Last updated: 20 September 2026
This Privacy Policy explains what personal data Landed collects, why, and how it is handled, in line with the EU General Data Protection Regulation (GDPR).
This policy applies to everyone who creates a Landed account. Landed is currently operated by an individual, Martijn van Rooij, operating as a sole proprietor (eenmanszaak) based in the Netherlands, acting as the data controller for the personal data described below. A registered business (KVK) number and business address will be added here once registration is complete. Contact details are in Section 11.
This policy does not cover third-party websites or services you may reach through links in the app.
Landed collects the following categories of data. Identity documents (government ID, selfie photo): to verify you're a real person. Contact details (email address, phone number): for account access and verification. Relocation proof, for newcomers (a document showing your recent move): to confirm eligibility as a newcomer. Profile information (name, age, city, languages, interests, your "why I moved" text, photo): to build your profile for other members. Location context (current city, city moved from): to match you with nearby members. Messages and meetups (chat messages, icebreaker answers, proposed meetup venues and times): to operate the app's core features. Trusted-contact info (a name, phone, or email you choose to add): to let you share meetup plans with someone you trust. Reports and reviews (reports you file or that are filed against you, post-meetup reviews): for community safety and trust scoring. Usage data (login times, device and browser info, in-app actions): for security and troubleshooting.
Your government ID is deleted once reviewed (see Section 5). We do not retain the document itself long-term.
If you choose to add a trusted contact so you can share your meetup plans, we use their name and contact details only for that purpose. You are responsible for informing anyone you list as a trusted contact that you have shared their details with Landed. You can remove a trusted contact's details at any time from your Profile settings.
We use your data to: verify your identity, age, and (for newcomers) recent relocation; show your profile to other members and let them find you through search and filters; operate messaging, icebreakers, meetup proposals, and reviews; calculate your trust score and act on reports; send you notifications about invites, messages, and meetups; investigate reports and enforce our Terms of Service; and improve the app's safety features and fix problems.
Our legal bases under GDPR are: performance of a contract (running the account and features you signed up for), legitimate interest (community safety, fraud prevention, service improvement), and legal obligation where applicable. Where we rely on consent (for example, an optional trusted contact's details), you may withdraw it at any time.
Where your trust score is used to automatically restrict messaging or invitations, this is an automated decision based on the factors described in our Terms of Service. You may contact us at any time to request a human review of that decision.
We do not sell your data. We share limited data with the following processors, only as needed to run the app. Supabase receives your account data and app database, for hosting, authentication, and storage (hosted in the EU). Twilio receives your phone number, to send the SMS code used to verify your phone; Twilio is a US company, and transfers are protected through Standard Contractual Clauses and any additional safeguards required under applicable EU data protection law. OpenStreetMap receives nothing from us; we only read public venue location data from it, to suggest meetup spots.
We may also disclose data where required by law, to protect the rights and safety of our members, or in connection with a merger, acquisition, or sale of assets (with notice to you).
Government ID: automatically deleted from our systems as soon as it has been reviewed and a decision (approved or rejected) is recorded. We retain only the outcome, not the document. Deleted chats: when you delete a conversation, it is hidden from your view immediately. The underlying messages are permanently deleted once both participants have deleted the conversation, or after each participant's own 7-day window has passed. Account deletion: deleting your account permanently erases your profile, matches, chats, and messages, and removes you from Discover. This cannot be undone. Reports and moderation records: retained for up to 3 years after the report is resolved or the associated account is closed, to maintain community safety and resolve disputes. Usage data (login times, device/browser info, in-app actions): retained for up to 12 months from collection, then deleted or anonymized.
We keep data no longer than necessary for the purposes described in this policy, or as required by law.
If you're in the EU/EEA, you have the right to: access the personal data we hold about you; correct inaccurate or incomplete data (most profile fields can be edited directly in the app); delete your data (via account deletion in Profile settings, or by contacting us); restrict or object to certain processing, including processing based on legitimate interest; port your data to another service, where technically feasible; withdraw consent at any time, where processing is based on consent; and lodge a complaint with your national data protection authority (in the Netherlands, the Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl).
To exercise any of these rights, contact us using the details in Section 11.
We apply database-level access controls so that sensitive fields, including verification status and trust score, cannot be altered by a member directly, and can only change through reviewed, server-side processes. Other members' profile data is only ever exposed through a restricted view that excludes sensitive fields. Data is encrypted in transit. Phone verification uses a real one-time code sent by SMS, checked server-side, rather than a code a member could set themselves.
No system is completely secure, and we cannot guarantee absolute security. If we become aware of a data breach affecting your personal data, we will notify you and the relevant authority as required by law.
Landed is intended for adults aged 18 and over only. We do not knowingly collect personal data from anyone under 18. If we become aware that a minor has created an account or that we hold data belonging to a minor, we will delete the associated account and data.
If you believe a minor is using Landed, please contact us using the details in Section 11.
Landed does not currently use cookies, third-party analytics, or advertising tracking technologies. If we introduce any in the future, we will update this section to describe what is used and why, and obtain any consent required by law before doing so.
We may update this Privacy Policy as Landed evolves. If we make material changes, we will notify you through the app before they take effect.
For any question about this policy or your data, or to exercise your rights under Section 6, contact JustLandedApp@gmail.com.
Landed is currently operated by an individual, Martijn van Rooij, operating as a sole proprietor (eenmanszaak) based in the Netherlands; a registered business (KVK) number and business address will be added here once registration is complete.