Last updated 3 September 2026
This policy describes what personal data the Group Awesome service holds, why it holds it, and what you can ask us to do about it.
Group Awesome.
Email: [email protected]. Use this address for anything in this policy, including requests about your own data.
The account, group and event records behind the Group Awesome service, together with the technical records the service keeps about its own use.
Personal data is processed in order to:
The legal bases are the contract between you and Group Awesome — your account, your groups and your events — and Group Awesome's legitimate interest in the security of the service, in aggregate usage statistics, and in answering the people who write to us. The newsletter rests on your consent, which you give by entering your address and can withdraw at any time.
Your data is not used for advertising. It is not sold, rented or handed to data brokers, and it is not used for automated decision-making or profiling.
Account: name, email address, the password as a hash, whether and when the email address was verified, the two-factor authentication secret and recovery codes (stored encrypted) if you turn that on, when you accepted the terms of service, and when you were shown the introduction to your personal group.
Groups and membership: group name, description, image, location, category, language and website address, whether the group is public, how it lets people join, and which account holds which role in it.
Invitations: the email address invited, the role offered, who sent the invitation, when it expires and when it was accepted.
Requests to join: the message you write with the request, its status, and which group admin reviewed it and when.
Events: title, description, the location as you typed it and — where it could be resolved — its coordinates, start and end times, capacity, any repeat schedule, and the account that created it.
RSVPs: your answer and any note you add to it.
Sessions: a session identifier, the account it belongs to, the IP address and the browser's User-Agent string, and the time of last activity. Sessions expire and are removed.
Contact messages: the name and email address you type into the contact form, the subject if you write one, the message itself, the page you sent it from, and whether it has been dealt with. No IP address and no browser information is stored alongside it.
Newsletter: your email address, where on the site you signed up and when, and — if you withdraw later — when you unsubscribed. No IP address and no browser information is stored alongside it.
Usage statistics: for each page load, the path, the HTTP method, the response status code and how long the response took, the referring domain and address if there was one, any utm_* campaign parameters in the address, the date, and a visitor identifier.
That visitor identifier is a SHA-256 hash of the IP address, the User-Agent string and a random value that is thrown away and regenerated every day. The IP address and the User-Agent string themselves are never written to the statistics, and yesterday's identifiers cannot be matched against today's. Usage statistics are deleted after 90 days.
Account, group and event data is kept for as long as the account exists and the group or event is published.
Contact messages are deleted automatically one year after they arrive, whether or not they were answered. Ask us sooner and yours is removed straight away.
A newsletter subscription is kept until it is withdrawn. Write to us and the address comes off the list.
You can delete your account yourself, at any time, from your account settings. Doing so permanently removes the account and the records tied to it: your group memberships, the events you created, your RSVPs, your requests to join and the invitations you sent. A group is not deleted along with the account that created it, because other people may still be members of it — write to us if a group needs removing too.
From you, through the service's own forms — registration, group and event editing, invitations, requests to join, RSVPs, the contact form and the newsletter signup — and automatically from your browser when a page is loaded or a session is created.
Only strictly necessary cookies are used: a session cookie that keeps you signed in, and a token that protects the service's forms against cross-site request forgery. There are no advertising cookies and no third-party tracking cookies, which is why the service does not ask you for cookie consent.
Your light or dark appearance choice is kept in your browser's local storage and is never sent to the server.
Data is not disclosed to outside parties for their own purposes and is never sold. The service is hosted in the European Union. These third parties are involved in running it:
Some of these providers are companies established outside the EU that run infrastructure inside it. Where a transfer outside the EU or EEA does take place, it relies on the safeguards in Chapter V of the GDPR, such as the European Commission's standard contractual clauses.
Data is handled carefully and protected by appropriate technical and organisational measures. All traffic is served over HTTPS. Passwords are only ever stored as hashes — plaintext passwords are never kept, and nobody at Group Awesome can read them. Two-factor secrets and recovery codes are stored encrypted. Access to personal data is limited to the people who need it to run the service.
Under the GDPR you have the right to:
Send requests in writing to [email protected]. We may ask you to confirm your identity, and will answer within one month, as the GDPR requires.
If you believe your data is being handled unlawfully, you have the right to lodge a complaint with the data protection supervisory authority of the EU country where you live or work.
This policy is updated as the service changes. Material changes will be announced in the service.
The rules for using the service are set out separately in the Terms of Service.