Privacy Policy
Last updated: 30 June 2026
Manifest (“we”, “us”, the “App”) is a logbook, gear passport, and events platform for skydivers. This policy explains what personal data we collect, why, and your rights over it.
Data controller: André Larsen, Dubai, United Arab Emirates. Contact: support@jumpmanifest.com.
1. Data we collect
You provide:
- Account: email address and password (passwords are stored hashed by our auth provider; we never see them in plain text).
- Profile: name, optional avatar photo, licence type and licensing body, ratings, bio, home dropzone, coaching details.
- Content you create: jump logs, gear items and service history, event listings and RSVPs, messages to other users, reports you file.
- Credential & verification documents: if you choose to upload them, images of your licence, rigger ticket, insurance, medical or other credentials — for your in-app credentials wallet and, if you apply, for blue-check verification. These are stored privately and access-controlled, visible only to you and to authorised Manifest admins reviewing a verification request.
Collected automatically / with permission:
- Approximate device location — only when you tap “Near me” to sort dropzones/events by distance. Location is used in-memory to compute distance and is not stored on our servers.
- Background location (optional) — only if you turn on automatic jump logging. Manifest then registers geofences around dropzones so iOS can prompt you to log your jumps when you leave one. This uses the “Always” location permission, but dropzone enter/exit detection happens on your device — we do not store your continuous location or movements on our servers. You can turn it off in the app or revoke the permission in your device settings at any time.
- Notification permission and local reminder scheduling (gear service and currency reminders are scheduled on your device).
- Usage data: in-app product-interaction events (screens viewed, features used) and crash reports, collected to keep the app reliable and improve it.
- Basic technical data needed to run the service (e.g. session tokens).
2. Why we use it (legal bases)
- To provide the service (contract): accounts, logbook, gear, events, messaging.
- Legitimate interests: safety/moderation (reports, suspensions), preventing fraud and abuse, product improvement, and internal aggregated statistics (for example, counting how many jumpers list a given home dropzone or country). These aggregates are only used to operate and improve Manifest and are never sold or shared.
- Consent: device location (“Near me” and optional background geofencing for automatic jump logging) and notifications — you can decline or revoke these at any time in your device settings.
3. Who we share it with
We do not sell your personal data. We share it only with service providers who process it on our behalf:
- Supabase — database, authentication, and file storage (hosting our backend).
- Expo — app delivery and, where enabled, push notification delivery.
- PostHog (EU region) — product analytics and crash reporting (in-app usage events and crashes, to keep the app reliable).
Other users see the parts of your profile and content you choose to make public (e.g. your name, avatar, public jumps, events you host). Verified-badge status is visible to other users.
4. International transfers
Our providers may process data outside your country (including the EU/EEA and the United States). Where required, transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses.
5. Retention
We keep your data while your account is active. When you delete your account (Profile → Delete account), your profile and associated content are deleted promptly via an automated cascade. Credential and verification documents you upload are kept only while they remain in your wallet or your account is active — removing the credential or deleting your account removes them; we may keep a minimal record that a verification check took place, without retaining the document itself. Some records may be retained where required by law or to resolve disputes.
6. Your rights
Depending on your location (including the EU/EEA under the GDPR), you have the right to access, correct, delete, restrict, or port your data, and to object to certain processing. You can:
- Edit your profile in-app.
- Delete your account in-app (Profile → Delete account) — this erases your data.
- Contact us at support@jumpmanifest.com for any other request.
You may also lodge a complaint with your local data protection authority.
7. Children
Manifest is not directed to children under 16. We do not knowingly collect data from children under 16. If you believe a child has provided us data, contact us and we will delete it.
8. Security
We use industry-standard measures (encryption in transit, hashed passwords, row-level access controls). No system is perfectly secure; please use a strong, unique password.
9. Changes
We may update this policy. Material changes will be notified in-app or by email. The “Last updated” date above reflects the current version.
10. Contact
André Larsen — support@jumpmanifest.com — Dubai, United Arab Emirates.