Privacy Policy

Last Updated: January 2026 · Version: 1.0 (Beta)


1. Introduction

Bloc (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and services (collectively, the “Service”).

Please read this Privacy Policy carefully. By using Bloc, you agree to the collection and use of information in accordance with this policy.

2. Data Controller

Contact Email: hello@bloc.so

Website: bloc.so

For the purposes of applicable data protection laws (including GDPR where applicable), Bloc is the data controller responsible for your personal information.

3. Information We Collect

3.1 Information You Provide Directly

Account Information:

  • Phone number (required for registration and authentication)
  • Name (optional, for profile personalization)
  • Personal Identification Number (PIN) - stored as cryptographic hash only

Tontine Information:

  • Tontine names and descriptions you create
  • Member names and phone numbers you add to tontines
  • Contribution amounts you define
  • Dates and schedules you set

3.2 Information Collected Automatically

Device Information:

  • Device type and model
  • Operating system and version
  • Unique device identifiers
  • Mobile network information

Usage Data:

  • App interactions and features used
  • Session duration and frequency
  • Error logs and crash reports (via Sentry)
  • Performance metrics

Location Data:

  • We do NOT collect precise geolocation data
  • General location may be inferred from IP address or phone number country code for service delivery

3.3 Information We Do NOT Collect

We explicitly do NOT collect:

  • Payment card information (no payment processing in current version)
  • Precise GPS location
  • Contact lists from your device
  • Messages or communications content
  • Biometric data (Face ID/Touch ID processed locally on device only)

4. How We Use Your Information

4.1 Service Delivery

  • Create and manage your Bloc account
  • Authenticate you via phone number and PIN
  • Enable tontine creation, management, and participation
  • Calculate and display tontine schedules and allocations
  • Send notifications about tontine activities
  • Provide customer support

4.2 Service Improvement

  • Analyze usage patterns to improve features
  • Debug errors and crashes
  • Optimize performance
  • Develop new features

4.3 Legal and Security

  • Comply with legal obligations
  • Prevent fraud and abuse
  • Enforce our Terms of Service
  • Protect users' rights and safety

4.4 Communications

  • Send service-related notifications (payment reminders, payout confirmations)
  • Respond to your inquiries
  • Provide important updates about the Service

We do NOT use your information for:

  • Selling to third parties
  • Marketing or advertising (current version)
  • Sharing with partners for their marketing

5. Legal Basis for Processing (GDPR)

For users in the European Union, we process your personal data based on:

  • Contract Performance: Processing necessary to provide the Service you requested
  • Legitimate Interests: Improving our Service, preventing fraud, ensuring security
  • Consent: Where you have explicitly agreed (e.g., optional notifications)
  • Legal Obligation: Compliance with applicable laws

6. Data Storage and Security

6.1 Where We Store Your Data

Your data is stored on secure servers provided by Google Cloud Platform in the European Union (Europe region). No data transfers outside the EU occur in the current version.

6.2 Security Measures

Technical Safeguards

  • End-to-end encryption (TLS/SSL)
  • Encryption at rest for database
  • PIN stored as cryptographic hash
  • Secure session management
  • Regular security audits

Organizational Safeguards

  • Access controls and authentication
  • Limited personnel access
  • Confidentiality agreements
  • Regular security training

6.3 Data Retention

  • Active accounts: Data retained while account is active
  • Account deletion: Personal data deleted within 30 days of request
  • Backup systems: Data may persist for up to 90 days in backups
  • Anonymized/aggregated data: May be retained indefinitely for analytics

7. Data Sharing and Disclosure

7.1 Information Shared Within Tontines

When you participate in a tontine, your name and phone number are visible to the organizer, and your contribution amount and payout schedule are visible to all members. This is essential for tontine transparency and trust.

7.2 Third-Party Service Providers

ProviderPurposeData SharedLocation
Google CloudHosting & storageAll app dataEU
SentryError monitoringDevice info, error logsEU/US

7.3 What We NEVER Do

  • Sell your personal data to third parties
  • Share your data for others' marketing purposes
  • Rent or trade your information
  • Use your data in ways not described in this policy without consent

8. Your Rights

8.1 Rights Under GDPR (EU Users)

Right to Access

Request a copy of your personal data

Right to Rectification

Correct inaccurate or incomplete data

Right to Erasure

Request deletion of your data ("right to be forgotten")

Right to Restrict Processing

Limit how we use your data

Right to Data Portability

Receive your data in portable format

Right to Object

Object to processing based on legitimate interests

Right to Withdraw Consent

Withdraw consent at any time

Right to Lodge Complaint

File complaint with your data protection authority

8.2 How to Exercise Your Rights

Contact us at hello@bloc.so. We will respond within 30 days.

8.3 Rights Within the App

  • Update your profile information
  • Delete tontines you created
  • Leave tontines you joined (with organizer consent)
  • Delete your account (Settings > Account > Delete Account)

9. Children's Privacy

Bloc is not intended for users under 18 years of age. We do not knowingly collect information from children under 18. If you believe we have collected information from a child under 18, please contact us immediately at hello@bloc.so.

10. International Data Transfers

All data is currently stored in the EU. No international transfers occur in the current version. If we transfer data outside the EU/EEA in the future, we will use Standard Contractual Clauses (SCCs), implement additional safeguards, notify you, and provide opt-out mechanisms where legally required.

11. Cookies and Tracking

The Bloc mobile app does NOT use cookies, as it is a native application. Current version does NOT include analytics tracking. If added in future versions, we will update this policy and provide opt-out mechanisms.

12. Notifications

Service Notifications (Essential)

  • Payment reminders
  • Payout confirmations
  • Tontine status changes
  • Security alerts

Optional Notifications

  • Product updates
  • Tips and best practices

You can manage notification preferences in App Settings > Notifications or Device Settings > Bloc > Notifications.

13. Third-Party Links

Bloc may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read their privacy policies before providing any information.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email notification and in-app notice. Minor changes will be reflected in the “Last Updated” date. Your continued use of Bloc after changes constitutes acceptance of the updated policy.

15. Data Breach Notification

In the unlikely event of a data breach affecting your personal information, we will notify you within 72 hours of becoming aware (as required by GDPR), inform you of the nature of the breach, describe steps we are taking to address it, provide recommendations to protect yourself, and notify relevant authorities as required by law.

16. Contact Us

Email: hello@bloc.so

Response Time: Within 30 days

17. Supervisory Authority

EU users have the right to lodge a complaint with their local data protection authority, including:

  • France: CNIL (Commission Nationale de l'Informatique et des Libertés)
  • Côte d'Ivoire: ARTCI (Autorité de Régulation des Télécommunications/TIC de Côte d'Ivoire)

18. Beta Testing Notice

IMPORTANT: Bloc is currently in beta testing phase.

  • The Service may contain bugs or errors
  • Features may change or be removed
  • Data structures may evolve
  • All privacy protections still apply during beta
  • Report issues to hello@bloc.so

By using Bloc, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.

Bloc · hello@bloc.so