Privacy Policy
1. Data we collect
We collect only the minimum necessary to run SpeedDate. Here's what we store:
| Data | When collected | Purpose |
|---|---|---|
| Name | Registration | Display to event participants |
| Email address | Registration | Account access, event confirmations, reminders |
| Age | Registration | Age-appropriate event matching |
| IP address | Every request | Security, rate limiting, fraud prevention |
| Session cookie | Login | Keeping you logged in |
| Event participation | During events | Match calculation, statistics |
| Match ratings | Post-event | Showing mutual matches |
We do not collect: phone numbers, social media profiles, location, payment card details (donations processed by PayPal), or any biometric data.
2. How we use your data
- Authenticate your account and maintain your session
- Send event confirmations, reminders, and match notifications
- Calculate mutual matches at the end of events
- Detect and prevent abuse, spam, and fraud
- Improve the platform using anonymised, aggregated statistics
We do not use your data for advertising, profiling, or sale to third parties — ever.
3. Storage & security
All data is stored on servers within the EU. We use:
- HTTPS/TLS for all data in transit
- bcrypt hashing for passwords (never stored in plain text)
- Prepared statements to prevent SQL injection
- Session tokens stored server-side, rotated on login
- Automatic purging of expired sessions and tokens
5. Cookies
We use only essential cookies. No tracking or advertising cookies.
| Cookie | Purpose | Duration |
|---|---|---|
sd_sess | Session authentication | 7 days |
sd_cookie | Cookie consent preference (localStorage) | Permanent (localStorage) |
6. Your rights under GDPR
If you are in the EU/EEA, you have the following rights:
Request a copy of all personal data we hold about you.
Correct inaccurate or incomplete personal data.
Request deletion of your account and all associated data.
Receive your data in a machine-readable format.
Object to processing based on legitimate interests.
Limit how we process your data in certain circumstances.
To exercise any of these rights, email privacy@speed-dating.org. We respond within 30 days.
7. Data retention
- Account data — retained while your account is active, deleted within 30 days of account deletion request
- Event participation logs — anonymised after 12 months
- Server logs (IP) — retained for 90 days for security purposes
- Contact form messages — retained for 12 months then deleted
8. Contact & complaints
Data controller: SpeedDate
Email: privacy@speed-dating.org
If you believe we have mishandled your data, you have the right to lodge a complaint with your local data protection authority.