legal
privacy policy
what we collect, why, for how long, who can access it - and how to exercise your rights. without the unreadable wall of text.
last updated : 10 june 2026
the essentials
- your profile is visible to other members: first name, age, photo, bio and interests, along with your attendance at the events you join.
- we collect what makes the service work: account, profile, events, messages, event locations - nothing is sold, to anyone.
- payments are processed by Stripe: your card numbers never pass through our servers.
- the site uses no advertising cookies or third-party trackers - which is why no banner is shown to you.
- deleting your account erases your data immediately and permanently.
- for any request: support@2gather.events (subject [personal data]) - reply within 30 days. in case of lasting disagreement, you can refer the matter to the CNIL.
who is responsible for your data
2gather, publisher of the 2gather.events website and the 2gather mobile app, is the controller of your data. for any question about your data: support@2gather.events, subject [personal data].
the data we collect
data marked required is essential to create an account or use the relevant feature; without it, sign-up or the feature is refused. everything else is optional.
| category | data | nature |
|---|---|---|
| account | email, first name, date of birth, password (stored hashed) | required |
| profile | photo, bio, gender, interests, languages, preferences | optional |
| events | events created, joined or bookmarked, ratings left | tied to usage |
| location | event addresses; device position in the app, only if you allow it (you can always enter an address instead) | optional |
| payments | amounts and transaction history - never your card numbers, handled by Stripe | if paid event |
| messages | messages and reactions in event rooms and conversations (app) | tied to usage |
| technical | connection logs, device identifier, notification token | operation |
| identity verification | if you request it: id document and selfie, analysed on our own servers, with no external provider | voluntary |
why, and on what legal basis
| purpose | legal basis |
|---|---|
| provide the service: account, profile, creating and joining events, messaging, map | contract |
| recommend events and profiles based on your interests | contract (core of the service) |
| verify age (18 minimum) and protect minors | contract and legitimate interest |
| security, fraud prevention, moderation of content and accounts | legitimate interest: protecting members and the integrity of the service |
| billing of paid events and retention of supporting documents | legal obligation |
| retention of connection data | legal obligation |
| app push notifications (new messages, event reminders) | consent - can be turned off at any time in the settings |
how long we keep it
| data | duration |
|---|---|
| account, profile, messages, photos | as long as the account exists; erased immediately on deletion |
| connection tokens (sessions) | 30 days maximum, daily purge |
| deleted events | purged 30 days after deletion |
| bookmark and viewing history | 6 months |
| history used for recommendations | 12 months, then anonymised - can be reset on request at any time |
| read notifications | 90 days |
| technical logs | short rotation with a capped size |
| accounting records for payments | 10 years (commercial code), in restricted-access archive |
who has access to your data
other members, first - that's the principle of an event network: your public profile (first name, age, photo, bio, interests), your presence in the participant list of an event you join, and your messages for their recipients. your email address and phone number are never visible to other members.
then, our providers - each for its own task, never for advertising:
| provider | task | location |
|---|---|---|
| OVHcloud | photo and media storage | France (Roubaix) |
| Stripe Payments Europe | payments for paid events | Ireland / EU |
| Resend | transactional emails (verification, password) | United States |
| Google (Firebase) | push notifications, usage statistics and app crash reports | EU / United States |
| Google Maps Platform | address search and geocoding | EU / United States |
| Apple | sign in with Apple, notifications, in-app purchases | EU / United States |
| RevenueCat | managing the app's premium subscriptions | United States |
| Sentry | error monitoring - sensitive fields masked before sending | United States |
| Giphy | GIF search in conversations | United States |
finally, the authorities, only on a legally grounded request. we never sell your data and we display no advertising.
does your data leave the EU?
your data is mainly processed in Europe (media stored in France). some of the providers above are established in the United States: these transfers are framed by the safeguards laid out by the GDPR - adequacy decision (Data Privacy Framework) or the European Commission's standard contractual clauses, depending on the provider. write to us to obtain a copy.
how it is protected
traffic encryption (HTTPS), hashed passwords, media accessible only through authenticated links, restricted and logged internal access. the detail - including how to report a vulnerability - is on the security page. in the event of a data breach that poses a risk to you, we notify the CNIL within 72 hours and we inform you.
your rights
- access - obtain a copy of all the data we hold about you.
- rectification - correct inaccurate information, directly in settings or on request.
- erasure - delete your account from settings or the app: erasure is immediate and permanent.
- restriction - request a temporary freeze on the use of your data.
- objection - object to processing based on our legitimate interest.
- portability - retrieve the data you provided to us, in a machine-readable format.
- withdrawal of consent - at any time, as easily as you gave it (for example: turning off notifications).
- post-mortem directives - decide what happens to your data after your death.
write to support@2gather.events (subject [personal data]) from your account's email address. we reply within one month; if the request is complex, this period may be extended by two months and we let you know within the first month. in case of serious doubt about your identity, we may ask for verification.
if, after contacting us, you believe your rights are not being respected, you can lodge a complaint with the CNIL (cnil.fr/fr/plaintes - 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07).
mobile app
- location - optional, used to show you nearby events. you can always enter an address instead, and revoke the permission in the phone's settings.
- photos and camera - only when you add a profile or event photo.
- notifications - can be turned off at any time, globally or by type.
- measurement and stability - the app uses Firebase (aggregated usage statistics, crash reports) and Sentry (errors, sensitive fields masked) to run and improve. the website itself ships no measurement tool.
recommendations and profiling
to rank the events and profiles we suggest to you, we use your interests, distance, your stated preferences and your past activity. no decision producing legal effects is made automatically. the history used for these recommendations is kept for 12 months then anonymised - and you can request its reset at any time, without deleting your account.
minors
2gather is reserved for adults (18 and over). the date of birth is verified at sign-up and any account detected as belonging to a minor is deleted.
changes to this policy
if we change this policy significantly, you are informed by email or in the app before it takes effect. the date of the last update appears at the top of the page.
a question, a request?
write to us from your account's address, subject [personal data] - reply within 30 days. you can also manage your information directly in settings.
