Privacy Policy
Last updated 30 June 2026
The Gathering Table respects your privacy. This policy explains what personal data we collect, why, who we share it with, how long we keep it, and your rights over it.
Who we are
The Gathering Table is the data controller for the personal data described here. You can reach us at hello@thegatheringtable.app, and we'll provide our registered postal address on request.
What we collect
Your account: name, email address, mobile number, date of birth, password (stored only as a secure hash), membership tier and status.
Family members: if you add an under-18, their name, date of birth and (optionally) a mobile number, provided by you as their parent or guardian. When we verify a child in person we record only that verification happened and the method used — we do not keep any copy of identity documents.
Your activity: bookings, attendance, waitlist position, favourites, and any missed-booking balance.
Your profile & social content: profile photo, bio, chosen interests, photo gallery, and the content you create on the platform — direct messages, group/club/venue chat messages, posts on community and venue walls, polls, and game moves. If you report another member, we keep a copy of the reported content and your report so we can act on it. (These social features are not yet switched on.)
If you run or apply to run events: your venue/host contact details and page content. If you ask to be notified or apply to host: the email and details you give us.
Technical: we record limited security information such as IP addresses against rate-limiting and abuse-prevention records, and device tokens if you enable push notifications.
Why we use it & our lawful basis
- Running your membership, bookings and events — performance of our contract with you.
- Verifying your phone/email, keeping accounts secure, preventing abuse, and operating moderation — legitimate interests.
- Operating the social features (messaging, walls, profiles) you choose to use — performance of our contract and your use of the service. (These social features are not yet switched on.)
- Sending news and offers by email — only with your consent, which you can withdraw at any time.
- Meeting legal and safety obligations, including online-safety duties — legal obligation / legitimate interests.
Who we share it with
We use trusted providers who process data on our behalf under their own security and privacy terms: Supabase (database, accounts & file storage), Twilio (sends your verification text), Zoho (sends our emails), Stripe (processes payments, when enabled), Vercel (hosting), Vercel Analytics (privacy-friendly, cookieless usage statistics) and postcodes.io (converts venue postcodes into map coordinates so members can find venues near them). We don't sell your data. If you use "show nearest to me", your device's location is used only in your browser and is never sent to our servers.
Visible to other members: your name, profile photo, bio, interests and participation stats are visible to other signed-in members, and your gallery to your connections. Posts you make on community/venue walls are public. Please don't share anything you wouldn't want other members to see. (These social features are not yet switched on.)
Children's data
Children are added and managed only by a parent or guardian. They have no separate login and cannot use the social/messaging features — those are for verified adults (18+) only. We collect the minimum needed (name, date of birth, optional phone) and verify each child in person before they become active, keeping no copies of any documents. Contact us anytime to update or remove a child's details.
How long we keep it
We keep your account and activity data while you're a member. If you delete your account, your profile, family members, photos and private messages are removed and your login is closed; some records (such as the financial history behind a missed-booking balance) may be retained without identifying you where we have a legal or accounting reason. Where we keep a copy of reported content for moderation, we remove the verbatim content roughly 90 days after the report is resolved, keeping only the outcome record.
Your rights
You have the right to access, correct, or delete your data, to object to or restrict certain processing, and to data portability. You can delete your account yourself at any time from your profile page, or contact us to exercise any other right. You can also complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
Cookies & analytics
We use only essential cookies needed to keep you logged in — we don't use advertising trackers. To understand how the site is used we use Vercel Analytics, which counts page views without setting cookies and without identifying you personally.
Contact
For any privacy request, email hello@thegatheringtable.app.