Privacy Policy

Last updated: 10 September 2026

1. Who we are

Pophunt is operated by Didem Erol, trading as Pophunt, based in the United Kingdom. You can contact us at [email protected].

2. What data we collect

Account data

Third-party sign-in

If you sign in with Google, Facebook, or Apple, we receive your provider user ID, email address (or Apple relay address), and display name from that provider. We do not request any additional permissions beyond basic profile and email.

Device identifier

A pseudonymous device ID is stored locally in your browser to prevent duplicate votes and reports. This identifier is not linked to your name or email address unless you are logged in.

Location data

User-generated content (UGC)

Event titles, descriptions, cover photos, and comments you post. Your display name, avatar, bio, and posted events can appear on a public profile visible to visitors without an account. Do not publish your home address, private contact details, or another person's private information.

Push notification tokens

If you grant permission in your browser, a FCM token is stored per device to send push notifications. This is optional and can be revoked at any time via Settings.

Analytics

If you accept the consent prompt, we enable Firebase Analytics for screen views and interaction events (e.g., "event_viewed", "vote_cast"). Analytics may involve device identifiers and usage information; pseudonymous data can still be personal data. Declining the prompt leaves analytics disabled.

Support and legal correspondence

If you contact us, we process your email address, any name you provide, your message, and relevant attachments or content links. The support form sends your name, email, and message through Resend to our Gmail inbox. It also records your email address, a hashed IP-based identifier, and the submission time to help limit abuse. Direct email is handled by our email provider.

We use this information to respond, investigate complaints, protect people and their rights, and establish or defend legal claims. Access is limited to people who need it for those purposes. Relevant information may be shared with an affected person, adviser, authority, or service provider where appropriate and lawful; we do not routinely disclose private contact details to other users.

Moderation records

If your event, comment, or account is reviewed or actioned by a moderator or admin, we keep an internal log of that action — what was done and, optionally, why. Moderators can see event, report, and comment content to do their job, but they cannot see other users' account details. This log is retained indefinitely for accountability and is readable only by admins.

3. Why we collect it and our lawful basis

DataPurposeLawful basis
Account dataProvide the service (post events, comment, save)Contract performance
Device ID (votes/reports)Prevent vote manipulation and duplicate reportsLegitimate interest
Location (event pin)Place your event on the mapContract performance
Push tokensSend notification alerts you opted in toConsent
AnalyticsUnderstand how the app is used and improve itConsent
Support, legal complaints, and abuse preventionRespond to requests, protect users and rights, and handle disputesLegitimate interests; legal obligation where a specific law requires processing
UGCDisplay and share events and commentsContract performance

4. How long we keep it

5. Who we share data with

We use the following providers to operate the service. Their roles depend on the service and their terms. Public content is also shared with visitors, as described above:

ProviderData shared
Supabase (database & auth)All app data
Google Cloud (Maps, Firebase, FCM)Map tile usage, analytics, push tokens, OAuth profile
Meta Platforms (Facebook Login)OAuth profile (name, email, Facebook user ID) — only if you sign in with Facebook
Apple (Sign in with Apple)OAuth flow — only if you sign in with Apple
ResendTransactional emails and support-form name, reply address, and message
Google (Gmail)Support and legal correspondence, including sender details, messages, and attachments
SentryDiagnostic error events; we apply filtering to reduce personal information before sending
CloudflareAll HTTP traffic, IP addresses

We do not sell your personal data.

Our primary database, authentication, and file storage (Supabase) are hosted in the EU (Frankfurt, Germany). Other sub-processors above may process data outside the UK/EEA, primarily in the United States — see "International data transfers" below.

6. International data transfers

Your core account, event, and comment data is stored on Supabase infrastructure located in the EU. Some of the sub-processors we use may process data in other countries, including the United States, as part of their standard service. Where that happens, we expect those providers to apply appropriate safeguards under applicable data protection law.

7. Your privacy rights

The rights below are available to every Pophunt user regardless of where you live. Where you complain if something goes wrong depends on your country.

If you're in the UK — UK GDPR

If you're in the EU/EEA — EU GDPR

You have the same rights as above — access, rectification, erasure, portability, objection, and withdrawing consent — exercised the same way, via Settings or by contacting us. If you believe we haven't handled your data lawfully, you can complain to your national data protection authority; find yours at edpb.europa.eu.

If you're in the US — state privacy laws (e.g. California's CCPA/CPRA)

8. Cookies & device storage

We store a pseudonymous device ID in your browser's local storage to prevent duplicate votes and reports. You are prompted to consent to this before it is written. We do not use third-party advertising cookies.

9. Children's privacy

Pophunt's current minimum age is 13. The email-registration form asks for a date of birth and performs a self-declared age check. Social sign-in does not currently perform that check. We do not independently verify users' ages. If you believe an underage child has an account, contact us so we can investigate and remove the account where appropriate.

Some countries — including several EU member states — set a higher digital age of consent than 13 (GDPR allows anywhere from 13 to 16). If you are between 13 and your country's digital age of consent, by registering you confirm that a parent or guardian has agreed to these terms on your behalf.

10. Changes to this policy

Material changes will be notified via an in-app banner and by email to registered users at least 14 days before they take effect. A privacy notice explains how we use information; continuing to use the Service does not provide consent for a new purpose that requires it.

11. Contact

For privacy enquiries or requests about your personal information, including if you do not have an account, email [email protected]. We normally respond within one month and explain any lawful extension or refusal. See Support for details.