Privacy Policy
Last updated: December 22, 2025
Jump to Section
Introduction
At NABA (“we,” “our,” or “us”), we value your privacy and are committed to protecting your personal information. This Privacy Policy describes how we collect, use, store, share, and protect your information when you use our website, mobile applications, and services (collectively, the “Services”).
To use our Services, we require your explicit consent to the collection, use, and sharing of your information as described in this Privacy Policy. You can withdraw your consent at any time through your account settings. If you do not agree with our policies and practices, please do not use our Services.
IMPORTANT: This Privacy Policy is compliant with applicable data protection laws, including but not limited to the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other regional privacy regulations.
Information We Collect
We collect several types of information from and about users of our Services:
Information You Provide to Us
- Account Information: When you register for an account, we collect your name, email address, phone number, and other profile information.
- Profile Information: Information you add to your profile, such as your photo, job title, and other details you choose to provide.
- Contact Information: Information about contacts you add to the platform, including their names, email addresses, phone numbers, and other details.
- Team and Event Information: Data you provide when creating or managing teams and events, including member lists, locations, descriptions, and schedules.
- Communications: Information you provide when you contact us or communicate with other users through our platform.
Information We Collect Automatically
- Usage Data: Information about how you use our Services, including access times, pages viewed, features used, and other actions taken within the application.
- Device Information: Information about the device you use to access our Services, including hardware model, operating system, unique device identifiers, and mobile network information.
- Location Data: We will request explicit consent each time before collecting precise or approximate location information from your device. You can revoke this permission at any time through your device settings. We store location data securely for no longer than 30 days, and we do not share it with third parties except as required to provide our core services.
- Cookies and Similar Technologies: We use cookies and similar tracking technologies to collect information about your browsing activities and to distinguish you from other users of our Services. See our Cookies and Tracking section for details on opting out.
Information from Third Parties
- Authentication Services: When you sign in using third-party authentication providers (like Auth0), we receive information from these services, such as your name, email address, and profile picture.
- Social Media: If you choose to link your social media accounts, we may receive information from those platforms according to their privacy policies and your permission settings.
Google Calendar Integration
Our Services include integration with Google Calendar. When you choose to connect your Google Calendar with our Services, we may access:
- Calendar event information (event titles, dates, times, locations, descriptions (NABA-created events only))
- Calendar availability
Limited Use and Protection of Calendar Data:
We only access and use your Google Calendar data to:
- Sync events between our platform and your Google Calendar
- Display your calendar availability for scheduling events
- Create, update, or delete events (NABA-created events only) in your Google Calendar when you make changes in our platform
We implement strict security measures to protect your Google Calendar data, including encryption and restricted access controls. This data is only processed within our application to provide the calendar integration functionality you request. We do not use your Google Calendar data for advertising purposes, and we do not sell or share this data with any third parties.
You have full control over this integration and can disconnect it at any time in your account settings. Upon disconnection, we will delete all your Google calendar data within 7 days. Events previously created or synchronized may remain in either system according to your calendar settings.
Google API Services User Data Policy Compliance
Our use of Google Calendar data strictly adheres to Google's API Services User Data Policy. We only request access to the minimum scope of data necessary to provide calendar functionality.
How We Use Your Information
We use the information we collect for various purposes, including:
- Providing, maintaining, and improving our Services
- Creating and managing your account
- Processing transactions and sending related information
- Facilitating team and event management
- Enabling communication between users
- Sending administrative notifications, such as updates, security alerts, and support messages
- Responding to your comments, questions, and requests
- Personalizing your experience and providing content tailored to your interests
- Monitoring and analyzing usage patterns, trends, and effectiveness
- Detecting, preventing, and addressing technical issues, fraud, or illegal activities
- Complying with legal obligations
Data Security
We implement appropriate technical and organizational security measures to protect your personal information from unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encrypting sensitive data in transit (using TLS) and at rest (using AES-256)
- Regularly reviewing and updating our security practices
- Restricting access to personal information to authorized personnel
- Using industry-standard security protocols
- Monitoring our systems for potential vulnerabilities
- Conducting regular security audits and assessments
While no method of transmission over the Internet or electronic storage is 100% secure, we follow industry best practices to protect your data. In the event of a data breach that affects your personal information, we will notify you within 72 hours of discovery, as required by applicable law.
Your Rights and Choices
Depending on your location, you may have certain rights regarding your personal information, including:
- Access: You can request copies of your personal information that we hold.
- Correction: You can ask us to correct inaccurate information or complete incomplete information.
- Deletion: You can ask us to delete your personal information in certain circumstances.
- Restriction: You can ask us to restrict the processing of your information in certain circumstances.
- Objection: You can object to our processing of your personal information in certain circumstances.
- Data Portability: You can request the transfer of your information to another organization or directly to you.
To exercise these rights, please contact us using the information provided in the “Contact Us” section below. We will respond to your request within 30 days.
You can also update most of your personal information directly through your account settings. If you wish to deactivate your account, you can do so in your account settings. Upon deactivation, we will:
- Delete all your personal data within 30 days
- Retain only information required by law or for legitimate business purposes
- Stop processing any new data related to your account
GDPR, CCPA, and Other Privacy Law Compliance
NABA complies with applicable data protection laws, including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). For California residents, we provide additional rights as required by the CCPA, including the right to know what personal information is collected, the right to request deletion, and the right to opt-out of sales of personal information (though we do not sell personal information).
Children's Privacy
Our Services are not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If we discover or are notified that we have collected personal information from a child under 13, we will immediately delete such information from our systems.
If you are a parent or guardian and believe that your child has provided us with personal information, please contact us immediately using the information in the “Contact Us” section, and we will take steps to delete such information.
For teenagers (13-18 years old) who may use our Services (such as for school events or youth activities), we require parental or guardian consent before collecting any personal information. This consent may be provided through a parent/guardian's account, a consent form provided by the organizing institution, or another verifiable method. Youth accounts have additional privacy protections, including limited data collection and restricted sharing options.
International Data Transfers
Your personal information may be transferred to, and processed in, countries other than the country in which you reside. These countries may have data protection laws that are different from the laws of your country.
Whenever we transfer your personal information to other countries, we ensure appropriate safeguards are implemented to protect your information and to ensure a level of protection is in place that is consistent with applicable data protection laws.
For transfers of personal data from the European Economic Area (EEA), United Kingdom, or Switzerland to countries not deemed to provide an adequate level of data protection, we implement Standard Contractual Clauses (SCCs) approved by the European Commission, or other suitable data transfer mechanisms, to ensure GDPR compliance. You may request a copy of these SCCs by contacting us through the information provided in the Contact Us section.
Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process the data, and applicable legal requirements.
Our specific retention periods are as follows:
- Account information: Retained for the duration of your account plus 30 days after deletion
- Calendar data: Retained only as long as necessary for synchronization, and deleted within 7 days of disconnecting the integration
- Event data: Retained for 24 months after the event concludes
- Usage data: Retained for 12 months
- Inactive accounts: Personal data from accounts inactive for 24 months will be automatically deleted
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the “Last updated” date at the top of this page. We may also provide additional notice, such as adding a statement to our homepage or sending you a notification.
We encourage you to review this Privacy Policy periodically for any changes. Your continued use of our Services after any changes to this Privacy Policy will constitute your acceptance of such changes.
Third-Party Services
Our Services may contain links to third-party websites, services, or applications that are not operated by us. If you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the privacy policy of every site you visit.
We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
Contact Us
If you have any questions about this Privacy Policy or our privacy practices, please contact us at: