Privacy Policy
stepin.dance helps adult social dancers find real dance socials, RSVP, see who else is going, and message to meet on the floor. This explains what we collect, why, who we share it with, and your choices. Questions or requests: privacy@stepin.dance.
Adults only (18+)
stepin.dance is for adults 18 and older. Misrepresenting your age violates our Terms and can result in removal.
What we collect
We keep what we need to run the service and nothing we don’t:
- Account: your email, a password (stored only as a salted scrypt hash — never in plain text), and your display name.
- Profile: your role (lead / follow / both), dance styles, level, the nights you’re usually free, an optional short bio, and your city.
- Activity: the socials you RSVP to, and the messages you send other dancers to coordinate meeting up.
- Organizers: if you run a venue, your venue name, email, hashed password, and the socials you publish.
- Technical: a signed, http-only session cookie to keep you logged in, your IP address for rate-limiting and abuse prevention, and standard server logs.
What we do NOT collect
- No photos and no biometrics. The app does not use your camera.
- No precise/GPS location — city is the only location field, and you type it.
- No phone number.
- No payment details — the app is free.
How we use it
- Run the service, match you to relevant socials, and show who’s going.
- Deliver your messages to the dancers you contact.
- Keep the community safe — prevent spam, abuse, and fake accounts.
Who we share it with
Infrastructure providers that host the app and database (our web host and managed Postgres database) process data on our behalf under their security terms. We do not sell your data and we do not share it for advertising.
Your choices and rights
You can view and update your profile in the app. You can delete your account; deletion removes your profile, your RSVPs, and your messages. To request a copy of your data or deletion (including GDPR / CCPA requests), email privacy@stepin.dance. Some of this is handled manually while the product is early — we’ll confirm and action your request.
How we protect it
- Passwords are salted and hashed (scrypt) — we never store or can read your password.
- Sessions are signed (HMAC), http-only cookies; the site is served over HTTPS with HSTS and a content-security policy.
- Rate limiting protects auth, RSVP, and messaging endpoints.
- No system is perfectly secure; we keep the data surface small to reduce risk.
Changes
We’ll post changes here and update the date above. This is an early-stage policy written in good faith and is pending review by counsel.