Privacy Policy
What Parmo collects, why, who processes it, how long it is kept, and how to get it deleted.
Version 1.6 · in effect since 1. Okt. 2026
Who we are
RAVEMANIA, Nicolas Palfi ("Parmo", "we") operates the Parmo website at https://parmo.io and the Parmo mobile app. Our registered address is Tersteegenstraße 15, 40474 Düsseldorf, Deutschland. For everything described here we are the data controller.
Privacy questions, access requests and complaints: privacy@parmo.io. We answer within 30 days.
Parmo connects event organizers with creators. Organizers brief a campaign; creators post an Instagram story about it; Parmo checks that the story went up and stayed up, and releases the reward when it did. Almost everything below follows from that one loop.
What we collect
We collect only what a described purpose needs. Nothing in this list is bought from a data broker, and nothing is inferred about you beyond what the table says.
| Data | Where it comes from | Why we have it |
|---|---|---|
| Email address, password | You, at sign-up (or Apple/Google if you use social sign-in) | Your account and sign-in. Passwords are stored only as salted hashes by our auth provider; we never see them. |
| Display name, first and last name, gender, public handle, city, birthdate | You, in your profile | Your profile, identifying you to the other side of a booking, showing events near you, and confirming you are 18 or older. |
| Approximate device location (latitude and longitude) | Your device, only after you grant the permission | Sorting the event feed by distance. Declining the permission costs you distance sorting and nothing else. |
| Approximate city of your internet connection (a city name and its centre point, derived from your IP address by our hosting provider) | Your request, only while you are signed in as a promoter and have not set a city | Choosing where the event feed starts, marked "(approx.)" on screen. Used for that one request and never stored; set a city or pick another place in the feed and it is no longer used. |
| Instagram data: your Instagram profile and follower count, daily account statistics, where and when your audience is, your recent posts, the stories you post for a gig with their statistics and our copy of them, and an access token | The Instagram API, only after you connect your account, and only for the account you connected | Each item is listed below under "Instagram data", with the permission it comes from, why we have it, who can see it and how long we keep it. |
| Campaign and booking records: which campaigns you applied to, were invited to or completed, the reward agreed, deadlines, screening answers | Your use of Parmo | Running the marketplace and settling rewards. |
| Uploads: event flyers, brand assets, reward artwork, and any file you attach to a dispute | You | Showing the campaign, and letting a person settle an argument about a reward. |
| Payment data: none today | Nobody: Parmo processes no payments | Rewards on Parmo are guest-list spots, drinks and similar, handed over at the event. No money moves through Parmo and we collect no card, bank or payout details. If paid rewards launch, Stripe will process them, and this policy will say so before that happens. |
| Reports you file about an event, a campaign or a profile (the reason and an optional note), and the accounts you block | You | Moderation, and keeping someone you blocked away from you. |
| Ratings and written feedback between an organizer and a creator, and any dispute you raise | You and the other party to a booking | Trust between strangers, and resolving disagreements about a reward. |
| Push notification tokens and web push subscriptions | Your device, after you allow notifications | Sending the notifications you turned on. Nothing else is read from your device. |
| Email we send you, and email you send to a campaign inbox: recipient, subject, delivery status, and, for inbound mail, the message and its attachments | Us, and you | Delivering tickets and reward codes, proving what was sent, and forwarding what an organizer sends to a campaign address. |
| Referral code and who invited whom | You, when you share or enter a code | Crediting invites. |
| Product usage signals: whether you chose the list or the map view, which guided tours you have seen, server logs of requests including IP address and user agent, and error reports when something breaks (the error, the page or screen, your browser or app and system version) | Your use of Parmo | Keeping the service up, investigating abuse and faults, and deciding which of two views to open by default. Not used to build advertising profiles. |
| Product analytics events: which step of a flow you reached (for example connecting Instagram, accepting a gig, posting a story), the page or screen it happened on, record identifiers such as the event or campaign involved, and, once you are signed in, your account’s internal identifier, role and city. On the website also each page you view (its address) and when you leave it; in the phone app also when the app is opened, sent to the background, installed or updated. Never your name, email, handle, coordinates or anything you typed | Your use of Parmo | Seeing where people get stuck so we can fix it. Not used to build advertising profiles and not shared with anyone else. On the website a signed-out visitor is anonymous and not recognised from one page load to the next. The phone app sends these events whether or not you are signed in, under a random identifier it keeps in its own storage and resets when you sign out. |
We do not collect contacts, calendars, health data, precise background location, microphone or camera input other than a photo you deliberately submit as proof, or any advertising identifier. Parmo carries no advertising SDK. Its product analytics (PostHog, below) runs without cookies and without the advertising identifier.
Instagram data
Creators connect a professional (business or creator) Instagram account through Instagram’s own login. Parmo uses three permissions: instagram_business_basic (your profile, posts and stories), instagram_business_manage_insights (statistics about your account and your stories) and instagram_business_content_publish (posting a story for you). This is everything we read or do with them.
| Data | Permission | Why | Who can see it | How long we keep it |
|---|---|---|---|---|
| Profile: Instagram user id, username, name, profile picture, biography, website, account type, follower count, number of posts | instagram_business_basic | Knowing which account you connected, checking an organizer’s follower minimum, and showing organizers who they would book | You. Organizers and other signed-in Parmo users in the creator directory and invite list (everything here except the user id). Our admins | Refreshed about every six hours while connected. Kept until you disconnect, ask Meta to delete it, or delete your account |
| Daily account statistics: reach and views per day, follower and post count per day, and your average reach over the last 30 days | instagram_business_manage_insights | Showing you how your account develops, and giving organizers one average-reach figure | You (the history, in the phone app). Your average reach: the same people as your profile. Our admins | One entry per day, kept until you disconnect, ask Meta to delete it, or delete your account |
| Your audience: the cities your followers are in, their age groups, and the hours they are online (Instagram reports these only once an account has about 100 followers) | instagram_business_manage_insights | Showing you who follows you and when to post, and showing organizers where your audience is | You. Summed per city with every other creator’s for the anonymous reach map on our organizer pages, which shows no account and no per-person number. Our admins | Replaced at every refresh. Kept until you disconnect, ask Meta to delete it, or delete your account |
| Your 12 most recent posts: id, type, image or thumbnail link, time, link, like and comment counts, and each post’s daily like and comment count. We do not fetch or store their captions | instagram_business_basic | Working out your engagement (likes and comments per post) for your statistics. The posts themselves are not shown anywhere in Parmo | You, as engagement figures. Our admins | The list is replaced at every refresh; the daily counts are kept until you disconnect, ask Meta to delete them, or delete your account |
| Your current stories, when you open the story picker: ids, type, image or video links, time, link | instagram_business_basic | Letting you pick which live story is the one for a gig | Only you | Not stored. Only the story you pick is kept, as the next row |
| The story you post for a gig: its id, link, type, image or video links and posting time, and our own copy of the image or video | instagram_business_basic | Proving the story went up and was still online at the deadline (we ask Instagram whether it is still there until then). Our copy is the evidence if a reward is disputed | You and the organizer of that gig. Our admins | Our copy: 180 days after the gig is settled (longer only while a dispute is open), or until you delete your account or ask Meta to delete your data. The id and links: until you delete your account or ask Meta to delete your data |
| That story’s statistics: views, reach, replies, taps forward and back, exits, swipes away, shares, profile visits, follows, total interactions | instagram_business_manage_insights | Deciding whether the story reached its audience, and reporting the result to the organizer who booked it | You. The organizer of that gig (views, reach, replies, taps, exits, shares, profile visits, follows). Our public benchmarks use them only as totals and medians over at least 30 stories. Our admins | As long as the gig record (see "How long we keep it"). If you delete your account, the numbers stay with the organizer’s record of the gig without your name |
| Stories Parmo posts for you: the organizer’s story image or video, with the mention the brief asks for | instagram_business_content_publish | Posting a gig’s story on your account, only as described below | Your Instagram audience, like any story you post yourself | On Instagram, 24 hours like any story. At Parmo, as the row above |
| Your Instagram access token | All three | Reading the above and posting on your behalf | Nobody. It is encrypted (AES-256-GCM) before it is stored, used only on our servers and never sent to the app or website | Until you disconnect, remove Parmo in Instagram (we delete it the moment Meta tells us), ask Meta to delete your data, or delete your account |
Parmo posts a story for you only for a gig you took (you asked to join and the organizer accepted, or you accepted an invite) and only if, when you took it, you chose to let Parmo post it rather than post it yourself. It goes out at the time the brief sets; you are told when it is booked and can move or cancel it until then.
We never read your password, your messages, your follower list or anyone else’s content. Instagram data is never sold, never used for advertising, and never shared with anyone other than the people named in the table and the processors listed below.
Stopping or undoing the Instagram connection
- Disconnect in Parmo: Profile → Instagram on the phone, Settings → Connected accounts on the web. This deletes the connection and its token, and with them your synced profile, daily statistics, audience and recent posts. What belongs to gigs you already did (the story, its statistics, our copy for its 180 days) stays with the gig, because it is the organizer’s record too.
- Remove Parmo in Instagram (Settings → Apps and websites): Meta tells us, and we delete your token at once and cancel any story still waiting to be posted. Nothing is refreshed after that. What was already synced stays until you disconnect in Parmo, ask Meta to delete it, or delete your account, so reconnecting later picks up where you left off.
- Ask Meta to delete your data (from the same Instagram screen): we erase your Instagram username, name, profile picture, biography, website, account type, follower and post counts, average reach, audience, daily statistics and posts, and the Instagram ids, links and our copies of the stories you posted for gigs. The measured story numbers stay with each gig without the link to your Instagram account. You get a confirmation code and a page at
/data-deletion/followed by the code, where you can check that it happened. - Delete your Parmo account: removes all of it, as described in the Account and Data Deletion Policy.
Legal bases (GDPR Article 6)
| Purpose | Basis |
|---|---|
| Providing your account, running bookings, settling rewards, sending service email | Performance of a contract (Art. 6(1)(b)) |
| Verifying that a story was posted and stayed online | Performance of a contract (Art. 6(1)(b)) |
| Device location, push notifications, connecting Instagram, and letting Parmo post a gig’s story for you | Your consent (Art. 6(1)(a)), given per permission and withdrawable at any time in your device or Parmo settings |
| Security, fraud and abuse prevention, service logs and error reports, keeping records of what we sent | Legitimate interests (Art. 6(1)(f)) in a service that works and is not defrauded |
| Product analytics (PostHog), and cookieless page-view counts and speed measurements (Vercel Web Analytics and Speed Insights) | Legitimate interests (Art. 6(1)(f)) in finding where the product fails people and fixing it |
| Guessing your city from your IP address to choose where the event feed starts, until you set a city | Legitimate interests (Art. 6(1)(f)) in showing a new promoter events near them instead of an empty feed; nothing is stored |
| Keeping accounting and tax records of payments, if paid rewards launch | Legal obligation (Art. 6(1)(c)) |
Who else processes your data
We do not sell personal data, and we do not share it for advertising. These are the processors Parmo runs on, each bound by a data processing agreement and each used only for what is listed.
| Processor | What it handles | Where |
|---|---|---|
| Supabase | Database, authentication, file storage: everything in the tables above except mail | EU (Frankfurt) |
| Vercel | Hosting the website and API, and the request logs that come with it | EU (Frankfurt) for functions; edge network worldwide |
| Stripe | Not in use yet. Parmo processes no payments today; if paid rewards launch, Stripe will process them and this policy will be updated before then | None today |
| Meta Platforms (Instagram Graph API) | The Instagram data listed above, which it provides when you connect, and publishing a story you let Parmo post | EU and US |
| Resend | Sending transactional email and receiving mail sent to a campaign inbox | EU and US |
| Upstash (QStash) | The job queue that schedules story checks. Carries record identifiers, not profile content | EU |
| Expo, Apple (APNs) and Google (FCM) | Delivering push notifications to your device | EU and US |
| OpenFreeMap | Map tiles. Your IP address reaches the tile server when a map is shown | EU |
| PostHog | Product analytics: the usage events described above. The website sends them with PostHog’s setting that keeps your IP address off the stored event; events from the phone app arrive with your device’s IP address, which PostHog may store with them | EU (Frankfurt) |
| Vercel Web Analytics and Speed Insights | Counting page views and measuring page speed on the website, without cookies and as totals only. Your IP address is used to tell visits apart within a day and is not stored | EU and US |
| Sentry | Error reports from the website, the app and our servers: the error, where it happened, and browser or app and system version. No IP address, name or email, and no screen recording; a report from the app may carry your account’s internal identifier | EU and US |
| Google (Maps Platform) | Place search: the text you type into a city or venue field, sent from our server so Google does not see your IP address. In the app, when you tap Use my location, your device’s coordinates, to turn them into a place name | EU and US |
We also disclose data where the law requires it, and to our professional advisers where necessary to a legal claim. If Parmo is ever sold or merged, account data transfers with it, and we will tell you before that happens.
Transfers outside the EEA rely on the European Commission’s Standard Contractual Clauses, or on an adequacy decision where one covers the recipient.
What other people can see
Parmo is a marketplace, so some of your profile is deliberately visible. It is worth knowing exactly how much.
- Organizers and other signed-in Parmo users can find you in the creator directory and the invite list. They see your display name, city, and your Instagram username, name, profile picture, biography, website, account type, follower and post count and average reach.
- An organizer you do a gig for additionally sees that gig’s story (our copy), its statistics (listed under "Instagram data"), your rating and your proof.
- Our admins can see your account and its data to give support and to moderate, and can sign in as you to see what you see. Each time they do, it is recorded in your account’s audit trail.
- A creator on a campaign sees the organizer’s brand, the event, the reward and the organizer’s rating.
- Your email address, birthdate, exact location and Instagram token are never shown to another user.
How long we keep it
| Data | Kept for |
|---|---|
| Account and profile | Until you delete your account |
| Instagram connection, synced profile, statistics, audience and posts | Until you disconnect in Parmo, ask Meta to delete your data, or delete your account. Removing Parmo in Instagram deletes the access token at once; the rest stays until one of those three. Item by item under "Instagram data" |
| Bookings, proofs, ratings | Until you delete your account. The other party’s record of a completed booking survives your deletion in anonymized form, because it is their history too |
| Stored story media (our copy of a story you posted) | Until you delete your account, or 180 days after the booking is settled and its reward decided, whichever comes first. A story with an open dispute is kept until the dispute is resolved. The reach and view counts we measured stay; only the picture goes |
| Payment records | Parmo processes no payments today. If paid rewards launch, accounting records are kept 10 years and receipts 8 years, as tax law requires, whether or not the account still exists |
| Email delivery log | 12 months, then deleted automatically |
| Server and security logs, error reports | Up to 90 days, set by our hosting and error-reporting providers |
| Push tokens | Until you turn notifications off, or the device stops accepting them |
Your rights
If you are in the EEA or the UK you have the right to access your data, correct it, delete it, restrict or object to how we use it, take it elsewhere in a portable form, and withdraw any consent you gave. Exercising a right never costs you the service, and never costs you money.
- Delete your account, yourself, now: Profile → Email & password → Delete account, in the app or on the web. It removes your login and the data that belongs to you immediately, with no email to us and no waiting; what other people keep of a gig you did together stays with your name removed. See the Account and Data Deletion Policy for exactly what goes and what stays.
- Access or export: write to privacy@parmo.io and we will send a machine-readable copy within 30 days.
- Withdraw a permission: location and notifications are in your device settings; the Instagram connection is in Parmo under Profile → Instagram on the phone or Settings → Connected accounts on the web, and also revocable from Instagram itself (see "Stopping or undoing the Instagram connection").
- You may also complain to your local data protection authority.
How it is protected
- Everything travels over TLS, and is encrypted at rest by our database and storage provider.
- Every table is protected by row-level security in the database itself, so one account cannot read another’s rows even if application code is wrong.
- Instagram access tokens are encrypted (AES-256-GCM) before they are stored. They and every other secret stay on our servers, never in the app or website bundle.
- Access to production data is limited to the people who need it, administrative actions are logged, and an admin signing in as your account is recorded in its audit trail.
No system is perfect. If a breach ever affects your data we will notify the relevant authority within 72 hours and tell you directly where the law requires it. Security reports are welcome at privacy@parmo.io.
Children
Parmo is for adults. You must be 18 or older to hold an account; we ask for your birthdate at sign-up and the database refuses a date under 18. We do not knowingly collect data from children, and if we learn that an account belongs to someone under 18 we delete it. If you believe a minor has an account, tell us at privacy@parmo.io.
Tracking and cookies
Parmo does not track you across other companies’ apps and websites, does not use the advertising identifier, and shows no ads. The mobile app therefore never asks for App Tracking Transparency permission, because there is nothing to ask about.
The website sets only cookies that are strictly necessary for something you asked for: keeping you signed in, remembering your language and layout, and carrying an invite link, a destination or a Near me position through sign-in or a search. On the website, product analytics stores nothing on your device: no cookie, no local storage, so a signed-out visitor is not recognised from one visit to the next. The phone app keeps a random analytics identifier in its own app storage (not a cookie, and not readable by other apps), reset when you sign out. Details are in the Cookie Policy.
Changes to this policy
When we change something substantive we bump the version at the top of this page, and tell you by email or in the app before it takes effect. The current version and its effective date are always shown here.