Privacy
Privacy Policy
Last updated: 1 October 2026
Language note: This Privacy Policy was prepared in Bulgarian. The Bulgarian text is binding. Translations (including this English version) are provided for convenience only, and in case of any discrepancy the Bulgarian text prevails.
1. Data controller
The controller of your personal data within the meaning of Regulation (EU) 2016/679 (GDPR) and the Bulgarian Personal Data Protection Act (ZZLD) is:
- Name: "Support Wing" EOOD („Съпорт Уинг“ ЕООД)
- UIC/BULSTAT: 208345662
- Registered office and address of management: 13 Roza St., Karavelovo 4350, Bulgaria (ул. Роза 13, Каравелово, 4350, България)
- Email for data protection matters: [email protected]
- General email: [email protected]
- Website: https://www.onhuddle.co
Data Protection Officer (DPO): We have not appointed a Data Protection Officer. For any question, write to [email protected].
2. What this policy covers
Huddle is a platform for discovering events and for meeting people. This policy describes how we process personal data when you use:
- the Huddle iPhone app;
- the website onhuddle.co (including public event and organiser pages);
- the emails we send you.
It applies to registered users, event organisers, ticket buyers and website visitors without an account.
3. What data we collect
3.1. Account and sign-in
- Email address — required to create an account.
- Sign-in method — a one-time code sent by email, "Sign in with Apple", "Sign in with Google", or a passkey. We do not use passwords. When you sign in with Apple or Google, the provider gives us your email and (if you share it) your name. For "Sign in with Apple" we store, encrypted, a token that we use to revoke Huddle's access to your Apple ID when you delete your account.
- Session data — access tokens and which sign-in method you last used.
- Acceptance of the terms — the date and version of the Terms of Use you accepted when you created your account.
3.2. Profile
- Name, username, profile and cover photo, short description (bio), a location you enter yourself, profession, languages, interests, goals, pronouns, social media links and profile photos.
- Date of birth — you enter your full date of birth when you set up your profile. Other users see the day and month on your profile. We also use it to determine your age group (see section 5).
- Gender — you choose from a list (including "Prefer not to say") or describe it in your own words. Your gender is shown on your profile according to your profile visibility setting (section 6).
- Required fields. Date of birth and gender (where you can choose "Prefer not to say") are required to finish setting up your profile in the app. We need them for age-group features and for beacon audiences (section 5). If you do not provide them, you cannot complete profile setup.
- Phone number — only if you provide it (for example as a contact number on an order).
- Sexual orientation — optional. See section 4.
- Music taste — if you connect your profile to Spotify, we receive a list of your favourite artists to show on your profile.
3.3. Content and communication
- Messages: direct messages (DMs) and messages in group chats — in Spaces, Hubs, events and Beacons — including photos and GIFs. Messages are stored on our servers, are not end-to-end encrypted, and are checked automatically for violations of the Community Guidelines (sections 5 and 7).
- Published content: events you create, beacons, questions in hubs, photos and notes in albums, venue reviews, descriptions of spaces and hubs.
- GIFs: when you search for a GIF, our server sends your search words to GIPHY. The GIF images themselves load from GIPHY's servers, so GIPHY receives your device's IP address and technical data whenever GIFs are shown to you, including GIFs other people send you. GIPHY does not receive your name, email or account.
- Reports and blocks: the reports you submit (which content, the reason) and the users you have blocked.
- Recent searches: we store your latest searches in the app to show them to you again.
- Feedback and communication with us: the content of emails you send us.
3.4. Connections and contacts
- Connections: who you have added, connection requests, connections made via QR code.
- Contacts (only if you choose): if you allow access to your contacts, the app reads only the email addresses in them. Each email is converted on your device into a SHA-256 code, and only these codes (up to 2,000) are sent to us. This is not encryption: anyone who already knows an email address can compute the same code, which is how we compare it with Huddle accounts. Your contacts' names and phone numbers are not read and not sent. We use the codes only to find matching Huddle accounts and show you which of your contacts are already on Huddle. The codes are discarded immediately after the comparison and are not stored. You can withdraw access at any time in your iPhone settings.
- Being found: by default other users can find you this way if your email is in their contacts. You can switch this off in the app under Settings → Privacy ("Find me by email" / "Find me by phone number"). Users with a private profile or with "open to connect" switched off (a setting in the website profile) are not shown.
3.5. Location
- Precise location while you use the app. With your permission we use your device's GPS location to show you events and beacons nearby and to centre the map. If you do not give permission, we estimate an approximate city from your IP address using a database we host ourselves (no third party).
- "For You" feed log. When you load recommendations, we record a pseudonymous log entry of what was shown to you, together with your location rounded to about 100 m. We use it to improve how recommendations are ranked. The entry contains no name or email and is deleted automatically after 24 months or when you delete your account.
- Beacons. When you drop a beacon at your current location, the exact coordinates are seen only by you, invitees (for a private beacon) and approved participants (for a public beacon). Everyone else sees an approximate point within an area of about 1 km. A beacon placed at a specific place (a venue, an event) shows that place to everyone who can see the beacon. Public beacons, with their host and the approximate point, appear on the map to anyone who looks at that area in the app, including people without an account, unless the host has limited the audience (section 5) or one of you has blocked the other. Live updates about new beacons reach people within an area about 3–4 km across.
- Location sharing with connections (optional, off by default). If you switch it on, the app asks for "Always" permission and sends your location on significant changes (e.g. a new neighbourhood or city), including when the app is not open. The server stores only the city and country, an area code of about 5 × 5 km and the city centre — exact coordinates are not stored. Only connections with whom you have both switched sharing on can see you, and only at the precision you chose (city or country only). You can switch sharing off with one tap; your location record is then deleted. Sharing is also switched off when you sign out.
- Travel plans you share with your connections (city and dates).
3.6. Payments and tickets
- When you buy a ticket for a paid event, we collect your name, email and (optionally) a contact phone number, order details (tickets, amounts, discounts, refunds) and the payment status.
- Your card details are entered directly into Stripe and never reach our servers.
- Organisers who sell tickets create a Stripe Connect account. Their identity verification and payout details are collected and processed by Stripe.
3.7. Device and technical data
- A device identifier provided by Apple for our app (identifierForVendor), a push notification token and platform — to send you notifications.
- IP address, device and operating system type and version, app version, server logs.
- Crash and error reports (see section 3.8) — linked to your account's internal identifier, without email or name.
- Notification settings (including "quiet hours").
3.8. Analytics, session recordings and crash reports
In the iPhone app:
- We use PostHog (servers in the EU) for usage analytics: which screens and features are used, events such as "ticket purchased" or "event created". This data is linked to your account identifier and email.
- PostHog also captures session recordings (a sequence of screenshots of the app) so we can find interface problems. Text you type and images are masked on the device before a recording is sent. Screens with tickets, QR codes, payment details and the demographic questions are masked entirely, and recording is paused during payment.
- If you are in the EEA, the United Kingdom or Switzerland, usage analytics and session recordings start only after you allow them when you first open the app. Elsewhere they are on by default. You can change this at any time under Settings → "Share usage analytics"; while it is off, the app sends no events or recordings.
- We use the Sentry SDK for crash, hang and performance reports. The data is sent to Better Stack (servers in the EU) and is linked only to your account's internal identifier.
On the website:
- For visitors from the EEA and the United Kingdom, analytics (PostHog) is switched on only after consent through the cookie banner. Session recordings require separate consent. You can change your choice under "Cookie preferences" at the bottom of the page. For visitors outside the EEA and the United Kingdom, analytics is on by default and can be switched off the same way.
- Website errors are sent to Better Stack without cookies and without your account data.
3.9. Data we receive from other sources
- From Apple and Google — when you sign in (section 3.1).
- From Spotify — if you connect your profile (section 3.2).
- From organisers — when an organiser adds you to a guest list or sends you an invitation.
- Public event information. Huddle shows events from public sources (organiser websites, ticketing platforms, public social media pages). This information may include the names of organisers and performers. If you are an organiser and want us to correct or remove such an event, write to [email protected].
3.10. Visitors without an account
If you register for an event as a guest, join a waiting list or download material from the website, we collect your email (and your name, if you give it) to fulfil your request and send you the related emails.
4. Sexual orientation and other sensitive data (Art. 9 GDPR)
Sexual orientation is a special category of personal data under Art. 9 GDPR.
- Optional. When you set up your profile you can select a sexual orientation or "Prefer not to say", or skip the question. Not answering does not limit your use of Huddle.
- Legal basis: your explicit consent (Art. 9(2)(a) GDPR), which you give by selecting a value yourself.
- Who sees it: only you, on your own profile. It is never shown to other users and our API never returns it to anyone but you.
- What it is used for: only to be shown on your own profile. We do not use it for recommendations, beacon targeting, analytics or advertising, and we do not share it with third parties. In session recordings the demographic questions are masked entirely.
- Withdrawing consent: you can withdraw your consent by changing or deleting the value at any time under "Edit profile", or by writing to [email protected]. Withdrawal does not affect the lawfulness of processing before it.
- Retention: until you delete it or delete your account.
A gender description in your own words may also reveal sensitive data. It is therefore never used for filtering, never sent to analytics systems, and is shown only according to your profile visibility setting. If you choose to share sensitive data yourself in your bio, messages or other content, it will be visible to the people who can see that content.
5. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Creating and maintaining your account, sign-in, profile, connections, messages, events, beacons, spaces and hubs | sections 3.1–3.4 | Performance of a contract (Art. 6(1)(b)) |
| Nearby events and beacons, map | section 3.5 (precise location) | Performance of a contract; access to the device location happens only with your permission |
| Location sharing with connections | section 3.5 | Consent (Art. 6(1)(a)), which you withdraw by switching the feature off |
| Finding friends through contacts | email codes (SHA-256) | For you: consent (Art. 6(1)(a)) through the contacts permission. For the people in your contacts: legitimate interest (Art. 6(1)(f)) in helping people who know each other connect; their codes are used only for the comparison and are not stored |
| Sexual orientation | section 4 | Explicit consent (Art. 9(2)(a)) |
| Music taste from Spotify | section 3.2 | Consent (Art. 6(1)(a)) |
| Personalising "For You" (interests, location, connections, interactions) | sections 3.2, 3.5 | Performance of a contract and legitimate interest (Art. 6(1)(f)) in showing useful recommendations |
| Beacon targeting: a beacon host can show a beacon only to women or men, to a given age group or to a given profession. Your gender is used only if your profile is public; "non-binary", a self-description and "Prefer not to say" are never used. Age group is used only for people over 18. Profession is used only if you picked it from the list | gender, date of birth, profession | Performance of a contract |
| Moderation, safety, handling reports, preventing fraud and abuse | content, reports, technical data | Legitimate interest (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c)), including under Regulation (EU) 2022/2065 (Digital Services Act) |
| Ticket payments, refunds, accounting | section 3.6 | Performance of a contract; legal obligation |
| Notifications (push and in-app) | section 3.7 | Performance of a contract; push notifications only with your iOS permission |
| Usage analytics and session recordings in the app | section 3.8 | Consent (Art. 6(1)(a)) in the EEA, the UK and Switzerland; elsewhere legitimate interest (Art. 6(1)(f)) in improving the app, with the right to object by switching analytics off |
| Analytics and session recordings on the website (EEA/UK) | section 3.8 | Consent (Art. 6(1)(a)) |
| Crash and error reports | sections 3.7–3.8 | Legitimate interest (Art. 6(1)(f)) in keeping the service working |
| Getting-started emails (a welcome and up to 3 tips in the first week) and emails about your events | email, name | Legitimate interest (Art. 6(1)(f)); you can unsubscribe from every such email |
| Marketing messages | Consent (Art. 6(1)(a)), where you have given it | |
| Defending legal claims, responding to requests from authorities | the data needed | Legitimate interest; legal obligation |
Automated decision-making. Photos you upload and some text (e.g. event descriptions) are checked automatically. Content with severe violations may be rejected automatically, and doubtful content is held for human review. If your event is rejected, you can appeal in the app and the decision is reviewed by a person. We do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Art. 22 GDPR.
6. What other users see
- Profile in the app. Signed-in users see on your profile your name, photos, bio, profession, day and month of birth, languages, interests, goals, your mutual connections and the events you attend or organise. Your pronouns, gender and connection count depend on the "Profile visibility" setting (Settings → Privacy → "Profile visibility"): public (default), connections only or private. This setting does not hide your name, photo and events.
- Public page on the website. Your name, username, profile photo, bio and, depending on your profile visibility setting, your number of connections are shown at onhuddle.co/u/[username] to anyone, including people without an account. The page is not shown if you switch "open to connect" off in your website profile.
- Never shown to others: your email, your sexual orientation, your recent searches, your phone number (except to an organiser you gave it to on an order).
- Content. Public events and organiser pages are also visible on the website, including to people without an account. Messages in a group chat are seen by the chat's participants.
- Organisers. When you buy a ticket or register for an event, the organiser receives your name, email and (if you gave it) your contact phone number, as well as your answers to the registration questions.
- Reports. A user who is reported does not learn who reported them.
- Blocking. Blocked users cannot see your profile, beacons and messages, and vice versa.
7. Processors and other recipients
We do not sell personal data. We share data only with the following providers, who process it on our behalf under contract (Art. 28 GDPR), or with the independent controllers named below:
| Recipient | Purpose | Data | Where |
|---|---|---|---|
| Hetzner Online GmbH | Platform servers and database | all platform data | Germany (Falkenstein and Nuremberg) |
| netcup GmbH | Server for the pseudonymous feed log | section 3.5 (feed log) | Germany (EU) |
| Cloudflare, Inc. | Storage and delivery of photos and media (R2, CDN), website protection and delivery | photos, IP address, technical data | global network (EU and USA) |
| PostHog Inc. | Usage analytics and session recordings | section 3.8 | EU (Frankfurt) |
| Better Stack, Inc. | Crash and error reports (via the Sentry SDK) | sections 3.7–3.8 | EU (Germany) |
| Grafana Labs | Server monitoring and server logs | technical data, IP address in logs | USA |
| Ably Real-time Ltd | Real-time delivery of messages and notifications | messages, account identifier | United Kingdom |
| OpenAI, L.L.C. | Automated moderation of text and photos; categorising beacons and spaces; translating and enriching event listings | the content being checked (message text, photos you upload, your profile name and bio, beacon and space texts, event listings); not your email address | USA |
| Algolia SAS | Event search | public event listings, search words | USA |
| Resend (Plus Five Five, Inc.) | Sending emails (sign-in codes, notifications, getting-started emails) | email, name, email content | USA |
| Stripe | Processing ticket payments, organiser accounts (Stripe Connect) | section 3.6 | EU (Stripe Payments Europe, Ltd., Ireland) / USA |
| Apple | Sign in with Apple, push notification delivery (APNs) | section 3.1, push token | EU / USA |
| Sign in with Google; address search when creating an event on the website (Google Places) | section 3.1; the search text | USA | |
| Spotify AB | Music taste (optional) | access token, favourite artists | Sweden (EU) |
| Discord, Inc. | Internal alerts to moderators about reports, held content, new events and organiser verifications | identifiers of the content, its author and the reporter, the reason, and the title and public link of the event or hub concerned; no personal names, email addresses or report text | USA |
| GIPHY | GIF search and display | search words (sent by our server); IP address and technical data when GIF images load on your device; not your name, email or account | USA |
Stripe (for payments), Apple, Google and Spotify also act as independent controllers under their own policies. Organisers of events for which you buy tickets or register are independent controllers of the data they receive (section 6).
External ticket websites. Some links to external ticket websites are affiliate links. They contain a code that identifies the event, not you. When you open such a link, the external website and the affiliate network process your data under their own policies.
We may also disclose data to competent authorities where the law requires it, and in a restructuring, merger or sale of the company — while keeping the level of protection set out in this policy.
8. Transfers outside the EEA
Our servers are in Germany. Where a provider processes data outside the EEA (see the table in section 7), the transfer is based on a European Commission adequacy decision (including the EU-US Data Privacy Framework for certified providers) or on standard contractual clauses approved by the European Commission (Arts. 45–46 GDPR). You can request a copy of the applicable safeguards at [email protected].
9. Retention periods
| Data | Period |
|---|---|
| Account, profile, connections, messages, content, reports and blocks | until you delete them or delete your account, or 3 years after your last sign-in (we email you before deleting an inactive account) |
| Email codes from contacts | not stored |
| Location shared with connections | until you switch sharing off or delete your account |
| Pseudonymous "For You" feed log | 24 months (some records 12 months); deleted when you delete your account; backups are deleted within 35 days |
| Analytics (PostHog) | 12 months for events; 30 days for session recordings. Deleting your account does not delete them automatically — they are deleted when the period expires. You can ask for earlier deletion at [email protected] |
| Crash and error reports (Better Stack) | 30 days; deleted when the period expires |
| Server logs | 30 days |
| Orders and payments | 10 years after the end of the year of payment (Bulgarian Accountancy Act). When you delete your account the order is detached from it, but the contact name, email and phone on the order remain until the period expires |
| Moderation records (decision, reason and an excerpt of up to 500 characters of the problematic text) | 2 years; detached from your account when you delete it |
| Evidence of severe violations (e.g. child sexual abuse material) | kept in separate storage with restricted access for as long as needed to protect users, defend legal claims and answer requests from the competent authorities |
| List of unsubscribed email addresses | as long as needed to honour your unsubscribe |
| Database backups | 35 days |
10. Deleting your account
You can delete your account in the app: Settings → "Delete account". Deletion is immediate and permanent: your profile, connections, messages, events, beacons, album photos and other content, including the photo files, are deleted at once, your sessions are ended, and Huddle's access to your Apple ID (if you signed in with Apple) is revoked.
If you organise upcoming events, you must cancel or delete them first — the app shows you which ones. This protects people who have bought tickets.
After deletion only the data listed in section 9 remains (orders, moderation records, analytics and crash data until their periods expire).
11. Security
We apply appropriate technical and organisational measures: encryption in transit (HTTPS), password-less sign-in, encrypted storage of tokens on the device (Keychain), access to data limited to authorised persons, separate permissions for moderators. No method of transmission or storage is 100% secure.
Personal data breach. In case of a breach likely to result in a risk to your rights, we will notify the Commission for Personal Data Protection within 72 hours (Art. 33 GDPR). If the risk is high, we will also notify you without undue delay (Art. 34 GDPR). We document all breaches. If you suspect a breach, write to us immediately at [email protected].
12. Your rights
Under the GDPR and the ZZLD you have the right to:
- access your data (Art. 15);
- rectification (Art. 16) — you can change most data yourself under "Edit profile";
- erasure (Art. 17) — including by deleting your account (section 10);
- restriction of processing (Art. 18);
- portability (Art. 20);
- object to processing based on legitimate interest (Art. 21) — e.g. by switching analytics off in Settings;
- withdraw consent at any time, without affecting the lawfulness of processing before the withdrawal;
- not be subject to a decision based solely on automated processing (Art. 22).
Settings in the app (the app interface is in English): profile visibility and being found by email and phone (Settings → Privacy); who can message you first ("Only connections can message me"); location sharing with connections (off by default); analytics ("Share usage analytics"); notifications and quiet hours; blocking; account deletion ("Delete account"). You manage the location, contacts, photos, camera and notification permissions in your iPhone settings.
To exercise your rights, write to [email protected]. We will reply within one month (Art. 12(3) GDPR). We may ask you to confirm that the email address is yours.
Right to complain. If you believe we process your data unlawfully, you can lodge a complaint with the Commission for Personal Data Protection (Комисия за защита на личните данни, KZLD):
- Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592 (гр. София 1592, бул. „Проф. Цветан Лазаров“ № 2)
- Phone: +359 2 915 3 518
- Email: [email protected]
- Website: https://www.cpdp.bg
13. Cookies and similar technologies
Website. We use:
- strictly necessary cookies — for sign-in (httpOnly session cookies), security, and remembering your cookie choice. They do not require consent;
- PostHog analytics cookies and local storage — only after consent for visitors from the EEA and the United Kingdom (section 3.8);
- session recordings — only after separate consent for visitors from the EEA and the United Kingdom.
You can change your choice at any time under "Cookie preferences" at the bottom of the page, or delete cookies in your browser.
App. The app stores settings and temporary copies of data (cache) on your device, and sign-in tokens in the iOS Keychain. The PostHog and Sentry SDKs store an anonymous identifier and unsent events on the device. We do not use advertising identifiers (IDFA) and we do not track users across apps and websites owned by other companies.
14. Children
Huddle is not intended for anyone under 16 and we do not knowingly collect data from children under 16. If you are 16 or 17, you need the consent of a parent or guardian. If you are a parent or guardian and believe a child under 16 has given us data, write to [email protected] and we will delete the account and the data.
15. Changes to this policy
We may update this policy. We will publish the new version on this page with a new "Last updated" date. For material changes we will notify you in advance by email or with a visible notice in the app.
16. Contact
For questions about this policy or your personal data:
- Email: [email protected]
- General email: [email protected]
- Address: "Support Wing" EOOD, 13 Roza St., Karavelovo 4350, Bulgaria (ул. Роза 13, Каравелово, 4350, България)
- Website: https://www.onhuddle.co