Legal · Privacy
Last updated: May 27, 2025
Spotly ("we," "us," or "our") takes your privacy seriously. This Privacy Policy explains how we collect, use, share, and protect your information when you use the Spotly mobile app and website (together, the "Service").
By accessing or using Spotly, you agree to the terms outlined below. If you have questions, see Section 12 ("Contact Us").
When you sign up and use Spotly, you may choose to provide some or all of the following personal information:
Whenever you use the Service—whether on mobile or web—we automatically collect certain technical and usage data, including:
We use the information collected in Section 1 for all of the following purposes:
We do not sell your personal information.
We may share your data in the following scenarios:
We retain your personal data (profile, reservations, payment tokens) for as long as your account remains active. If you request deletion (see below), we'll delete or anonymize it unless we are required to keep it for legal reasons (e.g., tax records, fraud investigations).
We keep aggregated, cookieless analytics (via Vercel) indefinitely in a form that does not identify you. Raw logs (device tokens, IP addresses, crash reports) are retained for up to 12 months, then purged or anonymized.
For compliance with local regulations, we retain transaction receipts and billing records for at least 5 years (or as required by Macedonian law).
While we strive to protect your data, no system is 100% secure. If we become aware of a breach affecting your personal information, we will notify you within 72 hours (or as required by law).
We implement industry-standard safeguards to protect your data, including:
Depending on where you live, you may have the following rights regarding your personal data:
We only process your personal data where we have a valid legal basis to do so under applicable data protection law (including the EU General Data Protection Regulation (GDPR) and the Republic of Macedonia's Law on Personal Data Protection). Depending on the activity, we rely on one or more of the following bases:
[TO VERIFY WITH LEGAL COUNSEL: Confirm the specific lawful basis assigned to each processing purpose in Section 2, especially the boundary between consent and legitimate interest for analytics and personalization, and confirm this reflects your actual practices.]
To create and manage your account and to process the reservations, ticket purchases, and other transactions you request, we process your data because it is necessary to provide the Service you have asked for.
For optional activities—such as sending marketing emails, push notifications, location-based recommendations, and setting non-essential cookies—we rely on your consent. You can withdraw your consent at any time (see Section 9), without affecting the lawfulness of processing carried out before withdrawal.
To keep our platform secure, prevent fraud and abuse, analyze and improve the Service, and send service-related communications, we rely on our legitimate interests—balanced against your rights and freedoms. You may object to processing based on legitimate interests at any time.
To retain transaction and tax records and to respond to valid requests from competent authorities, we process your data to comply with our legal obligations.
We use limited automated processing to personalize venue and event recommendations based on your location, preferences, and past activity. These do not produce legal or similarly significant effects on you, and you can opt out of personalization in your settings.
Spotly is operated from the Republic of Macedonia. Some of our service providers (for example, AWS and Vercel for hosting, Vercel for cookieless analytics, and Stripe for payments) may store or process your personal data on servers located outside of Macedonia and the European Economic Area (EEA). For EU users, card payments are handled by Stripe Payments Europe, Ltd. (Ireland).
[TO VERIFY WITH LEGAL COUNSEL: Confirm the exact processing locations of each sub-processor (AWS, Vercel, Stripe, Casys, and any others) and the specific transfer mechanism—adequacy decision, SCCs, or other—in place for each, and ensure a signed Data Processing Agreement (DPA) is in place with each processor.]
Spotly is intended for adults. You must be at least 18 years old to create an account and complete transactions. We do not knowingly collect or maintain personal data from anyone under the age of 16 without verified parental or guardian consent, in line with applicable data protection law. If we discover that a person under this age has provided us with personal information without the required consent, we will promptly delete it.
[TO VERIFY WITH LEGAL COUNSEL: Confirm the applicable minimum digital-consent age under Macedonia's data protection law and ensure the age threshold is stated consistently across the Terms of Use (Section 2) and this Privacy Policy.]
We may update this Privacy Policy from time to time (e.g., to reflect new features or legal requirements). When we make material changes, we will:
If you have any questions, requests, or concerns about this Privacy Policy or Spotly's data practices, please contact us by email at support@myspotly.com, or through our website at myspotly.com/contact.
[TO VERIFY WITH LEGAL COUNSEL: Determine whether your processing activities require you to appoint a Data Protection Officer (GDPR Art. 37) and/or an EU representative (GDPR Art. 27). If so, add their contact details here.]