This Privacy Policy explains how Greenflag Tech, Inc., a Delaware corporation ("Greenflag Tech," "Greenflag," "we," "us," or "our") collects, uses, discloses, retains, and protects personal information when you use Greenflag, the trygreenflag.com website, our mobile applications, our public profile pages, our server APIs, and related services (together, the "Services").
Greenflag is a dating app with one defining trait: your profile is built by your friends. That means we handle not only your information, but also content your friends create about you, and content you create about other people. This Policy explains how that works. If you do not agree with this Policy, do not use the Services.
Controller and Contact
Greenflag Tech, Inc. is responsible for personal information processed under this Policy.
Principal place of business:
1401 21st Street #4114
Sacramento, CA 95811
United States
Privacy and data requests: privacy@trygreenflag.com
Legal: legal@trygreenflag.com
Support: support@trygreenflag.com
Safety and reports: safety@trygreenflag.com
Website: https://trygreenflag.com
We have not appointed a Data Protection Officer. If that changes, we will update this Policy.
Quick Summary
- Greenflag is for adults only: you must be 18 or older.
- We collect your phone number, photos, basic facts, approximate location (to place you in a metro), and the content your friends create about you.
- We require photo verification (a liveness check and face match) through our vendor Didit to reduce fake profiles.
- We use your approximate location to lock discovery to your metro and to power nearby experiences. Each time you open the app we update a single, blurred "last known location" (rounded to an area of a few city blocks); we keep no history of your movements and we do not show your exact location to other users.
- We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
- Content screening is machine-only: AI systems review content, not people. Humans are involved only when a safety report is opened or the law requires it (see Section 5).
- We use a small set of service providers (listed in Section 10) for verification, messaging, AI features, hosting, payments, analytics, and error reporting.
- You can access, correct, delete, or export your information, subject to the limits in this Policy.
This summary is for convenience only; the full Policy controls.
Information We Collect
3.1 Information you provide
- Account and verification: your phone number (verified by SMS one-time code), display name, date of birth / age, and the photos and basic facts (such as height, neighborhood, and interests) you upload as raw assets.
- Photo verification: a live selfie/liveness capture and the face-match result used to confirm you match your chosen profile photo (processed by Didit; see Section 10).
- Your friend roster: the phone numbers and names of the friends, family, or loved ones you invite to vouch for you, so we can send them an invitation.
- Content from your Vouchers: the pitch slides, captions, and written vouches your friends create about you, including the stated relationship (for example, "his sister").
- Content you create about others: if you act as a Voucher, the pitch and vouch content you create about the person you are vouching for.
- Messages and interactions: messages you send in a match and your "Curious" interest signals.
- Support, reports, and feedback: messages, reports of other users, survey responses, and attachments you choose to send us. When you send in-app feedback we attach technical context to help us reproduce the problem: the screen you were on and the few screens before it, error codes from recent failed requests, your network type, screen size and text size, and the app settings and permissions that change how the app behaves. It never includes the contents of your messages, the text you typed on those screens, or a device identifier.
3.2 Information collected automatically
- Device and app information: device and installation identifiers, app version, operating system, platform, language, and device type.
- Location: approximate location, used at signup to determine your metro for city-locked discovery and reverse geocoding the area label, and thereafter refreshed once each time you open the app to keep discovery local and power nearby experiences. Before it leaves your device, your position is rounded to an area of roughly a few city blocks; we never receive or store your exact coordinates. We store only your most recent rounded position (a single "last known location" that is overwritten on each update), never a trail or history of where you have been, and we do not collect location in the background. You can control device location permissions at any time, but core discovery needs at least an approximate metro.
- Usage and diagnostics: IP address, request timestamps, routes, status, latency, rate-limit and abuse-prevention signals, security logs, feature-usage events, crash reports, and error diagnostics.
- Purchase metadata: plan/access status and receipts from the app stores (we do not receive your full card number).
3.3 Information from third parties
We may receive information from the app stores (purchase and receipt status), our verification and infrastructure providers, and anyone who reports you or interacts with you on the Services.
Sensitive Information
Some information on Greenflag may be considered sensitive, including your photos and face/biometric verification data, approximate location, and information that may reveal characteristics like sexual orientation. Orientation may be inherent in a dating context, and you may also choose to state it directly: the profile has an optional sexuality field you can fill in or leave blank. It is display only. We never use it to rank, filter, or decide who sees you, and leaving it blank publishes nothing. You can clear it at any time from Your details. We collect and use this only to operate the Services (to verify you, build and show profiles, lock discovery to your metro, and keep the community safe) and we apply the protections described in this Policy. We do not use this information for advertising, and we do not sell it.
A note on verification: Didit performs a liveness check and a 1:1 face match to confirm you match your chosen photo. The face geometry involved may be considered biometric information under laws such as the Illinois Biometric Information Privacy Act (BIPA) and similar Texas, Washington, and other state laws. This data is used only to confirm the verification result. We do not use it to build a facial-recognition database, to identify you across other services, or for advertising, and we do not sell it or disclose it except to Didit (which processes it on our behalf to perform the check) or as required by law.
Where biometric-privacy laws apply, we collect and process this data with your consent, which you give when you choose to complete verification. We retain the biometric data used for the face match only as long as needed to perform and maintain your verification, and in any event we delete it (or require our vendor to delete it) within a reasonable period, generally within 30 days, after the verification is complete, unless a longer period is required to comply with law or to address a safety or security matter. You can decline verification, but your profile will not go live without it.
How We Use Information
We use information to:
- create and verify your account and confirm you are 18+;
- build, display, translate, and distribute friend-built profiles and vouches;
- run city-locked discovery, the "Curious" mechanic, matching, and messaging;
- send the SMS verification code and service, security, account, and (where permitted) product messages;
- process purchases and access through the app stores;
- detect, prevent, and respond to fraud, abuse, harassment, safety incidents, and violations of our Terms and Community Guidelines, including reviewing reports and applying enforcement;
- analyze usage in privacy-preserving ways to improve the product;
- comply with legal obligations and protect the rights, safety, and security of users, the public, and Greenflag Tech.
Content review and AI-assisted processing. Greenflag makes active use of AI throughout the Services, including for trust and safety. To keep the community safe and to enforce our Terms and Community Guidelines, profiles, photos, vouches, media, and messages may be screened for fraud, abuse, harassment, illegal content, and safety risks, and that screening is performed by automated AI systems, not people. Your private conversations, and the photos and media you share in them, are never read or viewed by Greenflag staff in the ordinary course of operating the Services: if your content is processed at all, it is processed by machines. Human review happens in exactly two situations: (1) when a safety report is opened about a conversation, profile, or piece of content (whether filed by a user, filed anonymously through a shared safety link, or generated by our automated systems when they detect content that appears illegal or indicates a risk of serious harm), our safety team reviews the reported content, and only that content, to resolve the report; and (2) when we are legally required to act, such as responding to valid law-enforcement requests in connection with an investigation or preserving records under a legal obligation. Outside those two paths, no person at Greenflag reviews your chats or shared media. AI also powers product features you invoke directly, such as suggesting the time and place of a date you are about to share with your friends, and helps rank and surface profiles in discovery and support matching. We follow industry data-minimization standards: an AI system receives only the minimum content needed for the specific feature, only when that feature actually runs, and the AI service providers that process content for us (Section 10) do so under data processing agreements that bar them from using it for their own purposes: your content is not used to train their models. These automated processes do not produce legal or similarly significant effects about you without the ability for human review where required by law; you can contact us to ask about a decision. By using the Services, you consent to this AI-assisted processing.
Legal Bases (where required, e.g. Mexico and Canada)
Where data-protection laws require a legal basis, we rely on one or more of:
- Performance of a contract: to provide the Services you request;
- Consent: for example, to send the SMS verification code, to complete photo/biometric verification, to access device location, or for optional marketing (you can withdraw consent);
- Legitimate interests: to secure, maintain, and improve the Services, prevent abuse, and keep the community safe;
- Legal obligation: to comply with tax, consumer-protection, law-enforcement, and other legal requirements.
For users in Mexico, we process personal data in accordance with the Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP); this Policy serves as our privacy notice ("aviso de privacidad"), and you may exercise your ARCO rights (Access, Rectification, Cancellation, Opposition) and withdraw consent as described in Section 11.
How Profiles Affect Privacy
Because friends build your profile, content about you may be created and shared by other people. You control whether your profile is published and can hide or unpublish it. However:
- Your live profile is visible to other users in your metro as part of discovery.
- Content that is visible to other users can be screenshotted, copied, or re-shared by others outside our control. Unpublishing your profile does not retrieve copies others already saved.
- We show your neighborhood/metro-level area, not your exact location, and we encourage limiting identifying details. Photos are inherently identifying, so share only what you are comfortable making visible.
If your friends include other people's information in your pitch, or you do so in someone else's, you are responsible for having any consent required.
SMS Verification
We send a one-time verification code by SMS (through Twilio) when you or your invited friends sign in or verify a number. By entering a number and continuing, you consent to receive that code; message and data rates may apply. We use the number to verify and secure accounts, not for marketing. Additional details about our SMS practices are described in our internal SMS consent documentation and may be surfaced in-app at the point of verification.
Analytics, Crash Reporting, and Cookies
- Analytics (Mixpanel and Firebase Analytics): we use product analytics designed around bounded, behavioral events (feature usage, onboarding steps, platform). Analytics are not intended to include message contents, vouch text, or secrets.
- Crash and error reporting (Sentry and Firebase Crashlytics): crash reports include technical diagnostics and are intended to be scrubbed of message contents and secrets.
- Push notifications (Firebase Cloud Messaging): our mobile apps use Firebase Cloud Messaging to deliver push notifications to your device. This relies on a device push token; you can control notifications in your device settings.
- Email open measurement (Postmark): our service emails include a small tracking image that tells us the first time a message is opened, so we can tell whether our emails are useful. We record only that a message was opened and which kind of email it was. We do not rewrite the links in our emails to route through a tracking service. Most email apps let you block remote images, which prevents this measurement entirely, and you can turn off email notifications in your settings.
- Cookies / local storage: our apps use device storage, secure storage, and similar technologies to operate. Our website uses a small number of cookies and similar local-storage technologies for anonymous product analytics (Mixpanel), which we use to understand how the site is used. We do not use cookies for advertising or for cross-context behavioral tracking, and we honour browser Do Not Track and Global Privacy Control signals on the website.
Your Privacy Rights and Controls
Depending on where you live, you may have rights to access, correct, delete, port, or restrict your personal information; to object to certain processing; to withdraw consent; to opt out of marketing; to opt out of "sale"/"sharing" or targeted advertising (note: we do not sell or share for targeted advertising); and to limit the use and disclosure of sensitive personal information to what is necessary to provide the Services (which is already how we use it). Users in Mexico may exercise ARCO rights under the LFPDPPP (Section 16). Users in Canada may exercise access, correction, and consent-withdrawal rights under PIPEDA and provincial privacy law (Section 17).
Authorized agents. Where the law allows, you may use an authorized agent to submit a request on your behalf; we may ask the agent for proof of authorization and may still ask you to verify your identity directly.
Opt-out preference signals. Although we do not sell personal information or share it for targeted advertising, where required by law we will treat a recognized browser- or device-level opt-out preference signal (such as Global Privacy Control) as a valid opt-out request for the browser or device that sends it.
To exercise rights, use the in-app controls or contact privacy@trygreenflag.com. You can also:
- Delete your account in the app, or on the web at https://trygreenflag.com/account-deletion/ by confirming a code we text to the phone number on your account. Either way removes your profile from discovery and deletes your account data subject to the retention exceptions in Section 12.
- Hide or unpublish your profile at any time.
We may need to verify your identity (for example, via the phone number on your account) before acting. Some requests may be limited where content is also someone else's (for example, a vouch your friend wrote), where we must keep records for legal, security, or safety reasons, or where information is controlled by another person. We will not discriminate against you for exercising these rights.
Appeals. If we deny your request, you may appeal by replying to our response (please reference "Privacy Request Appeal"); we will respond within the time the law requires. Depending on your state or country, you may also complain to your local data-protection or consumer authority, for example your U.S. state attorney general, the California Privacy Protection Agency, the Office of the Privacy Commissioner of Canada or your provincial privacy commissioner, the competent Mexican data-protection authority, or your regional regulator.
Data Retention
We keep personal information only as long as needed for the purposes in this Policy. These are general guidelines, not fixed guarantees, and actual periods may vary with our legal obligations and safety needs:
- Profile, vouch, and message data is kept while your account is active and deleted or de-identified within a reasonable period (generally within about 30 days) after you delete your account, except as noted below.
- Location is stored as a single approximate "last known location" that is overwritten each time you open the app; prior values are not retained, and the stored value is deleted with your account.
- Inactive accounts. We may close and delete accounts that have been inactive for an extended period (for example, around two years), after any notice the law requires.
- Verification (biometric) data is retained only as long as needed to confirm and maintain your verification status and, as described in Section 4, is generally deleted within 30 days of completing verification.
- Safety, abuse, and ban records may be retained longer, for example for a period after an account is banned, to enforce bans, prevent banned users from returning, investigate abuse, and protect the community.
- Payment, tax, and legal records are retained for the periods required by law (often several years, such as up to about seven years for tax and accounting records), and records of consent are kept as needed to demonstrate compliance.
- Backups, logs, and content already shared (such as a screenshot someone saved) may persist after deletion as described in Sections 7 and 11.
Security
We use technical, organizational, and administrative safeguards designed to protect personal information, including encryption in transit, platform secure storage for secrets, access controls, rate limiting, and redaction rules for analytics and crash reporting. No method is perfectly secure; we cannot guarantee that unauthorized access, loss, or misuse will never occur. Protect your device, phone number, and account. If we learn of a breach affecting your information, we will notify you and authorities where required by law.
International Transfers
We are based in the United States, and we host the Services on infrastructure located in the United States. We use service providers that may process information in the United States and in other countries, which may have different privacy laws than where you live. Greenflag serves users in the United States, Canada, and Mexico, and your information will generally be processed in the United States. If you are in Canada or Mexico, this means your personal information is transferred to and stored in the United States, where it may be accessible to U.S. courts, law enforcement, and regulatory authorities under U.S. law. Where required, we use appropriate safeguards (such as standard contractual clauses or other lawful transfer mechanisms) for international transfers.
California and U.S. State Privacy Disclosures
We do not sell personal information or share it for cross-context behavioral advertising as defined under U.S. state privacy laws (including the CCPA/CPRA). Depending on your use, we may collect these categories of personal information:
- Identifiers: phone number, name, device identifiers, customer IDs, IP address;
- Customer records / commercial information: purchase, access, and transaction records;
- Internet/network activity: app and server request metadata and feature-usage events;
- Geolocation: approximate location for metro placement and nearby features, collected when you open the app and stored only as a single rounded last-known value;
- Biometric information: liveness/face-match verification data;
- Audio/visual information: your photos and any chat media you send;
- Characteristics that may be sensitive: information inherent to a dating context;
- Inferences: limited product-usage inferences for service improvement.
We collect, use, disclose, and retain these for the purposes and for the periods described in this Policy (see Section 12), and we disclose them only to the service providers and other recipients listed in Section 10. We do not sell personal information, do not share it for cross-context behavioral advertising, and do not use or disclose sensitive personal information beyond the purposes permitted under the CCPA/CPRA (such as providing the Services, verification, and safety). We do not offer financial incentives in exchange for your personal information.
California residents, and residents of other U.S. states that have enacted comprehensive consumer privacy laws (including Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Delaware, Maryland, Minnesota, New Jersey, and others), may exercise rights to know, access, correct, delete, and port their information; to opt out of sale/sharing/targeted advertising; to limit the use of sensitive personal information; and to appeal a denied request (see Section 11). You may not be discriminated against for exercising these rights, and you may use an authorized agent. To exercise these rights, contact privacy@trygreenflag.com. Because Greenflag verifies accounts by phone, we generally verify requests using the phone number on your account.
Washington and Nevada: consumer health data. Some information inherent to a dating service (for example, data that may reveal sexual orientation) could be treated as "consumer health data" under Washington's My Health My Data Act and Nevada law. We collect and use such information only to provide and secure the Services as described in this Policy and with your consent where required; we do not sell it, and we apply the protections described here. Washington and Nevada residents may contact privacy@trygreenflag.com to exercise applicable rights.
Mexico: LFPDPPP / Aviso de Privacidad
For users in Mexico, Greenflag Tech, Inc., with a domicile at 1401 21st Street #4114, Sacramento, CA 95811, United States, acts as the data controller ("responsable"), and this Policy serves as our privacy notice ("aviso de privacidad"). Our privacy contact ("departamento de datos personales") is privacy@trygreenflag.com.
Sensitive personal data. We process sensitive personal data ("datos personales sensibles"), including your photographs, the biometric data used for photo verification, and data inherent to a dating context from which sexual preference may be inferred, only with your express consent, which you give through an affirmative action in the app before that processing begins. You may withdraw that consent at any time, though doing so may mean we can no longer provide the Services.
Primary and secondary purposes. The purposes described in Section 5 that are necessary to provide the Services (creating and verifying your account, building and showing friend-built profiles, running discovery and messaging, processing purchases, keeping the community safe, and meeting our legal obligations) are primary purposes. Marketing and product-update communications (Section 19) are a secondary purpose that is not necessary to the Services; you may refuse or withdraw consent for it at any time by using the unsubscribe link or contacting privacy@trygreenflag.com, without affecting your access to the Services.
Transfers. As described in Section 14, your personal data is transferred to and stored in the United States, and is shared with the service providers listed in Section 10, who process it on our behalf.
You may exercise your ARCO rights (Acceso, Rectificación, Cancelación, Oposición), limit the use or disclosure of your data, and withdraw consent by contacting privacy@trygreenflag.com. You may also file a complaint with the competent Mexican data-protection authority.
Canada: PIPEDA and Provincial Privacy Law
If you are in Canada, we handle your personal information in accordance with the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and, where they apply, substantially similar provincial laws such as British Columbia's *Personal Information Protection Act*, Alberta's *Personal Information Protection Act*, and Quebec's private-sector privacy legislation.
- Consent. We collect, use, and disclose your personal information with your consent, for the purposes described in this Policy. For sensitive information (including your photographs, the biometric data used for photo verification, and information inherent to a dating context from which sexual orientation may be inferred) we rely on your express consent, which you give through an affirmative action in the app. You may withdraw consent at any time, subject to legal and contractual restrictions and reasonable notice, though doing so may mean we can no longer provide the Services.
- Access and correction. You may request access to the personal information we hold about you and ask us to correct it if it is inaccurate or incomplete. Contact privacy@trygreenflag.com, or use the in-app export and editing controls.
- Storage outside Canada. As described in Section 14, we are based in the United States and store personal information there. While your information is outside Canada, it is subject to the laws of the United States and may be accessible to U.S. courts, law enforcement, and regulatory authorities. We remain accountable for information we transfer to service providers for processing.
- Commercial electronic messages. Where we send commercial electronic messages to Canadian recipients, we do so in accordance with Canada's Anti-Spam Legislation (CASL), including identifying ourselves, providing our mailing address, and offering an unsubscribe mechanism. Verification codes and other transactional messages are not marketing.
- Complaints. If you are not satisfied with how we have handled your personal information, you may complain to the Office of the Privacy Commissioner of Canada, or to your provincial privacy commissioner where one has jurisdiction (for example, the Information and Privacy Commissioner for British Columbia, the Information and Privacy Commissioner of Alberta, or the Commission d'accès à l'information du Québec).
Children
Greenflag is strictly for adults. The Services are not directed to anyone under 18, and we do not knowingly collect personal information from anyone under 18. If you believe someone under 18 is using Greenflag or has provided information to us, contact safety@trygreenflag.com and we will act, including terminating the account.
If we become aware of apparent child sexual abuse material (CSAM) or the sexual exploitation of a minor, we will remove it, preserve relevant evidence, and report it as required by law to the National Center for Missing & Exploited Children (NCMEC) and/or to law enforcement. We may retain and disclose related information for those reporting, investigative, and child-safety purposes even where we would otherwise delete it.
Marketing Communications
If you opt in or provide contact information, we may send product updates and (where permitted) marketing messages. You can opt out using the unsubscribe link or by contacting support@trygreenflag.com. We may still send non-marketing service, security, account, payment, and legal messages.
Third-Party Links
The Services may link to or integrate with third-party sites and services governed by their own privacy practices. We are not responsible for their privacy, security, or content.
Changes to This Policy
We may update this Policy from time to time. When changes are material, we will provide notice by posting the updated Policy, updating the "Last Updated" date, and/or sending in-app or email notice. Your continued use of the Services after the update takes effect means you acknowledge the updated Policy.
Contact
Greenflag Tech, Inc.
1401 21st Street #4114
Sacramento, CA 95811, United States
Privacy and data requests: privacy@trygreenflag.com
Legal: legal@trygreenflag.com
Support: support@trygreenflag.com
Safety and reports: safety@trygreenflag.com
← Back to Greenflag