Privacy Policy
Version 2026-07-29
This policy explains what personal data Latin Fire processes, why, who it is shared with, and which rights you have. It applies to latinfire.ai and every Latin Fire app surface.
1. Who we are
Latin Fire is operated by Stichting Latin Fire, Blaak, Rotterdam, the Netherlands, registered with the Dutch Chamber of Commerce under KvK number 97109738. Stichting Latin Fire is the controller for the processing described in this policy.
Questions about this policy or your data? Email us at info@latinfire.net.
2. What data we process
Account data — your email address, display name, chosen language, and login credentials. Passwords are stored by our authentication provider in hashed form; we never see them.
Profile data you choose to add — username, bio, city, country of origin, dance styles, languages, professional roles, per-role details, rates, awards and career milestones, and any photos or links you provide. You decide what goes in, and most of it is public by design.
Contact details — an email address and phone number you may add to your profile. You choose who can see each of them: everyone, signed-in members only, or nobody. New profiles default to signed-in members only.
Business details, if you enter them — registered business name, country of registration, registration number and VAT number. These are private: they are never shown on your public profile. They are visible to you, and to our reviewers if you request the professional badge.
Proof of registration, if you request the professional badge — a document you upload from your national business register. It is stored privately, is readable only by our reviewers through a link that expires after ten minutes, and is deleted as soon as the request is accepted or declined. We keep the decision, never the document.
Images you upload — profile picture, cover image, organization logo and banner, showcase photos. These are stored publicly: anyone holding the file's address can open it. Before storing, we strip embedded metadata, including any GPS location your camera recorded.
Community activity you actively perform — saved events and lists, your agenda, friendships, reviews, claims, and ticket interest — stored with your account.
Chat conversations — signed in, stored with your account; signed out, stored under a random identifier kept in a cookie on your browser (see Cookies) and attached to your account if you sign up later.
Rewards data — your referral code, who signed up through it, and your points history.
Usage and security data — session information, rate-limit counters, security logs, and technical records our infrastructure providers keep to deliver and protect the platform.
Product-usage events — in-app actions such as saving or sharing, recorded with your account id to understand and improve how the platform is used.
Newsletter — if you subscribe, your email address and language, until you unsubscribe.
3. Why we process it, and on what basis
| What | Why | Basis |
|---|---|---|
| Account, profile, publishing | To provide the service you signed up for | Performance of a contract |
| Transactional email (sign-in codes, confirmations) | To operate your account | Performance of a contract |
| Chat replies | To answer you, which requires sending your message to our AI provider | Performance of a contract |
| Business details and proof of registration | To decide a professional badge you asked for | Performance of a contract, and our legitimate interest in a trustworthy platform |
| Rate limiting and security logs | To keep accounts and the platform secure | Legitimate interest |
| Product analytics | To understand use in aggregate | Legitimate interest |
| Newsletter | To send what you asked for | Consent |
We do not sell personal data, we do not send marketing without your consent, and we make no automated decisions with legal effects about you. Professional badges are decided by a person.
4. Who we share it with
We use the following processors. Each is bound by a data-processing agreement, and where a provider processes data outside the European Economic Area that transfer is covered by the EU Standard Contractual Clauses.
| Provider | What it handles | Where |
|---|---|---|
| Supabase | Database, authentication, file storage | European Union (Frankfurt) |
| Vercel | Hosting and delivery of the web app | European Union, with a global edge network |
| OpenAI | Generates Chat replies from the messages you send | United States |
| Tavily | Web search, when Chat looks something up beyond our own data | United States |
| Resend | Transactional email and the newsletter | European Union |
| PostHog | Cookieless product analytics | European Union |
| Google Maps | Renders maps; your browser contacts Google directly to load them | United States |
We also share data where the law requires it.
5. Cookies
Latin Fire uses essential cookies to keep you signed in and to remember your language and theme, plus one functional cookie (lf-anon-id): a random identifier that lets your anonymous Chat conversations persist. It expires after 180 days and is not used for tracking or advertising.
Our product analytics runs cookieless and stores nothing on your device. We set no advertising or cross-site tracking cookies.
Google Maps may set its own cookies when a map loads. That is Google's processing, described in Google's privacy policy.
6. Where your data lives
Our database, authentication and file storage run on Supabase in the European Union (Frankfurt). The rest is set out in the table in section 4.
7. How long we keep it
| What | How long |
|---|---|
| Account and profile data | While your account exists |
| Proof-of-registration documents | Deleted the moment a badge request is accepted or declined |
| Anonymous Chat conversations | 90 days, unless you sign up and they move to your account |
The lf-anon-id cookie | 180 days |
| Read notifications | 90 days |
| Rate-limit counters | Purged once the window they measure has passed |
| Newsletter subscription | Until you unsubscribe |
If you delete your account, or ask us to, your personal data is removed. Residual copies in backups expire automatically shortly afterwards.
8. Your choices
You control what your profile shows. You can set who sees your email address and phone number, hide your booking calendar, hide the events you are attending, hide your rates per role, and remove yourself from the public People directory.
You can also delete anything you have added, or your whole account.
9. Your rights
Under the GDPR (AVG) you can ask us for access to your data, correction, deletion, restriction of processing, a portable copy, and you can object to processing based on legitimate interest. Where processing is based on consent, you can withdraw it at any time.
To exercise any of these rights, email info@latinfire.net. You also have the right to lodge a complaint with the Dutch data-protection authority, the Autoriteit Persoonsgegevens.
10. Children
Latin Fire is not intended for children under 16, and you must be at least 16 to create an account. If you believe a child has given us personal data, email info@latinfire.net and we will remove it.
11. Changes
When this policy changes materially, we will announce it on this page, update the date above, and ask you to acknowledge it where the change requires that.

