Privacy Policy
Effective Date: July 26, 2026
This Privacy Policy describes how Gatherly Ltd ("Gatherly," "we," "us," or "our") collects, uses, discloses, and protects your personal data. This policy is designed to comply with global standards, including the General Data Protection Regulation (GDPR) and relevant U.S. State Privacy Laws.
1. Data Controller and Contact
- Entity: Gatherly Ltd
- Address: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
- Email: [email protected]
2. Categories of Data We Collect
We process the following data to provide our matching and dinner group services:
- Identity & Profile Data: Name, gender, date of birth (to verify you are 18+), biography, occupation, nationality, and profile photo.
- Contact Data: Phone number (verified via SMS) and optional email address.
- Special Category / Sensitive Data: Dietary restrictions, which may reveal health or religious information.
- Location Data: Precise GPS coordinates and your chosen "Max Distance" radius.
- Preference & Interest Data: Cuisine, alcohol, and smoking preferences; dinner length; available dates; and questionnaire responses.
- Technical Data: IP address, device type, app version, time zone, and system logs.
- Match & Event Data: Match history, dinner dates, restaurant details, and cancellation status.
- Purchase Data: What you bought, when, and from which store. We never receive your card or bank details.
- Push Notification Tokens: An identifier for your device, so we can send you notifications.
- Diagnostic Data: Crash reports from the mobile app, containing the state of the app when it stopped working.
3. Legal Bases for Processing
Where applicable (e.g., EEA/UK), we rely on the following legal bases:
- Contractual Necessity (Art. 6(1)(b)): To create your account and arrange your dinners.
- Explicit Consent (Art. 9(2)(a)): For your dietary restrictions, and for device permissions such as location and camera.
- Legitimate Interest (Art. 6(1)(f)): For the security of the service and the prevention of fraud and abuse.
- Legal Obligation (Art. 6(1)(c)): To comply with tax, safety, or law enforcement requirements.
4. How Your Dinner Group Is Chosen
Your dinner group is put together automatically, without a person deciding. The data used to do it is the data you gave us for that purpose:
- the city you signed up in, and how far you are willing to travel;
- the languages you speak;
- your dietary needs and your cuisine, alcohol, smoking and dinner length preferences;
- your questionnaire answers and your interests;
- the dates you said you were free.
Nothing else about you is used, and the outcome is only which dinner you are placed in. If you want a person to look at your matching status, email [email protected].
5. Data Sharing & Recipients
We do not sell your personal data. We share it only with:
- The other people at your dinner: your first name only, and only once the dinner has been confirmed with a restaurant. We do not give them your last name, photo, phone number, email address, or anything else from your profile. If you cancel, your name stops being shown to them.
- Our service providers: the companies listed below, each processing only what their part of the service needs.
- Professional Advisers: Insurers, auditors, or legal counsel where necessary.
- Law Enforcement: Only if required by a binding legal order.
The providers we use, and what each of them receives:
- DigitalOcean — stores everything listed in section 2.
- Backblaze — your profile photo.
- Twilio — your phone number, to send your verification code.
- HERE — your location, to identify your country and city.
- Google — your device's push token and crash reports; your location, to find restaurants near your group; your Google account details, if you sign in with Google.
- RevenueCat — your purchases, to confirm what you bought.
- Cloudflare — technical data at login, to check you are not a script.
- Grafana Labs — our logs, which can contain your IP address.
- Zoho — your email address, to deliver emails we send you.
6. International Transfers
Your data is stored in the United States, and several of the providers in section 5 are based there. If you are in the EEA or the UK, your data is therefore transferred outside it. We rely on:
- Adequacy Decisions by the European Commission.
- Standard Contractual Clauses (SCCs) and relevant supplemental measures.
7. Your Rights
Depending on your location, you may have the following rights:
- Access & Portability: Request a copy of your data in a machine-readable format.
- Rectification & Erasure: Correct inaccurate data or request the "Right to be Forgotten."
- Object to Automated Processing: Request a human review of your matching status.
- Withdraw Consent: At any time for optional data or device permissions.
- Lodge a Complaint: With your local Data Protection Authority (DPA).
You can delete your account yourself, at any time, from the settings screen in the app; section 8 sets out exactly what that removes. For anything else, email [email protected] and we will handle it by hand.
8. Data Retention
We keep your data until you delete your account. We do not currently delete or anonymise accounts automatically after a period of inactivity.
Deleting your account from the app erases your profile, your photo, your preferences and questionnaire answers, your notifications and everything else listed in section 2. Two things survive it, and we want to be direct about that:
- Purchase records are kept, because we are required to keep records of sales. The link to you is severed, so what remains is a transaction with no account attached to it.
- A dinner you were part of continues to exist for the other people at it, with you removed from it. If that leaves too few people for the dinner to go ahead, it is cancelled and the others get their dinner credit back.
Server logs are kept for our logging provider's standard period.
9. Security Measures
We take appropriate technical and organisational measures to protect your personal data against loss, misuse and unauthorised access. Traffic between the app and our servers is encrypted, passwords are never stored in a readable form, staff access is restricted to those who need it, and we keep backups. No service can promise perfect security, and we do not.
10. Children's Privacy
Gatherly is strictly for individuals aged 18 and older. If we discover we have collected data from a minor, we will delete it immediately and terminate the account.
11. Changes to this Policy
Material changes will be notified via in-app alerts. Your continued use of the app after the effective date constitutes acknowledgment of the updated policy.
Questions about this policy?