Privacy Policy

Last updated: December 22, 2025

Introduction

At NABA (“we,” “our,” or “us”), we value your privacy and are committed to protecting your personal information. This Privacy Policy describes how we collect, use, store, share, and protect your information when you use our website, mobile applications, and services (collectively, the “Services”).

To use our Services, we require your explicit consent to the collection, use, and sharing of your information as described in this Privacy Policy. You can withdraw your consent at any time through your account settings. If you do not agree with our policies and practices, please do not use our Services.

IMPORTANT: This Privacy Policy is compliant with applicable data protection laws, including but not limited to the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other regional privacy regulations.

Information We Collect

We collect several types of information from and about users of our Services:

Information You Provide to Us

  • Account Information: When you register for an account, we collect your name, email address, phone number, and other profile information.
  • Profile Information: Information you add to your profile, such as your photo, job title, and other details you choose to provide.
  • Contact Information: Information about contacts you add to the platform, including their names, email addresses, phone numbers, and other details.
  • Team and Event Information: Data you provide when creating or managing teams and events, including member lists, locations, descriptions, and schedules.
  • Communications: Information you provide when you contact us or communicate with other users through our platform.

Information We Collect Automatically

  • Usage Data: Information about how you use our Services, including access times, pages viewed, features used, and other actions taken within the application.
  • Device Information: Information about the device you use to access our Services, including hardware model, operating system, unique device identifiers, and mobile network information.
  • Location Data: We will request explicit consent each time before collecting precise or approximate location information from your device. You can revoke this permission at any time through your device settings. We store location data securely for no longer than 30 days, and we do not share it with third parties except as required to provide our core services.
  • Cookies and Similar Technologies: We use cookies and similar tracking technologies to collect information about your browsing activities and to distinguish you from other users of our Services. See our Cookies and Tracking section for details on opting out.

Information from Third Parties

  • Authentication Services: When you sign in using third-party authentication providers (like Auth0), we receive information from these services, such as your name, email address, and profile picture.
  • Social Media: If you choose to link your social media accounts, we may receive information from those platforms according to their privacy policies and your permission settings.

Google Calendar Integration

Our Services include integration with Google Calendar. When you choose to connect your Google Calendar with our Services, we may access:

  • Calendar event information (event titles, dates, times, locations, descriptions (NABA-created events only))
  • Calendar availability

Limited Use and Protection of Calendar Data:

We only access and use your Google Calendar data to:

  • Sync events between our platform and your Google Calendar
  • Display your calendar availability for scheduling events
  • Create, update, or delete events (NABA-created events only) in your Google Calendar when you make changes in our platform

We implement strict security measures to protect your Google Calendar data, including encryption and restricted access controls. This data is only processed within our application to provide the calendar integration functionality you request. We do not use your Google Calendar data for advertising purposes, and we do not sell or share this data with any third parties.

You have full control over this integration and can disconnect it at any time in your account settings. Upon disconnection, we will delete all your Google calendar data within 7 days. Events previously created or synchronized may remain in either system according to your calendar settings.

Google API Services User Data Policy Compliance

Our use of Google Calendar data strictly adheres to Google's API Services User Data Policy. We only request access to the minimum scope of data necessary to provide calendar functionality.

How We Use Your Information

We use the information we collect for various purposes, including:

  • Providing, maintaining, and improving our Services
  • Creating and managing your account
  • Processing transactions and sending related information
  • Facilitating team and event management
  • Enabling communication between users
  • Sending administrative notifications, such as updates, security alerts, and support messages
  • Responding to your comments, questions, and requests
  • Personalizing your experience and providing content tailored to your interests
  • Monitoring and analyzing usage patterns, trends, and effectiveness
  • Detecting, preventing, and addressing technical issues, fraud, or illegal activities
  • Complying with legal obligations

How We Share Your Information

We may share your personal information in the following situations:

  • With Team Members and Event Participants: Information shared within teams or events is visible to other members or participants as part of the core functionality of our Services.
  • With Service Providers: We may share information with third-party vendors, consultants, and other service providers who need access to such information to carry out work on our behalf. These include:
    • Cloud hosting and storage providers
    • Analytics and performance monitoring services
    • Customer support tools
    • Authentication and security service providers
    • Payment processors

    All service providers are contractually obligated to use your data solely to provide services to us and are prohibited from selling, renting, or using your data for their own marketing purposes.

  • For Legal Reasons: We may disclose information if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency).
  • Business Transfers: If we are involved in a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on our website before your information becomes subject to a different privacy policy. You will be given the opportunity to delete your data prior to any such transfer.
  • With Your Consent: We may share your information with third parties when you have given us your explicit consent to do so.

We do not sell your personal information to third parties.

Data Security

We implement appropriate technical and organizational security measures to protect your personal information from unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encrypting sensitive data in transit (using TLS) and at rest (using AES-256)
  • Regularly reviewing and updating our security practices
  • Restricting access to personal information to authorized personnel
  • Using industry-standard security protocols
  • Monitoring our systems for potential vulnerabilities
  • Conducting regular security audits and assessments

While no method of transmission over the Internet or electronic storage is 100% secure, we follow industry best practices to protect your data. In the event of a data breach that affects your personal information, we will notify you within 72 hours of discovery, as required by applicable law.

Your Rights and Choices

Depending on your location, you may have certain rights regarding your personal information, including:

  • Access: You can request copies of your personal information that we hold.
  • Correction: You can ask us to correct inaccurate information or complete incomplete information.
  • Deletion: You can ask us to delete your personal information in certain circumstances.
  • Restriction: You can ask us to restrict the processing of your information in certain circumstances.
  • Objection: You can object to our processing of your personal information in certain circumstances.
  • Data Portability: You can request the transfer of your information to another organization or directly to you.

To exercise these rights, please contact us using the information provided in the “Contact Us” section below. We will respond to your request within 30 days.

You can also update most of your personal information directly through your account settings. If you wish to deactivate your account, you can do so in your account settings. Upon deactivation, we will:

  • Delete all your personal data within 30 days
  • Retain only information required by law or for legitimate business purposes
  • Stop processing any new data related to your account

GDPR, CCPA, and Other Privacy Law Compliance

NABA complies with applicable data protection laws, including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). For California residents, we provide additional rights as required by the CCPA, including the right to know what personal information is collected, the right to request deletion, and the right to opt-out of sales of personal information (though we do not sell personal information).

Cookies and Tracking Technologies

We use cookies and similar tracking technologies to track activity on our Services and to hold certain information. Cookies are files with a small amount of data that may include an anonymous unique identifier.

You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Services.

We use the following types of cookies:

Essential Cookies

Required for the operation of our Services. They enable basic functions like page navigation and access to secure areas.

Analytical/Performance Cookies

Allow us to recognize and count the number of visitors and see how visitors move around our Services.

Functionality Cookies

Used to recognize you when you return to our Services, enabling us to personalize content and remember your preferences.

Targeting Cookies

Record your visit to our Services, the pages you have visited, and the links you have followed.

Children's Privacy

Our Services are not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If we discover or are notified that we have collected personal information from a child under 13, we will immediately delete such information from our systems.

If you are a parent or guardian and believe that your child has provided us with personal information, please contact us immediately using the information in the “Contact Us” section, and we will take steps to delete such information.

For teenagers (13-18 years old) who may use our Services (such as for school events or youth activities), we require parental or guardian consent before collecting any personal information. This consent may be provided through a parent/guardian's account, a consent form provided by the organizing institution, or another verifiable method. Youth accounts have additional privacy protections, including limited data collection and restricted sharing options.

International Data Transfers

Your personal information may be transferred to, and processed in, countries other than the country in which you reside. These countries may have data protection laws that are different from the laws of your country.

Whenever we transfer your personal information to other countries, we ensure appropriate safeguards are implemented to protect your information and to ensure a level of protection is in place that is consistent with applicable data protection laws.

For transfers of personal data from the European Economic Area (EEA), United Kingdom, or Switzerland to countries not deemed to provide an adequate level of data protection, we implement Standard Contractual Clauses (SCCs) approved by the European Commission, or other suitable data transfer mechanisms, to ensure GDPR compliance. You may request a copy of these SCCs by contacting us through the information provided in the Contact Us section.

Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process the data, and applicable legal requirements.

Our specific retention periods are as follows:

  • Account information: Retained for the duration of your account plus 30 days after deletion
  • Calendar data: Retained only as long as necessary for synchronization, and deleted within 7 days of disconnecting the integration
  • Event data: Retained for 24 months after the event concludes
  • Usage data: Retained for 12 months
  • Inactive accounts: Personal data from accounts inactive for 24 months will be automatically deleted

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the “Last updated” date at the top of this page. We may also provide additional notice, such as adding a statement to our homepage or sending you a notification.

We encourage you to review this Privacy Policy periodically for any changes. Your continued use of our Services after any changes to this Privacy Policy will constitute your acceptance of such changes.

Third-Party Services

Our Services may contain links to third-party websites, services, or applications that are not operated by us. If you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the privacy policy of every site you visit.

We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

Contact Us

If you have any questions about this Privacy Policy or our privacy practices, please contact us at:

Address

4340 Oakwood Ave, North Charleston, SC 29405

Phone

703-403-2066