Privacy Policy
1. Introduction
This Privacy Policy describes how Listo ("we," "us," or "our") collects, uses, and protects your personal information when you use Listo ("the Service").
During registration, you will be asked to explicitly accept this Privacy Policy. If you do not agree, please do not use our Service.
2. Information We Collect
Information You Provide
- Account Information: Phone number, email address, username
- Profile Information: Display name, profile picture (optional)
- Content: Posts, photos, videos, and other media you choose to create or share, including any location tags you add to your content
- Communications: Messages you send to us for support
- SMS Verification: Phone number and related messaging metadata (such as delivery status and timestamps) when you use SMS-based account verification
Information We Collect Automatically
- Usage Data: How you use our app, features accessed, time spent
- Device Information: Device type, operating system, IP address
- Location Data: General location (city/region) only when you choose to share it for relevant recommendations. If you tag a location on a post, that location becomes part of your content.
- Advertising Identifiers: Device advertising IDs (IDFA on iOS, Advertising ID on Android) to deliver personalized ads and measure ad performance
- Calendar Access: If you grant permission, we may write events to your device calendar when you choose to save an event from Listo. We do not read or access any existing calendar entries.
Information from Third Parties
- Social Login: If you sign in with Google or Apple, we receive basic profile information (name, email address) from those services
- Contacts: If you choose to sync your device contacts, we collect names, phone numbers, and email addresses from your address book to help you find people you may know on Listo. This is always optional. You can revoke contact access and request deletion of synced contact data at any time through the app settings.
- Public Event and Venue Data: Event and venue information from publicly available sources
3. How We Use Your Information
We use your information to:
- Provide and maintain our Service
- Create and manage your account
- Verify your identity via your phone number
- Show you relevant event recommendations
- Power social features, including suggesting people you may know based on your contacts, mutual connections, and in-app interactions
- Add events to your device calendar when you choose to save them, if you have granted calendar permission
- Deliver personalized advertisements
- Measure advertising effectiveness and improve our ad services
- Respond to your support requests
- Improve our Service and develop new features
- Ensure security and prevent fraud
- Comply with legal obligations
We may also use aggregated, anonymized data (which cannot identify you) to improve our services and, in the future, to provide insights to partners.
Advertising and Analytics
We use advertising identifiers and usage data to:
- Show you personalized ads based on your interests and app usage
- Measure how well advertisements perform
- Understand how users interact with our Service
- Improve the relevance of ads you see
We do not directly share personally identifiable information with advertising partners. Our advertising partners access data through their own SDKs and tools operating within our app, subject to your device-level privacy settings and permissions.
4. How We Share Your Information
Public Information
When you make a post public, the following may be visible to anyone:
- Your posts, photos, videos, and any location tags on that content
- Attribution associated with your posts (e.g., your username)
- Your public profile information
You control the audience for each post — public, followers only, or private.
Service Providers
We may share information with third-party service providers who help us operate our Service:
- Cloud hosting and infrastructure providers
- Analytics services
- Customer support tools
- Security services
- SMS and communication providers
We require these providers to protect your information and use it only for the services they provide to us. No mobile information will be sold or shared with third parties or affiliates for marketing or promotional purposes. Phone numbers collected for SMS verification are shared only with our messaging platform provider as necessary to deliver verification codes, and to comply with legal obligations.
Advertising Partners
We work with third-party advertising partners whose SDKs operate within our app. These partners may collect advertising identifiers and usage data to deliver personalized ads and measure ad performance. They may combine this information with data from other apps and websites in accordance with their own privacy policies. You can limit this through your device's privacy settings.
Affiliate Partners
Some content in the Service may be associated with affiliate relationships through which we may earn a commission. This is disclosed within the app. Affiliate partners may receive limited data related to clicks or transactions (such as a session identifier) but do not receive your personal profile information.
Legal Requirements
We may disclose your information if required by law or to:
- Comply with legal processes
- Protect our rights and safety
- Prevent fraud or illegal activities
5. Data Security
We implement reasonable security measures to protect your information, including:
- Encryption of data in transit
- Secure data storage
- Limited access controls
- Regular security assessments
However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected users and applicable regulatory authorities as required by applicable law.
6. Data Retention
We retain your information for as long as your account is active or as needed to provide our Service. You can delete your account at any time through the app settings.
Specific retention periods:
- Account data (including phone number): Until account deletion
- Synced contact data: Retained while your account is active. You may request deletion at any time through the app settings. Data is deleted upon account deletion.
- Advertising data: Retained according to our advertising partners' policies, typically 12–24 months
7. Your Rights and Choices
Account Control
- Access and update your profile information
- Delete your account and associated data
- Control the audience for each post (public, followers only, or private)
- Manage notification preferences
Communication Preferences
- Opt out of promotional emails
- Control push notifications
Contacts
- Sync your device contacts to find people you may know — this is always optional
- Revoke contact access at any time through your device settings
- Request deletion of previously synced contact data through the app settings
Location Data
- Location sharing for recommendations is always optional
- You choose whether to tag a location on any individual post
Calendar
- Granting calendar access is always optional
- We only write to your calendar — we never read existing entries
- You can revoke calendar access at any time through your device settings
Data Portability
You may request a copy of the personal data we hold about you in a structured, commonly used format. To make a portability request, contact us at help@mylisto.app. We will respond within 30 days.
Advertising Choices
We present an in-app privacy prompt before enabling personalized advertising. You can update your ad preferences at any time through the privacy controls in the app settings.
iOS Users:
- On first launch you will be asked whether to allow tracking across other apps and websites via Apple's App Tracking Transparency prompt
- You can change this at any time through your device settings
- Even if you decline tracking, you will still see ads, but they will be less relevant to your interests
Android Users:
- Control ad personalization through your device settings
- You can opt out of personalized ads or reset your advertising ID
- Visit www.aboutads.info for additional opt-out options
Note: Opting out of personalized advertising does not mean you will see fewer ads; it means the ads you see will be less relevant to your interests.
8. Region-Specific Rights
European Union (GDPR)
If you're in the EU, you have additional rights:
- Access: Request information about your personal data
- Correction: Fix inaccurate information
- Deletion: Request deletion of your data
- Portability: Receive your data in a portable format — contact help@mylisto.app and we will respond within 30 days
- Objection: Object to certain types of processing
- Restriction: Request that we restrict processing of your data in certain circumstances
Contact us at help@mylisto.app to exercise these rights.
Legal Basis for Processing
Under GDPR Article 13, we are required to inform you of the legal basis on which we process your personal data:
| Processing Activity | Legal Basis | |---|---| | Creating and managing your account | Contract — necessary to provide the Service | | Phone number verification | Contract — necessary to provide the Service | | Showing event recommendations | Contract — necessary to provide the Service | | People You May Know / contacts sync | Consent — opt-in, revocable at any time | | Location sharing for recommendations | Consent — opt-in, revocable at any time | | Calendar write access | Consent — opt-in, revocable at any time | | Personalized advertising | Consent — obtained via in-app consent prompt | | Analytics and usage data | Legitimate interest — improving and securing the Service | | Fraud prevention and security | Legitimate interest — protecting users and the platform | | Complying with legal obligations | Legal obligation |
Where we rely on consent, you have the right to withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. Where we rely on legitimate interest, you have the right to object. Contact us at help@mylisto.app to exercise either right.
California (CCPA/CPRA)
California residents have the right to:
- Know what personal information we collect and how we use it
- Correct inaccurate personal information
- Delete personal information
- Limit the use of sensitive personal information (including phone number) to what is necessary to provide the Service
- Opt out of the sale or sharing of personal information
We do not sell your personal information. We do share advertising identifiers with third-party advertising partners for cross-context behavioral advertising as described in Section 4. California residents may opt out of this sharing at any time through the privacy controls in the app settings, which will switch advertising to a non-personalized mode. Contact us at help@mylisto.app to exercise any of the above rights.
Brazil (LGPD)
If you are located in Brazil, your personal data is processed in accordance with the Lei Geral de Proteção de Dados (LGPD — Law No. 13,709/2018). You have the right to:
- Confirmation: Confirm whether we process your personal data
- Access: Request access to your personal data
- Correction: Correct incomplete, inaccurate, or outdated data
- Anonymization, blocking, or deletion: Request anonymization, blocking, or deletion of unnecessary or excessive data, or data processed in non-compliance with the LGPD
- Portability: Request portability of your data to another service provider
- Deletion: Request deletion of personal data processed with your consent
- Information: Obtain information about public and private entities with which we have shared your data
- Objection: Object to processing carried out on grounds other than your consent if you believe it is non-compliant with the LGPD
- Consent revocation: Withdraw consent at any time
Legal Basis for Processing (LGPD)
We process your personal data under the following legal bases as defined by the LGPD:
- Execution of a contract (Art. 7, V): account creation, phone verification, event recommendations
- Consent (Art. 7, I): contacts sync, location sharing, calendar access, personalized advertising
- Legitimate interest (Art. 7, IX): analytics, fraud prevention, security
- Legal obligation (Art. 7, II): compliance with applicable laws
Data Protection Contact: For any LGPD-related requests or to contact our designated data protection representative, reach us at help@mylisto.app. We will respond within 15 days as required by the LGPD.
Canada (Quebec Law 25 / PIPEDA)
If you are located in Canada, including Quebec, your personal information is handled in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and, for Quebec residents, the Act Respecting the Protection of Personal Information in the Private Sector (Law 25).
You have the right to:
- Access: Request access to the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete personal information
- Withdrawal of consent: Withdraw consent to the collection, use, or disclosure of your personal information, subject to legal or contractual restrictions
- Portability: Request that we provide your personal information in a structured, commonly used technological format — contact help@mylisto.app and we will respond within 30 days
- De-indexing: Request that we cease disseminating your personal information or de-index any hyperlink attached to your name that provides access to information about you, where dissemination causes you harm or the information is no longer accurate
Privacy Officer: We have designated a person responsible for the protection of personal information. To reach them or to exercise any of the above rights, contact help@mylisto.app. We will acknowledge your request promptly and respond within 30 days.
Automated Decision-Making: We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects without human involvement.
9. Third-Party Services
Our Service may contain links to other websites or integrate with third-party services. These have their own privacy policies, and we are not responsible for their practices.
10. Children's Privacy and Age Requirements
Age Requirement: Our Service is intended for users 18 years of age and older only. We do not knowingly collect personal information from anyone under the age of 18.
Child Safety Commitment: If we discover that we have collected personal information from someone under 18, we will:
- Delete the information immediately
- Terminate the account
- Take steps to prevent future access
Parental Notice: If you are a parent or guardian and believe your child under 18 has provided us with personal information, please contact us immediately at help@mylisto.app so we can delete the information and terminate the account.
Reporting Underage Users: If you believe someone under 18 is using our Service, please report it to help@mylisto.app with the subject line "Underage User Report."
Age Verification: We rely on users to provide truthful information about their age during registration. Creating an account with false age information violates our Terms of Service and will result in account termination.
11. International Data Transfers
Your information may be transferred to and processed in countries other than your own, including the United States. Where required by applicable law, we ensure appropriate safeguards are in place for such transfers, including Standard Contractual Clauses for transfers from the European Union and equivalent measures for other jurisdictions.
12. Changes to This Policy
We may update this Privacy Policy occasionally. We will notify you of material changes through the app or by email. Continued use of the Service after changes take effect constitutes acceptance of the updated policy. For material changes, we may require you to re-confirm your acceptance.
13. Contact Us
Questions about this Privacy Policy or to exercise any of your rights? Contact us at help@mylisto.app.
Last Updated: April 6, 2026
PP-EN-V3-20260413