Privacy Policy – Footsteps Space
Effective Date: 02 August 2025 | Last Updated: 01 July 2026
Footsteps Space (“we”, “our”, “us”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your information when you use our websites, mobile applications, and related online services on footsteps.space and its subdomains (together, the “Services”). By using a Service, you agree to the practices described here.
- DPDP Act (Digital Personal Data Protection Act, 2023 – India)
- GDPR (General Data Protection Regulation – European Union)
- CCPA/CPRA (California Consumer Privacy Act / California Privacy Rights Act – United States)
1) Who We Are and How to Contact Us
Footsteps Space is owned and operated from Hyderabad, Telangana, India.
- Email (general queries and data requests): footsteps.space@gmail.com
- Grievance Officer (DPDP Act):
Name: Vivek Mankonda
Email: footsteps.space@gmail.com
Response time: within 30 days of receipt
2) Products We Operate
- Footsteps — travel identity and journey stories (mobile app and footsteps.space).
- Emu — emu.footsteps.space — a web app for hosts to plan small real-world experiences, manage guest lists, track contributions and expenses, and share guest registration links.
- Other subdomains of footsteps.space may be added over time. This policy applies unless a product links to a separate policy.
3) Data We Collect
3.1 Shared across Services
- Account identifiers and profile information from sign-in providers (name, email address, profile photo where available).
- Device type, browser or app version, IP address, and diagnostic or performance logs.
- Essential cookies and similar technologies for authentication and site operation; analytics cookies on our websites (see §3.6).
3.2 Footsteps app only
- Profile bio and photos you choose to add.
- Content you create (stories, images, captions, comments).
- Location data: precise location only with your permission when tagging a story; approximate location may be derived from IP address.
3.3 Emu only
- Host accounts — sign-in via the methods available for Emu (see §3.5); we store display name and avatar from your profile.
- Guest registrations — sign-in is required before registering through an invite link; registration data (party size, meal choices, contact details you provide) is linked to your account.
- Experience data you create as a host: titles, dates, venues, maps links, descriptions, cover images, contribution and expense records.
- Host-entered guest records — when you manually add walk-in guests, you may enter names, phone numbers, emails, and related notes. These are host management records; those individuals do not receive a guest account unless they register through an invite link.
- Co-host access — co-hosts you invite can view and manage guest contact details for that experience.
- Local browser storage — before sign-in, Emu may store draft experience data in your browser (IndexedDB) until you sign in to sync to the cloud.
3.4 Automatically collected
- Usage patterns, crash reports, and performance analytics to keep Services reliable and secure.
3.5 Sign-in and account access
Depending on the product and platform, you may sign in using one or more of the following:
- Footsteps app: Google, Apple Sign In, and/or email and password.
- Emu (hosts and guests): Google; we may add Apple Sign In or email and password over time.
- Other Services: similar sign-in options may be offered where supported.
When you use Google or Apple, we receive basic profile information (such as name, email address, and profile photo where available). We do not receive your password for those services. Apple may provide a private relay email address instead of your personal email.
When you use email and password, we collect your email address directly and store your password only in hashed form through our authentication provider—we never store plain-text passwords. We may send email verification, password reset, and security notices to the address you provide.
3.6 Cookies and similar technologies
Our websites use cookies and similar technologies for essential functions (including authentication sessions) and for analytics (for example, page performance measurement). We do not use advertising or marketing cookies on footsteps.space or Emu. You can limit non-essential cookies through your browser settings.
4) How We Use Your Data
- Provide, operate, and maintain the Services.
- Authenticate you and sync your data across devices where applicable.
- Display your content to others according to your settings (Footsteps public stories).
- Operate guest registration, host tools, and co-host collaboration on Emu.
- Suggest relevant content and connections on the Footsteps app where applicable.
- Improve performance, security, and user experience.
- Communicate about updates and support (you can opt out of non-essential marketing).
- Prevent fraud, abuse, and security risks.
- Comply with legal obligations and enforce our terms.
5) How We Share Your Data
- With other users: Footsteps public stories and profiles may be visible worldwide. On Emu, guest registration details are visible to the experience host and invited co-hosts; invite links are not public search listings.
- With service providers: cloud hosting, authentication, analytics, email support, and similar operational vendors under contracts that limit use of your data.
- Corporate transactions: if we are involved in a merger, acquisition, or sale of assets.
- Legal compliance: where required by courts, regulators, or law enforcement.
We do not sell your personal data for money.
6) Public Content and Search (Footsteps app)
If you post a public story or maintain a public profile on Footsteps, your content and location tags may be viewable by anyone and indexed by search engines. Cached copies may persist after deletion outside our direct control.
7) Data Retention
- We retain personal data only as long as necessary for the purposes in this policy.
- Deleted data may remain in backups for a limited period (typically up to 90 days) before secure removal.
- When you delete your account, we remove or anonymize data linked to your account subject to the exceptions below.
8) Your Rights (GDPR, CCPA/CPRA, DPDP Act)
Depending on your location, you may have the right to access, correct, delete, restrict, object to, or port your personal data, and to withdraw consent where processing is based on consent.
- Access and portability: use in-app Download my data on Emu, or email us.
- Correction: update your profile through your sign-in provider or account settings where available, or contact us.
- Erasure: use in-app Delete account or email us (see §14).
EU (GDPR): we aim to respond within 30 days.
California (CCPA/CPRA): you may request disclosure and deletion; we do not sell personal data for money.
India (DPDP Act): Footsteps Space acts as a Data Fiduciary; contact our Grievance Officer for redressal.
9) Security Measures
We use reasonable technical and organizational safeguards, including encryption in transit, access controls, and monitoring. No method of transmission or storage is completely secure.
10) Data Breach Notification
If a breach materially affects your personal data, we will notify you without undue delay and within 72 hours where required by law.
11) Children’s Privacy
Our Services are not intended for children under 13 (or the age of digital consent in your jurisdiction). We do not knowingly collect personal data from children. Contact us to request deletion if you believe a child has provided data.
12) International Data Transfers
Your data may be processed outside your country on cloud infrastructure. Where required, we use appropriate safeguards for cross-border transfers.
13) Automated Processing (Footsteps app)
On Footsteps, we may use automated systems to recommend content and detect abuse. Significant decisions affecting your rights include human review where required by law.
14) Account and Data Deletion
- Footsteps app: delete your account in app settings where available, or email footsteps.space@gmail.com.
- Emu — hosts: delete your account in Account settings. Deletion is blocked while you host active upcoming published experiences; cancel or complete those experiences first.
- Emu — guests: delete your account in Account settings; this removes your profile and registrations linked to your account.
- Host-entered walk-in records: individuals without an Emu account may request erasure by contacting the host or emailing us.
- We generally complete deletion requests within 30 days. Backup retention may delay full purge from all systems.
- Some records may be retained where required by law.
15) Links to Other Websites
Our Services may link to third-party sites (for example, Google Maps). Their privacy practices are governed by their own policies.
16) Changes to This Policy
We may update this policy from time to time. Material changes will be posted on this page with an updated “Last Updated” date and, where appropriate, notified in-app or by email.
17) Governing Law
This policy is governed by the laws of India. If you reside outside India, your data may be processed under different data protection laws.
Questions: footsteps.space@gmail.com