Privacy Policy for RateMe

Last updated: November 30, 2025

This Privacy Policy describes how PDC Software AS ("we", "us", "our") collects, uses, and protects personal data when you use the RateMe mobile application ("the App").

We act as the Data Controller in accordance with the EU General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act.

1. Who We Are

PDC Software AS

Organization number: 931 228 137

Registered address: Welhavens gate 21, 0350 Oslo

Email for privacy inquiries: support@pdcsoftware.no

2. Where This Policy Applies

This Privacy Policy applies to the App and any websites, events or services we operate under the Rate Me brand. For clarity, these are referred to as our "Services". If a specific Service uses a separate privacy policy, that will apply instead.

3. Information We Collect

We collect information to provide meaningful connections and interactions in the App. This includes data you provide, data generated during use, and data from third parties.

3.1 Information you provide

When you create an account and use the App, you provide certain information, for example:

  • Phone number and email address when registering
  • Name, age or date of birth, and your profile preferences (such as the age range or general location of the people you wish to see)
  • Profile pictures and other content you choose to upload
  • Payment details if you subscribe or purchase features (via e.g. RevenueCat)
  • Information when you contact customer support, or participate in surveys/promotions

Although we require users to provide their name and age during registration, this information is used solely for internal processing, safety purposes, and matching logic. It is never displayed on your public profile.

3.2 Information we receive from others

We may receive information about you from:

  • Other users (for example if they report you)
  • Social media accounts you connect or upload from (e.g., using Apple Sign-In, or if the user chooses to link their account)
  • Partners or advertisers (for example when you interact with ads)

3.3 Information we automatically collect

When you use the App, we gather technical and usage data, including:

  • Device and network information (IP address, device ID, OS version)
  • Usage information (features used, timestamps, interactions with other users)
  • Cookies, SDKs or similar technology to recognise devices or browsers
  • If you consent, precise or approximate geolocation data
    • Location permissions can be changed at any time in your device settings, and the Service continues to function with reduced accuracy even if location access is disabled
  • We do not use your data for cross-app or cross-site tracking unless you explicitly consent through your device's tracking permissions

4. How We Use Your Information

We use your data for a variety of purposes, including:

4.1. Provide and manage your account and the Services

  • Create and manage your account
  • Provide customer support and respond to your requests
  • Communicate with you about updates or your account

4.2. Enable connections with other users

We require your name and age during registration for internal verification and matching logic, but this information is never shown to other users.

We process your information to help you discover and interact with other users while maintaining a minimised and privacy-aware profile format.

Only your profile photo(s) are shown to other users. Your name, age and other personal details are not displayed on your public profile. However, users may indirectly infer certain attributes—such as your broad age range or general location—based on the filters and categories they select (for example, viewing "people aged 18–24 in Oslo").

We use your selected preferences (e.g., age range, distance, location category) to:

  • Display other users' profile photos that match your chosen filters
  • Allow you to browse and interact with relevant profiles
  • Recommend profiles that align with your selections and usage patterns
  • Adjust recommendations over time based on how you use the Service

This processing is necessary to provide the core functionality of the App while limiting the visibility of your personal data to only what is essential.

4.3. Offer new features and complementary services

  • If we launch new apps or extensions, we may use your data for onboarding

4.4. Marketing and advertising

  • Run and measure campaigns to promote our Services
  • Send you offers and communications if you have consented

4.5. Improvement and development of Services

  • Conduct surveys or focus-groups
  • Analyse usage patterns to enhance user experience
  • Test features and optimise performance

4.6. Safety, fraud prevention and compliance

  • Detect and prevent misuse, abuse, fraud or illegal activity
  • Enforce our Terms of Use and protect the rights of our users
  • Fulfil legal obligations and cooperate with authorities

4.7. Legal basis for processing

  • Contractual necessity: to provide the Service to you
  • Legitimate interests: for marketing, safety, service improvement
  • Consent: for special categories of data (e.g., precise location)

5. How We Share Your Information

We share your personal data under the following circumstances:

5.1 With other users

Your profile information name and age is not visible to other users, only profile pictures are visible. You choose what to share and can adjust settings accordingly.

5.2 With service providers and partners

We engage third-party providers who assist us in hosting, analytics, support, marketing, payments, and security. They handle your data under contract and confidentiality obligations.

We impose strict contractual, technical, and organizational requirements on all of our service providers to ensure that personal data is processed securely and in full compliance with GDPR. All processors are bound by confidentiality obligations, data protection agreements and are regularly assessed to ensure ongoing compliance with our standards.

These processors include (but are not limited to):

  • Firebase (hosting, authentication, analytics)
  • Vercel (infrastructure and hosting)
  • RevenueCat (subscription and purchase management)
  • Apple (authentication via Sign in with Apple)

We do not sell your personal data to any third party.

5.3 With affiliated companies

We may share data within our corporate group for operational and security purposes, such as preventing users banned on one platform from re-joining.

5.4 With your consent

We may ask you to agree to share specific data with third parties (e.g., for additional features). You can withdraw consent at any time.

5.5 For legal reasons

We may disclose your data to comply with legal obligations, to protect users, or to defend our rights.

6. International Transfers

Some of our service providers are located outside the EU/EEA, including in the United States. This means that your personal data may be transferred to or processed in countries that may not offer the same level of data protection as the EU/EEA.

For transfers to the United States:

  • Google/Firebase participates in the EU–US Data Privacy Framework (DPF) and is certified under this mechanism, which provides an approved legal basis for transfers under GDPR.
  • For other providers located in the United States, such as Vercel Inc., RevenueCat Inc., and Apple Inc., we rely on Standard Contractual Clauses (SCCs) combined with additional technical and organizational safeguards, including encryption, access controls, and strict contractual obligations.

These measures ensure that your data remains protected and that transfers comply with Articles 44–49 of the GDPR.

7. Your Rights

  • Uninstallation. You can stop an app from collecting information by uninstalling it using your device's standard uninstallation process. Please note that uninstalling an app does NOT close your account. To close your account, you must use the account deletion functionality provided within the Service.
  • Account closure. You can close your account by using the account closure feature directly within the Service.

Under GDPR you have rights including:

  • Accessing a copy of your data
  • Rectifying inaccurate information
  • Erasing your data ("right to be forgotten")
  • Restricting processing
  • Objecting to profiling
  • Data portability
  • Withdrawing any consent given

You can exercise these via the App contact form or by contacting: hei@pdcsoftware.no

You have the right to complain with your local supervisory authority, such as the Norwegian Data Protection Authority (Datatilsynet).

To protect you and all our users, we may ask you to provide identification before we can respond to the above requests. Please note that we may refuse requests, for example if we are unable to verify your identity, if the request is unlawful or invalid, or if fulfilling it would infringe trade secrets, intellectual property, or the privacy and rights of others.

8. Data Retention

We retain your data only as long as necessary for business or legal purposes:

  • Account data: while your account is active.
  • Deleted accounts: Some account data is stored for up to 3 weeks after deletion.
  • Location data: Up to 30 days.
  • Usage logs: Up to 12 months.
  • Records of consent: Up to 3 years after deletion.

We retain different types of data for different amounts of time to balance your privacy with our need to operate a safe, reliable, and legally compliant Service. The retention periods are based on industry practice and GDPR's principle of storage limitation.

Account data is kept while your account is active so that you can use the Service normally. Inactive accounts are removed after a period of time to reduce data we store and to prevent abandoned profiles from being misused. Location data is kept only for a short period (up to 30 days) because it is sensitive and only needed to provide accurate matching and safety features. Technical and usage logs are stored for a limited time to detect fraud, investigate misuse, maintain security, and diagnose issues that may occur after your session has ended. Records of consent are kept for a longer period so we can demonstrate compliance with GDPR if a user or supervisory authority requests documentation. Once the retention periods expire, the data is either deleted or irreversibly anonymised.

9. Minors

Our Services are intended only for persons aged 18 or older. If we become aware that a user under 18 has registered, we will remove the account and delete the data.

We do not knowingly collect or process data from individuals under 18, and we use automated and manual measures to detect and remove underage accounts.

10. Changes to This Privacy Policy

We may update this policy from time to time. If we make significant changes we will notify you via the App or email and publish the new version.

11. Contact Us

If you have questions about this Privacy Policy:

PDC Software AS

Email: support@pdcsoftware.no