Privacy Statement
Augmento FZCO Last updated: 16 September 2026 Effective date: 16 September 2026 for new users. 30 September 2026 for existing users (see section 17).
1. Who we are
This Privacy Statement explains how Augmento FZCO ("Augmento", "we", "us", "our") collects, uses, shares, and protects personal data when you interact with our websites, apps, App Clips, AR experiences, dashboards, APIs, SDKs, and related services (the "Services").
Data controller: Augmento FZCO Dubai Silicon Oasis, Dubai, United Arab Emirates Email: privacy@augmento.com Data Protection Officer: dpo@augmento.com
Augmento is based in the UAE. Our participants are in the UAE, Brazil, the European Union and the United States, so we follow the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, the "PDPL"), the EU General Data Protection Regulation ("GDPR") and Brazil's Lei Geral de Proteção de Dados ("LGPD").
For Brazilian users (e.g. Seleção Eterna / CBF activations), Augmento acts as controller under the LGPD and has appointed a Brazilian Data Protection Officer (Encarregado), reachable at dpo-br@augmento.com.
Augmento Drops. Augmento Drops is our no-app AR campaign platform. Brands create campaigns in a dashboard. Participants join through a web page or our iOS App Clip or app, find "drops" on a map, collect them in AR, answer quizzes and questionnaires, earn coins and claim rewards. For Augmento Drops:
- Augmento is a controller for participant accounts, rewards, referrals, the public leaderboard, Proof of Presence scoring and Augmento's own marketing.
- In the brand dashboard, Augmento acts as a processor for the brand.
- The brand is a separate controller for its own marketing and for any data it exports.
For other Customers (Enterprise clients, sponsors, brand partners) who use our Services to deliver experiences to their own end users, Augmento generally acts as a data processor on their behalf. Their privacy notice will apply to those interactions in addition to this Statement.
2. Scope
This Statement applies to:
- Visitors to augmento.com, discover.augmento.com, and related domains.
- Users of Augmento Studio (our SaaS dashboard).
- Participants in Augmento Drops campaigns (treasure hunts, AR collectibles, quizzes, rewards, leaderboards), and brands using the Augmento Drops dashboard.
- Visitors and participants in Augmento ART experiences at galleries, exhibitions, and cultural venues.
- Participants in Custom Projects: bespoke AR/3D experiences delivered at events, venues, exhibitions, and brand activations.
It does not apply to third-party websites, apps, or services that link to, embed, or are linked from our Services. Read their privacy notices separately.
3. Information we collect
We collect the following categories of personal data:
3.1 Identity data
Name, email address, phone number, date of birth (where age verification is required), profile photo or avatar, username, country of residence.
3.2 Authentication data
Hashed passwords, OAuth tokens, and session identifiers. Augmento Drops participants sign in with an email and password, with Google, or with Sign in with Apple.
3.3 Behavioural data
Interactions with AR experiences: items collected, levels reached, leaderboard position, completion times, click and scroll events, pages visited, session duration, drop-off points, conversion events.
3.4 Affinity and preference data
Stated preferences, opted-in interests (e.g. football team, art genre, neighbourhood), survey responses, quiz answers, sponsor interactions.
3.5 Social-graph data (where you connect)
If you choose to connect a social account or share content, we may collect public profile fields, friend lists you authorise, and shared content metadata.
3.6 Device and technical data
IP address, device model, OS and browser version, language, timezone, screen size, app version, crash logs, performance traces, AR-capability signals (camera, gyroscope, ARKit/ARCore availability). We use IP addresses to derive coarse location. In Augmento Drops we also store a hashed IP address with each claim (Proof of Presence) and the IP address with each consent record (see section 3.12).
3.7 Location data
- Coarse location (city/region) derived from IP, used for analytics and content localisation.
- Precise GPS location only when an experience needs it, and only after you grant the permission.
- In Augmento Drops, we use your location live to show the map and to place drops near you. Drops are always placed within a random radius around you, never at your exact spot. We also store a location reading with each claim to check that you were really there (Proof of Presence). Section 3.12 lists what is stored and section 12.1 says how long we keep it.
- In other experiences, precise location is processed in real time and is not retained beyond what is needed to validate the relevant action, unless you opt in to additional features.
3.8 Camera, sensor, and microphone data
AR experiences process camera frames, motion sensors, and (rarely) microphone input on-device. We do not transmit raw camera or microphone streams to our servers, except where a specific experience explicitly requires it (e.g. a user-initiated photo or video capture you choose to share). When that happens, it is disclosed in-experience and consent is collected.
In Augmento Drops you can record a short AR clip. We record one only when you tap record or share. The clip shows the AR scene, which includes your surroundings, and it is shared with the campaign's brand, who can view it in their dashboard.
3.9 User-generated content
Photos, videos, comments, or other content you choose to capture, upload, or share.
3.10 Payment data
We do not currently process card payments inside the Services. Paid work is invoiced and settled by bank transfer or via an external payment link shown on the invoice; any card details you enter there are handled by that external provider, not by us. We never collect or store payment card numbers on our systems. If we introduce in-product payments, we will use a PCI-DSS-compliant payment processor and update this Statement beforehand.
3.11 Communications data
Emails, support tickets, chat messages with our team, and feedback you send us.
3.12 Augmento Drops participant data
When you take part in an Augmento Drops campaign, we collect:
Account
- First name, last name and email.
- How you sign in: email and password, Google, or Apple.
Campaign activity
- The drops you collected and when.
- Your quiz and questionnaire answers, including any free text you type into an "Other" answer (up to 200 characters).
- Coins you earned and spent, and rewards you claimed and redeemed.
Proof of Presence (stored with each claim, to prevent fake claims)
- GPS latitude, longitude and accuracy, how old the GPS reading was, and your distance to the drop.
- A hashed IP address, device and session identifiers, your browser or app user agent, network type and country.
- A presence score and verdict.
AR clips
- A short video of the AR scene, which shows your surroundings.
- Recorded only when you tap record or share.
- Shared with the campaign's brand, who can view it in their dashboard.
Referrals
- Who invited whom, for each campaign, and the coins earned for it.
Consent records
- The exact marketing text you were shown, which boxes you ticked or left unticked, the time, your IP address, user agent and country, and the channel (web or iOS).
Unsafe spot reports
- If you report a drop location as unsafe: the location, the reason you chose and any note you add.
Public leaderboard
- Your first name, the initial of your last name and your coin total. Anyone who has the campaign's leaderboard link can see it.
Reminders
- Reminders to finish a hunt are scheduled locally on your device and are not sent to our servers. You can turn them off in Account.
Age
- Some campaigns are for adults (18+) and ask you to confirm your age before you play.
4. How we collect personal data
- Directly from you when you sign up, fill in a form, scan a marker, complete a quiz, or contact us.
- Automatically through cookies, SDKs, app telemetry, and server logs as you use the Services.
- From Customers and partners: for example, a sponsor or rights-holder may share an attendee or member list with us so we can deliver an experience to them.
- From third parties, such as authentication providers (Google and Apple), public sources, or analytics partners.
5. Why we use personal data (purposes)
| Purpose | Examples |
|---|---|
| Provide the Services | Authenticate users, deliver AR experiences, track collectibles, render leaderboards. |
| Run Augmento Drops campaigns | Place drops near you, track coins and rewards, deliver rewards, credit referrals, share campaign data with the brand (see section 10.2). |
| Account management | Customer support, password resets, billing. |
| Personalisation | Show relevant drops, regional content, language. |
| Analytics and product improvement | Understand engagement, fix bugs, optimise AR performance. |
| Sponsor and rights-holder reporting | Aggregated and (where consented) identified attribution metrics. |
| Marketing communications | Newsletters, product updates, event invites, only with consent or where permitted. |
| Security and fraud prevention | Detect abuse, bots, account takeovers. Check that Augmento Drops claims were made in person (Proof of Presence). |
| Legal compliance | Tax records, anti-money-laundering, regulator requests. |
6. Legal bases for processing
Where the UAE PDPL, GDPR, LGPD, or similar laws apply, we rely on the following legal bases:
- Consent: for marketing, precise location, optional camera/microphone features, and certain cookies.
- Contract: to provide the Service you signed up for.
- Legitimate interests: for analytics, product improvement, security, and limited direct marketing to existing customers, balanced against your rights.
- Legal obligation: for tax, accounting, and regulator obligations.
- Vital interests: in rare safety-related situations.
You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
7. AR-specific privacy notes
Augmented reality experiences raise specific privacy considerations. We commit to:
- On-device processing by default. Camera, motion, and microphone data are processed locally by ARKit, ARCore, or the browser's WebXR/WebAR engine.
- Explicit, contextual permissions. We request camera and location permissions only when the experience needs them, with a clear in-context explanation.
- No silent recording. We never record audio or video without an explicit user action (e.g. you tap "Capture", or record or share in Augmento Drops).
- No facial recognition. We do not run facial-recognition or biometric-identification algorithms on people in the camera view.
- No retention of raw frames. Raw camera frames used by tracking are not retained or transmitted, except as part of media you choose to capture and share. In Augmento Drops, AR clips you record are shared with the campaign's brand (see section 3.8).
8. AI-assisted features
Some features rely on third-party artificial-intelligence services acting as our processors:
- Website and dashboard chat: messages you type into our chat are sent to Anthropic (Claude models), together with relevant excerpts from our knowledge base, to generate a reply.
- Document processing: documents uploaded to our internal knowledge tooling are processed by OpenAI (text embeddings and parsing).
- Media generation and labeling: images may be generated or automatically labeled using Google Gemini.
- Quiz generation: in the Augmento Drops brand dashboard, a brand can generate quiz questions with OpenAI. Only the topic and settings the brand enters are sent. No participant data is sent.
We send these providers only the content needed to run the feature. Under our API agreements, inputs and outputs are not used to train their foundation models. Please do not enter sensitive personal data into chat features.
9. Cookies and similar technologies
We use cookies, local storage, and SDK identifiers to operate, secure, and improve the Services. Categories include:
- Strictly necessary: authentication, security, load balancing.
- Functional: remembering preferences and settings.
- Analytics: Google Analytics 4 (loaded via Google Tag Manager), Microsoft Clarity, and PostHog (EU-hosted), loaded only after you accept the consent banner; plus server logs and performance monitoring.
- Marketing: only with consent and only on properties where applicable (e.g. campaign landing pages).
Separately from consent-gated analytics, we use Sentry for error and crash reporting on the basis of our legitimate interest in keeping the Services secure and functional. Error reports may include your IP address, device information and, when an error occurs, a replay of the affected session so we can reproduce the fault.
You can manage non-essential cookies through our cookie banner (where shown) and your browser settings. A full cookie list is maintained at augmento.com/cookies (or available on request).
10. Sharing and disclosure
We share personal data with:
10.1 Sub-processors and infrastructure providers
Hosting and infrastructure
- Amazon Web Services: hosting, database, file storage and sign-in (Amazon Cognito) for Augmento Drops, in the USA (us-east-2 region).
- Vercel: hosting for the Augmento website and HQ dashboard (US and EU regions).
- Supabase: database, authentication and file storage for the Augmento website and HQ dashboard.
- Cloudflare: CDN and security in front of Augmento Drops, R2 object storage, video streaming (Stream) and bot protection (Turnstile).
- Upstash: rate limiting.
- Postmark: transactional email for Augmento Drops.
- Resend: transactional email from the Augmento website and HQ dashboard.
Maps and location
- Mapbox: maps in Augmento Drops on the web.
- Apple: maps in the Augmento Drops iOS app (MapKit).
- Google: Maps and Places APIs.
- ipapi.co: approximate location and time zone derived from your IP address in Augmento Drops.
Analytics and monitoring
- PostHog: product analytics on our websites (EU-hosted, with consent).
- Google: Tag Manager and Analytics 4 (with consent).
- Microsoft: Clarity session replay and heatmaps (with consent).
- Sentry: error and crash reporting for our websites and the Augmento Drops iOS app (EU-hosted).
AI (see section 8)
- Anthropic: chat and translation features.
- OpenAI: document processing, and quiz generation in the Augmento Drops dashboard.
- Google: Gemini media generation and labeling.
Media
- Cloudinary: media upload and processing.
Sign-in and distribution
- Apple: Sign in with Apple, App Store and App Clip delivery.
- Google: Google sign-in and Google Play.
- Stytch: OAuth for API and connector integrations.
Payments
- Stripe: payments for brand subscriptions and invoices. Card details are entered on Stripe's pages, never on ours.
A current sub-processor list is maintained at augmento.com/subprocessors.
10.2 Brands running Augmento Drops campaigns, and other Customers
When you join an Augmento Drops campaign, the brand running it receives your name, email, questionnaire answers, the rewards you claimed and your AR clips. The brand gets this to run the campaign and deliver your rewards, not for marketing.
We ask about marketing as two separate, optional choices. Both are unticked by default, and you never have to agree to either to take part:
- "Send me news and offers from [brand]"
- "Send me news from Augmento"
The brand only sees whether you agreed to the brand's own emails. It never sees your answer about Augmento.
You can change either answer at any time in Account (in the app and in the web menu), or with the unsubscribe link in any email.
Once a brand exports participant data, that copy is held by the brand under the brand's own privacy policy.
For other experiences run by a Customer (e.g. a football federation, hospitality brand, art gallery, event organiser), aggregated and (with your consent) identified data may be shared with that Customer per their privacy notice and our Data Processing Agreement.
10.3 Professional advisors
Lawyers, accountants, auditors, and M&A advisors, under confidentiality.
10.4 In a corporate transaction
If Augmento is acquired, merges, or sells substantially all assets, personal data may be transferred to the successor, subject to this Statement (or a substantially equivalent one).
10.5 Legal and regulatory
Where required by law, court order, regulator, or to protect Augmento's rights, property, or safety, or those of users or the public.
10.6 Public leaderboard
Augmento Drops campaigns have a public leaderboard. It shows your first name, the initial of your last name and your coin total, and anyone who has the campaign's leaderboard link can see it.
We do not sell personal data in the conventional sense and do not engage in cross-context behavioural advertising for our own benefit. Customers may run sponsor-attributed campaigns via our infrastructure, and where this constitutes "sale" or "sharing" under California law, we provide opt-out controls (see Section 13).
11. International transfers
Augmento is based in the UAE. Personal data may be transferred to and processed in countries other than your own, including the United States, the European Union, and the United Kingdom, where our sub-processors and cloud regions are located.
Augmento Drops data is hosted by Amazon Web Services in the United States (us-east-2 region). For those transfers we rely on:
- From the UAE: the cross-border transfer provisions of the PDPL (Articles 22 and 23), supported by AWS's data processing terms.
- From the EU: Standard Contractual Clauses.
- From Brazil: the ANPD's standard contractual clauses.
For our other Services, where required, we rely on:
- Standard Contractual Clauses approved by the European Commission (for EEA/UK transfers).
- LGPD-compliant transfer mechanisms for transfers from Brazil.
- Contractual safeguards and security measures with all sub-processors.
A list of countries where data may be processed and the safeguards applied is available on request from dpo@augmento.com.
12. Data retention
We retain personal data only as long as needed for the purposes described, then delete or anonymise it.
| Category | Default retention |
|---|---|
| Account and identity data | While the account is active + 24 months |
| Behavioural and analytics data | 25 months in identified form, then aggregated |
| Marketing communications | Until you unsubscribe + 12 months |
| Support tickets and communications | 36 months |
| Billing, invoices, tax records | 7 years (UAE/EU compliance) |
| Server and security logs | 12 months |
| Raw AR camera frames (transient) | Real-time only, not retained |
| Identified location data outside Augmento Drops | Not retained beyond the session unless you opt in |
| Augmento Drops participant data | See section 12.1 |
We may retain data longer where required by law, to defend legal claims, or to investigate suspected violations.
12.1 Augmento Drops
These periods are enforced automatically by a job that runs every day.
| Data | Retention |
|---|---|
| Account, answers, rewards, referrals, consent records | Until you delete your account |
| Location and device details from Proof of Presence (GPS, IP hash, device and session identifiers, user agent) | While the campaign runs, then deleted 90 days after the campaign ends. Never kept longer than 2 years from the claim. The presence score and verdict stay for campaign reporting. |
| AR clips | While the campaign runs, then deleted 180 days after the campaign ends. Never kept longer than 2 years from recording. |
| Data belonging to a campaign the brand deletes | Location details and clips removed within a day |
| Backups | Database snapshots and backups are kept for 7 days. Deleted data can persist in those backups until they expire. |
"Campaign ends" means the brand switches the campaign off.
13. Your rights
Depending on where you live, you may have the following rights:
- Access: request a copy of the personal data we hold about you.
- Rectification: correct inaccurate or incomplete data.
- Erasure / "right to be forgotten": subject to legal limits.
- Restriction: limit how we process your data.
- Portability: receive your data in a structured, machine-readable format.
- Objection: object to processing based on legitimate interests, including direct marketing.
- Withdraw consent: at any time, where processing is based on consent.
- Lodge a complaint with a supervisory authority: the UAE Data Office, the ANPD in Brazil, your data protection authority in the EU, or the ICO in the UK.
To exercise rights, email privacy@augmento.com or dpo@augmento.com. We respond:
- Under the GDPR: within 1 month (extendable by up to two further months for complex requests, with notice).
- Under the LGPD: within 15 days.
- Under the UAE PDPL: within 14 days.
- Everywhere else: within 30 days.
13.1 Brazilian users (LGPD)
You have specific rights under the LGPD, including confirmation of processing, access, correction, anonymisation/blocking/deletion of unnecessary or excessive data, portability, information about sharing, and revocation of consent. Brazilian DPO: dpo-br@augmento.com.
13.2 California residents (CCPA/CPRA)
You may request to know, delete, or correct personal information, and opt out of "sale" or "sharing". Submit requests to privacy@augmento.com with subject "California Privacy Request". We will not discriminate against you for exercising your rights.
13.3 EEA / UK residents (GDPR / UK GDPR)
You have the rights listed above. You may also lodge a complaint with your local DPA. We have not yet appointed an EU representative under Article 27 GDPR. We are appointing one, and their name and contact details will be published here.
13.4 UAE residents (PDPL)
You have the rights the PDPL gives you over your personal data. You can make a request to privacy@augmento.com, and you can complain to the UAE Data Office.
13.5 Augmento Drops participants
Deleting your account
- In the app: go to Account, then Delete my account, and confirm twice.
- On the web: open the Account menu, then Delete my account.
- Without the app: email privacy@augmento.com from the email address linked to your account, with the subject line "Delete my account". We complete verified requests within 30 days.
Deleting your account removes your profile, sign-in identity, coins, rewards, drop history, quiz and questionnaire answers, referrals, Proof of Presence records, consent records and AR clips. Data a brand has already exported is held by that brand.
Your other rights To access your data, get a copy of it, correct it, object to how we use it, or restrict how we use it, email privacy@augmento.com. There is no in-app data export yet.
Help Participant help, including how to delete your account without the app, is at augmento.com/support.
Marketing choices You can change your marketing choices at any time in Account or with the unsubscribe link in any email (see section 10.2).
14. Children's privacy
Our Services are not directed at children under 16 (or the equivalent age of digital consent in your country). We do not knowingly collect personal data from children under that age without verifiable parental or guardian consent. If you believe we have collected such data, contact privacy@augmento.com and we will delete it.
For experiences that may be played by minors with parental consent (e.g. family-friendly football fan experiences), additional safeguards are applied: minimal data collection, no behavioural advertising, and parental controls where required.
Some Augmento Drops campaigns are for adults only (18+). These campaigns ask you to confirm your age before you play.
15. Security
We implement reasonable technical and organisational measures to protect personal data, including:
- Encryption in transit (TLS 1.2+) and at rest for sensitive datastores.
- Access controls, role-based permissions, MFA on administrative accounts.
- Network segmentation, WAF, and DDoS protection (Cloudflare, Vercel).
- Regular dependency, vulnerability, and penetration scanning.
- An incident response plan. Where required, we notify a personal data breach to the relevant GDPR supervisory authority within 72 hours, to the ANPD in Brazil within 3 business days, and to the UAE Data Office without undue delay and in any case within 72 hours of becoming aware, and we tell affected users where required.
- Sub-processors are vetted and contractually bound to equivalent standards.
No system is 100% secure. If you suspect an incident, email security@augmento.com.
16. Automated decisions and profiling
We may use automated processing to detect fraud, prevent abuse, score engagement, and personalise content. In Augmento Drops, for example, we calculate a presence score and verdict for each claim to detect fake claims (see section 3.12). We do not make decisions producing legal or similarly significant effects on you solely by automated means without human review. You may request human review of any such decision.
17. Changes to this Statement
We may update this Privacy Statement from time to time. Material changes will be notified via in-product notice or email at least 14 days before they take effect. The "Last updated" date at the top reflects the most recent version. Previous versions are available on request.
18. Contact
Augmento FZCO Dubai Silicon Oasis, Dubai, United Arab Emirates
| Topic | |
|---|---|
| General privacy | privacy@augmento.com |
| Data Protection Officer (global) | dpo@augmento.com |
| Brazilian DPO (Encarregado) | dpo-br@augmento.com |
| Security incidents | security@augmento.com |
| General contact | hello@augmento.com |