Privacy Policy

Last reviewed: June 2026

This policy explains what personal data HangPlan collects, why, who sees it, and what your rights are. It's written in plain English. If something's unclear, email us and we'll explain it.

1. Who is responsible for your data?

The data controller is [COMPANY NAME / REGISTERED ADDRESS / ICO REGISTRATION NO]. That means this entity decides how and why your personal data is processed.

Privacy contact: [PLACEHOLDER: privacy contact email / DPO if applicable]

2. What data we collect and why

We only collect what's needed to run the service:

Account data

Email address and a hashed password (if you use email/password sign-up), or your name, email, and profile picture imported from Google (if you use Google sign-in). Used to identify you and authenticate your sessions.

Profile data

Full name, profile photo, bio, location (free text), and contact info (free text). All optional. Visible to people you share events with. Used to help your friends recognise you and to personalise your experience.

Event and planning data

Event names, descriptions, locations, cover images, dates, your availability markings, date votes, activity proposals, and activity votes. Used to run the event-planning features.

Social content

Chat messages (direct messages, group chats, event chats), photos you upload to events, comments on the event feed, and ephemeral online-presence status. Used to power the social features of HangPlan.

Operational data

A log of emails we've sent you (for our own records and to avoid duplicate delivery), rate-limit counters, and invite-queue status. During the beta we also keep an internal admin activity log — sign-ups, sign-ins, and events created or confirmed — so our team can support the service and understand how it's used. It's visible only to our admins and is automatically deleted after 90 days. Used to run the service reliably and prevent abuse.

Beta feedback (beta only)

If you submit feedback using the beta feedback widget, your free-text comment is sent to GitHub as a repository issue, along with automatically captured context: page URL, viewport size, browser user-agent, and your user ID and email address. This mechanism is used only during the beta period to help us fix issues quickly.

3. Our legal basis for processing

[PLACEHOLDER: confirm lawful bases — likely performance of a contract for core features, legitimate interests for security/operations, and consent for any future analytics. Confirm before launch.]

4. Cookies

We use essential cookies to keep you signed in (via Supabase's authentication library). We currently have no analytics or tracking cookies. For full details, see our Cookie Policy.

5. Who we share your data with

We don't sell your data. We use the following third-party services to run HangPlan. Each is contractually bound to process your data only as instructed.

Supabase

Our database, authentication, file storage, and realtime infrastructure. Stores your account, profile, events, messages, and uploaded files. Production data region: [CONFIRM: Supabase region — likely EU/London].

Brevo (formerly Sendinblue)

Sends transactional emails and event invitations on our behalf. Processes recipient email addresses and email content. See Brevo's privacy policy.

Google

If you choose “Sign in with Google”, Google authenticates you via OAuth and shares your name, email, and profile picture with us. See Google's privacy policy.

GitHub (beta only)

Beta-feedback submissions are sent to a private GitHub repository as issues. Each issue may contain your feedback text, page URL, browser info, and your user ID and email. This is used only during the beta period. See GitHub's privacy statement.

Vercel

Hosts the HangPlan web application at the edge. Processes request metadata (IP address, request logs) as part of serving the app. See Vercel's privacy policy.

6. International data transfers

[CONFIRM: whether any processor stores/transfers data outside the UK/EEA and the safeguard used — e.g. adequacy decision, standard contractual clauses.]

7. How long we keep your data

[PLACEHOLDER: define retention periods per data category — e.g. account data kept while account is active + X years, chat messages kept for Y months, email logs kept for Z months. Do not ship unfilled.]

When your account is deleted, your personal data is removed from our systems within a reasonable period, except where we're required to retain it by law.

8. Your rights

Under UK GDPR, you have the following rights. To exercise any of them, contact us at [PLACEHOLDER: privacy contact email / DPO if applicable].

  • Access. Request a copy of the personal data we hold about you.
  • Rectification. Ask us to correct inaccurate or incomplete data.
  • Erasure. Ask us to delete your data ("right to be forgotten"), subject to legal exceptions.
  • Restriction. Ask us to pause processing your data in certain circumstances.
  • Portability. Receive your data in a structured, machine-readable format.
  • Objection. Object to processing based on legitimate interests.
  • Withdraw consent. Where processing is based on consent, withdraw it at any time without affecting past processing.

We aim to respond within one month. If you're not satisfied with our response, or believe we're processing your data unlawfully, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.

9. Security

We use HTTPS for all data in transit, Supabase's encrypted storage at rest, server-side authorization on every data mutation, and row-level security policies on every database table. Passwords are never stored in plain text — they are hashed by Supabase Auth before being stored.

No system is perfectly secure. If you discover a security issue, please report it to [PLACEHOLDER: privacy contact email / DPO if applicable].

10. Changes to this policy

If we make material changes, we'll update the “Last reviewed” date above and, where appropriate, notify you by email. Continued use of HangPlan after a change constitutes acceptance of the updated policy.