Privacy Policy
For the OnlyDance app, website, community and ticketing services
Your privacy
OnlyDance uses personal data to operate dance-community and ticketing services, keep them secure, provide support, send required event/payment messages and meet legal obligations. We do not sell personal data.
1. Controller and contact
OnlyDance OD, also referred to as OnlyDance ("we", "us" or "our"), is an app and brand operated by Mohamed Hassouna in Krakow, Poland. Mohamed Hassouna is the data controller for personal data processed through the OnlyDance platform, unless this Policy or the event page states that another party is responsible for a specific processing purpose.
App and brand: OnlyDance OD / OnlyDance
Developer / service provider: Mohamed Hassouna
Location: Krakow, Poland
Contact: support@onlydanceapp.com
An event organizer may be an independent controller for attendee data it uses to organize, manage or communicate about its own event. The organizer’s identity is shown with the relevant event or during checkout.
2. Data we collect
Depending on the features you use, we may process:
- Account and profile data: name, email, login/authentication details, profile image, dance preferences, location and content you choose to provide.
- Ticket and transaction data: buyer/attendee contact details, event, order, ticket, payment status, transaction reference, fees, check-in, refund, chargeback and complaint information.
- Organizer data: contact, identity, representative authority, event, verification, payout and business/tax information where needed.
- Technical and support data: IP address, device/app information, security logs, feature activity, permission choices and communications with us.
- Consent and notice records: marketing-consent status, consent source, date, channel and withdrawal history.
Required information is identified when requested. If you do not provide it, the relevant account, ticket, organizer, payment or support feature may not be available. Other profile information is optional.
3. Why we use data and legal bases
We use personal data to:
- provide accounts, profiles, community features, event listings, tickets, order confirmations, check-in and support under our agreement with you;
- process payments, refunds, payouts, chargebacks and fraud checks, including through Stripe or another payment provider shown in checkout;
- protect OnlyDance, users, organizers and payments against fraud, misuse and security threats based on legitimate interests;
- maintain accounting, tax, legal, complaint and transaction records where required by law;
- send optional marketing or use non-essential analytics only where we have valid consent or another legal basis required by law.
You may withdraw consent at any time. This does not affect processing already carried out lawfully.
4. Firebase/Google, Stripe and where data is stored
OnlyDance uses Firebase/Google Cloud services to operate app infrastructure, including authentication, database/storage, hosting, logs, security and notifications where enabled. App data is stored and processed in Firebase/Google Cloud in the locations configured for the relevant Firebase service. Where Firebase offers a location choice for a service, we use EEA/Europe locations where reasonably available for the production service.
Some Firebase/Google services and support/security operations may process data outside the European Economic Area, including in the United States or other countries. Where this happens, we rely on Google/Firebase data-processing terms, standard contractual clauses and other safeguards required by data-protection law.
OnlyDance uses Stripe or another payment provider shown in checkout for card/payment processing, fraud checks, refunds, chargebacks and organizer payouts. Payment-card details are processed by the payment provider and not stored by OnlyDance. Stripe or another payment provider may process data under its own privacy notice and may act as an independent controller for legal compliance, fraud prevention, sanctions screening, payment-network rules and reporting.
5. Sharing data
We may share only the information reasonably needed for the relevant purpose with event organizers, payment and payout providers, Firebase/Google and other hosting/technology providers, professional advisers, authorities where legally required, and a successor in a genuine business transaction.
For third-party events, we may provide the organizer with attendee information needed to operate admission, manage check-in, communicate event changes, handle event complaints or meet legal duties. Organizers must not use attendee data for unrelated marketing without a valid legal basis and required consent.
6. Data received from organizers or other sources: GDPR/RODO Article 14
If we receive your email or other personal data from an organizer, attendee, public event source or another third party rather than directly from you, we will provide the information required by GDPR/RODO Article 14 within the required time limit, normally in the first message to you where appropriate. This includes the source of the data, purposes, legal basis, controller contact, recipients, retention, rights and complaint options.
We will use such data only for a valid purpose, for example event operation, ticket support, safety, legal duties, or marketing only if the required consent/legal basis exists.
7. Marketing, PKE Article 398 and service messages
Acceptance of the Terms or this Privacy Policy is not marketing consent. Direct marketing by email, SMS, push notification, telephone or similar electronic communications will be sent only where we have the consent required by GDPR/RODO and Article 398 of the Polish Electronic Communications Law (PKE), or another lawful basis where permitted.
Marketing consent should be collected separately from acceptance of Terms/Privacy, identify the channel, and be recorded with the date, source and withdrawal status. You may withdraw marketing consent at any time by the method shown in the message or by contacting us. We may still send service, security, ticket, payment, refund and event-operation messages where needed to provide the service or meet legal obligations.
8. Retention
We keep personal data only for as long as reasonably needed for the purposes above. Account/profile data is generally kept until account deletion plus a reasonable backup/security period. Ticket, payment, tax, accounting, complaint and settlement records are kept for the legally required period or for the period needed to establish, exercise or defend claims. Consent records are kept while the consent is active and for a period needed to prove compliance after withdrawal.
9. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction or portability of your data, object to certain processing, and withdraw consent. To make a request or ask for account deletion, contact support@onlydanceapp.com. We may ask for information needed to verify your identity and will respond within the applicable legal time limits.
You may complain to the President of the Personal Data Protection Office in Poland (Prezes Urzędu Ochrony Danych Osobowych) or another competent supervisory authority in your EU/EEA country.
10. Security and personal-data breaches
We use appropriate technical and organizational measures designed to protect personal data and use service providers such as Firebase/Google and Stripe for security-critical infrastructure. No online service can guarantee absolute security, and users should keep login details secure.
If a personal-data breach occurs, we will assess and document it. Where required by GDPR/RODO, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of the breach. If the breach is likely to result in a high risk to individuals, we will also notify affected individuals without undue delay. Organizers and processors must notify OnlyDance promptly about suspected incidents involving OnlyDance platform data.
11. Device permissions, notifications and changes
OnlyDance may request permissions such as location, camera, photos or notifications when needed for a feature. You can manage permissions in your device settings. We may update this Policy when services, providers or legal obligations change. The current version and effective date will be published here, with additional notice where required by law.
← Back to the main page