MOC/wwBack

Legal

Privacy Policy

Last updated: 24 July 2026

The Bay is operated by MOC Worldwide OÜ, Estonian registry code 17538821, with its registered address at Harju maakond, Tallinn, Kesklinna linnaosa, Tartu mnt 67/1-13b, 10115, Estonia (“MOC”, “we”, “us”). MOC is the controller of the personal data described in this policy.

Privacy and support enquiries: info@mocworldwide.com

This policy applies to The Bay mobile application, the authenticated MOC Worldwide website, and the membership, community, event, marketplace and account services connected to them (together, the “Service”).

1. Who may use the Service

The Service is intended only for people aged 18 or over. Membership applications require a date of birth so that we can verify this age requirement.

2. Personal data we process

Depending on the features you use, we process the following categories.

Account and identity data

  • email address and phone number;
  • username, display name, profile photograph, biography and main city;
  • internal account identifier, account status, membership visibility, rank and membership dates;
  • legal name and date of birth supplied in a membership application;
  • authentication, session, QR sign-in and account-security data;
  • the browser label, site origin and timestamps used for website sessions.

Secrets used for QR login and website sessions are stored as cryptographic hashes rather than as the original secret.

Membership and payment data

  • membership application, reviewer decision and referral status;
  • subscription provider, product, entitlement, renewal or expiry status, cancellation status and related transaction or event identifiers;
  • Stripe customer and subscription identifiers and RevenueCat App User ID;
  • membership access history needed to apply re-entry and rank rules.

Apple and Stripe collect and process payment-card or Apple Account payment details directly. MOC does not receive or store complete card details.

Community and communications data

  • posts, threads, moments, polls, votes, comments, reactions, mentions and topic memberships;
  • photographs and other media you choose to upload;
  • direct and group conversations, messages and message attachments;
  • profile connections, read states, bookmarks and notification preferences;
  • reports, dispute details, moderation decisions and enforcement records.

Content posted to shared areas is visible to the audience indicated in the Service. Messages are visible to their conversation participants.

Events, places and marketplace data

  • events you create or organise, attendance requests, sign-ups and check-ins;
  • meetup signals, responses and travel-presence information;
  • venues, venue visits, reviews, ratings, photographs and feedback;
  • marketplace listings, bookmarks, deal participants, agreed terms, ratings, feedback and disputes.

MOC does not itself process payment for transactions arranged between users through the marketplace.

Location and contact data

  • city and country selected for profile, travel, event or meetup features;
  • location of venues and events, including address and coordinates;
  • while location permission is enabled and the app is in use, a last-known location rounded by the server to an approximately one-kilometre grid;
  • a precise device location transmitted temporarily when needed to find nearby venues. This exact value is used to perform the request and is not stored as a location-history record;
  • phone numbers from the device address book when you deliberately use the referral-matching feature.

Address-book matching is optional. The app sends normalised phone numbers to our backend to identify eligible existing accounts. We do not upload contact names. A phone number is retained as referral data only when you choose to request a referral involving that number.

We keep one coarse last-location row per profile rather than a historical location trail. It is overwritten by a newer value and removed when the account is deleted. Location permission can be withdrawn in iOS settings.

Discord data

If you connect Discord, we process the Discord account ID, username, global display name, avatar reference, OAuth state and role-synchronisation status. We use this only to link the accounts, invite or identify the user in the MOC server, and add or remove the membership role. Disconnecting Discord removes the managed member role and the stored account link.

Device, usage and technical data

  • Expo push token, platform and push-delivery status;
  • notification content required to deliver alerts;
  • app version, build and platform used for maintenance and minimum-version checks;
  • product interactions such as reactions, votes, attendance, read state and feature use;
  • IP address, request metadata, timestamps, security events and error logs generated by our infrastructure and service providers;
  • camera, photo-library, contacts, location and notification permission status. We access these capabilities only when needed for the feature the user chooses.

We do not use personal data for third-party advertising, sell personal data, or track users across other companies’ apps or websites for advertising.

3. Why we process personal data

We process personal data for these purposes and legal bases:

Create and secure accounts, authenticate users and provide the Service

Typical data: account, profile, session, content and technical data

GDPR legal basis: performance of a contract; legitimate interests in security

Assess applications and operate the membership community

Typical data: identity, age, application, referral, rank and membership data

GDPR legal basis: steps requested before and performance of a contract; legitimate interests in operating a trusted private community

Process and verify subscriptions and provide paid access

Typical data: account identifiers, purchase and subscription status

GDPR legal basis: performance of a contract; legal obligations for accounting and consumer matters

Provide posts, messages, topics, events, marketplace and venue features

Typical data: content, interaction, event, place and marketplace data

GDPR legal basis: performance of a contract

Match referrals using contacts

Typical data: normalised phone numbers chosen by the user

GDPR legal basis: consent, expressed by granting permission and invoking the matching feature

Provide nearby and meetup features

Typical data: device location, coarse last location and city

GDPR legal basis: consent through the iOS permission; performance of the requested feature

Deliver push notifications

Typical data: push token, notification and delivery data

GDPR legal basis: consent through the iOS permission; performance of the requested feature

Link Discord and maintain the member role

Typical data: Discord identity and membership status

GDPR legal basis: consent and performance of the requested integration

Prevent abuse, enforce rules, resolve disputes and protect users

Typical data: reports, content, logs and enforcement records

GDPR legal basis: legitimate interests; compliance with legal obligations

Maintain records and respond to legal claims

Typical data: subscription, transaction, moderation and correspondence records

GDPR legal basis: legal obligation; establishment, exercise or defence of legal claims

Where processing relies on consent, consent may be withdrawn at any time. Withdrawal does not affect processing already carried out lawfully.

4. When we share data

We disclose data only as necessary to operate the Service, comply with law or protect users. Current categories of recipients include:

  • Supabase for authentication, database, storage, realtime and serverless backend services;
  • Apple for App Store subscriptions, Apple platform services and APNs;
  • RevenueCat for App Store receipt validation, entitlements, subscription analytics and lifecycle events;
  • Stripe for website checkout, subscription billing, invoices, tax information and the customer portal;
  • Expo for application updates, builds and push-notification delivery;
  • Google Maps Platform / Places for place search, place details and maps;
  • Discord when the user connects Discord and for server-role management;
  • Bird (MessageBird) for delivery of authentication SMS messages;
  • Vercel for hosting and serving the MOC website;
  • professional advisers, authorities or courts where disclosure is required or reasonably necessary.

These providers process data under their own terms and, where they act as our processors, under data-protection commitments. Notification content passes through Expo and Apple only for delivery.

We may disclose data in connection with a merger, financing, reorganisation or sale of all or part of the business, subject to applicable law and appropriate safeguards.

5. International transfers

Some providers may process data outside Estonia or the European Economic Area. Where required, we use an adequacy decision, the European Commission’s Standard Contractual Clauses, or another lawful transfer mechanism, together with supplementary safeguards where appropriate. Information about a specific transfer mechanism is available from the privacy contact above.

6. Retention

We keep personal data only for as long as reasonably necessary for the purposes described above:

  • account, profile and active membership data are generally retained while the account exists;
  • the latest coarse location replaces the previous row and is removed on account deletion; the Service does not maintain a location-history table;
  • QR approval tokens are short-lived, and authenticated website sessions expire after their configured session period or when revoked;
  • push tokens are retained while needed for delivery and removed when the account is deleted or the token is revoked or no longer valid;
  • personal profile moments and private Atlas/Guide collections are deleted when the account is deleted;
  • shared threads, polls, comments, marketplace records and messages may be retained under a de-identified “Deleted member” profile while needed to preserve community discussions, transaction evidence, safety records and dispute history, subject to moderation and legal-retention requirements;
  • subscription, invoice, accounting, fraud-prevention, dispute and legal records may be retained for the period required by law or needed to resolve a claim;
  • infrastructure logs and backups are retained on limited rolling schedules set according to security, recovery and legal needs.

When data is no longer required, we delete it or irreversibly anonymise it.

7. Account deletion and privacy controls

Users can edit profile and account information in the app. Device permissions can be changed in iOS settings, notifications can be disabled, Discord can be disconnected, and website sessions can be revoked.

Account deletion can be initiated in Profile → Settings → Manage Account → Delete Account. This deletes the authentication account, personal moments and their media, the private Atlas/Guide collection and data used only to operate the live account. It disconnects Discord and removes the profile’s public identity. Shared discussions and transaction, conversation, moderation or legal records may remain under the de-identified label “Deleted member” where they are needed by other participants or for safety, fraud prevention, transactions, disputes or legal obligations.

Deleting a The Bay account does not automatically cancel a subscription managed by Apple or Stripe. Users should cancel an Apple subscription in their Apple Account subscription settings and a Stripe subscription through the MOC billing portal. We will make this distinction clear before account deletion.

For additional access, correction, deletion or objection requests, email info@mocworldwide.com.

8. Your data-protection rights

Subject to applicable law, users may have the right to:

  • access personal data and receive a copy;
  • correct inaccurate or incomplete data;
  • request deletion or restriction;
  • object to processing based on legitimate interests;
  • receive data in a portable format where applicable;
  • withdraw consent;
  • lodge a complaint with a supervisory authority.

In Estonia, the supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon). Users may also contact the authority in the EEA country where they live or work.

We may need to verify identity before fulfilling a request. Statutory exceptions may apply.

9. Security

We use measures designed to protect personal data, including authenticated access, row-level database controls, restricted administrative interfaces, private media storage with time-limited access links, hashed session secrets, encrypted network connections and access logging. No system can guarantee absolute security.

10. Children

The Service is not directed to anyone under 18, and applications from people under 18 are rejected. If we learn that a minor has provided personal data, please contact us so that we can investigate and delete it where appropriate.

11. Changes

We may update this policy when the Service, providers or legal requirements change. We will publish the updated version and its effective date and, where required, provide additional notice in the Service.

12. Contact

MOC Worldwide OÜ
Registry code 17538821
Harju maakond, Tallinn, Kesklinna linnaosa
Tartu mnt 67/1-13b, 10115
Estonia
info@mocworldwide.com