Privacy Policy

    Last updated: April 2026 · Version 2.0

    1. Who we are (Controller)

    PeersUp ("we", "us", "our") is the data controller for personal data processed through peersup.com and the PeersUp app. For all privacy-related inquiries, contact us at privacy@peersup.com.

    2. Data we collect

    • Account data: name, email, password (hashed), country, profile picture.
    • Profile content: bio, links, social handles, contact details you publish.
    • Payment data: processed by Stripe; we only store transaction IDs, last 4 digits, and invoice metadata.
    • Usage data: page views, click events, device/browser info, approximate location (city/country).
    • Communications: support tickets, emails sent through our CRM tools.
    • Cookies & device IDs: see our Cookie Policy.

    3. Why we process your data (purposes & legal basis)

    PurposeLegal basis (GDPR Art. 6)
    Provide the service (account, profile hosting, NFC linking)Contract (b)
    Process payments & invoicingContract (b) + Legal obligation (c)
    Service improvement & analyticsConsent (a) — opt-in via cookie banner
    Marketing emails & newslettersConsent (a) — separate opt-in
    Retargeting pixels on profilesConsent (a)
    Fraud prevention & securityLegitimate interests (f)
    Tax/accounting record retentionLegal obligation (c)

    4. Sharing & sub-processors

    We never sell your data. We share it only with vetted sub-processors necessary to run the service (Supabase, Stripe, Resend, Cloudflare). The full list is available at /sub-processors. International transfers rely on Standard Contractual Clauses where applicable.

    5. Retention

    • Account & profile: until you delete your account (+30 days backup).
    • Analytics events: 14 months, then aggregated.
    • Invoices & payment records: 10 years (legal/tax).
    • Support tickets: 3 years after closure.
    • Consent records: 5 years (to prove valid consent).

    6. Your rights (GDPR Art. 15-22)

    You can access, rectify, delete, restrict, object, or port your data. Most actions are self-serve in your account. For more details, visit our GDPR Center. We respond to requests within 30 days.

    7. Security

    Data in transit is encrypted with TLS 1.2+. Data at rest is encrypted by our infrastructure provider. We use Row-Level Security on the database, role-based access internally, and CAPTCHA + rate limiting to deter abuse.

    8. Children

    PeersUp is not intended for users under 16. We do not knowingly collect data from children.

    9. Changes

    We will notify you of material changes by email and prompt re-consent where required.

    10. Complaints

    You may lodge a complaint with your local supervisory authority. List: edpb.europa.eu.

    11. Contact

    privacy@peersup.com