Draft — pending legal review
This document is a draft that has not yet been reviewed by a lawyer. It is not legal advice and is not yet in force. Text in highlighted [square brackets] is still to be completed.
Privacy Policy
- Version
- 2026-10-01
- Effective date
- (provisional)
- Last updated
Summary
- We collect what we need to run safe, verified Evenings — and as little else as possible.
- Identity verification is done by our provider, Didit. We keep only the result (such as “verified” and “over 18”) and a keyed hash used to enforce bans — never your ID document or selfie.
- We never record audio or video.
- Messages are deleted after 30 days (1 year if they are part of a report). Server logs are kept for 14 days.
- We do not sell your data. There are no advertising trackers in the app.
- You can export or delete your data in the app, and contact us at privacy@spareachair.com.
Who is responsible for your data
The controller of your personal data is [Legal entity name and legal form], [Registered address], company number [Company registration number and register] (“spareachair”, “we”, “us”).
Contact for all privacy questions and requests: privacy@spareachair.com.
Data Protection Officer: [Data Protection Officer — appointed? contact details].
This policy covers the spareachair mobile app and its backend (the “Service”), the website spareachair.com and the pre-launch waitlist.
What we collect
Account
Email address, password (stored only as a secure hash), email verification status, sign-in sessions, notification preferences, and a record of which version of our legal documents you accepted and when (with a hashed — not raw — IP address and your device’s user agent).
Identity verification result
When you verify your identity, the verification provider (Didit) checks your ID document and matches it to a selfie. Didit processes the document images, the selfie and the biometric data needed for the match. We receive and store only:
- the verification status (for example approved, declined, expired) and a reference to the verification session;
- whether you are over 18, and the country that issued your document (to confirm you are in the EU/EEA);
- a keyed hash (HMAC) computed from your document number, issuing country and date of birth using a secret key only we hold. The hash cannot be reversed into those details. We use it to stop one person having several accounts and to stop banned people from signing up again.
We discard your date of birth, document number and all other document data immediately after computing the result and the hash.
Profile
Display name, generated avatar (you cannot upload photos), short bio, occupation category, age band (for example 25–34), and your answers to “perspective prompts” (for example city or countryside) used for matching.
Participation and connections
Evenings you sign up for and attend, the tables you were seated at, “keep in touch” choices, your Connections, and the people you have blocked.
Messages
The text of messages you send at tables and in direct messages, and any flags added by automated moderation. Audio and video are transmitted live through our own media server and are never recorded or stored.
Reports and enforcement
Reports you make or that are made about you, including a copy of the last 50 messages of the reported conversation; moderation decisions, statements of reasons and appeals.
Device and technical data
Push notification token, device type, operating system and app version; IP addresses and request logs on our servers; error and crash reports.
Website and waitlist
If you join the waitlist: your email address and confirmation (double opt-in) record. On the website: cookies and similar technologies, but only those you consent to — see the Cookie Policy.
We do not collect your precise location, your contacts or photos.
Why we use your data and our legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating your account, running Evenings, matching you to tables, messaging, calls, Connections, service emails and notifications | Performance of our contract with you — Art. 6(1)(b) |
| Checking that you are 18+ and live in the EU/EEA before you take part | Performance of our contract (eligibility) — Art. 6(1)(b); legitimate interests in keeping the Service adult-only and safe — Art. 6(1)(f) |
| The biometric selfie match carried out by Didit | Your explicit consent — Art. 9(2)(a) with Art. 6(1)(a). We ask for it separately, in the app, before verification starts |
| Automated moderation, handling reports, enforcing our Terms and preventing ban evasion with the keyed hash | Legitimate interests in protecting users and the Service — Art. 6(1)(f); compliance with the Digital Services Act where it applies — Art. 6(1)(c) |
| Statements of reasons, handling notices of illegal content and appeals, responding to lawful requests from authorities | Legal obligation — Art. 6(1)(c) |
| Recording which legal documents you accepted | Legal obligation and legitimate interests in being able to show what you agreed to — Art. 6(1)(c) and (f) |
| Security, server logs and error monitoring | Legitimate interests in keeping the Service secure and working — Art. 6(1)(f) |
| Waitlist emails | Consent — Art. 6(1)(a) |
| Website analytics and advertising measurement | Consent — Art. 6(1)(a) and the ePrivacy rules on cookies |
| Establishing, exercising or defending legal claims | Legitimate interests — Art. 6(1)(f) |
Your consent to the biometric check can be withdrawn at any time by writing to privacy@spareachair.com. Withdrawal does not affect processing already carried out. Because verification is a condition for taking part, you cannot use the participation features without it.
Matching uses your prompt answers, occupation category and age band to seat people with different perspectives together. This is a form of profiling, but it has no legal or similarly significant effect on you.
Automated decisions. Automated moderation can block an individual message. We do not take decisions with legal or similarly significant effects on you — such as suspending or banning your account — solely by automated means, and you can always ask for a person to review a decision.
Sensitive information. Other than the biometric check, we do not ask for special categories of data (such as health, religion or political opinions). Please think carefully before sharing such information in conversations.
Where we rely on legitimate interests, we have balanced them against your rights, and you can object (see Your rights).
How long we keep your data
| Data | How long |
|---|---|
| Table and direct messages | 30 days, then deleted automatically |
| Messages copied into a report | 1 year |
| Reports and moderation flags | 1 year after the report is closed |
| Moderation decisions (enforcement records) | While your account exists, and 1 year after it is deleted |
| Keyed identity hash | While your account exists. If your account was banned, kept after deletion for as long as the ban applies |
| Identity verification result | While your account exists |
| ID document images and selfie (held by Didit, not by us) | [Didit retention period for ID images and selfies, per the DPA] |
| Account, profile, participation and Connections | Until you delete your account |
| Accounts that never finish sign-up | Deleted 7 days after sign-up if the email is not verified, 30 days after sign-up if identity is not verified |
| Legal acceptance records | While your account exists |
| Server logs and error reports | 14 days |
| Data export files | 7 days |
| Waitlist | Until you unsubscribe or we launch; unconfirmed sign-ups are deleted after 14 days |
When you delete your account we permanently delete your data, except the items above that we must or may keep after deletion (the keyed hash of a banned account, and reports and enforcement records needed to handle safety issues or legal claims).
Who we share data with
- Other users see your display name, avatar, bio, occupation category and age band, and the messages you send in conversations they are part of. They never see your email or verification details.
- Service providers (processors) that host and run the Service for us under data processing agreements — for example hosting (DigitalOcean), email (Resend), identity verification (Didit), error monitoring (Sentry), push notifications and app updates (Expo) and automated moderation ([Moderation API provider (OpenAI or Anthropic — to be decided)]). The full, current list is on our Sub-processors page.
- Authorities, when we are legally required to, for example in response to a valid order or to report a threat to someone’s life or safety.
We do not sell your personal data and we do not share it with advertisers.
International transfers
We host the Service in the EU. Some of our providers are established outside the EU/EEA (for example in the USA). Where data is transferred outside the EU/EEA, we rely on an adequacy decision (such as the EU–US Data Privacy Framework for certified companies) or the European Commission’s Standard Contractual Clauses, plus additional safeguards where needed. You can ask us for a copy of the relevant safeguards at privacy@spareachair.com.
Your rights
Under the GDPR you have the right to:
- access your data and get a copy of it;
- rectification — have inaccurate data corrected;
- erasure — have your data deleted;
- restriction — ask us to limit how we use your data;
- data portability — receive the data you gave us in a machine-readable format (JSON);
- object to processing based on legitimate interests;
- withdraw consent at any time, where we rely on consent, without affecting earlier processing;
- lodge a complaint with a supervisory authority — our lead authority is [Lead data protection supervisory authority (name, website)], and you can also complain to the authority in the EU/EEA country where you live or work.
You can export your data and delete your account directly in the app’s settings. For anything else, email privacy@spareachair.com. We will reply within one month (extendable by two months for complex requests, in which case we will tell you). We may ask you to confirm your identity before acting on a request.
Security
We protect your data with encryption in transit, access controls, the principle of least privilege, pseudonymised identifiers where possible, and regular backups. No system is perfectly secure; if a personal data breach is likely to put you at high risk, we will tell you.
Children
spareachair is only for adults. We do not knowingly collect data from anyone under 18. If we learn that a user is under 18, we will close the account and delete their data. If you think a minor is using the Service, please report it in the app or email privacy@spareachair.com.
Changes to this policy
We will update this policy when our processing changes. Each version has a version number and effective date at the top of this page. We will tell you about material changes in the app or by email before they take effect.
Contact
[Legal entity name and legal form], [Registered address] — privacy@spareachair.com.