1. Introduction
This Privacy Policy describes how Haps Ltd. ("Haps", "we", "us") handles personal data when you use the Haps mobile application, the haps.network website, and related services (together, the "Services").
We are the data controller for the personal data described here. If you have questions, contact us at privacy@haps.network.
Placeholder: Haps Ltd., [Company registered address — replace before launch], United Kingdom. Replace with your registered company details before launch.
2. Data we collect
We collect the following categories of personal data:
| Category | Examples | Source |
|---|---|---|
| Account data | Email address, display name, handle, password (hashed), or Google/Apple sign-in identifier | You, at sign-up |
| Profile data | Avatar image, bio, role (raver / promoter), promoter details | You |
| Activity data | RSVPs, saved events, follows, tickets purchased, QR check-ins, reviews | You, through use |
| Messages | Direct messages you send to friends or promoters in the app | You |
| Location data | Approximate or precise device location (only with permission) for the map and "near me" | Your device (opt-in) |
| Payment data | Ticket purchase records; card details are handled by our payment processor, not stored by us | You, via processor |
| Device & usage data | Device type, app version, IP address, push token, crash logs, basic analytics | Automatically |
| Website data | Newsletter signups, contact form submissions, cookie preferences | You, on haps.network |
3. How we use data
We use personal data to:
- Create and manage your account and authenticate you;
- Show you relevant events, promoters and map content;
- Process RSVPs, ticket purchases and QR entry;
- Deliver location drops and push notifications for events and promoters you follow;
- Enable messaging between users and promoters;
- Keep the platform safe — moderating content and preventing fraud, spam and abuse;
- Respond to support requests and communicate service updates;
- Send marketing or launch updates where you have opted in (e.g. our newsletter);
- Comply with legal obligations and enforce our Terms.
4. Legal bases (GDPR)
Where the GDPR applies, we rely on the following legal bases:
- Contract — to provide the Services you sign up for (accounts, tickets, RSVPs).
- Legitimate interests — to keep the platform safe, improve it, and prevent abuse.
- Consent — for precise location, push notifications, optional cookies and marketing emails. You may withdraw consent at any time.
- Legal obligation — to meet tax, accounting and law-enforcement requirements.
5. Location data
Location features are opt-in. We only access your device location after you grant permission, and we use it to show nearby events, power the "near me" view, and deliver geo-locked location drops once you have RSVP'd. You can revoke location permission at any time in your device settings; the rest of the app will keep working.
Event addresses you see (including dropped locations) are provided by promoters. Please respect the discretion that underground events depend on.
7. Payments
Ticket payments are processed by Stripe. We do not receive or store your full card number. Stripe processes your payment data under its own privacy policy. We retain a record of the transaction (amount, event, status) to provide your ticket and for accounting.
8. Data retention
We keep personal data for as long as your account is active or as needed to provide the Services. After you delete your account, we remove or anonymise your personal data within 30 days, except where we must retain certain records (e.g. transaction records for tax/accounting) for the period required by law.
9. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you;
- Correct inaccurate data;
- Delete your data ("right to be forgotten");
- Restrict or object to certain processing;
- Data portability;
- Withdraw consent at any time;
- Lodge a complaint with your local data protection authority.
California residents (CCPA/CPRA) have the right to know, delete, correct and opt out of the "sale" or "sharing" of personal information — we do not sell personal information. To exercise any right, email privacy@haps.network.
10. Account & data deletion
You can delete your account and associated data directly in the app, or by request. See our dedicated Account & Data Deletion page for step-by-step instructions and what is and isn't retained.
11. Security
We use industry-standard measures — encryption in transit, hashed passwords, access controls and row-level security on our database — to protect your data. No system is perfectly secure, but we work hard to safeguard your information and will notify you and regulators of breaches where required by law.
12. Children
Haps is not intended for anyone under 16, and some events are restricted to those 18 or 21+. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
13. International transfers
We may process and store data in countries other than yours. Where we transfer data outside the UK/EEA, we rely on appropriate safeguards such as Standard Contractual Clauses.
14. Changes to this policy
We may update this policy from time to time. We will post the new version here with an updated date and, for material changes, notify you in the app or by email.
15. Contact us
Questions or requests? Email privacy@haps.network or write to Haps Ltd., [Company registered address — replace before launch], United Kingdom.
