error reports with device details, an installation ID and your numeric account number, never your name or email. Advertising ID collection and ad features are turned off. The Google Maps and barcode-scanning components also send Google basic device and performance data.
Why: To send notifications, show you where you're signed in, understand how the app is used, fix crashes and keep FOMO Social secure.
Legal basis: Legitimate interests (running, securing and improving the app); your consent for push notifications through the notification permission.
Reports, support and verification
Reports you send about people or content, with the reason and details, and reports others send about you; problems you report and messages you send us; verification requests (your full name, a link and a message); and Instagram handles you recommend to an event organizer, with your note.
Why: To keep FOMO Social safe, help you, review verification requests and pass recommendations to the organizer you sent them to.
Legal basis: Legitimate interests (safety and support); legal obligation where the law requires us to act on or keep a report.
If you give us someone else's details, such as an attendee's name and email or an Instagram handle you recommend, please make sure they're happy for you to share them.
From brand and organizer accounts:
- Account details — brand name, sign-in email, password (stored as a hash), contact name and phone, category, website, logo, cover image and description, plus the names, emails and roles of team members you add.
- Events and guests — events, ticket tiers, seat maps and announcements you create, and guest lists you enter (names, email addresses or phone numbers).
- Campaigns and wallet — campaigns, earning rules, rewards and claims, and your FOMO points wallet: top-ups, allocations and spending.
- Payments — you buy points through Stripe, which handles your card details; we keep the purchase records.
We use this to provide the brand console under our Terms (contract), to keep financial records the law requires (legal obligation) and to prevent fraud (legitimate interests).
03 · How we use it
How we use it
- Provide FOMO Social — your account, posts, messages, events, tickets, Partner rewards and the brand console.
- Keep people safe — enforce our Terms, review reports, prevent fraud, spam and fake engagement, and secure accounts.
- Talk to you — sign-in codes, tickets, reminders, the push notifications you allow, answers to your requests and important service notices.
- Improve the app — analytics and crash reports from Firebase.
- Meet legal obligations — tax and accounting records, lawful requests from authorities, and reporting child sexual abuse material to NCMEC.
Where the GDPR or similar laws apply, we rely on these legal bases:
- Contract — to provide the service you signed up for under our Terms.
- Legitimate interests — for security, safety, fraud prevention, analytics and improving the service, weighed against your rights.
- Consent — for device permissions (location, camera, microphone, notifications) and connecting Instagram. You can withdraw it at any time.
- Legal obligation — for financial records and reports the law requires.
We don't sell personal data, we don't show ads or build advertising profiles, and we don't use your personal data to train AI models.
05 · How long we keep it
How long we keep it
We keep your data while your account is open. You can delete a post, comment or story at any time. When you delete your account, we delete its data straight away (see Deleting your account), except for these records:
- Ticket orders and payment records — 7 years, for tax and accounting law and to handle refunds and chargebacks. They're kept without your identity: the buyer name becomes "Deleted user", and your email, phone number, attendee names and emails, and selfie are removed. Card details are held by Stripe, never by us.
- Photo-release consent records — as long as the ticket order they belong to (7 years), as proof that consent was given (the wording, the event and the time), with your name, email address, IP address and device details removed.
- Resale, payout and points records — 7 years, for tax and accounting law, payouts, fraud prevention and disputes. They keep amounts, dates, statuses and a numeric reference to your former account, but no name, email address or phone number.
- Reports — reports about people or content, including ticket-resale reports, are deleted 1 year after a moderator acts on them or dismisses them. Reports still waiting for review aren't deleted, and neither is a report whose child-safety evidence is still being kept. The reported content itself is deleted with your account, except child-safety evidence.
- Child-safety evidence — if you delete your account while it, one of your posts or comments, or a comment someone else left under one of your posts has a child-safety report on it (open or already closed), we first keep a copy of the reported content and the identifying details of the account that posted it (user ID, username, name, email address, phone number, date of birth and sign-up date), together with the report. If your account itself was reported, the copy also includes your profile photo and bio, and the posts and stories you shared in the 30 days before the report: at most 100 of each, newest first. Direct messages aren't copied. We keep the copy for 1 year after the deletion, then a daily job deletes it and its photos and videos.
- Organizer guest lists — if an organizer invited you, the name, email address or phone number they entered stays on their guest list, no longer linked to your account.
- Backups — backups taken before you deleted your account still contain your data until they're replaced, for up to 90 days.
- Server logs — 30 to 90 days, for security and troubleshooting. They can include your account number, IP address and the requests your app made.
- Service providers — keep their copies under their own retention schedules: Stripe keeps payment records (and your payout account if you resold tickets), Google Firebase keeps crash reports and analytics, and Resend keeps email delivery logs. Instagram keeps the connection you approved until you remove it in Instagram. Deleting your account doesn't send them a deletion request.
- Brand accounts — kept while the account is open; wallet and financial records are kept for 7 years to meet record-keeping obligations.
06 · Deleting your account
Deleting your account
You can delete your FOMO Social account and its data at any time, in the app or on the web. Deletion is immediate and permanent: there's no grace period, and a deleted account can't be restored.
- In the app — open the menu, tap Settings, then Delete Account (under Account). Tap "I want to delete my account", enter your password if asked, and tap "Delete forever".
- On the web — go to thefomosocial.com/delete-account. You don't need the app installed.
What we delete: your profile; memories, Forts and stories with their photos and videos; likes, comments, bookmarks and shares; your direct messages (for the other person too) and your group-chat messages; followers, following and blocks; notifications and sign-in history; events you created in the app; your Instagram connection, Partner profile, points and reward claims; and the rest of your account data. You're signed out on every device.
What we keep: ticket orders and payment records without your identity, photo-release consent records without your details, resale and points accounting records, reports, a copy of anything on your account reported for child safety, and guest lists organizers entered, for the periods in How long we keep it. Backups and server logs age out within 90 days.
Before you delete: nothing is cancelled or refunded. Your tickets leave your account; a ticket you saved to your wallet or got by email still scans at the door, but it no longer appears in any account. Points and rewards are lost. A group chat you created passes to the member who was added to it earliest. Brand and organizer console accounts are separate and aren't affected; to close one, email us.
To delete some data and keep your account, delete a memory, Fort or story from its menu, or disconnect Instagram in FOMO Partner > Connected accounts.
07 · Permissions and choices
Permissions and choices
The app asks for each permission before it first uses it. You can say no, or turn a permission off later in your phone's settings, and the rest of the app keeps working.
- Location (precise and approximate) — for nearby events, the map, place suggestions and your sign-in city. Without it, you can still search by name, but nearby results and the map won't be based on where you are, and your sign-in history won't show a city.
- Camera — to take photos, record Forts and stories, take ticket selfies and scan tickets at the door. Without it, you can still post from your photo library, but you can't book events that require a selfie or scan tickets.
- Microphone — only while you record a Fort or story. Without it, your videos record without sound.
- Photos and videos — you choose items in your phone's photo picker and the app gets only those. On Android 12 and older, the app may ask for storage access to read the files you pick.
- Notifications — push notifications about messages, followers, events and tickets. Turn them off in your phone's settings, or choose which ones you get in the app under Settings > Notifications. Without them, you won't get alerts, but everything still shows up in the app.
The app doesn't access your contacts, calendar, SMS, call log or other files, and it has no ads.
In the app, Settings > Privacy lets you make your account private, choose who can comment, who sees your event attendance and friends list, and whether people can find you in search; you can also block or restrict people. Partner members can disconnect Instagram at any time in FOMO Partner > Connected accounts. The app doesn't have a switch to turn off analytics or crash reporting.
08 · Your rights
Your rights
Depending on where you live, you have rights over the personal data we hold about you:
- Access — request a copy of what we hold.
- Correction — edit your profile in the app at any time, or ask us to fix anything else that's wrong.
- Deletion — delete your account in the app or on the web, or ask us to delete specific data, subject to the records we must keep (see How long we keep it).
- Portability — receive your data in a machine-readable format.
- Object / restrict — object to processing based on legitimate interests, or ask us to limit it, in certain cases.
- Withdraw consent — turn off a permission in your phone's settings or disconnect Instagram. This doesn't affect what we did before.
EU and UK residents have these rights under the GDPR and UK GDPR and can complain to their local data protection authority. California residents have rights under the CCPA / CPRA to know, delete and correct their data and to opt out of the sale or sharing of personal data; we don't sell it or share it for cross-context behavioural advertising. Residents of other US states with privacy laws have similar rights, and if we turn down a request you can ask us to reconsider. We won't treat you differently for using your rights. To use any of them, email privacy@thefomosocial.com.
We may need to confirm it's you first, for example by asking you to write from the email address on your account.
10 · Security
Security
- HTTPS (TLS) encryption for all traffic between the app, the website and our servers.
- Passwords are stored only as hashes, and Instagram access tokens are encrypted in our database.
- Optional two-step verification sends a code to your email each time you sign in.
- Card data is fully out of our scope — Stripe holds it under their PCI-DSS Level 1 compliance.
No system is invincible. If we detect a breach that affects you, we'll notify you without undue delay and within any timelines required by law.
11 · International transfers
International transfers
Dealide Inc. is based in the United States, and our servers and most of our service providers process data in the United States and other countries. If you use FOMO Social from outside the US, your data is transferred to the US, where privacy laws may differ from yours. When we transfer personal data out of the EU or UK, we rely on safeguards such as the European Commission's Standard Contractual Clauses.
12 · Children
Children
FOMO Social is not for children under 13. The app asks for your date of birth at sign-up, and our servers refuse to create an account for anyone under 13. Where local law sets a higher minimum age for consenting to online services, that higher age applies. Brand and organizer accounts must be run by someone who is at least 18.
We don't knowingly collect personal data from children under 13. If we learn that someone under 13 has an account, we delete the account and its data. If you think a child under 13 is using FOMO Social, report their profile in the app or email privacy@thefomosocial.com.
We explain how we protect minors from abuse and exploitation in our Child Safety Standards.
13 · Changes to this policy
Changes to this policy
We'll update this policy when our features or the law change, and the date at the top shows when it last changed. If we make a material change, we'll tell you before it takes effect: app users in the app or by email, and brand account owners by email at least 30 days ahead. Minor edits, such as typo fixes and clarifications, we'll simply publish with a new date.
14 · Contact us
Contact us
Questions, requests, or want to know what we hold about you? Dealide Inc. is the controller of your data. Reach out:
- Email: privacy@thefomosocial.com
- Child safety: safety@thefomosocial.com
- Postal: Dealide Inc., 1606 Headway Cir STE 9766, Austin, TX 78754, USA.
We aim to respond within 30 days, faster where the law requires it.
