Spree Technologies, LLC ("Spree," "we," "our," or "us") respects your privacy. This Privacy Policy describes how we collect, use, disclose, share, and otherwise process information when you access or use the Spree mobile application, the website at spree-app.com and related domains, and our other services and features (collectively, the "Services").
This policy explains our practices; it is not a request for blanket consent to every use of information. We request permission or consent separately where required, including for optional location sharing and certain marketing communications.
1. Who This Policy Applies To
This Privacy Policy applies to information we collect through the Services from users in the United States, including consumers and people using authorized venue, organizer, promoter, scanner or other business features.
The Services are intended exclusively for individuals who are at least twenty-one (21) years of age. We do not knowingly permit people under 21 to use the Services. If we learn that an account belongs to someone under 21, we will close it and delete or restrict the associated information, except for records we must or may lawfully retain for a specific legal, transaction or safety purpose. Contact [email protected] if you believe someone under 21 is using Spree.
2. Information We Collect
2.1 Information You Provide
When you create an account, make purchases, join social features, or otherwise use the Services, you may provide:
- Identifiers and contact information: name, phone number, email address, username, and similar identifiers. Consumer sign-in uses a one-time passcode sent to your phone number; we do not issue a consumer account password.
- Age and profile information: date of birth, gender selection, profile photo, display name, optional Instagram username, preferences and visibility choices. If additional age or identity verification is needed, we explain the information requested and relevant handling at that time.
- Social information and content: follows and mutual connections; invitations, group membership and roles; group names and covers; plans, participation responses, stops and private/custom places; chat text and photos; reports and other content you submit.
- Transaction information: purchases, passes, tickets, payments, redemptions, refunds, rewards and related details. Payment providers receive the payment credentials needed to process your payment; Spree does not store your full card number.
- Reservation information: requested date and time, party size, arrival window, and preferences or notes you submit for a table or bottle service request.
- Communications: messages and feedback you send to us, including email and support requests, and information supplied in a content or safety report.
- Referral and sharing information: referral codes, invitation/share links and associated tokens, and records of referrals, link interactions and host or promoter attribution.
2.2 Events and Photography
Spree or photographers working for it may photograph or record activities that Spree organizes or operates. Subject to the event notices and applicable law, images may be used for event recaps and promotion as described in Section 13 of the Terms. Separate permission is sought for featured advertising subjects or endorsements. Independent venues and organizers have their own practices. Photos uploaded to private chats and groups are not made available for advertising by this provision. Contact event staff or [email protected] about photography concerns.
2.3 Information Collected Automatically
When you access or use the Services, we and our service providers may automatically collect:
- Device and session information: device and operating-system details, app version, browser details, IP address, session and authentication records, app-install identifiers, push-notification tokens and delivery status.
- Usage and operational information: screens and features viewed, actions taken, invitations, participation responses, venues and events viewed, ticket activity, scans, redemptions, rewards, timestamps and relevant administrative activity.
- Location information: approximate location derived from IP address or city-level signals and, with your permission, precise device location for features such as nearby venues, distance calculations and optional plan sharing. Plan sharing is explained below.
- Log and diagnostic data: access logs, crash or error information, performance data, referring URLs and information used to investigate security or payment problems.
- Link attribution: the link token and relevant event, venue, sharer or promoter, along with opening times and platform. We can associate link interactions with a browser session, app installation or signed-in account, and associate earlier guest interactions with your account when you sign in. For supported links opened shortly before installation or sign-up, we may compare a hashed IP address and device type to match the link. An uncertain match may require manual code entry or may not be attributed.
- Cookies, local storage and similar technologies: as described in Section 7.
Optional plan location sharing requires a separate choice for the particular plan; joining a group, buying or scanning a ticket, or granting general location permission does not activate it. Eligible participants in that plan who are also sharing can see your latest available location and its update time. A leader or admin has no additional access merely because of that role.
On supported iOS devices, active sharing may continue in the background or while the phone is locked with the required background permission. Android sharing currently updates only while the app is in the foreground. A scheduled share starts once its start time has arrived and you next open or use the app with the necessary permissions. Connectivity, device settings and operating-system limits can delay or prevent updates.
You can stop sharing in the plan and change device permissions. The applicable sharing period, plan end, leaving or removal, ineligibility and blocking also restrict access. The feature shows your latest available position, rather than a route history. Section 8 explains retention. Private plan coordinates are not provided to a venue or promoter simply because you attend its event, and we do not use them for targeted advertising.
2.4 Information From Third Parties
We may receive information about you from:
- Partner venues, organizers, co-organizers, hosts, promoters and authorized staff in connection with your transactions, reservations, admission, scans, redemptions and support requests;
- Payment processors and fraud-prevention providers, including transaction status, payment-method details other than full card numbers, risk signals, refunds and payment disputes;
- Service providers supporting authentication, messaging, mapping, diagnostics, measurement and other operational functions; and
- Other users, including referrals, invitations, shared plans, reports and content that mentions or depicts you.
2.5 Sensitive Information
Precise geolocation is sensitive personal information under some laws. Private communications may also be sensitive, and anything you choose to upload can contain sensitive details. We use this information for the features you request, safety and security, support, dispute resolution and other purposes permitted by applicable law. General acceptance of this policy is not permission to activate optional location sharing.
We do not ask you to submit government identification documents in ordinary social use. If additional age or identity verification is needed, we will explain the information requested and the relevant handling at that time. Do not send unrelated sensitive information through chat or support.
3. How We Use Information
We use information to:
- Create and secure accounts, authenticate sessions, enforce eligibility and assigned access, and maintain preferences;
- Provide discovery, friends, invitations, groups, plans, chat, photos, guestlists and optional location sharing;
- Process tickets, payments, corrective refunds, redemptions, reservations, rewards and attribution, and reconcile related records;
- Provide authorized venue, organizer, co-organizer, promoter and staff tools, including relevant attendance, customer, sales and settlement reporting;
- Send requested notifications, service messages and security alerts, and marketing where permitted and subject to required consent and choices;
- Investigate reports, moderate content, prevent fraud, abuse and unauthorized access, and enforce our rules;
- Support users, diagnose problems, measure product performance and improve the Services;
- Produce appropriately aggregated or de-identified research and nightlife insights as described in Section 4;
- Comply with legal, financial and recordkeeping obligations, respond to lawful requests and resolve disputes; and
- Evaluate or complete a corporate transaction as described below.
We do not treat private messages or location-sharing consent as permission to use their contents in advertising.
4. De-Identified and Aggregated Data
We may derive aggregated or de-identified information ("De-Identified Data") for research, product improvement and reporting. Removing a name alone does not necessarily de-identify a record. We take reasonable measures to prevent information described as de-identified from being associated with a person, maintain it in that form, and require recipients to maintain it in that form and not attempt re-identification.
For externally published or licensed aggregate insights, each reported group includes at least 20 distinct individuals. Smaller units are suppressed or combined. Meeting a numeric threshold alone is not sufficient if the result could still reasonably identify a person. This threshold does not apply to authorized operational records needed to provide a ticket, reservation, admission, support or business service under Section 5.
We may retain and use genuinely de-identified information for lawful research, reporting and product purposes. We do not sell identifiable attendance records, private chats or precise plan locations.
5. How We Share and Disclose Information
In addition to our use and disclosure of De-Identified Data under Section 4, we may share or disclose personal information as follows:
5.1 Service Providers
We disclose information needed by providers supporting hosting, storage, authentication, messaging, push delivery, mapping, payments, security and other operational services. Providers processing information on our behalf are subject to applicable contractual restrictions. Some providers, including payment platforms, may also act independently for their own legal, fraud-prevention or payment-network responsibilities under their policies.
Stripe receives information needed for payment and connected-account services. Map providers, including Mapbox where used, may receive technical and request information when maps load. Push and message-delivery providers receive tokens, routing details and the content needed to deliver notifications. Device notification previews may expose information to someone with access to your screen; manage preview settings if needed.
We do not upload your address book to find friends. Camera or photo selection does not grant access to your entire photo library: we receive photos you choose to upload and information generated by the relevant feature, such as a QR scan.
5.2 Partner Venues, Hosts, and Promoters
Authorized businesses and staff receive information relevant to their assigned venue, organization, event, reservation or function. Depending on that role, this may include customer or attendee identity and necessary contact details, tickets, admission and scan status, reservation information, purchases and refunds, host or promoter attribution, and sales, rewards or settlement records. Not every role receives every category.
For example, a scanner needs admission information, an organizer needs relevant event operations and customer support information, and a promoter may receive information about attributed activity. These operational records can identify individual customers. Unrelated organizations and venues do not gain access merely by having an account or operating in the same city. A dashboard role does not confer access to private group chat or live plan locations.
Independent partners are responsible for their own lawful use of information they receive. A transaction or ticket is not blanket permission for unrelated marketing. Partners' separate policies may apply to their own handling, including information you provide directly at a venue.
If you submit a table or bottle service request, the venue receives the reservation details and contact information needed to evaluate and honor it. The venue may report the final closed-check amount so we can calculate associated points and reconcile the reservation.
5.3 Analytics and Measurement Partners
We may disclose technical identifiers and information about activity in the Services to providers supporting product measurement, diagnostics and attribution. Providers acting on our behalf are subject to applicable contractual limits on their use. Our own link-attribution practices are described in Section 2.3.
We do not share personal information for cross-context behavioral advertising, and we do not use third-party advertising SDKs, pixels or tags in the Services or on our website. Changes to these practices are subject to Section 6. Private chat content and private plan coordinates are not used for targeted advertising.
5.4 Mobile Information and SMS Consent
We use your phone number for authentication and permitted service communications. We do not share your mobile number or text-message marketing opt-in data with third parties or affiliates for their marketing or promotional purposes. Necessary phone and contact details may be disclosed for the operational purposes in Section 5.2 and to messaging providers to deliver requested messages; this does not authorize those recipients to send unrelated marketing. Message and data rates may apply. You can reply STOP to opt out of eligible text messages and HELP for help. Authentication may be unavailable if you cannot receive the required verification messages.
5.5 Corporate Affiliates and Transactions
We may share information with current or future affiliates and subsidiaries for purposes consistent with this Privacy Policy. In the event of a merger, acquisition, financing, sale of assets, reorganization, bankruptcy, or similar transaction, information may be transferred or disclosed as part of that transaction, including during diligence.
5.6 Legal and Safety
We may disclose information if we believe in good faith that disclosure is necessary or appropriate to: (a) comply with applicable law, legal process, subpoena, or governmental request; (b) enforce our Terms of Service or other agreements; (c) detect, prevent, or address fraud, security, or technical issues; (d) protect the rights, property, safety, or well-being of Spree, our users, venues, or the public; or (e) cooperate with law enforcement.
Authorized Spree personnel may access information needed for support, moderation, security, reconciliation and legal obligations. Reports may preserve relevant text, photos, account details and context as evidence. Chat is not end-to-end encrypted. We do not promise to screen all content before it appears.
5.7 With Your Consent
We may share information for other purposes with your consent or at your direction.
5.8 Other Users and Social Visibility
Profiles and eligible event guestlists may be visible to other eligible signed-in Spree users, according to your settings and the feature's access rules. In this context, a public profile means visibility within Spree to eligible signed-in users, rather than an anonymously accessible web profile. Public-profile, guestlist and optional Instagram visibility are enabled by default for new accounts unless changed; existing saved choices are preserved.
Your profile can show dates and public venues or events from past plans you joined and marked yourself In for. This nights-out history is visible by default to other eligible signed-in users who can view your profile. You can limit it to mutual followers or hide it in Your nights out. Public-profile settings and blocking also restrict access. Private/custom places and private group details are not included. These entries reflect past plans and do not verify attendance or a ticket scan. Your personal ticket history is shown separately to you.
Profile visibility and event guestlist visibility are separate. Hiding your full profile does not itself hide an event guestlist entry. Use the global guestlist setting and any available per-event controls. Guestlists may remain available after an event. Basic identity needed for permitted interactions, such as group membership or a message, can remain visible when your expanded profile is private.
Active group members can access the group's available plans and plan chat, including earlier messages when they join. Pending invitees receive a limited preview that may show the group's name, cover, inviter and a preview of members; it does not grant access to plans, chat or live locations. Group leaders and admins have the membership and planning permissions assigned to their roles.
Plan location is shared only through the arrangements described in Section 2.3. Blocking restricts interactions and visibility between affected accounts, but it cannot recall information already received. Other users may keep screenshots or copies outside our control.
6. We Do Not Sell Personal Information
We do not sell personal information or share it for cross-context behavioral advertising, as those terms are defined in applicable state privacy laws. We do not use private plan location or private chat content for targeted advertising. We do not use third-party advertising SDKs or advertising pixels in the Services.
If those practices change, we will provide required notices, choices and consent requests before the new activity begins. A change to this policy alone does not override a consent requirement. We use sensitive information for the requested features and other permitted operational, safety and legal purposes, subject to applicable restrictions.
7. Cookies and Tracking Technologies
The website and app use cookies, local storage, session and app-install identifiers, link tokens and similar technologies to operate and secure the Services, maintain sign-in and preferences, support link and referral attribution, and diagnose and measure product performance. Section 2.3 explains how link interactions may be connected to an account.
We do not use third-party advertising SDKs, pixels, web beacons or advertising tags in the Services. Browser controls can restrict cookies or local storage, but disabling essential storage may prevent sign-in or other features. Some information remains cached on your device until refreshed, cleared or removed.
7.1 Do Not Track and Opt-Out Preference Signals
Some browsers transmit Do Not Track (DNT) signals. The Services do not currently respond to those signals because there is no universally adopted technical response. Global Privacy Control (GPC) and other legally recognized opt-out preference signals are different; we honor them where applicable law requires.
As described in Section 6, we do not sell personal information or share it for cross-context behavioral advertising, so there is currently no such activity to opt out of. If our practices change, we will provide the notices, choices and consent requests required before the new activity begins. Contact [email protected] with questions.
7.2 Device Permissions and Notifications
You can use available profile, guestlist, blocking, location-sharing and notification controls in Spree. Device settings separately control location, camera, photo and notification permissions. Optional permissions may be denied while you continue using features that do not require them.
Camera and photo features receive the content you choose to capture or upload; selecting an image does not give Spree access to your entire photo library. We do not upload your address book to find friends. Withdrawing a device permission does not recall an image or information already shared.
Spree asks whether you want notifications and explains their purpose, including events, drops, specials and offers. Push delivery requires device permission and depends on your choices and in-app preferences. The Spree Activity category includes promotional messages and its category setting defaults to on unless you change it. We send promotional notifications subject to any required consent; the category default alone does not supply that consent. You can change notification categories in the app or disable notifications in device settings. SMS marketing consent, where offered, is separate.
Notification previews can expose message content to someone with access to your screen. Manage device previews if needed.
8. Data Retention
We retain personal information for as long as reasonably necessary to provide the relevant service, fulfill transactions, comply with legal and financial obligations, resolve disputes and address safety, fraud or abuse. We consider the information's sensitivity, whether the related account or transaction remains active, whether others still use shared content, and any specific need for continued retention. When information is no longer needed, we delete it or de-identify it.
The following criteria apply to the principal categories:
| Category | Retention criteria |
|---|---|
| Account and profile information | Maintained while the account is active. Following a verified deletion request, we close the account and process deletion or de-identification of personal information, subject to the specific transaction, legal, security and other exceptions below. |
| Account-deletion matching records | Restricted matching hashes of phone numbers and, where used, email addresses support a 90-day re-registration restriction. The restriction expires after that period; expired matching records are removed through cleanup rather than necessarily at the exact expiry time. These records remain personal information. Separate referral-eligibility, transaction or fraud records can be retained longer for their stated purposes. |
| Age and account demographic information | Retained while needed for account features and eligibility. Continued retention after account deletion is limited to a specific legal, security or transaction need, rather than continued profile display or marketing. |
| Transaction and payment records | Purchases, fees, refunds, chargebacks, payouts and related financial records are retained as needed for tax, accounting, reconciliation, payment-network rules and legal claims, including after account deletion. |
| Passes, scans, check-ins and rewards | Retained while needed to fulfill purchases, verify activity, administer benefits, provide authorized operational records or resolve disputes, then deleted or de-identified when no longer needed. |
| Referral and share-link attribution | Link interactions, attribution and benefit-eligibility records are retained while needed to apply referrals, credit authorized activity, prevent abuse and resolve disputes. Temporary installation-matching records have short matching windows and are removed through cleanup; a matching window is not a promise that all related records are erased at that exact time. |
| Groups, plans and chat | Shared history may remain while the group uses the feature. Leaving a group or ending a plan does not automatically erase it. Account deletion removes your chat text and uploaded chat photos from active chats; limited system records, other shared content and retained evidence are handled under the exceptions described here. |
| Reported content and moderation | Reported text or images are ordinarily available as report evidence for 30 days from the report. A specific documented legal or safety reason can justify a time-bounded extension. Moderation decisions and enforcement records may be retained separately to administer restrictions and prevent repeated abuse. |
| Plan location | The sharing feature uses a separate store of the latest available position, rather than a route history. Stored positions are removed when sharing is revoked or the applicable sharing period ends and are subject to stale-position cleanup. Sharing permissions, session metadata and relevant security records may be retained separately for their operational or legal purposes. |
| Support, device, log and diagnostic information | Retained according to the support, security, debugging or performance purpose, and any continuing investigation or dispute. We limit retention according to the type and sensitivity of the information. |
| De-Identified Data | May be retained longer, including indefinitely, subject to the safeguards and external-reporting rules in Section 4. |
Deleting an account does not erase copies, screenshots or messages already recorded by other people. Retained information remains subject to this policy, and shared history is not a blanket exemption from a valid privacy request.
Residual copies of information may remain in restricted backups until replaced or deleted under the applicable backup cycle. Retained copies are used only for the purposes justifying retention, such as restoration, security or legal obligations. We do not retain a deleted account merely to continue marketing to it. The active plan-location feature does not maintain a route archive for advertising.
9. Security
We use safeguards designed to protect information, including encrypted connections, authentication and access controls. Access to business and administrative functions depends on assigned roles and scope. These safeguards are not a guarantee against every error, unauthorized disclosure or loss. Private chat is not end-to-end encrypted and should not be used to send passwords, financial credentials or other unnecessary sensitive information.
Keep control of your sign-in phone number and credentials. Report suspected unauthorized access to [email protected].
10. Your Rights and Choices
Depending on applicable law and its coverage, you may have rights to access, correct, delete or obtain a portable copy of information; withdraw consent; limit certain sensitive-information uses; opt out of covered sales, targeted advertising or certain profiling; and appeal a denied request. We do not penalize you for exercising rights protected by law.
Use the available profile, visibility, location, blocking and notification controls for those choices. To make a privacy request or ask about retained information, contact [email protected]. We verify requests proportionately using information reasonably necessary to protect your account and respond within applicable legal time limits. An authorized agent may act where permitted, subject to verification. If a request is denied, you may appeal by replying with "Privacy Appeal" in the subject line; our response will explain applicable next steps.
Account deletion. You can request deletion in the app's account settings, normally confirmed by a phone one-time passcode, or contact us for assistance. Your phone number is subject to the disclosed 90-day re-registration restriction. If you choose to delete your account, your unused passes and tickets, including paid passes, and remaining points and rewards are forfeited under the account-closure provisions in the Terms. You may contact [email protected] for a case-by-case review, but a resolution is not guaranteed. Refunds already owed and rights that applicable law does not allow us to exclude remain preserved. Deletion ends your active group membership; group leadership may transfer to another eligible member. The retention exceptions in Section 8 apply. Tell us if you cannot access your former phone number so we can assess an alternative verification method.
11. State-Specific Disclosures
11.1 California Residents
If California privacy law applies to our processing of your information, you have the rights described in Section 10, subject to its coverage and exceptions.
The categories of personal information described in this policy include identifiers and contact records; account and demographic information, including gender; commercial, ticket and attendance information; internet and device activity; approximate and precise geolocation; visual and communication content; and preferences or inferences used for discovery. Precise geolocation and the contents of certain private communications may qualify as sensitive personal information.
Sections 2, 3 and 5 describe the sources, purposes and recipient categories. Section 8 explains retention criteria. We do not sell personal information or share it for cross-context behavioral advertising, and we use sensitive information for requested features and other legally permitted purposes. Section 7.1 addresses applicable opt-out preference signals.
California residents may also request information about disclosures for third parties' direct marketing under California Civil Code Section 1798.83 by emailing [email protected].
11.2 Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and Other States
If you are a resident of a state with a comprehensive consumer privacy law that gives you rights similar to those described in Section 10, those rights apply to you. You may exercise them as described in Section 10.
11.3 Nevada Residents
Nevada residents may direct us not to sell certain covered information to a third party by emailing [email protected]. As described in Section 6, we do not sell covered information.
12. International Users
The Services are operated from the United States. Information may be processed in the United States and other countries where relevant providers operate. Privacy laws may differ from those where you live. We use safeguards required by applicable law for covered international transfers.
13. Third-Party Links and Services
Links to venue sites, social media, payment services and other third-party destinations are governed by those providers' practices. Review their policies before providing information. Our inclusion of a link does not authorize the third party to access private Spree group information.
14. Changes to This Policy
We will update this policy when our practices change and identify the effective date. For material changes, we will provide notice through the Services or other appropriate means and obtain separate consent where required. Changes will not retroactively authorize an incompatible use of previously collected information merely because you continue using Spree.
15. Contact Us
If you have questions or concerns about this Privacy Policy or our information practices, contact us:
Spree Technologies, LLC
Attn: Privacy
9393 N 90th St, Suite 102 #37
Scottsdale, AZ 85258
[email protected]