Last updated: April 2026 · Version 2.0
PeersUp ("we", "us", "our") is the data controller for personal data processed through peersup.com and the PeersUp app. For all privacy-related inquiries, contact us at privacy@peersup.com.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide the service (account, profile hosting, NFC linking) | Contract (b) |
| Process payments & invoicing | Contract (b) + Legal obligation (c) |
| Service improvement & analytics | Consent (a) — opt-in via cookie banner |
| Marketing emails & newsletters | Consent (a) — separate opt-in |
| Retargeting pixels on profiles | Consent (a) |
| Fraud prevention & security | Legitimate interests (f) |
| Tax/accounting record retention | Legal obligation (c) |
We never sell your data. We share it only with vetted sub-processors necessary to run the service (Supabase, Stripe, Resend, Cloudflare). The full list is available at /sub-processors. International transfers rely on Standard Contractual Clauses where applicable.
You can access, rectify, delete, restrict, object, or port your data. Most actions are self-serve in your account. For more details, visit our GDPR Center. We respond to requests within 30 days.
Data in transit is encrypted with TLS 1.2+. Data at rest is encrypted by our infrastructure provider. We use Row-Level Security on the database, role-based access internally, and CAPTCHA + rate limiting to deter abuse.
PeersUp is not intended for users under 16. We do not knowingly collect data from children.
We will notify you of material changes by email and prompt re-consent where required.
You may lodge a complaint with your local supervisory authority. List: edpb.europa.eu.