Skip to content

Legal

Privacy Policy

Version 2026-10 · last updated 6 October 2026

In short

  • Flits (Nafite B.V.) is responsible for your data. Questions? Email info@nafite.com.
  • We collect as little as possible. We only use your phone number to keep out fake accounts and no-shows: it is stored encrypted and never shared with venues.
  • We only store your location rounded (about 150 m) and delete it after 24 hours. Venues never see your location.
  • A venue only sees what it needs for your deal: your first name and initial, the number of people or items, your note, a label such as "Top guest" or "New", your expected arrival time and your order number.
  • No ad tracking in the app, no IDFA, no third-party analytics. Our own statistics are pseudonymised and you can switch them off.
  • You can download your data (within 72 hours), have it corrected or delete your account. You can also complain to the Dutch Data Protection Authority.

1. Who we are

Flits is an app and website where hospitality venues post a deal when things are quiet or when they have something left over, and where guests claim or buy that deal. There is one app for guests (guest mode) and venues (business mode). The website is for promotion only.

The controller of your personal data under the GDPR is:

Nafite B.V., trading as Flits
Spoorstraat 30A, 6511 AH Nijmegen

Chamber of Commerce (KvK) number: 76060217

Privacy email: info@nafite.com

Flits is the controller for accounts, location, claims, orders and business accounts. For payment data, Stripe is partly a controller in its own right (see section 6).

This policy covers the Flits app, the website joinflits.com and contact with our support team. Venues and their staff will find what applies specifically to them in section 13.

2. What data do we process?

We only process data we need for the purposes in section 3. Below, per category, what it is and where it comes from.

2.1 Account

  • Email address. You sign in with a 6-digit code we email to you. There is no password.
  • First name (required) and, optionally, your surname.
  • Language, account status and when you last used the app.
  • 18+ confirmation: only when you claim a deal that includes alcohol, we store that and when you confirmed (once) that you are 18 or over. We do not store a date of birth.

2.2 Phone number

  • Before your first claim or purchase, you confirm your mobile number once with a text message code (or via WhatsApp if the text does not arrive). The code is sent by our provider Bird.
  • We store your number encrypted. Only our servers and authorised Flits staff can read it.
  • We also store a hash of your number (a one-way code created with a secret key). We use it to make sure one number belongs to one account and to check whether a number has been blocked.
  • We log when you started verifications and whether they succeeded (to fight abuse and keep costs under control).
  • Your number is never shared with venues and never used for marketing.

2.3 Location

  • With your permission, the app uses your location to show nearby deals and to notify you when something goes live.
  • We only store your location rounded (a geohash of about 150 m) and delete it after 24 hours. With Always permission, the app sends a rounded update at most once every 15 minutes. We only ask for Always after your 2nd redemption.
  • Saved places (such as Home or Work) are places you save yourself, with a radius and time windows. We keep them until you delete them.
  • When you tap "I'm here" (table deal) or "swipe to collect" (takeaway deal), the app checks once whether you are at the venue. We keep the distance to the venue; it can serve as evidence in a complaint or chargeback.
  • If you do not give permission, you choose a city and only get notifications from venues you follow.
  • Venues never see your location.

2.4 Device and security

  • Details about your device: push token, app and iOS version, whether notifications and location are on, and which mode (guest or business) you last used.
  • App Attest: a cryptographic key from Apple that lets us check that requests come from a genuine Flits app. We keep a hash of that key so that no more than 2 accounts per device can claim within 30 days.
  • Your IP address, briefly, in technical logs at our hosting providers.

2.5 Taste profile, preferences and notification settings

  • Cuisines, diet, budget, usual party size, interest (table, takeaway or both). You can leave all of these empty.
  • Allergens you flag. This may say something about your health. We only use it to highlight or hide deals containing that allergen and to avoid notifying you about them. We only do this with your explicit consent; you withdraw it by removing the flag.
  • Notification settings (daily maximum, quiet hours, days, notification types, radius, minimum discount), followed and hidden venues.

2.6 Claims, orders and redemptions

  • Table deals: which deal, party size, expected arrival time, your note to the venue, status (checked in, cancelled, no-show), the deal's terms at the time you claimed, and how you found the deal (for example via a notification or the map).
  • Takeaway deals: order number, quantity, amounts and VAT, type of payment method, status, when you collected, any refunds and the receipt.
  • Redemptions: how and when the deal was redeemed (scan, code or swipe).
  • Strikes and reliability score: no-shows, late cancellations, appeals and their outcome (see section 9).
  • Credit and invitations: your invite code, who invited you, and your Flits credit.
  • Waiting lists and reminders you turn on.

2.7 Payment data

  • You pay for takeaway deals in advance in the app via Stripe (Apple Pay, iDEAL | Wero or card).
  • Your card and bank details are entered and stored at Stripe, not at Flits. We only see and store a Stripe customer ID, the type of payment method and, for display, the card brand and last 4 digits.

2.8 Support

  • Your conversations with our in-app support, including attachments (up to 3 photos per message), the claim or order it is about, and your rating of the help you received.
  • Staff may add internal notes that you do not see. You can request them through your right of access.

2.9 Reviews

  • After a redemption you can leave a review: stars, tags, text, photos and, if relevant, a problem ("Deal not honoured" or "Product didn't match").
  • Published reviews are publicly visible in the app and on the website, with your first name and initial.

2.10 Content reports and complaints

  • If you report a deal, venue, review or user, or complain about a takeaway order, we keep your report, the reason, your explanation and any evidence (such as photos).
  • If someone else reports something about you, we process that report as well.

2.11 Push notifications and email

  • Which notifications we sent you, whether they were delivered and opened, and what you did with them. Also why a notification was not sent (for example because of your daily maximum or quiet hours).
  • Which emails we sent you (such as sign-in codes, receipts and support replies). We do not receive automatic delivery or open events from SendGrid. If an email doesn't arrive or you report it as spam, our support team can manually mark your email address as "not working".
  • Whether (and when) you agreed to receive the newsletter.

2.12 Product analytics (pseudonymised)

  • To improve the app, we record how it is used: for example which screens you open, whether a claim succeeds or fails, and whether you opened a notification. Each event includes the mode, app version and city.
  • This data is stored pseudonymised in our own database in the EU. We send it to no third-party analytics service. No precise location, no payment information, no email address and no phone number goes into analytics.
  • Before you sign in, we only store the events of the first launch (such as the welcome screens and whether you allowed location and notifications). We link those to a random installation code of the app, not to an account.
  • We sometimes test two versions of a feature (A/B test). Which version you see is determined by a fixed calculation on your account ID; the variant is stored with the events.
  • You can switch this off in the app: Profile → Account → "Don't share product analytics". After that we no longer store events from you.
  • We do not use the advertising identifier (IDFA) and we do not ask for tracking permission through App Tracking Transparency, because we do not track you outside the app.

2.13 App error reports and crash reports

  • If something goes wrong in the app, we send an error report to our own database: app and iOS version, screen, error code and technical details. These reports contain no personal data.
  • We only receive crash reports through Apple (App Store Connect), and only if you have chosen on your device to share analytics with app developers. You decide this in your iOS settings.

2.14 Website visits

  • Our website uses Vercel Web Analytics, which counts visits and a few actions (such as a click on "Download") without cookies. See our Cookie Policy.
  • If you join a city's waiting list or sign up for the newsletter, we keep your email address (and the city).
  • Forms are protected by a hidden field, a minimum completion time and a limit on requests per IP address and email address. We do not use a third-party captcha service.

2.15 Callback form for venues

If you ask to be called back on our website, we process: venue name, city, your name, job title, email address, phone number, type of venue, number of locations and which campaign brought you to the site. A City Lead will contact you.

We only use your searches in the app to show results. The list of recent searches is kept only in the app's memory and disappears when you close the app. We do not store your searches.

What we doLegal basis (art. 6 GDPR)
Account, claims, orders, strikes and redemptionsPerformance of the contract
Location for nearby dealsConsent (via iOS and our explanation screen), can be withdrawn at any time
Push notifications about dealsConsent
Marketing email (newsletter)Consent (separate tick box)
Fraud prevention: App Attest, device linking, phone verification, location when swiping, GPS for venue façade verificationLegitimate interest
Support conversationsPerformance of the contract
Invoices and payment dataLegal obligation (kept for 7 years)
Product analytics (own table)Legitimate interest; pseudonymised, can be switched off in the app; no tracking via ATT/IDFA; no third-party analytics service

In addition:

What we doLegal basis
Flagged allergens (and dietary preferences that may reveal health or religion)Explicit consent (art. 9(2)(a) GDPR), withdrawn by removing the flag
Reviews and content reports or complaintsPerformance of the contract; for reports also our legal obligation under the Digital Services Act
App error reports and marking an email address that doesn't workLegitimate interest (a working app and reliable email)
Security, technical logs and backupsLegitimate interest (a safe and available service)
City waiting listConsent
Callback form for venuesAt your request, before entering into a contract
Moderation, and reporting a data breach or criminal offences where requiredLegal obligation

Where we rely on legitimate interest, we have weighed our interest (preventing abuse, keeping the service safe and working well) against the impact on your privacy, taking into account that we use as little data as possible. You can always object (section 11).

Where we ask for consent, you can always withdraw it: in the app (notifications, newsletter, allergens) or in your iOS settings (location, notifications). Withdrawal applies from that moment on.

4. What does the venue see?

For each claim or order, Flits shares only the following with the venue:

  • your first name and the initial of your surname (for example "Sanne K.");
  • the number of people (table) or the number of items (takeaway);
  • your note to the venue;
  • your reliability label: "Top guest" (score of 90 or higher) or "New" (fewer than 3 claims), otherwise nothing;
  • your expected arrival time (ETA);
  • the order number and status (for example checked in or "I'm here").

The venue never sees your phone number, email address or location. The venue may only use this data to honour your deal; this is set out in our partner terms.

The venue may also see:

  • your review and, if you report a problem, your report, so the venue can respond within 48 hours;
  • a support conversation, only if our support team invites the venue to it.

5. Do we share data with others?

We never sell your data. We only share it:

  • with the venue, as described in section 4;
  • with our service providers (processors), who only act on our instructions (section 6);
  • with Stripe, which is partly a controller in its own right (section 6);
  • with public authorities where the law requires it, for example the tax authorities or under a court order.

6. Service providers (sub-processors) and transfers outside the EEA

ProviderPurposeLocation / safeguards
SupabaseDatabase, sign-in, file storageEU region Frankfurt; data processing agreement (DPA)
VercelHosting of the website and our internal back office; Web Analytics (cookieless)Hosting in the EU; Vercel is a US company, see below
BirdSending the text message (or WhatsApp) code for phone verificationDutch company, EU platform
SendGridSending email (sign-in codes, receipts, support replies, newsletter)Processing in the US under the EU-US Data Privacy Framework and/or standard contractual clauses
StripeTakeaway payments, refunds, payouts to venues, venue subscriptionsSee below
Google (Google Maps Platform)Maps in the app and on the website, venue search and addressesNo guest personal data except the IP address when the map loads; appropriate safeguards for transfers to the US
ApplePush notifications (Apple Push Notification service, using your device's push token) and crash reports via App Store ConnectCrash reports only if you have allowed this on your device
GitHubStoring our weekly, encrypted database backup (90 days)Encrypted before it is stored; appropriate safeguards for transfers to the US

Stripe processes your payment data on our behalf. For some purposes Stripe is a controller in its own right, namely verifying the identity of venues (KYC), fraud prevention and complying with financial regulation. Stripe's own privacy policy applies to that.

Transfers outside the EEA. Some providers (such as SendGrid, Vercel, Google and Stripe) are, or are part of, US companies. All transfers outside the European Economic Area are covered by appropriate safeguards: an adequacy decision (the EU-US Data Privacy Framework) or the European Commission's standard contractual clauses, with supplementary measures where needed. You can request a copy of the safeguards at info@nafite.com.

7. Profiling: how we choose deals for you

We use your data to estimate which deals you will find interesting. This is profiling. We do it in two ways.

Relevance of your feed and notifications. The order of deals in your feed, and who receives a notification, is based on a simple weighted score. It looks at: distance, your preferences (cuisine, budget, diet, type of deal, whether you follow the venue), the value of the deal, whether you can make it in time, the venue's quality, previous redemptions and whether the venue is new. Ignored notifications from a venue count slightly against it. After 5 ignored notifications in a row, we lower your daily maximum by 1 for 7 days and ask whether you'd like fewer notifications. Sponsored deals get a fixed, labelled position and no higher score.

Reliability score (table deals only). See section 9.

What this means for you: you mainly see deals that are likely to suit you, and fewer notifications you don't want. As a result you may sometimes miss a deal that is further away or matches your preferences less well; you can still find it through the map, filters and search.

Objecting. If you don't want this, object via info@nafite.com or in-app support. Your feed will then be sorted by distance instead of relevance.

8. Automated decisions

We do not make decisions with legal effects for you without a person being able to review them. Some things do happen automatically, because they are needed to keep Flits fair for venues and guests:

  • Strikes. If you don't show up and haven't checked in, you automatically get a strike. Cancelling later than 10 minutes before the end of your arrival window counts as half a strike. 2 strikes within 60 days automatically means 7 days without claiming table deals; 3 strikes means 30 days. Strikes expire after 90 days.
  • Limits linked to the reliability score (section 9).
  • Abuse limits: one number per account, no more than 2 claiming accounts per device per 30 days, blocked numbers and disposable email addresses.

If you tapped "I'm here" while you were at the venue, you do not get an automatic strike: the venue has to confirm whether you were there, and if the venue does not respond within 2 hours, you get no strike.

Human review. For every strike or restriction, the app shows which rule was applied, based on which fact, and how to appeal. You can appeal in the app (Profile → Reliability). A Flits staff member who did not make the original decision reviews your appeal within 5 working days. You may explain your side. If your appeal is upheld, we withdraw the strike or restriction.

9. Reliability score

Because you don't pay in advance for a table deal, we keep a reliability score from 0 to 100:

  • you start at 80;
  • +2 per check-in (up to +20 per 30 days);
  • −15 per no-show;
  • −6 per late cancellation;
  • no change if your no-show is excused or the venue cancelled the deal;
  • without activity, your score moves 1 point per week back towards 80.

Consequences: below 50, your notifications get a lower priority. Below 30, you can add no more than 2 people per claim. The venue does not see your score, only the label "Top guest" (90 or higher) or "New" (fewer than 3 claims), and otherwise nothing.

You can see your score, your strikes with their expiry dates and the rules in the app (Profile → Reliability). There is no score for takeaway deals: you pay for those in advance.

10. How long do we keep your data?

DataRetention period
Location (device)Up to 24 hours, rounded
Push notifications13 months
Claims, orders, redemptions24 months linked to you, then anonymised. Financial data of orders 7 years
Strikes90 days active, then 12 months in an archive
Invoices, payouts, refunds7 years (tax retention obligation)
Deleted account30 days to restore, then erased or anonymised
Support conversations and attachments24 months after closing, then deleted (longer if a dispute or chargeback is ongoing, until it is resolved)
Venue verification photos12 months after approval
Product analytics13 months
App error reports (no personal data)90 days
Account, profile, preferences, saved placesAs long as your account exists, or until you change or delete them
ReviewsAs long as your account exists; then anonymised
Content reports24 months after they are resolved
Callback requests from the website12 months after the last contact, unless a contract follows
BackupsDaily backups 7 days, weekly encrypted copy 90 days

Data you have had deleted may remain in an encrypted backup until the end of that period. We only use backups to restore the service after an outage.

11. Your rights

You have the following rights:

  • Access and copy. In the app (Profile → Privacy & data → Download my data) you can request a copy of your data. Within 72 hours you receive an email with your data as a JSON file (for other services, also suitable for portability) and as a PDF (to read).
  • Rectification. You can update your name, email address, phone number and preferences yourself in the app. You change your email address and phone number with a code; your phone number at most once every 30 days.
  • Erasure. In the app (Profile → Privacy & data → Delete account) you can delete your account. You confirm with Face ID or an email code. Open table claims are cancelled without a strike. If you have a takeaway order that hasn't been collected yet, you first collect it or cancel it (with a refund, if that's still possible within the cancellation period); you can then delete your account. You then have 30 days to restore your account; after that we erase or anonymise your data. We keep invoices and payment data for 7 years (legal obligation). If you own a venue on Flits, you first transfer ownership or close the organisation.
  • Restriction. You can ask us to temporarily stop using your data, for example while we assess a correction or objection.
  • Objection. You can object to processing based on legitimate interest, including profiling (your feed is then sorted by distance, section 7). You can always object to use for direct marketing.
  • Data portability. You can receive your data in a common, machine-readable format (JSON).
  • Withdrawing consent. See section 3.
  • No automated decision without a human. See section 8.

For anything you cannot do yourself in the app, email info@nafite.com or start a conversation with support. We respond within one month (for complex requests this may be extended by two months; we will let you know). We may ask you to prove your identity, for example by sending a code to your email address.

Complaints. Not happy with how we handle your data? Please tell us first. You always have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl) or the supervisory authority in the country where you live.

12. Security

We protect your data with measures including:

  • access rules on every table in the database, so each user can only see their own data;
  • encryption: your phone number is stored separately encrypted, secret keys are kept in a secure vault, and all connections use TLS (with certificate pinning in the app);
  • no card data in our own systems (it stays with Stripe);
  • App Attest and limits against abuse;
  • access to our internal back office only for designated staff, with mandatory two-factor authentication; every staff action is logged;
  • a database in the EU, daily backups and an encrypted weekly copy, with a restore test every quarter;
  • a data protection impact assessment (DPIA) before launch, and a penetration test before launch and yearly after that.

Found a security issue? Report it to info@nafite.com (see our responsible disclosure page at joinflits.com/security).

If something does go wrong with your data (a data breach), we report it to the Dutch Data Protection Authority within 72 hours where required, and we inform you if the breach poses a high risk to you.

13. For venues: business owners and staff

When you use Flits for a venue, Flits also processes personal data: of business owners (owners and managers) and of staff who use the app in business mode. Flits is the controller for this data.

What data:

  • Account: the same data as for guests (email address, first name, verified phone number). We also use the applicant's verified number to reach the owner if there is a problem with a deal or payout.
  • Organisation and venue: (legal) name, KvK number, branch number, SBI code, VAT number, billing email and address, and the venue's address and details. Part of this we retrieve from the KvK (Dutch Business Register). For sole traders and partnerships, this may be personal data.
  • Venue verification: an email address on your own domain with a code, or a façade photo taken in the app with its GPS location and time, and the calculated distance to the address.
  • Team: who is a member, with which role (owner, manager, staff, group admin), who invited whom, and which permissions someone has.
  • Actions in the app: who launched a deal, confirmed allergens, scanned a code or handed over an order, and when. This is needed for the service, food safety and resolving disputes.
  • Subscription and invoices: plan, status, invoices and payments (via Stripe Billing).
  • Payouts: via a Stripe Connect account per venue. Stripe verifies the business owner's identity (KYC) and is a controller in its own right for that. Flits only sees the status of the connection and the payouts.
  • Acceptance of the partner terms: version, time and who accepted.
  • Support, moderation and view-only access by Flits support (logged; you are notified when this happens).
  • Emails such as daily and monthly reports, trial reminders and payment links (via SendGrid).
  • Callback requests via the website (section 2.15).

Legal bases: performance of the contract with the venue (account, venue, subscription, payouts, moderation); legal obligation (invoices and payment data for 7 years); legitimate interest (venue verification with GPS, fraud prevention, data of staff using the app for the venue, logging of actions).

Retention: see section 10. Invoices, payouts and refunds 7 years; verification photos 12 months after approval; other data as long as the venue is a customer and afterwards as long as needed to wrap things up.

Guest data: as a venue, you only receive the data listed in section 4 for each claim or order. You may only use it to honour the deal (see the partner terms).

Rights: business owners and staff have the same rights as in section 11.

14. Children

Flits does not ask for a date of birth and does not check your age. If you are under 16, you may only use Flits with the permission of your parent or guardian. For processing based on consent (location, notifications, newsletter, flagged allergens), your parent or guardian gives that consent. For deals that include alcohol you must be 18 or older. Think your child has an account without your permission? Email info@nafite.com and we'll help you delete the account.

15. Changes

We may update this privacy policy, for example when the app changes or the law changes. The version and the date of the last change are always shown at the top. We will tell you about important changes in advance in the app or by email. If a change requires new consent, we will ask for it first.