← Home

Privacy Policy

Last updated: 22 September 2026

Short version: We use Facebook Login to identify you. We store your name, email, and profile photo so you can post and manage listings in your local community directory. We do not sell your data or use it for advertising.

1. Who we are

Collabify Ltd operates the Conexa mobile application and the Conexa platform registry at https://conexa.collabify.net. Conexa is a platform for independent, community-run local directories. Each community directory is operated separately by its own administrator.

For privacy questions, contact us at privacy@collabify.net.

2. What data we collect and why

Account data (via Facebook Login)

When you log in with Facebook we receive and store:

This data is used to create and manage your account. We do not receive your friends list, posts, or any other Facebook data.

Community membership

Some community directories check whether you are a member of an associated Facebook Group to determine your access level. This check is performed at login and the result (member / not a member) is stored alongside your account. We do not store your group membership list.

Listings and content you post

If you create a listing (business, club, or job), we store the content you submit: name, description, location, contact details, images, opening hours, and the date posted. This content is publicly visible within that community directory.

Device storage

The app stores a JSON Web Token (JWT) in your device's secure storage (iOS Keychain / Android Keystore). This token authenticates your subsequent requests to the community site. It does not contain personal data beyond your user ID.

Usage data

We do not use analytics SDKs or advertising trackers. Standard web server logs (IP address, request path, timestamp) are kept for security and diagnostic purposes and are automatically purged after 30 days.

3. How we use your data

We do not use your data for advertising, profiling, or any automated decision-making.

4. Third parties

Meta (Facebook) — we use Facebook Login for authentication. By logging in with Facebook you are also subject to Meta's Privacy Policy. We do not share your data back to Facebook beyond what the OAuth flow requires.

Community site operators — when you join a community directory, your account data (name, email, photo, Facebook ID) is stored on that community's server. Each community operates under its own privacy policy, which you should review separately.

Hosting infrastructure — community sites and the Conexa registry are hosted on shared hosting infrastructure in the United Kingdom. No data is transferred outside the UK/EEA.

We do not sell, rent, or share your personal data with any other third party.

5. Legal basis for processing (UK GDPR)

We process your personal data on the following bases:

6. How long we keep your data

We retain your account data for as long as your account is active on any Conexa community site. If you request deletion, we will remove your personal data within 30 days.

Listings you have posted may be retained in anonymised form by the community directory operator, or deleted at your request.

Server access logs are purged automatically after 30 days.

7. Your rights

Under UK GDPR you have the right to:

To exercise any of these rights, email privacy@collabify.net. We will respond within 30 days.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

8. Data deletion

To delete your account and all associated personal data:

  1. Email privacy@collabify.net with the subject line "Delete my account"
  2. Include the email address associated with your Facebook account
  3. We will confirm deletion within 30 days

You can also revoke Conexa's access to your Facebook account at any time via Facebook Settings → Apps and Websites. Revoking access prevents future logins but does not automatically delete data already stored. Email us to request full deletion.

9. Security

Authentication tokens are stored in your device's operating-system-level secure storage (iOS Keychain, Android Keystore). Passwords are hashed using bcrypt. All data in transit is encrypted via HTTPS/TLS.

10. Children

The Conexa app is not directed at children under 13. We do not knowingly collect personal data from anyone under 13. If you believe a child under 13 has provided us with personal data, please email privacy@collabify.net and we will delete it promptly.

11. Changes to this policy

If we make significant changes to this policy we will update the date at the top of this page. Continued use of Conexa after changes are posted constitutes acceptance of the updated policy.