In this Privacy Policy we explain what data we collect when you use “Vestal” (hereinafter, the “App” or the “Service”), how we use it, with whom we share it and what rights you have over it.
By using the App, you accept the practices described in this Policy. We recommend that you read it carefully.
The Service is intended exclusively for people over 18 years of age. If you are under that age, you must not use the App.
1. Data controller
The controller of your personal data is:
| Legal Name | Vestal |
|---|---|
| General and Support Email | vestal.theapp@gmail.com |
If you wish to contact the person in charge of privacy, you can write to the email indicated above.
2. Scope of this Policy
This Policy applies to all personal data that we process when:
- You use our mobile App (on iOS or Android).
- You interact with pages or resources linked from the App that relate to this Policy.
In this Policy, “user” refers to any person who accesses or uses the App.
In order to use the App, you must accept this Policy and provide us with those data that are essential to deliver the Service. If you decide not to accept an essential processing activity (such as creating your profile or publishing it), we will not be able to provide the Service.
2.1. User roles in Vestal
The App allows two main types of use, which determine what features are available and what data are visible to other users:
- Looking for a room (Applicant): Users who are looking for a shared home. They can apply to listed homes, view the profiles of current housemates in those homes, and send requests to join a household.
- Looking for a housemate (Housemate): Users who have an available room in a property and are looking for new housemates. This role includes both the main user of the home and existing housemates who decide to use the Service. These users can view applicants’ profiles when they apply to their property.
2.2. Home access code and visibility
When a user in the Housemate role registers a home in the App, the Service generates a unique home code associated with that property. This code allows other users to:
- Join that home as housemates (in this case, an additional PIN code may be required), and
- Send applications to join that home as Applicants.
Although the code is technically generated by Vestal, control over how it is used and shared belongs to the Housemate who registered the home. This user decides with whom they share the code and through which channels (for example, private messaging, social media or any other medium).
Vestal does not publish or communicate this code outside the App on its own initiative. We only process applications that arrive through a valid code that has been shared by the Housemate themselves.
In addition, when creating or managing a home, the Housemate will be explicitly asked whether they want their home to:
- Also be visible to other Applicants within the App (for example, in listings or exploration sections), or
- Not be generally visible, so that only users who have the code can access the home and/or apply to it.
The Housemate can change this visibility setting at any time from the home settings. If they unpublish the listing or change its status so that it is no longer available, the code will stop allowing new applications.
3. What data we collect about you
We organize data into categories to make it easier to understand. All information you publish is under your sole responsibility. Given the nature of the Service, we urge you to be cautious: any content you publish may become visible to other users.
| Category | What it includes |
|---|---|
| Account Creation Data |
|
| Profile Data* |
|
| Housing and Co-living Data* |
|
| User-generated Content |
|
| Activity Data |
|
| Technical and Device Data |
|
| App Usage Data |
|
| Communication Data |
|
| Approximate Geolocation |
|
* You can update this information at any time from your account, except for your date of birth and phone number, which cannot be modified.
4. What we use your data for and the legal basis
| Purpose of processing | Legal basis | Categories used |
|---|---|---|
| Providing the Service: creating an account, verifying age, enabling profile creation, using the Service | Performance of a contract | Account, Profile, Housing, Activity, Content |
| Displaying optional special-category data (gender identity) | Explicit consent | Profile |
| Applications and matching: showing profiles, displaying preferences about applications, enabling chat | Performance of a contract | Profile, Preferences, Activity, Content |
| Improving the App, fixing bugs, optimizing performance | Legitimate interest* | Technical, Usage, Activity |
| Protecting the platform: security, abuse, fraud | Legitimate interest* | Technical, Usage, Account |
| Basic functionality analytics | Legitimate interest* | Technical, Usage, Device |
| Service communications (operational notifications) | Performance of a contract | Account, Activity |
| Responding to your queries | Legitimate interest* | Communications |
| Complying with legal obligations | Legal obligation | Data required under applicable law |
Legitimate interest
Our legitimate interests include:
- ensuring security and preventing fraud and abuse
- improving the functionality of the Service
- obtaining internal metrics to make decisions based on real performance
These interests do not override your rights. You can object at any time (Art. 21 GDPR).
Special-category data
For gender identity, we ask for your explicit consent (Art. 9.2.a GDPR). You can withdraw it by removing that data or by contacting us.
Any sensitive data that you voluntarily publish in text fields or photos will be processed on the legal basis that you have manifestly made them public (Art. 9.2.e GDPR).
About matching
Vestal does NOT use automatic compatibility algorithms. You decide who you want to live with by manually reviewing other users’ profiles and preferences. The current housemates in your home can see others’ living preferences to assess applicants’ compatibility.
5. With whom we share your data
We never sell your personal data. We only share what is necessary to operate the App.
5.1. Other users
Your profile is visible to other users of the App in order to facilitate matching and co-living. The type of data and who can see it is summarised below:
| Type of data | Who can see it | Examples |
|---|---|---|
| Your personal profile | All users who can see your profile (e.g. homes you apply to, people you interact with in the App). |
|
| Your housing listing (if you have published one) | Users browsing or applying to your home, depending on the visibility settings you have chosen (code-only or also visible within the App). |
|
| Internal housemate information | Only current housemates of a given home. |
*This internal information is never visible to the applicant or to users outside that home. Internal deliberations regarding applicants are protected by the privacy of current tenants. |
| Data that are never shared with other users | No other users. Only Vestal (where necessary to operate the Service). |
Chat messages are visible only to the participants in that conversation and are never made public to the rest of the users of the App. |
Important: Do not share sensitive or personal information (such as bank details, exact address or identity documents) on your public profile, in descriptions or in the chat. Vestal is not responsible for any misuse of information that you choose to disclose voluntarily.
Note on geolocation: The App does NOT access your real-time GPS location. The area/neighbourhood shown on your profile or housing listings is solely the one you declare manually. Other users CANNOT see your exact address or your real-time location.
Important note on chats: Chats in Vestal are associated with properties, not with individual users. This allows the group’s communication history to be preserved even when housemates change. If you delete your account, your messages in chats of homes where you have lived will remain visible to current and future housemates of that property.
5.2. Service providers (data processors)
All of them act under contract in accordance with Art. 28 GDPR.
| Category | Provider | Purpose |
|---|---|---|
| Infrastructure and database | Firebase Cloud Functions | Backend and database hosting |
| Authentication, Notifications, Firestore | Google Firebase | Auth, DB, push notifications |
| Analytics | Google Analytics for Firebase | Usage metrics and events |
| SMS verification | Firebase Authentication | Sending verification codes |
5.3. Moderation, security and abuse
We may review profiles, photos or messages only when necessary to: investigate fraud or abuse, protect other users or comply with legal obligations. Access is strictly limited.
5.4. Legal authorities
We will share data when required by law, when we must respond to a court order or when we need to investigate fraud or abuse.
5.5. Corporate operations
In the event of a merger, sale or restructuring, your data may be transferred to the new entity under the same safeguards.
6. International transfers
Our providers may be located inside or outside the EU. Our main servers and databases are located in data centers within the EU. We ensure your protection through:
- Destinations covered by an adequacy decision; or
- Standard Contractual Clauses (SCCs) issued by the European Commission.
The case of Google/Firebase is covered through SCCs and additional safeguards.
7. Analytics and tracking technologies
The App does not use cookies, but it does use technical identifiers such as:
- Firebase Installation ID
- Device ID
- Firebase Analytics events
They are used exclusively to: improve stability, understand how the App is used and fix bugs. Never for advertising or commercial tracking. When legally required, we will ask for your consent before enabling non-essential analytics.
8. Push notifications
The App may send you push notifications to inform you about:
- New co-living requests in homes you manage
- Messages in the chat of your home
- Votes from your housemates about applicants
- Responses to your requests (accepted/rejected)
- Important service updates
- Reminders about scheduled visits
To receive notifications, the App will ask for your explicit consent the first time you use it. You can disable them at any time from:
- Your device settings (iOS or Android), or
- The App settings
Disclamer: The notification token is used solely for this purpose and is not shared with third parties for advertising purposes.
Legal basis: Consent (Art. 6.1.a GDPR) and performance of a contract for essential service notifications (such as new requests or messages from housemates).
9. Surveys, testimonials and collaborations
From time to time, we may invite you to participate in surveys, testimonials or marketing contributions. Your participation is voluntary. If you do not wish to receive these invitations, you can inform the data controller.
10. Data retention
- Account and profile data: as long as your account remains active.
- After deleting your account: your data will be blocked for 30 days in case of incidents or claims and, after that period, will be deleted or anonymised.
- Information for fraud prevention or bans: up to 2 years.
- Retention for legal reasons: up to 5 years.
If the user leaving was the sole owner/creator of a property listing, they must transfer ownership to another housemate or the listing will be removed.
For the sake of the integrity of a home’s history, chat messages associated with properties in which you have participated may remain visible to other housemates. The Service cannot guarantee the removal of personal data voluntarily included within the text body of messages sent to other users.
If you do not access your account for a continuous period of 12 months, we may delete it due to inactivity.
11. Underage users
The Service is limited to people over 18 years of age. We request your date of birth during registration and will delete any accounts that we detect belong to minors.
The Service implements reasonable measures to verify age, but cannot fully guarantee the truthfulness of the age declared by users.
12. Your rights
You can exercise the following rights under the GDPR:
- Access
- Rectification
- Erasure
- Objection
- Restriction
- Portability
- Withdrawal of consent
We will respond within a maximum period of 1 month.
📩 To exercise these rights, write to: vestal.theapp@gmail.com
You can also lodge a complaint with your local data protection authority. In Spain: AEPD
(www.aepd.es).
12.1. How to Delete Your Account
If you wish to permanently delete your Vestal account and all associated data, you can do so at any time by following the instructions on our dedicated page: Delete Your Account.
Once the deletion process is complete, your data will be removed from our servers as described in section 10 (Data Retention) of this policy.
13. Security
We apply appropriate technical and organisational measures, including:
- Encryption
- Internal access controls
- Monitoring
- Environment isolation
- Secure backups
No system is infallible, but we will act promptly in the event of any incident.
14. Changes to this Policy
We may update this Policy at any time. When there are important changes, we will notify you in the App.