Privacy Policy
1. Who we are
Pophunt is operated by Didem Erol, trading as Pophunt, based in the United Kingdom. You can contact us at [email protected].
2. What data we collect
Account data
- Display name, email address, profile photo (avatar), bio, and home city — provided by you on signup.
- Date of birth — entered in the email-registration form for a self-declared minimum-age check. The form does not send or store your date of birth. This is not independent age verification.
Third-party sign-in
If you sign in with Google, Facebook, or Apple, we receive your provider user ID, email address (or Apple relay address), and display name from that provider. We do not request any additional permissions beyond basic profile and email.
Device identifier
A pseudonymous device ID is stored locally in your browser to prevent duplicate votes and reports. This identifier is not linked to your name or email address unless you are logged in.
Location data
- Your chosen home city (from a fixed list of 5 UK cities).
- A map pin you place when creating an event — stored as latitude/longitude.
- If you grant device or browser location permission, we use your position for nearby-city selection, distance sorting, and the map location indicator. The map can update your position while it is open, including when permission was granted in an earlier session. You can revoke permission in device or browser settings. Event pins you publish are visible to others; they are not private location records.
User-generated content (UGC)
Event titles, descriptions, cover photos, and comments you post. Your display name, avatar, bio, and posted events can appear on a public profile visible to visitors without an account. Do not publish your home address, private contact details, or another person's private information.
Push notification tokens
If you grant permission in your browser, a FCM token is stored per device to send push notifications. This is optional and can be revoked at any time via Settings.
Analytics
If you accept the consent prompt, we enable Firebase Analytics for screen views and interaction events (e.g., "event_viewed", "vote_cast"). Analytics may involve device identifiers and usage information; pseudonymous data can still be personal data. Declining the prompt leaves analytics disabled.
Support and legal correspondence
If you contact us, we process your email address, any name you provide, your message, and relevant attachments or content links. The support form sends your name, email, and message through Resend to our Gmail inbox. It also records your email address, a hashed IP-based identifier, and the submission time to help limit abuse. Direct email is handled by our email provider.
We use this information to respond, investigate complaints, protect people and their rights, and establish or defend legal claims. Access is limited to people who need it for those purposes. Relevant information may be shared with an affected person, adviser, authority, or service provider where appropriate and lawful; we do not routinely disclose private contact details to other users.
Moderation records
If your event, comment, or account is reviewed or actioned by a moderator or admin, we keep an internal log of that action — what was done and, optionally, why. Moderators can see event, report, and comment content to do their job, but they cannot see other users' account details. This log is retained indefinitely for accountability and is readable only by admins.
3. Why we collect it and our lawful basis
| Data | Purpose | Lawful basis |
|---|---|---|
| Account data | Provide the service (post events, comment, save) | Contract performance |
| Device ID (votes/reports) | Prevent vote manipulation and duplicate reports | Legitimate interest |
| Location (event pin) | Place your event on the map | Contract performance |
| Push tokens | Send notification alerts you opted in to | Consent |
| Analytics | Understand how the app is used and improve it | Consent |
| Support, legal complaints, and abuse prevention | Respond to requests, protect users and rights, and handle disputes | Legitimate interests; legal obligation where a specific law requires processing |
| UGC | Display and share events and comments | Contract performance |
4. How long we keep it
- Account data: Until you delete your account.
- Expired events: Automatically deleted 90 days after the event's end date.
- Push tokens: Deleted 90 days after their last refresh.
- Device ID votes: Retained indefinitely, keyed to a device identifier rather than your account or name. This is pseudonymous, not anonymous — votes from the same device can be linked to each other — and can be removed on written request.
- Support and legal correspondence: Kept for as long as needed to resolve the matter and meet any applicable legal or claims-related need. We review closed cases for deletion or minimisation; a legal hold may require specific records to be kept longer.
- Third-party OAuth identifiers: Deleted alongside your account.
5. Who we share data with
We use the following providers to operate the service. Their roles depend on the service and their terms. Public content is also shared with visitors, as described above:
| Provider | Data shared |
|---|---|
| Supabase (database & auth) | All app data |
| Google Cloud (Maps, Firebase, FCM) | Map tile usage, analytics, push tokens, OAuth profile |
| Meta Platforms (Facebook Login) | OAuth profile (name, email, Facebook user ID) — only if you sign in with Facebook |
| Apple (Sign in with Apple) | OAuth flow — only if you sign in with Apple |
| Resend | Transactional emails and support-form name, reply address, and message |
| Google (Gmail) | Support and legal correspondence, including sender details, messages, and attachments |
| Sentry | Diagnostic error events; we apply filtering to reduce personal information before sending |
| Cloudflare | All HTTP traffic, IP addresses |
We do not sell your personal data.
Our primary database, authentication, and file storage (Supabase) are hosted in the EU (Frankfurt, Germany). Other sub-processors above may process data outside the UK/EEA, primarily in the United States — see "International data transfers" below.
6. International data transfers
Your core account, event, and comment data is stored on Supabase infrastructure located in the EU. Some of the sub-processors we use may process data in other countries, including the United States, as part of their standard service. Where that happens, we expect those providers to apply appropriate safeguards under applicable data protection law.
7. Your privacy rights
The rights below are available to every Pophunt user regardless of where you live. Where you complain if something goes wrong depends on your country.
If you're in the UK — UK GDPR
- Access — download a copy of your data via Settings → Export my data.
- Rectification — edit your display name, bio, and avatar in your profile.
- Erasure — request deletion via Settings → Delete account, or contact us. Some records may need to be retained for legal obligations or claims; we will explain any applicable exception. Backup copies may remain until their retention period ends.
- Portability — the data export is machine-readable JSON.
- Objection — opt out of push notifications any time in Settings.
- Withdraw consent — push notification permission can be revoked in your browser settings.
- Complaint — you can lodge a complaint with the ICO at ico.org.uk/concerns.
If you're in the EU/EEA — EU GDPR
You have the same rights as above — access, rectification, erasure, portability, objection, and withdrawing consent — exercised the same way, via Settings or by contacting us. If you believe we haven't handled your data lawfully, you can complain to your national data protection authority; find yours at edpb.europa.eu.
If you're in the US — state privacy laws (e.g. California's CCPA/CPRA)
- Right to know / access — download a copy of your data via Settings → Export my data.
- Right to delete — delete your account via Settings → Delete account.
- Right to correct — edit your profile directly.
- We do not sell personal information and do not share it for cross-context behavioural advertising, so there is no "opt out of sale/sharing" toggle — there is nothing to opt out of.
- We will not discriminate against you (e.g. degrade the Service or charge you more) for exercising any of these rights.
- To exercise any of these rights, contact [email protected].
8. Cookies & device storage
We store a pseudonymous device ID in your browser's local storage to prevent duplicate votes and reports. You are prompted to consent to this before it is written. We do not use third-party advertising cookies.
9. Children's privacy
Pophunt's current minimum age is 13. The email-registration form asks for a date of birth and performs a self-declared age check. Social sign-in does not currently perform that check. We do not independently verify users' ages. If you believe an underage child has an account, contact us so we can investigate and remove the account where appropriate.
Some countries — including several EU member states — set a higher digital age of consent than 13 (GDPR allows anywhere from 13 to 16). If you are between 13 and your country's digital age of consent, by registering you confirm that a parent or guardian has agreed to these terms on your behalf.
10. Changes to this policy
Material changes will be notified via an in-app banner and by email to registered users at least 14 days before they take effect. A privacy notice explains how we use information; continuing to use the Service does not provide consent for a new purpose that requires it.
11. Contact
For privacy enquiries or requests about your personal information, including if you do not have an account, email [email protected]. We normally respond within one month and explain any lawful extension or refusal. See Support for details.