Privacy policy
What Popalong collects, why, and what you can do about it. Written to be read, not to be survived.
Last updated 3 September 2026
Who we are
Popalong is an app for creating events and inviting people to them. It is run by Oliver Glaas, a sole trader based in the United Kingdom, who is the data controller for the personal data described in this policy.
For anything about your data — including a request to see it, correct it or delete it — contact privacy@popalong.app.
This policy is written to satisfy Articles 13 and 14 of the UK GDPR. If you were invited to an event and don’t have a Popalong account, section 3 is the part written for you.
What we collect
When you create an account: your name, email address, and either a password (which we store only as a scrambled hash, never the password itself) or your Google account details if you sign in with Google — that is your name, email address and profile picture.
When you create an event: its title, description, date and time, the venue name and address you enter, the map coordinates for that address, and any cover image you upload.
When you invite people: the email address or phone number you enter for each guest, and any name you give them. See section 3 — this is other people’s data, and you are responsible for it too.
When you reply to an invitation:your answer, the number of extra guests you’re bringing, when you replied, and your name if you don’t have an account.
When you use event chat: the messages you send and when you sent them. These are visible to everyone on that event.
Automatically: your IP address, which appears in server logs and is used briefly to limit how often sensitive actions can be repeated. We also record aggregated, anonymous page-view counts that cannot be traced back to you.
We do not use your data for advertising, we do not sell it, and we do not build profiles of you.
If someone invited you to an event
You may be reading this because you received an invitation from Popalong without ever signing up. Here is exactly what happened.
Where we got your details. We did not get them from you. Somebody organising an event entered your email address or phone number in order to invite you, in the same way they might have added you to a group chat. We hold only what they entered, plus your reply if you give one.
Why we’re allowed to. Our lawful basis is legitimate interests: sending an invitation is what the host asked for and what you would reasonably expect when a friend organises something. We use your details only to deliver that invitation, record your answer and show it to the host and the other guests.
How to make it stop. Every email we send you about an event has a Don’t contact me againlink at the bottom. One click, one confirmation, and we stop emailing that address about events — this one and any future invitation, from any host. It takes effect straight away. If the link no longer works because the event or the invitation has since been deleted, email privacy@popalong.app instead and we will do exactly the same thing by hand. You never have to create an account, and you never have to explain why.
To honour that we keep a record of the address itself, and only the address, on a do-not-contact list. It is the one thing we don’t delete when we delete everything else: without it, the next person who typed your address in would reach you all over again.
We only process the specific contacts a host chooses to invite. We never upload or scan anybody’s address book.
Why we use your data
UK GDPR requires a lawful basis for each thing we do with your data. Ours are:
| What we do | Why | Lawful basis |
|---|---|---|
| Run your account | So you can sign in and use the app | Performance of a contract (our terms) |
| Send invitations and track RSVPs | It is the point of the product, and what the host asked for | Legitimate interests |
| Send reminders and event updates | So guests aren't left with out-of-date details | Legitimate interests |
| Send account emails, such as verification and password resets | So you can prove the address is yours and recover access | Performance of a contract |
| Limit repeated sign-in and sign-up attempts | To protect accounts from password guessing and the service from spam | Legitimate interests |
We do not send marketing email, so no part of this policy relies on your consent. If that ever changes, we will ask first.
Who else sees it
We use a small number of specialist providers to run the service. They process data on our instructions only, under a contract, and cannot use it for their own purposes.
| Provider | What it does | What it sees | Where |
|---|---|---|---|
| Neon | Database hosting | Everything stored in the app: accounts, events, invitations, RSVPs, chat messages, notifications | United States |
| Vercel | Website hosting and traffic analytics | Requests to the site, including IP addresses in server logs. Analytics is aggregated and cookieless | United States |
| Resend | Sending email | Recipient names and email addresses, and the contents of invitations, reminders and account emails | United States |
| Cloudflare R2 | Image storage | Event cover images uploaded by hosts | United States and global edge network |
| Sign-in with Google, and looking up event addresses on a map | For sign-in: your Google account name, email address and profile picture. For maps: the event address a host types | United States | |
| Upstash | Rate limiting, to block password guessing and spam | IP addresses and email addresses, held briefly as counters | United States |
Other guests on an event also see your name, your answer and any messages you post. The host additionally sees the email address or phone number their invitation was sent to.
We may disclose data if the law requires it, but we will not hand it over on request without a legal obligation.
Where your data goes
The providers listed above are based in the United States, so your data is transferred outside the UK. Those transfers rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or on the provider’s certification under the UK Extension to the EU-US Data Privacy Framework, as set out in each provider’s data processing agreement.
If you want to know which mechanism a specific provider relies on, ask at privacy@popalong.app and we will tell you.
How long we keep it
| What | How long |
|---|---|
| Your account, and the events, RSVPs and messages attached to it | Until you delete your account. Deleting it removes them immediately. |
| An invitation to someone without an account | Until the host deletes the invitation or the event, or the person asks us to remove it. |
| Notifications | Automatically pruned to the 10 most recent read and 100 most recent unread per person. |
| Email verification and password reset links | 24 hours and 1 hour respectively, then they stop working and are deleted when used. |
| Rate-limiting counters | Between 10 seconds and 1 hour, depending on the limit. |
| A record that you asked us to stop emailing you | Kept indefinitely, on purpose. It is the only way to make sure a later invitation doesn't reach you, so it survives deleting everything else. |
Two exceptions worth stating plainly.Deleting your account removes your data from our database immediately, but a cover image you uploaded may remain in image storage afterwards — email privacy@popalong.app and we will remove those too.
And if you have asked us to stop emailing you about events, we keep that one record even after everything else is deleted, and even if you ask us to erase your data. Deleting it would undo the very thing you asked for: the next invitation to that address would go through. UK GDPR allows us to keep the minimum needed to honour an objection, and the minimum here is the address on its own.
How we protect it
- Passwords are hashed with bcrypt before they are stored. Nobody at Popalong can read your password, and we will never ask you for it.
- All traffic to the site and between our providers is encrypted in transit, and data is encrypted at rest by our database provider.
- Guest lists, RSVPs and event chat are readable only by the host and the people on that event. Private events are not discoverable by anyone else.
- Sign-in, registration, password reset and invitation replies are rate limited, which blocks password guessing and bulk abuse.
- Invitation links are personal to one guest. Treat yours like a password and avoid forwarding it, since anyone holding it can reply on your behalf.
Your rights
You have the right to:
- Access. Ask for a copy of the personal data held about you.
- Rectification. Have inaccurate data corrected. You can change your own name and password in the app at any time.
- Erasure. Ask for your data to be deleted. You can delete your own account from your profile page, which removes it straight away.
- Restriction. Ask us to pause processing your data while a concern is being resolved.
- Objection. Object to processing based on legitimate interests, including being invited to events. Every invitation email carries a one-click link that does this immediately, and you can email us instead if you prefer.
- Portability. Ask for the data you gave us in a machine-readable format, or to have it sent to another service.
To use any of them, email privacy@popalong.app. We will respond within one month, and it is free. We may ask you to confirm your identity first, so that nobody else can use these rights to get at your data.
Age
Popalong is for adults. You must be 18 or over to create an account, as set out in our terms of service. We do not knowingly collect data about children. If you believe someone under 18 has an account, tell us at privacy@popalong.app and we will delete it.
Changes to this policy
We will update this page when the product changes what it collects or how it is used, and the date at the top will change with it. If a change materially affects your rights, we will tell account holders by email rather than leaving you to notice.
Complaints
If something about how we handle your data concerns you, please raise it with us first at privacy@popalong.app — most things are quicker to fix directly.
You also have the right to complain to the UK’s data protection regulator, the Information Commissioner’s Office, at ico.org.uk/make-a-complaint or on 0303 123 1113. You do not have to come to us first.