Privacy Policy

Effective date: 2026-04-22 · Last updated: 2026-04-22

This Privacy Policy ("Policy") describes how Lorenzo Frascolla, a sole proprietor doing business as Namas ("Namas," "we," "us," or "our"), collects, uses, discloses, and safeguards personal information when you use the Namas mobile application (the "App") or our website at namas-app.com (the "Site," and together with the App, the "Service"). Namas is the data controller for purposes of the EU/UK GDPR and the "business" for purposes of the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA/CPRA").

By creating an account or otherwise using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with any part of this Policy, do not use the Service.

1. Scope and eligibility

The Service is intended solely for users who are 18 years of age or older. We do not knowingly collect personal information from individuals under 18. If we discover that we have collected personal information from someone under 18, we will delete it as soon as reasonably practicable and may terminate the associated account. If you believe we have inadvertently collected information from a minor, contact us at contact@namas-app.com.

2. Categories of personal information we collect

The following table summarizes the categories of personal information we collect, consistent with the enumerated categories under the CCPA/CPRA, the sources of that information, the business purposes for which we use it, and the categories of third parties with whom we share it.

Category Examples Source Purpose Shared with
Identifiers Name, email, account ID, IP address, device ID You; automatically from your device Account creation, authentication, communications, fraud prevention Hosting and auth provider (Supabase), notification provider (Expo)
Commercial information Bookings, session history, ratings, promo code usage You; other users you transact with Operating the marketplace Counterparty user (Coach/Client), payment processor (Stripe)
Financial information Payment method token, last 4 digits, billing ZIP, payout bank details (Coaches only) You (via Stripe); Stripe Processing payments, issuing refunds, remitting payouts, tax reporting Stripe, Inc. (payments); tax authorities where required by law
Internet/network activity App events (sign-up, booking, cancellation), crash logs, diagnostic data Automatically from your device Service operation, debugging, fraud/abuse detection, product analytics Error-tracking and analytics providers
Geolocation data (approximate) City/area entered by you; coarse IP-derived location You; automatically Session discovery by location, fraud detection None (retained internally)
Audio/visual information Profile photos and session photos you upload You Displaying profiles and listings Other users on the Service
Professional or credential information (Coaches) Biography, certifications, coaching history you disclose You Marketplace listings, Client decision-making Other users on the Service
Inferences Derived preferences (e.g., categories you browse) Automatic Personalizing session discovery and recommendations None outside our service providers
User-generated content Direct messages, ratings, reports, support correspondence You Enabling messaging, trust and safety, support Recipient user(s); law enforcement as legally required

We do not knowingly collect sensitive personal information as defined under the CPRA (for example, government ID numbers, precise geolocation, racial or ethnic origin, religious beliefs, union membership, genetic or biometric data, or health information). Please do not submit such information through the Service.

3. How we use personal information

We use personal information for the following purposes:

4. Legal bases for processing (EEA/UK users)

If you are located in the European Economic Area or the United Kingdom, our legal bases for processing your personal information are:

5. How we disclose personal information

We do not sell personal information, and we have not sold or "shared" (as defined by the CPRA for cross-context behavioral advertising) personal information in the preceding 12 months. We disclose personal information only in the following circumstances:

6. Device permissions

The App may request:

We do not collect precise (GPS-level) device location.

7. Cookies, tracking, and analytics

The Site does not set advertising or analytics cookies. A strictly necessary cookie may be used to remember your theme preference (light/dark). The Site loads fonts from Google Fonts, which may log request metadata under Google's policies. The App does not use web cookies; it uses local device storage (AsyncStorage / Secure Store) to maintain your authenticated session and user preferences. We do not operate behavioral advertising, nor do we use cross-site tracking. Because we do not engage in cross-context behavioral advertising, we honor Global Privacy Control (GPC) signals by default.

8. Your rights

8a. All users

You may, subject to applicable law:

To exercise any of these rights, email contact@namas-app.com. We will respond within the timeframe required by applicable law (typically 45 days under CCPA/CPRA, and 30 days under GDPR). We may ask you to verify your identity before acting on a request. We will not discriminate against you for exercising any of these rights.

8b. California residents (CCPA/CPRA)

In addition to the rights above, you have the right to request information about the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties with whom we have disclosed such information. You also have the right to opt out of "sale" or "sharing" of personal information and to limit the use of sensitive personal information. Namas does not sell or share personal information for cross-context behavioral advertising, and does not use or disclose sensitive personal information for purposes that would trigger the right to limit. If this ever changes, we will update this Policy and provide the required disclosures and "Do Not Sell or Share" mechanism.

You may designate an authorized agent to make a request on your behalf. We may require the agent to provide signed permission, and we may require you to verify your identity directly.

8c. EEA/UK residents (GDPR)

You have the right to lodge a complaint with your local data protection authority if you believe our processing violates the GDPR. A list of EU supervisory authorities is available at edpb.europa.eu.

9. Retention

We retain personal information for as long as your account is active and as needed to provide the Service. Following account deletion, we remove personal information from active systems within 30 days, except where retention is required for:

10. Security

We implement administrative, technical, and physical safeguards designed to protect personal information, including TLS encryption in transit, encrypted storage at rest, row-level security on our database, scoped access control, rate-limiting, and vendor due diligence. No system is perfectly secure. If we become aware of a personal data breach affecting your information, we will notify affected users and applicable regulators within the timeframes required by law (for example, without undue delay and, where feasible, within 72 hours under the GDPR).

11. International data transfers

Namas is operated from the United States, and personal information is processed in the United States and any region where our service providers operate. If you access the Service from outside the United States, you consent to the transfer of personal information to the United States. Where required, we rely on appropriate transfer mechanisms, including the European Commission's Standard Contractual Clauses, for transfers from the EEA/UK.

12. Children under 18

The Service is not directed to children under 18, and we do not knowingly collect personal information from children. Because the Service is restricted to users 18 and older, the Children's Online Privacy Protection Act ("COPPA") does not apply to the Service. If you are a parent or guardian and believe a minor has provided us with personal information, email contact@namas-app.com and we will take steps to delete that information.

13. Third-party services

The Service integrates with third-party services, including Stripe for payments. Their collection and use of information is governed by their own privacy policies (for example, stripe.com/privacy). We are not responsible for the privacy practices of third parties, and we encourage you to review their policies.

14. Do Not Track

The Service does not respond to Do Not Track ("DNT") browser signals because no universal standard has been adopted. As noted above, we do not engage in cross-context behavioral advertising and honor Global Privacy Control (GPC) signals.

15. Changes to this Policy

We may update this Policy from time to time. If we make material changes, we will notify you by email or in-app notice at least 30 days before the changes take effect, except where a shorter period is required by law. The "Last updated" date above will reflect the most recent change. Your continued use of the Service after the effective date constitutes acceptance of the revised Policy.

16. Contact

Lorenzo Frascolla, sole proprietor d/b/a Namas — United States.
Email: contact@namas-app.com

1. Who the Service is for

The Service is intended for users 18 years of age or older. We do not knowingly collect information from anyone under 18. If we learn we have collected information from a user under 18, we will delete it.

2. Information we collect

2a. Information you provide

2b. Information collected automatically

2c. Payment information

Payments are processed by Stripe, Inc. We do not store your full card number or CVC on our servers. Stripe collects payment details under its own privacy policy (stripe.com/privacy). We receive a limited token and the last 4 digits of the card for reference.

3. How we use information

4. How we share information

We do not sell your personal information. We share it only as follows:

5. Device permissions

On first use, the App may ask for:

We do not collect precise device location.

6. Data retention

We retain account data for as long as your account is active. When you delete your account (Profile → Delete Account), we remove your personal information from our active systems within 30 days, except where we must retain it for legal, tax, or fraud-prevention purposes (for example, payment records required by financial regulations). Anonymized analytics may persist indefinitely.

7. Your rights

Depending on where you live, you may have the right to:

California residents have rights under the CCPA, including the right to know what categories of information we collect and to request deletion. To exercise any of these rights, email contact@namas-app.com and we will respond within 30 days.

8. Security

We use industry-standard safeguards — TLS encryption in transit, encrypted storage at rest, row-level security on our database, and limited employee access. No system is perfectly secure; please choose a strong password and notify us immediately at contact@namas-app.com if you believe your account has been compromised.

9. Children under 18

The Service is not directed to anyone under 18. We do not knowingly collect information from users under 18. If you believe a minor has provided us with personal information, email contact@namas-app.com and we will delete it.

10. International users

Namas is operated from the United States. If you access the Service from outside the U.S., your information will be transferred to and processed in the U.S., which may have different data-protection rules than your country.

11. Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date above will reflect the most recent change. Material changes will be announced in-app. Continued use of the Service after an update means you accept the revised policy.

12. Contact

Lorenzo Frascolla, d/b/a Namas
contact@namas-app.com