Privacy Policy
Last updated 1 October 2026
PeoplePlusPlaces (“P+P”, “we”, “us”) helps a household know that the people they look out for are where they're expected to be, and helps them in an emergency. This policy explains what we collect, why, who can see it, how long we keep it, and the choices and rights you have.
1. Who we are
PeoplePlusPlaces is provided by NextNow Group (Pty) Ltd, 120 Bellairs Drive, Noordhang, 2169, South Africa (“we”, “us”). We are the responsible party (South Africa, POPIA) and data controller (Nigeria, NDPA) for the personal information described here.
Privacy enquiries: Privacy Officer, privacy@peopleplusplaces.com.
2. What we collect, why, and who can see it
| Information | Why we use it | Who can see it |
|---|---|---|
| Your mobile number | Your account; sign-in by a one-time code sent by text message; reaching you in an emergency if you are someone's trusted contact | Us. People who invite you see the number they typed |
| The name you choose, and how you describe the people in your household (e.g. “partner”) | Showing your household who is who | Members of your household |
| Your household, and invitations you send or accept | Bringing the people you look out for together | Members of that household. An invitation's details (the number, the name typed and how the person was described) are removed once it is no longer needed (section 7) |
| Other people's names and mobile numbers that you give us: when you invite someone (their number, and the name you call them), or add someone without a phone (e.g. an older relative) by name only. We never read your phone's address book: you type these in. | Making sure an invitation reaches the person you meant (when they join, their number must match); showing your household who is who; including people without a phone in plans and places | Their name: members of that household. Their number: you, us, and the person themselves. Please only add someone who would expect it |
| Children added by their parent or guardian: name, how they relate to you, and date of birth | Including them in your household's plans and places; applying the protections for their age (see section 9) | Their name: members of the household. Their date of birth: only the child and their guardians |
| Your date of birth (asked once when you create an account) | Applying the 13+ minimum and the protections for under-18s | You, and, if you are under 18, your guardians |
| Your location (precise, or approximate if that is all your phone allows), only while you choose to share it (“while using the app” or “always”) | Showing where you are to the specific people you chose; recognising when you arrive at or leave your places; confirming plans | Only the people you chose, only while you share |
| Places you save (e.g. Home, School) and their location | Recognising arrivals and departures | You, and the people you choose for each place |
| Arrivals, departures, and plan outcomes (e.g. “arrived 08:17”, “unable to confirm”) | Today's view, alerts you asked for, and plans | The people you share arrivals with |
| SOS and help requests: when, your location at that moment, and the place if it is one of yours | Alerting your trusted contacts by notification and text message; where available and included in your household's plan, asking a professional responder to help | Your trusted contacts; a responder, if one is requested |
| Device state, sent only while you share your location with at least one person: whether P+P has location permission (and which kind), whether location services are on, whether battery saver or Low Power Mode is on or off (never your battery level), whether the app is open or in the background, and whether your phone can watch your places in the background; with the app version, the platform (iPhone or Android) and a random ID for this installation of the app. We keep only the latest state, not a history | Telling the people you share with honestly when your location can't be updated (for example “location permission is off on their phone”), instead of showing an old location as current | Us. The people you share with see only a plain status such as “can't update location”, never the details |
| Your phone's notification token (issued by Google Firebase) and platform | Delivering notifications to this phone | Us, and Google to deliver the notification |
| Plan and subscription status (never card details) | Giving your household the plan it has | You. Other members see which plan the household has and who manages it, never the price |
| Usage analytics (optional, off unless you switch it on: Profile → Share usage analytics): which features and steps are used, as named events with a few choices attached (for example “place saved” with the kind of place, or “invite sent” with the method); a random ID for this installation of the app and a session ID; your phone's operating-system version; app version, platform and the country you chose. Nothing is sent before you sign in, or while it is off. When it is on, each event is stored individually and linked to your account, and our servers also record a few events themselves (for example a trial starting, or an arrival being detected: how it was detected, how late, and the kind of place, never where) | Understanding which features help and where people get stuck, so we can improve them | Our team only; we don't share it. It never includes your location, place names, addresses, phone numbers, names or anything you type. You can switch it on or off at any time (section 8) |
| IP address and the app's technical “user agent” (which names the app's networking software, not your phone model), recorded when you sign in (with your sign-in session) and when you ask for a sign-in code | Security: protecting your account, limiting repeated attempts, and investigating misuse | Us |
| Crash reports (Firebase Crashlytics: what the app was doing when it failed, phone model and operating system, and a random ID that Firebase gives this installation), only while Share usage analytics is on. While it is off, crash reporting is switched off and reports waiting on the phone are deleted, not sent | Finding and fixing faults | Our team and our crash-reporting provider. We attach no account, name or number to a crash report |
We do not use your location for advertising, we do not sell personal information, and we do not build profiles of you for anyone else.
Server and network logs. Like any internet service, our servers and our network provider (Cloudflare) see the IP address of every request, with its time and the address requested. We use these logs only to deliver the service, keep it reliable and protect it (for example, limiting how often a code can be requested, and investigating attacks or misuse), not for analytics and not to work out where you are. Operational and security logs are kept for a limited period according to security and operational requirements, and then deleted. Records the service needs to work and stay safe (sign-in sessions, delivery of alerts, the app version your phone uses so we can tell you when an update is required) are kept for their purpose only, whether or not usage analytics are on, and are never used as analytics.
3. Location, precisely
- P+P collects your location only while you share it with at least one person. Turning sharing off (per person, or entirely) stops collection. When you share with no one, the app also stops sending its device state (section 2).
- If you press SOS or ask for help, your location at that moment is sent even if you aren't sharing, because you asked for help (section 4).
- “While using the app” collects location only while P+P is open. “Always” also collects it in the background, which is what lets your household know you arrived when your phone is in your pocket. Your phone's settings show and control this at any time.
- A location that isn't fresh is always shown with its age (“18 min ago”), never as live.
- Area names for shared locations. When someone shares their location with you, our servers name the area they are in (for example “Northcliff, Johannesburg”), so your phone never sends another person's location to Apple or Google to look it up. To do this, our servers send our geocoding provider (Google Maps Platform) only an approximate point: the centre of a square of about 150 metres that the position falls in, never the exact position and never who it is. We keep only the area name, for that square, for up to 30 days, so the same area isn't looked up again. If someone is at one of your household's places, you see the place's name (“Home”) instead and no lookup is made.
- Address search for your own places. When you search for an address or drop a pin to save one of your places, your phone's own built-in geocoding service does the lookup: Apple's on iPhone, and Google's (through Google Play services) on Android. The text you search, or the pin's coordinates, go to Apple or Google for that purpose. We receive only the address you choose to save with a place.
- Raw location points are kept for a short period and then deleted (30 days — to be confirmed in the final policy). Arrivals, departures and plan outcomes are kept as part of your household's history while your account exists.
4. Safety features
- When you hold SOS or ask for help, your trusted contacts receive a notification and, for SOS, a text message. These contain your first name and, if known, the place and how recently your location was updated — not your coordinates.
- Where a professional response service exists and is included in your household's plan (currently in parts of Nigeria), your SOS location is shared with the responders of that service so they can reach you. P+P always tells you whether a responder was assigned.
- P+P is not an emergency service. In an emergency, call your local emergency number.
5. Who we share information with
Only the people you choose in the app, and these service providers who process it for us under contract and only on our instructions:
| Provider | Purpose | Where |
|---|---|---|
| DigitalOcean | Hosting our servers and database; encrypted backups | United Kingdom (London); backups in Germany (Frankfurt) |
| Google (Firebase Cloud Messaging, Firebase Crashlytics) | Delivering notifications; crash reports and diagnostics (device and app information, not linked to your account) | Global, including the United States |
| Google Maps (Maps SDK) | Showing maps. To show maps, Google receives technical and usage information about map use (such as device identifiers, IP address, performance and crash data), under Google's own terms | Global, including the United States |
| Google Maps Platform (Geocoding API), used by our servers | Naming the area of a shared location (section 3). Google receives only an approximate point (a square of about 150 metres), with no name, number or account | Global, including the United States |
| Apple (on iPhone) and Google (Google Play services, on Android): your phone's built-in geocoding | Address search when you save one of your own places (section 3). Apple and Google provide these services as part of your phone's operating system, under their own terms | Global, including the United States |
| Text-message gateways (e.g. BulkSMS) | Sign-in codes and SOS text messages | South Africa; Nigeria; and international carriers as needed to deliver a message |
| Cloudflare; Microsoft 365 | Our website and domain; our email | Global |
We may also disclose information where the law requires it, or where necessary to protect someone's life or safety.
Payments. In this Beta, paid plans can't yet be bought: households use the free plan, a free trial or a sponsor's plan, none of which needs payment details. When paid plans are offered, payment will be taken on a secure payment page from a payment provider, opened in your browser, and we will name that provider here before then. The payment provider will handle your card or payment details; we will receive only the subscription status (plan, price, period and dates), never your card details.
Sponsors. A school, employer, insurer or other sponsor may pay for features for your household. Sponsors receive no information about your household, your location or your activity.
6. Transfers outside your country
Our servers are in the United Kingdom and our backups in Germany, and some providers operate in the United States. We transfer personal information only to providers bound by contract to protect it to a standard at least equivalent to POPIA and the NDPA, or as otherwise permitted by those laws.
7. How long we keep information
- While your account exists: your account, household, places, plans and history.
- Raw location points: a short period (30 days).
- Device state: only the latest state for each phone, replaced each time it reports, while your account exists.
- Usage analytics (only if you switched them on): deleted 180 days after we receive them, or sooner when your account is deleted.
- Invitations: the number, the name typed and how the person was described are kept while the invitation can still be used. They are removed 30 days after it expires, is accepted, declined or withdrawn (once someone has joined, their own account and household membership hold what the household needs). A record that an invitation was sent, without those details, remains.
- Area names: kept per area square (no person, no exact position) for up to 30 days.
- Server and network logs (IP address, time, address requested): for a limited period according to security and operational requirements.
- IP address and user agent: on sign-in codes, deleted 7 days after the code was requested; on sign-in sessions, cleared 90 days after the session was last used.
- When you delete your account: sharing stops immediately. You can change your mind by signing in again within a limited period (90 days) and choosing to reactivate; your household, places and plans are kept until then, and sharing stays off until you turn it back on. After that, you leave your household and information about you — location, presence, devices, safety events, sharing choices, private places, sign-in sessions and codes, and usage analytics (including the analytics this installation sent before you signed in) — is deleted. Places you shared with your household remain with the household without naming you.
- Backups are encrypted and kept for up to 30 days, after which deleted information no longer exists in them.
- We may keep limited records longer where the law requires it. Subscription and trial records are kept after an account is deleted while we confirm what the law requires.
8. Your choices and rights
- Change what you share with each person, or stop sharing, at any time in the app.
- Choose who your SOS alerts (your trusted contacts) in the app.
- Usage analytics and crash reports are off unless you switch them on (Profile → Share usage analytics), and you can switch them off again at any time. While off, the app sends no analytics and no crash reports, and our servers record no analytics events for your account. Either way, safety alerts, location sharing, notifications and the records we need to run them work the same.
- Delete your account in the app (Profile → Delete account), or see peopleplusplaces.com/delete-account.
- Ask for a copy of your information, its correction, or its deletion, or object to a use of it, by writing to privacy@peopleplusplaces.com. We will respond within the time the law requires.
- You may complain to the Information Regulator (South Africa) or the Nigeria Data Protection Commission. We'd appreciate the chance to resolve your concern first.
9. Children and guardians
Children can be part of a household. A child's information is controlled by their guardians: the parent or legal guardian who added them, and any other adult that guardian explicitly adds. Being in the household, being its administrator, paying for its plan, sponsoring it, or describing yourself as the child's “parent” in the app gives no one a guardian's authority.
- Under 13: a child does not have their own account. Their guardian adds them by name, relationship and date of birth, confirming that they are the child's parent or legal guardian, and can include them in the household's places and plans. We collect no location from a child under 13.
- 13 to 17: a young person can have their own account, but joins their household only through an invitation from their guardian, which links the account to the person their guardian already added. Until then they cannot join a household, and their location is shared with no one. While they are under 18, their location, arrivals and safety alerts can be shared only with their guardians, never with anyone else in the household; their guardians are always alerted if they use SOS. Only a guardian can make plans about them, see those plans' outcomes, or remove them from the household.
- At 18: guardian authority ends automatically. The account, the household and the history stay the same; from then on the person alone decides what they share.
- Under 13s cannot use P+P on their own. If someone tells us they are under 13 when signing up, they can't go further, and we don't keep the date of birth they gave.
In this Beta we do not independently verify that an adult is a child's parent or legal guardian; we rely on, and record, their confirmation. A guardian can remove a child from the household in the app. To see, correct or delete a child's information, a guardian can write to the Privacy Officer at privacy@peopleplusplaces.com.
10. Security
Information is encrypted in transit; our database and backups are encrypted at rest and access is restricted to the people who run the service. Location is visible only to the people each person chooses. No system is perfectly secure; to report a vulnerability, write to the Security Team at security@peopleplusplaces.com.
11. Changes
We'll tell you in the app before a material change takes effect.
12. Contact
- Privacy enquiries: Privacy Officer — privacy@peopleplusplaces.com
- Security enquiries: Security Team — security@peopleplusplaces.com
- Support: PeoplePlusPlaces Support — support@peopleplusplaces.com
- Post: 120 Bellairs Drive, Noordhang, 2169, South Africa