Last reviewed: June 2026
This policy explains what personal data HangPlan collects, why, who sees it, and what your rights are. It's written in plain English. If something's unclear, email us and we'll explain it.
The data controller is [COMPANY NAME / REGISTERED ADDRESS / ICO REGISTRATION NO]. That means this entity decides how and why your personal data is processed.
Privacy contact: [PLACEHOLDER: privacy contact email / DPO if applicable]
We only collect what's needed to run the service:
Email address and a hashed password (if you use email/password sign-up), or your name, email, and profile picture imported from Google (if you use Google sign-in). Used to identify you and authenticate your sessions.
Full name, profile photo, bio, location (free text), and contact info (free text). All optional. Visible to people you share events with. Used to help your friends recognise you and to personalise your experience.
Event names, descriptions, locations, cover images, dates, your availability markings, date votes, activity proposals, and activity votes. Used to run the event-planning features.
Chat messages (direct messages, group chats, event chats), photos you upload to events, comments on the event feed, and ephemeral online-presence status. Used to power the social features of HangPlan.
A log of emails we've sent you (for our own records and to avoid duplicate delivery), rate-limit counters, and invite-queue status. During the beta we also keep an internal admin activity log — sign-ups, sign-ins, and events created or confirmed — so our team can support the service and understand how it's used. It's visible only to our admins and is automatically deleted after 90 days. Used to run the service reliably and prevent abuse.
If you submit feedback using the beta feedback widget, your free-text comment is sent to GitHub as a repository issue, along with automatically captured context: page URL, viewport size, browser user-agent, and your user ID and email address. This mechanism is used only during the beta period to help us fix issues quickly.
[PLACEHOLDER: confirm lawful bases — likely performance of a contract for core features, legitimate interests for security/operations, and consent for any future analytics. Confirm before launch.]
We don't sell your data. We use the following third-party services to run HangPlan. Each is contractually bound to process your data only as instructed.
Our database, authentication, file storage, and realtime infrastructure. Stores your account, profile, events, messages, and uploaded files. Production data region: [CONFIRM: Supabase region — likely EU/London].
Sends transactional emails and event invitations on our behalf. Processes recipient email addresses and email content. See Brevo's privacy policy.
If you choose “Sign in with Google”, Google authenticates you via OAuth and shares your name, email, and profile picture with us. See Google's privacy policy.
Beta-feedback submissions are sent to a private GitHub repository as issues. Each issue may contain your feedback text, page URL, browser info, and your user ID and email. This is used only during the beta period. See GitHub's privacy statement.
Hosts the HangPlan web application at the edge. Processes request metadata (IP address, request logs) as part of serving the app. See Vercel's privacy policy.
[CONFIRM: whether any processor stores/transfers data outside the UK/EEA and the safeguard used — e.g. adequacy decision, standard contractual clauses.]
[PLACEHOLDER: define retention periods per data category — e.g. account data kept while account is active + X years, chat messages kept for Y months, email logs kept for Z months. Do not ship unfilled.]
When your account is deleted, your personal data is removed from our systems within a reasonable period, except where we're required to retain it by law.
Under UK GDPR, you have the following rights. To exercise any of them, contact us at [PLACEHOLDER: privacy contact email / DPO if applicable].
We aim to respond within one month. If you're not satisfied with our response, or believe we're processing your data unlawfully, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
We use HTTPS for all data in transit, Supabase's encrypted storage at rest, server-side authorization on every data mutation, and row-level security policies on every database table. Passwords are never stored in plain text — they are hashed by Supabase Auth before being stored.
No system is perfectly secure. If you discover a security issue, please report it to [PLACEHOLDER: privacy contact email / DPO if applicable].
If we make material changes, we'll update the “Last reviewed” date above and, where appropriate, notify you by email. Continued use of HangPlan after a change constitutes acceptance of the updated policy.