Last updated: July 2026 (version 2026-07)
The short version
- We never sell your data. No advertising, no data brokers, no third-party tracking, no profiling of your visits.
- Hosts never learn who you are. Access is verified with a one-time code; your name and profile are never shared with the host.
- Location only when you use the map. We ask for your location just in time, use it on the spot, and do not build a location history or track you in the background.
- Payments stay with Stripe. Card details never reach us; your Relieved Credit is electronic money held by Stripe, a regulated institution.
- You are in control. Export your data or delete your account directly in your profile, at any time, without waiting periods.
The rest of this policy explains everything in detail: what we process in each situation, why, with whom we share it, how long we keep it, and your rights.
1. Who we are
The Relieved platform (relievedapp.com and the Relieved app) is operated by REBA Software, a sole proprietorship established in the Netherlands, registered with the Dutch Chamber of Commerce under number 42051273, Prins Hendrikstraat 51, Egmond aan Zee, the Netherlands. REBA Software is the data controller for the processing described in this policy. Our privacy contact point is support@relievedapp.com. We are established in the EU, so no EU or UK representative is required, and we are not required to appoint a data protection officer; the owner personally handles privacy matters.
One important exception: payments. Stripe Technology Europe, Limited, a regulated payment and electronic money institution authorised by the Central Bank of Ireland, is the independent data controller for payment data and for your Relieved Credit balance. Card and bank details go directly to Stripe and never reach our systems; we only receive transaction references, amounts, and statuses. Stripe's own privacy policy (stripe.com/privacy) applies to that processing.
2. What we process, in each situation
2.1 Creating and using an account
Username, email address, password (stored only as a hash), an emoji avatar, your country and the currency derived from it, your language, your marketing preference, and the time and version of your acceptance of the Terms. If you enable two-factor authentication, we store the authentication secret needed to verify your codes. If you sign in with Google (where offered), we receive your name and email address from Google as your login provider. An account is optional: you can also book as a guest (section 2.5).
2.2 The map and your location
When you open the map, your device or browser asks for permission to use your location. We use it at that moment to show nearby toilets and, when you book, to check that you are within walking distance. We do not track you in the background, we do not build a location history, and we do not use your location for anything else. Map tiles and address lookups are provided by Mapbox with telemetry disabled. If a dispute arises about a booking, a limited snapshot connected to that booking can serve as evidence for at most thirty days (section 5).
2.3 Booking and visiting
A booking record contains the booking reference, the chosen toilet, timestamps and status, the price breakdown, and your one-time access code. The host verifies your code, never your identity: your name, profile, and contact details are not shared with the host, and the Host Addendum forbids hosts from collecting visitor data. Because a booking links a place to a time, we treat this data with the same care as location data.
2.4 Paying
Top-ups and payments run through Stripe as independent controller (section 1). We process the transaction references, amounts, currencies, fee breakdown, and payout references needed to operate the marketplace, plus fraud signals that Stripe's systems (such as Stripe Radar) return to us so that we can prevent abuse. If you pay in another currency, we process the exchange rate and margin shown to you before payment.
2.5 Guest checkout
If you book without an account, we process only your email address (to send your access code and the legally required booking confirmation), the booking and payment references, and your recorded acceptance of the Terms. No account or payment profile is created; the data serves exactly one visit.
2.6 Reviews
A review contains your text, your rating, the publication date, and the date of the visit it concerns, linked to your account. When your account or the listing is deleted, the review is removed or anonymised. We never pay for reviews.
2.7 Becoming and being a host
For hosts we process business and contact details, the toilet's location and photos (reviewed by our moderation before publication), the VAT number with its VIES verification result, your trader or non-trader declaration, your Stripe Connect account reference, payout and invoice data, and the tax fields (tax identification number, property address, and cadastral reference) that EU platform tax reporting rules (DAC7) may require us to collect, verify, and report to the Dutch tax authority, which exchanges them with the tax authority of your country. For sole-trader hosts, business data such as invoices are also personal data and are treated as such.
2.8 Support, complaints, and disputes
When you contact us we process the correspondence, your booking reference, and the evidence needed to assess a claim, such as booking records, timestamps, and the limited location snapshot mentioned in section 2.2. Dispute evidence is kept for thirty days after the visit unless a dispute is ongoing. If a complaint goes to out-of-court dispute resolution, the file is shared with the competent body, such as the consumer mediator CM2C for French disputes; these bodies act as independent controllers.
2.9 Reports, moderation, and serious incidents
Reports about listings, reviews, or users are processed under the Digital Services Act: we record the report, our assessment, and our reasoned decision. For reports of serious criminal offences, such as hidden recording equipment, we keep a separate, strictly access-controlled incident file that can include criminal-offence data and victim data; we process it under Article 10 GDPR in conjunction with Dutch implementing law, follow a fixed internal protocol, notify the competent authorities where the law requires, and destroy the material when it is no longer needed.
2.10 Legal records
To be able to demonstrate compliance, we keep server-side records of your cookie choices, your acceptance of the Terms, and any withdrawal declarations you submit through the withdrawal function, each with timestamp and version.
2.11 Email
We send transactional email (access codes, booking confirmations, receipts, security messages) through our email service providers. Marketing email is sent only if you opted in, and every message contains a one-click unsubscribe; your opt-out is logged so we can honour it.
2.12 Cookies and technical logs
The website and app use only strictly necessary cookies: security and bot-protection cookies (Cloudflare), your login session (Supabase), Stripe's fraud-prevention cookies during payment, your own language and currency choice, and the cookie that remembers your cookie decision. Usage statistics are off by default and only ever activated with your opt-in consent through the cookie banner, where you can also change your choice at any time. Our infrastructure keeps standard security and access logs for a limited period. There are no advertising cookies and no third-party trackers.
3. Why we process your data, and on what legal basis
- Performance of our contract with you (Article 6(1)(b) GDPR): your account, the map and distance check, bookings and access codes, payments and payouts, reviews, and support.
- Legal obligations (Article 6(1)(c)): keeping the tax-relevant core of transactions, sending the consumer-law confirmations on a durable medium, platform tax reporting where DAC7 requires it, and notifying authorities of serious offences where the Digital Services Act requires it.
- Legitimate interests (Article 6(1)(f)): preventing fraud and abuse, moderating photos and reports, handling disputes with the evidence described above, and securing our network. We have balanced these interests against your rights; the outcome is documented internally, the data used is data we already hold for the service, decisions are made by a person and not automatically, and you can object at any time (section 7).
- Consent (Article 6(1)(a)): marketing email and optional usage statistics. Your device's location permission is the technical layer required by privacy law; the processing itself is needed to perform the service you request.
We do not use automated decision-making with legal or similarly significant effects, and we do not profile your visiting behaviour. Visit patterns could in theory hint at health; we therefore deliberately never analyse visit frequency, never log your use of accessibility filters, and never share visit data with anyone.
4. Who we share data with
4.1 Processors working for us
- Supabase: database, authentication, and storage, hosted in the EU.
- Mapbox: map tiles and address lookups (United States, see section 6), telemetry disabled.
- Cloudflare: content delivery, security, and the cookie banner (United States, see section 6).
- Email service providers: delivery of transactional and, with your consent, marketing email.
- Moneybird: bookkeeping and invoicing, in the Netherlands.
4.2 Independent controllers
- Stripe Technology Europe, Limited for payments and your Credit balance (section 1).
- Consumer mediators and dispute-resolution bodies when you escalate a complaint (section 2.8).
- Insurers and legal advisers if a claim or legal proceeding requires it.
- Public authorities where the law requires it: tax authorities, supervisory authorities, and law enforcement in response to valid legal requests or under our duty to report serious offences. We check every request and share no more than legally required.
4.3 Who we never share with
We never sell or rent your data. We share nothing with advertisers or data brokers. And hosts never receive your identity: not your name, not your email address, not your profile. The only thing a host can verify is your one-time access code.
5. How long we keep your data
- Account data: until you delete your account; deletion anonymises your profile immediately, or after the optional seven-day window you can choose to use up your Credit.
- Bookings and reviews: operationally until account deletion; reviews are then removed or anonymised.
- The tax-relevant core of transactions (amounts, dates, invoice data): seven years, as Dutch tax law requires, in minimised form and disconnected from your profile.
- Dispute evidence, including any location snapshot: thirty days after the visit, unless a dispute is ongoing.
- Consent, acceptance, and withdrawal records: as long as needed to demonstrate compliance.
- Support correspondence: up to two years after the file is closed.
- Serious-incident files: only as long as the investigation, proceedings, or legal claims require, reviewed at least yearly, then destroyed.
- Security and email delivery logs: for the limited standard periods of our infrastructure providers.
6. International transfers
Your data is stored in the EU. Two service providers, Mapbox and Cloudflare, process limited data in the United States. Both are certified under the EU-US Data Privacy Framework, and we additionally have the EU Standard Contractual Clauses in place with them, so the transfer remains lawful even if the Framework is ever suspended or invalidated; in that case we would also carry out a renewed transfer assessment. No other transfers outside the EEA take place.
7. Your rights
You have the right of access, the right to rectification, the right to erasure, the right to restriction of processing, the right to object (including to any processing based on legitimate interests, and always to direct marketing), the right to data portability, and the right to withdraw consent at any time without affecting earlier processing.
The two most common rights are built directly into the product: in your profile you can download a machine-readable copy of your data, and you can delete your account immediately, without waiting periods. For everything else, email support@relievedapp.com; we may ask you to confirm control of your account email, and we respond within one month. Exercising your rights is free.
8. Complaints
If you believe we handle your data incorrectly, contact us first at support@relievedapp.com and we will try to resolve it. You also always have the right to lodge a complaint with a supervisory authority (Article 77 GDPR): with the Dutch Autoriteit Persoonsgegevens as our lead authority, or with the authority of your own country, such as the CNIL in France, the Garante in Italy, or the AEPD in Spain.
9. How we protect your data
All traffic is encrypted in transit (TLS with HSTS) and data is encrypted at rest. Database access is restricted with row-level security, passwords are stored only as hashes, two-factor authentication is available on every account and enforced on our own administrative access, and access codes are single-use. By design there is no background location, no location history, no third-party analytics, and no advertising identifiers. If a breach is ever likely to pose a risk to you, we will notify the supervisory authority within 72 hours and inform you where the law requires.
10. Children
Relieved is for adults. You must be at least 18 to use the platform, and you confirm this when registering or paying as a guest. We do not knowingly process children's data; if we learn that we do, we delete it. Parents or guardians can contact support@relievedapp.com.
11. Changes to this policy
We may update this policy. For material changes we will notify you at least 21 days before they take effect, by email or in the app, consistent with how we announce changes to our Terms; where required or appropriate we will ask you to actively confirm again. The current version is always available at relievedapp.com/privacy, and the version number at the top tells you what applies.
12. Contact
- REBA Software (operating as Relieved)
- Prins Hendrikstraat 51, Egmond aan Zee, the Netherlands
- Chamber of Commerce (KVK): 42051273
- Privacy contact: support@relievedapp.com · relievedapp.com
© 2026 REBA Software · Relieved · Privacy Policy version 2026-07
← Relieved