Log in Register
Toggle sidebar

Privacy Policy

Last updated 3 September 2026

This policy describes what personal data the Group Awesome service holds, why it holds it, and what you can ask us to do about it.

1. Controller

Group Awesome.

2. Contact

Email: [email protected]. Use this address for anything in this policy, including requests about your own data.

3. What this policy covers

The account, group and event records behind the Group Awesome service, together with the technical records the service keeps about its own use.

4. Purposes and legal basis

Personal data is processed in order to:

  • create your account and sign you in
  • run the groups you own or belong to, including memberships, invitations and requests to join
  • publish and manage events, and record who is coming
  • send you the service email you need — email verification, password resets, and invitations to groups
  • answer the messages you send us through the contact form
  • send you the newsletter, if you asked for it
  • keep the service secure and see, in aggregate, how it is used

The legal bases are the contract between you and Group Awesome — your account, your groups and your events — and Group Awesome's legitimate interest in the security of the service, in aggregate usage statistics, and in answering the people who write to us. The newsletter rests on your consent, which you give by entering your address and can withdraw at any time.

Your data is not used for advertising. It is not sold, rented or handed to data brokers, and it is not used for automated decision-making or profiling.

5. What data is held

Account: name, email address, the password as a hash, whether and when the email address was verified, the two-factor authentication secret and recovery codes (stored encrypted) if you turn that on, when you accepted the terms of service, and when you were shown the introduction to your personal group.

Groups and membership: group name, description, image, location, category, language and website address, whether the group is public, how it lets people join, and which account holds which role in it.

Invitations: the email address invited, the role offered, who sent the invitation, when it expires and when it was accepted.

Requests to join: the message you write with the request, its status, and which group admin reviewed it and when.

Events: title, description, the location as you typed it and — where it could be resolved — its coordinates, start and end times, capacity, any repeat schedule, and the account that created it.

RSVPs: your answer and any note you add to it.

Sessions: a session identifier, the account it belongs to, the IP address and the browser's User-Agent string, and the time of last activity. Sessions expire and are removed.

Contact messages: the name and email address you type into the contact form, the subject if you write one, the message itself, the page you sent it from, and whether it has been dealt with. No IP address and no browser information is stored alongside it.

Newsletter: your email address, where on the site you signed up and when, and — if you withdraw later — when you unsubscribed. No IP address and no browser information is stored alongside it.

Usage statistics: for each page load, the path, the HTTP method, the response status code and how long the response took, the referring domain and address if there was one, any utm_* campaign parameters in the address, the date, and a visitor identifier.

That visitor identifier is a SHA-256 hash of the IP address, the User-Agent string and a random value that is thrown away and regenerated every day. The IP address and the User-Agent string themselves are never written to the statistics, and yesterday's identifiers cannot be matched against today's. Usage statistics are deleted after 90 days.

How long data is kept

Account, group and event data is kept for as long as the account exists and the group or event is published.

Contact messages are deleted automatically one year after they arrive, whether or not they were answered. Ask us sooner and yours is removed straight away.

A newsletter subscription is kept until it is withdrawn. Write to us and the address comes off the list.

You can delete your account yourself, at any time, from your account settings. Doing so permanently removes the account and the records tied to it: your group memberships, the events you created, your RSVPs, your requests to join and the invitations you sent. A group is not deleted along with the account that created it, because other people may still be members of it — write to us if a group needs removing too.

6. Where the data comes from

From you, through the service's own forms — registration, group and event editing, invitations, requests to join, RSVPs, the contact form and the newsletter signup — and automatically from your browser when a page is loaded or a session is created.

7. Cookies and local storage

Only strictly necessary cookies are used: a session cookie that keeps you signed in, and a token that protects the service's forms against cross-site request forgery. There are no advertising cookies and no third-party tracking cookies, which is why the service does not ask you for cookie consent.

Your light or dark appearance choice is kept in your browser's local storage and is never sent to the server.

8. Service providers and transfers

Data is not disclosed to outside parties for their own purposes and is never sold. The service is hosted in the European Union. These third parties are involved in running it:

  • Cloudflare — DNS and the reverse proxy in front of the site, and the object storage holding compressed database backups (transferred over TLS and encrypted at rest by the provider). Request metadata, including your IP address, passes through Cloudflare.
  • Bunny Fonts — serves the site's web font. Your browser fetches the font directly, so your IP address reaches Bunny. Bunny Fonts sets no cookies and keeps no personal data for tracking.
  • OpenStreetMap — when an organizer types an event location, that text is sent from our server to the Nominatim service to look up coordinates; nothing about you goes with it. When an event map is shown, your browser loads the map tiles from OpenStreetMap directly, so your IP address reaches them.

Some of these providers are companies established outside the EU that run infrastructure inside it. Where a transfer outside the EU or EEA does take place, it relies on the safeguards in Chapter V of the GDPR, such as the European Commission's standard contractual clauses.

9. How the data is protected

Data is handled carefully and protected by appropriate technical and organisational measures. All traffic is served over HTTPS. Passwords are only ever stored as hashes — plaintext passwords are never kept, and nobody at Group Awesome can read them. Two-factor secrets and recovery codes are stored encrypted. Access to personal data is limited to the people who need it to run the service.

10. Your rights

Under the GDPR you have the right to:

  • ask what data is held about you and receive a copy of it
  • have inaccurate data about you corrected
  • have your data erased — the "right to be forgotten"; you can do this yourself at any time by deleting your account in your settings
  • restrict or object to processing in certain situations
  • receive your data in a portable form
  • withdraw consent, where processing rests on it

Send requests in writing to [email protected]. We may ask you to confirm your identity, and will answer within one month, as the GDPR requires.

11. Complaints

If you believe your data is being handled unlawfully, you have the right to lodge a complaint with the data protection supervisory authority of the EU country where you live or work.

12. Changes to this policy

This policy is updated as the service changes. Material changes will be announced in the service.

The rules for using the service are set out separately in the Terms of Service.