Privacy Policy
Last updated: August 14, 2026
This policy is subject to change.
Burg Social, Inc. (“Burg Social,” “we,” or “us”) is committed to protecting your privacy. This Privacy Policy explains what information we collect, why we collect it, how we use and share it, how long we keep it, and your choices. By using the Burg mobile application (“Burg”), operated by Burg Social, Inc., the Burg Social website, or related services (the “Service”), you acknowledge the practices described here.
Burg is initially launching across Vermont, United States, on a statewide basis, and the Service may reference Vermont venues, events, and locations. We may expand to additional regions over time. This policy applies wherever the Service is offered unless we state otherwise.
1. Information We Collect
1.1 Account and Registration. Display name, username, email address, date of birth (collected during onboarding to confirm you meet Burg’s minimum age requirement and to apply age-restricted features), and password or authentication credentials.
1.2 Profile. Profile photo, biography, interests, preferences, social connections, group memberships, your self-selected profile gender marker, verification status, verified identity/status indicators, and verified name information if applicable (see Section 1.7).
1.3 User Content. Posts, place posts, comments, event content, Burg Group content, uploaded media, and other content you create.
1.4 Messages. Message content, participant identifiers, timestamps, and delivery metadata. Messages are treated as private communications protected by reasonable security safeguards. Messages are not end-to-end encrypted by default. We may access message content where required by law, to enforce our Terms, or in response to valid legal process.
1.5 Location Data. If you grant location permission, we collect location data to power hyperlocal discovery, nearby events, venue search, and related features. Location may be approximate or precise depending on settings. We do not share your precise live location with other users in real time without your explicit action. You can revoke location permission in device settings at any time.
1.6 Device and Technical Data. Device identifiers, IP address, OS version, app version, crash logs, diagnostics, client error reports, push notification tokens, and information about how you interact with the Service.
1.7 Verification Data. If you complete identity or age verification through Didit or another third-party verification provider (“Verification Provider”), we receive and store limited fields that may include first name, last name, full name, date of birth, age, gender information, and verification status or result metadata. The gender information we receive from the Verification Provider is displayed as a normalized sex marker derived from the government-issued ID used during verification; we refer to this value in our verification disclosures as your “ID Sex Marker” (see Section 3.1). Where supported, we may display a verified badge, verified identity/status indicators, verified name information, and a visual indicator reflecting your ID Sex Marker on your profile - shown as an icon rather than as printed text - to provide other users with additional trust context. The ID Sex Marker is separate from, and does not replace, your self-selected profile gender marker described in Section 1.2.
Burg Social uses Didit as an identity verification provider where verification is available. When you start verification, you may be redirected to or interact with Didit, and Didit may process information needed to complete the verification check, including verification-session information, identity document information, biometric or liveness information, device or fraud-prevention signals, and verification results. During identity verification, our identity-verification provider, Didit, may provide Burg with verification results and associated information, including gender information. Didit’s services are governed by Didit’s Terms & Conditions and Privacy Policy.
Burg Social does not store raw identity documents, selfie images, biometric templates, face geometry, or provider-decision payloads. The Verification Provider may process sensitive data - including government-issued documents, selfie images, and biometric data - under its own terms and privacy policy during the verification flow.
Didit acts as Burg Social’s data processor for identity verification. Burg Social configures Didit’s own verification-session retention to the minimum retention window Didit makes available, currently approximately 30 days from the verification session. Didit may nonetheless independently retain certain data for longer than that configured window to meet its own security, fraud-prevention, audit-logging, or legal-compliance obligations - for example, audit logs, fraud or abuse blocklist entries, or additional retention that a given jurisdiction’s biometric-privacy law separately requires - regardless of Burg Social’s configured window. Didit’s retention clock is tied to the verification session itself, not to Burg Social account-deletion events: Didit does not receive or act on Burg Social account-deletion signals, so deleting your Burg account does not shorten or reset Didit’s own independent retention timelines.
1.9 Safety and Moderation Data. Reports you submit, reports filed about you, blocked users, moderation actions, enforcement records, and security logs.
1.10 Push Notification Tokens. Device tokens used to deliver push notifications where you have enabled them.
1.11 Feedback and Contact Records. Information you provide when you contact our support team or submit feedback.
1.12 Product Interaction Data. When you use the Service, we may collect first-party interaction information such as views, detail opens, likes, dislikes, comments (as interaction events), RSVPs, saves, shares, follows, searches, taps, source or surface context, and venue, event, restaurant, or nightlife opens. These interaction records do not include raw private message content, raw post or comment body text, or precise latitude/longitude. We may derive coarse preference or interest scores from these interactions to personalize your experience (see Section 2). No third-party analytics SDKs, advertising identifiers, or device fingerprinting are used for this purpose.
1.13 Business and Venue Records. If you contact Burg Social on behalf of a business, venue, organizer, group, or Community Event, including through website business/venue email requests, we may collect and store business contact information, venue or event details, submitted descriptions or media, organizer names, and internal administrative notes. We use this information to review submissions, manage venue pages, communicate with businesses or organizers, maintain internal business records, and operate the Service.
2. How We Use Your Information
We use collected information to: create and maintain your account; provide Service features including posts, events, Burg Groups, discovery, and messaging; personalize your experience with relevant nearby content, including lightly ranking Home and Discover content according to coarse interests such as event categories, restaurants, nightlife, venues, groups, or posts derived from your first-party product interactions; administer venue pages, business submissions, and website business/venue requests; send push notifications (controllable in settings); facilitate verification through our Verification Provider; display your verified badge and verified identity/status or name information where applicable; use your verification status to determine feature eligibility, enforce verified-only audiences, apply Verified Only browsing preferences, apply leadership and Event-hosting limits, filter eligible discovery results, apply people-search and friend-request restrictions, determine Group Chat eligibility, update content audiences or Group memberships if verification becomes inactive, and prevent abuse and enforce safety rules; moderate content and enforce our Terms; investigate reports and cooperate with law enforcement when legally required; analyze usage to improve the Service; protect Service security and integrity; and comply with legal obligations. Personalization is a ranking adjustment, not an eligibility filter - it does not change what content you are allowed to see and does not override privacy, safety, age, verification, blocked-user, friends-only, or group visibility rules.
3. How We Share Your Information
3.1 With Other Users. Display name, profile photo, public posts, event content, and group participation are visible to other users per your settings and the applicable feature design. If your account is verified, your verified badge, verified name information (verified first name and last initial), and a visual indicator reflecting your ID Sex Marker are also visible to other users - this verified-identity display is automatic based on verification status alone and is not something you can separately turn off while remaining verified. The ID Sex Marker indicator is the normalized sex marker Burg receives from the identity verification process described in Section 1.7, shown on your verified profile as a small icon rather than as printed text; it is displayed only while your account remains verified and is separate from, and shown alongside rather than in place of, your self-selected profile gender marker. Your self-selected profile gender marker is also visible to other users unless you select “Prefer not to say,” in which case the public profile response omits it. Burg does not publicly display raw identity documents, selfie images, biometric templates, or any verification data beyond the verified name information and ID Sex Marker indicator described above.
3.2 With Service Providers. We share information with trusted service providers for cloud hosting, push notifications, content moderation, and customer support. Providers are contractually bound to use data only as directed.
3.3 With the Verification Provider. To complete verification, certain information is shared with the applicable Verification Provider, such as Didit. Their data practices are governed by their own privacy policy and terms, including Didit’s Terms & Conditions and Privacy Policy.
3.4 With Mapping Providers. On iOS, Burg uses Apple’s native map implementation. On Android, Burg uses Google’s native map implementation. Map-service requests may disclose the requested map area, zoom level, and ordinary network metadata such as IP address to the applicable provider. The applicable providers’ terms and privacy notices govern their processing.
3.6 For Legal and Safety Purposes. We may disclose information to comply with law, regulation, or legal process; protect the rights, property, or safety of Burg Social, users, or others; enforce our Terms; or detect or prevent fraud or illegal activity.
3.7 Business Transfers. Your information may be transferred in connection with a merger, acquisition, financing, or sale of assets. We will notify you of material changes in ownership or use.
3.8 With Your Consent. We may share information with third parties when you have consented.
3.9 No Sale of Personal Information. Burg Social does not sell your personal information to third-party advertisers or data brokers. We do not currently serve third-party targeted advertising in the Service.
4. Location Data
We collect location data only with your permission. You can revoke location access in device settings, but doing so may limit nearby discovery, event proximity, and venue search features. We do not share your precise live location with other users in real time unless you explicitly take an action that shares your location (for example, tagging a post at a specific place).
We do not intentionally store raw precise search-location logs. If raw precise search-location logs exist in our systems, they are generally retained for no more than 30 days. Precise coordinates associated with posts are generally stripped after 7 days while preserving the post content and general location context.
5. Public and Semi-Public Content
Content you post publicly - including public posts, place posts, event titles and descriptions, profile bios, display names, and verified identity/status labels - may be visible to other users and to the public. We cannot guarantee that others will not save, share, or screenshot your public content. Only share what you are comfortable with others seeing. Content audiences may also change: for example, a verified-only Burg Group you own or a verified-only Community Event or Group Event you created may automatically become public if your verification expires, is revoked, or otherwise becomes inactive, as described in our Terms of Service.
Posts may preserve the author’s profile photo (avatar) as it appeared at the time of posting, so that historical posts do not change every time a user updates their profile photo. When an account is deleted or anonymized, avatar snapshots associated with that user are cleared and the user’s posts render without an avatar, in accordance with the Account Deletion Policy.
6. Data Retention
We retain your information while your account is active and as long as necessary for the purposes described here. The following summarizes our general retention practices. Retention periods may be extended in specific cases for legal, safety, fraud-prevention, dispute-resolution, backup, or operational needs.
Account Data. Retained while your account is active. After account deletion, see our Account Deletion Policy.
Posts and Comments. Normal posts, place posts, and Burg Group posts may appear in the Home feed and on the dedicated place and group post surfaces for up to one week after they are created. Leaving those surfaces does not delete a post: it remains in the post history on its creator’s profile, and remains available to users who saved it, until the creator deletes it. We do not automatically delete posts because of their age. You may delete a post at any time, which also deletes its associated comments and post media and removes the post from every user’s Saved area. Posts and comments may also be removed through moderation, account deletion, or a legal or safety process.
Saved Items. Your saved venues, events, and posts are stored as private references to the original items, visible only to you. A saved item is removed when you unsave it, when the item is deleted by the person who created it, or when it is removed through moderation, account deletion, or a legal or safety process. Saved references are deleted when you delete your account.
Events. Event history is generally retained, including past and cancelled events. Cancelled events display a clear cancelled status.
Messages. Conversation deletion is per-user - when you delete a conversation, it is removed from your view but copies delivered to other participants may remain in their threads, devices, caches, or backups. After account deletion, your identity in conversations may appear as “Deleted User.” Message and conversation data is generally hard-deleted from our systems after all participants in a conversation have deleted it and an additional 30-day processing period.
Message Requests. Pending message requests generally expire after 180 days. Text from declined, withdrawn, or expired message requests is generally removed after 30 days.
Location Data. We do not intentionally store raw precise search-location logs. If they exist, they are generally retained for no more than 30 days. Precise post coordinates are generally stripped after 7 days.
Product Interaction Data. Raw first-party interaction events are generally retained for 180 days. Derived preference or interest scores are based on recent activity, use a 90-day scoring window, and are cleaned when stale or unsupported by recent signals. Account deletion removes raw interaction events and derived scores.
Verification Metadata. Limited verification fields and metadata are generally retained for the lifetime of your active account plus 3 years after account deletion. Failed or incomplete verification attempts are generally retained for 90 days. This is separate from Didit’s own verification-session retention, which Burg Social configures to Didit’s minimum available window of approximately 30 days, subject to Didit’s own independent retention exceptions (see Section 1.7).
Moderation and Safety Records. Reports, moderation actions, enforcement records, and related safety data are generally retained for 5 years. Records related to serious safety, legal, fraud, or repeat-abuse cases may be retained longer.
Intimate Image Removal (NCII) Request Records. This retention period is shorter than the Moderation and Safety Records above. Reported media itself is not retained as part of an Intimate Image Removal request - content actioned under our Intimate Image Removal Policy is removed, not preserved for evidentiary purposes. Requester-identifying information you submit with a request - your signature name, contact information, attestation, and any locator details - is generally retained for 90 days after the request is resolved and then purged. A minimal compliance and audit record describing what was removed, when, and the outcome is retained longer for legal and audit purposes.
Backups. Data may persist in backup and disaster recovery systems for up to 90 days after deletion from active systems.
Push Notification Tokens. Invalid or inactive push tokens are generally purged after 180 days, or immediately upon account deletion, notification disablement, logout, or provider invalidation.
Diagnostics and Error Reports. Raw diagnostics and client error reports are generally retained for 90 days. Aggregated or de-identified diagnostics may be retained for up to 24 months.
Support and Feedback Records. Support and feedback records are generally retained for 2 years.
Business Contact Records. Business leads and venue inquiries are generally retained for 3 years, or for the duration of an active business relationship plus 3 years.
Business Placement Records. Organizer names, administrative notes, and venue enrichment records are generally retained for the duration of the business relationship or relevant account relationship plus 3 years, or as required for accounting, legal, dispute-resolution, safety, or operational purposes.We will not retain your data longer than reasonably necessary for the purposes described above, subject to legal, safety, and operational exceptions.
7. Your Choices and Controls
-
Account Deletion: Profile -> Settings -> Account -> Delete account (see our Account Deletion Policy).
-
Location Permissions: Revoke anytime in device settings.
-
Notification Settings: Manage in-app or in device settings.
-
Profile and Content: Edit or delete in-app.
-
Blocking and Reporting: Tools available in-app.
-
Verification: Optional unless required to access certain features.
8. Minimum Age and Children’s Privacy
Burg currently requires users to be at least 18 years old to use the Service. We collect date of birth to confirm eligibility, and we may use identity or age verification to help confirm it; verified information may establish a different, authoritative date of birth. If Burg Social determines that an account holder does not currently meet the minimum age, access to the Service may be restricted until they become eligible - this is not a suspension or ban, and the account is not deleted solely for this reason.
The Service is not directed to children, and we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will delete it. If you believe a child has created an account, or that we hold information from a child under 13, please contact us at privacy@burgsocial.com.
9. Security
We use reasonable administrative, technical, and physical safeguards designed to protect information, such as encryption of data in transit and access controls. No system is perfectly secure. We cannot guarantee the absolute security of your information. If you believe your account has been compromised, contact us immediately at support@burgsocial.com.
10. Third-Party Links and Integrations
The Service may link to third-party websites, apps, or services. Burg Social is not responsible for their privacy practices. Review third-party privacy policies before sharing information with them.
11. Privacy Rights
Depending on where you live, you may have rights regarding your personal information, including the right to access, correct, or delete your data, or to opt out of certain uses. To submit a privacy request, contact privacy@burgsocial.com. We will respond to verified requests in accordance with applicable law. Vermont residents may also contact the Vermont Attorney General’s Consumer Assistance Program with consumer complaints.
12. Website
As of the last update, the Burg Social website (burgsocial.com) is a static public website that does not include Google Analytics, Firebase Analytics initialization, Google Tag Manager, advertising tags, tracking pixels, behavioral advertising cookies, cookies, local storage, session storage, IndexedDB, or on-site cookie-consent controls in the website code. Burg Social is preparing to host the static website through Firebase Hosting; hosting delivers the website and is separate from any Google Analytics measurement. If Burg Social later enables Google Analytics through its Firebase project, Burg Social may use aggregate website usage analytics to understand pages viewed, navigation through the website, general website interactions, referral information, browser and device information, and general technical or usage information. Burg Social does not currently intentionally send support-message contents, email-message contents, venue or event request templates, email addresses, passwords, identity-verification documents, government identification information, precise location, or sensitive personal information to Google Analytics through this website.
The website provides business/venue request email templates; free venue updates, missing venue requests, and venue event additions are submitted by email using those templates. Information sent through those business/venue email requests are handled as Business and Venue Records under Section 1.13 and may also be subject to the Venue and Business Contact Terms. The Support page currently provides support contact instructions and email links; information voluntarily sent to Burg Social for support is handled as support or feedback records under this policy. If we add analytics, cookies, local storage, consumer account forms, or other website features that materially change these practices, we will update this policy and our Cookie and Website Notice as needed.
13. Changes to This Policy
We may update this Privacy Policy. Material changes will be notified through the Service or other means, and the “Last updated” date will be revised. Continued use constitutes acknowledgment of the updated policy.
14. Contact Us
Privacy inquiries: privacy@burgsocial.com
Legal/General: legal@burgsocial.com
Phone: +1 802-316-8726
Website: burgsocial.com
Mailing Address:
Burg Social, Inc.
150 Dorset St Suite 245 - 275
South Burlington, VT 05403
United States
Legal notices may be sent to legal@burgsocial.com or to the mailing address above.