Privacy Policy
Last updated 2026-09-29
Pelipact is a web app where couples, housemates and friends trade favours at a shared table. To run it we hold some data about you, mostly your account and what happens at your tables. This policy explains what we hold, why, who else sees it, how long we keep it and what you can ask us to do. We are based in the Netherlands, so the General Data Protection Regulation (GDPR) and the Dutch rules that implement it apply.
1.Who we are
Pelipact is run by Pelipact, Van Heemstraweg 123, 6651 KH Druten, The Netherlands. We are the controller of the personal data in this policy: we decide what is collected and why, and you can hold us to account for it.
- Privacy questions and requests: info@pelipact.com
- Anything else, including account problems: info@pelipact.com
- Our data protection contact: info@pelipact.com
This policy covers the Pelipact website and app, the emails we send you and the notifications you allow. Our Terms of Service and Cookie Policy go with it.
2.The short version
- We collect what Pelipact needs to work, and little else.
- There are no ads, and we never sell or rent your data.
- The only optional tracking is Google Analytics, and it only runs after you say yes.
- The people at your table see what you do there. That is what a shared table is for.
- You can get a copy of your data, correct it or delete your account at any time.
- When you delete your account, your own data goes. Your tables keep their shared history, where you show as “Former member”.
3.What we collect
We hold six kinds of data about you, and nothing outside this list.
Account data. What lets you sign in and shows who you are.
- Your display name, the avatar and seal you pick, your settings, and your confirmation that you are 16 or older.
- Your email address and password, if you use them. We store the password only as a salted hash. A guest seat has neither.
- Your passkeys, if you add one. We hold only the public key; the private key never leaves your device.
- Two-factor authentication, if you turn it on: a secret and backup codes, stored encrypted.
- Your language and time zone, so emails, notifications, dates and quiet hours match you.
- Your active sign-in sessions, so you stay signed in.
Table data. What happens at the tables you sit at, created by you and the other members.
- Which tables you sit at, your seat and role, and how you joined. If someone invites you by link, the name they typed for you greets you at the door.
- Your pacts: every offer and counter, with its items, stickers, small print and dates.
- Your vouchers, your cash-ins with the times you suggested, and every ENJOYED stamp.
- Your table's play money: every coin made or spent, what waits in jars, and your Gold.
- Your Store shelf and what you buy there, what you put in the Mystery Chest, your opens and how each one was picked.
- Feed rows about you, your emoji reactions, bond points and memories.
- Whether you are looking at an offer right now. It is shared live and kept only while you look.
Notification data. Only if you turn notifications on for a device.
- The push address your browser gives us for that device, its keys and your browser's user agent.
- Your notification choices and quiet hours.
- Notifications waiting for your quiet hours to end, and a log of what we sent, without the text, kept for 30 days.
Technical data. What any web service sees, and the checks that keep bots out.
- Your IP address, your browser and device type, and the requests your browser makes. Cloudflare sees these on every request.
- Error and security logs: what failed, and which requests we refused. Private codes in links are blanked out before anything is written to a log.
- Cloudflare Turnstile results. Turnstile checks that a person, not a script, is signing up, signing in, resetting a password or taking a guest seat. It looks at your IP address and browser and gives us a pass or a fail, not a profile.
- Rate-limit counters, tied to your IP address or your account, kept for at most an hour.
Purchase data. Pelipact is free. If we add a paid premium plan later, Polar Software Inc. (Polar) will sell it as merchant of record. We would then receive what you bought, when, the price and whether the payment went through. We never receive your card or bank details.
Nothing is on sale yet, so we hold no purchase data about anyone.
Support data. If you write to us, we keep your message, your email address and whatever you tell us, so we can answer you and keep a record.
We do not ask for sensitive data such as your health, religion, politics or sex life, and we do not want it. Please keep it out of names, pacts and messages to us.
4.Why we use it, and on what basis
The GDPR requires a legal basis for every use of personal data. This table is the full list.
| Purpose | Legal basis | How long |
|---|---|---|
| Your account: signing you in, keeping you signed in and protecting the account (name, email address, password hash, passkeys, two-factor secret, sessions) | Performance of a contract, Article 6(1)(b) GDPR. Without it there is no account. | Until you delete your account. A session ends when you sign out, or 60 days after you last used it. |
| Running your tables: pacts, vouchers, play money, the Store, the Feed and the Mystery Chest | Performance of a contract, Article 6(1)(b) GDPR. | As long as the table exists. When you leave or delete your account, the shared history stays with the others, as explained below. |
| Emails about your account: confirming your address, resetting your password and telling you it changed | Performance of a contract, Article 6(1)(b) GDPR. We send no newsletters and no marketing. | We keep no copy. Resend keeps each email and its delivery record for 30 days. |
| Notifications on your devices | Consent, Article 6(1)(a) GDPR. You give it in your browser, and you can withdraw it in the app or in the browser. | Until you turn notifications off, sign out on that device, or the push service drops the address. The send log: 30 days. |
| Selling premium, once there is a premium plan | Performance of a contract, Article 6(1)(b) GDPR, and our duties under tax law, Article 6(1)(c) GDPR. | Purchase records: 7 years, as Dutch tax law requires. |
| Keeping Pelipact safe: bot checks, rate limits, logs, and looking into abuse | Legitimate interests, Article 6(1)(f) GDPR. Our interest is a service that bots and abusers cannot take over, which protects every member too. | Logs: only as long as we need them to fix errors and stop abuse. Rate-limit counters: at most an hour. |
| Answering your messages | Performance of a contract, Article 6(1)(b) GDPR, or our legitimate interest in answering people without an account, Article 6(1)(f) GDPR. | 24 months after the conversation ends. |
| Seeing how the site is used, through Google Analytics loaded by Cloudflare Zaraz | Consent, Article 6(1)(a) GDPR, and Article 11.7a of the Dutch Telecommunications Act for the storage itself. Nothing runs before you say yes. | Google keeps analytics data for 14 months. Your cookie choice is kept for 12 months. |
| Handling disputes and legal claims | Legitimate interests, Article 6(1)(f) GDPR. | As long as the claim is open, then for the legal limitation period. |
| Meeting other legal duties, such as answering a lawful order | Legal obligation, Article 6(1)(c) GDPR. | As long as the law requires. |
Where we rely on legitimate interests, we weigh them against your privacy first. You can ask how we did that, and you can object at any time, as explained under “Your rights”.
5.Analytics, and what happens before you choose
We use Google Analytics to see which pages people reach and where they get stuck. It is loaded through Cloudflare Zaraz, which also keeps your cookie choice.
Analytics is off until you say yes. Before that, no Google Analytics code loads, no analytics identifier is created and nothing is sent to Google. If you never see our cookie banner, analytics is not running at all. Pelipact works the same either way.
If you say yes, Google Analytics gets a random identifier for your browser, the pages you open, your rough location based on your IP address, and basic device and browser details. Google Analytics 4 does not store IP addresses. We do not turn on Google signals or advertising features, and we never send your name, your email address or what you trade.
You can change your mind at any time with “Cookie settings” in the site footer. If your browser sends a Global Privacy Control signal, we treat it as a no. Our Cookie Policy lists every cookie by name.
6.Who else sees your data
We do not sell or rent your data, and Pelipact carries no ads. The companies below help us run Pelipact. Most of them process data only on our instructions, under a data processing agreement. The push services and Polar act under their own responsibility.
| Recipient | What they do | Where |
|---|---|---|
| Cloudflare, Inc. | Serves the website and app, protects them and the API against attacks and bots, runs the Turnstile check, and runs Zaraz for your cookie choice. Every request from your browser to Pelipact passes through Cloudflare. | Worldwide, from the data center nearest you, which can include the United States. |
| Our hosting providers | Run the Pelipact API, its database and its session store, which hold your account and your tables. They can only be reached through Cloudflare. | The European Union. |
| Resend, Inc. and Infomaniak Network SA | Resend sends the emails about your account. Infomaniak hosts our mailbox, so it holds what you write to us. | Resend: the United States. Infomaniak: Switzerland. |
| Your browser's push service: Google, Mozilla, Apple or Microsoft | Delivers notifications to your device, if you turn them on. Messages are encrypted, so the push service cannot read them. It sees your device's push address and when a message arrives. | Chosen by your browser's maker, often in the United States. |
| Google Ireland Limited and Google LLC (Google Analytics) | Usage analytics, and only after you say yes. | The European Union and the United States. |
| Polar Software Inc. (Polar) | Sells premium as merchant of record, once there is a premium plan: takes the payment, charges VAT and handles refunds. Only if you buy. As the seller, Polar is a separate controller for the payment. | The United States. |
Two other groups can see some of your data. The people at your table see what you do there, as the next section explains. Authorities and courts see data only when the law requires it, and we tell you when that happens unless the law forbids it.
7.What the people at your table see
A table is shared. What you do at it is seen by the people you share it with.
- Everyone at a table sees your name and avatar, your Gold on your seat plate, your Store shelf and the Feed, which shows who made how many coins for whom.
- What is in a pact is seen only by the two people in it, except in a Den, where every member can read it unless the pact is marked “Just us two”.
- Memories and the bond between two people are seen by those two only.
- When you open an offer that waits for your answer, the other person sees that you are looking, but only while you look. Turn off “Share when I'm looking”, or peek privately, to stop that.
- Nobody at your table sees your email address, password, passkeys, two-factor or notification settings, or your other tables.
Anyone with your table's link sees its name and who invited them. Anyone with a Golden ticket link can open the offer in it. Share links only with the people they are meant for.
Pick a display name you are happy for your tables to see. You can change it at any time.
8.Sending data outside the European Economic Area
We keep data in the European Economic Area where we can. Some suppliers store data in, or can reach it from, other countries:
- Cloudflare serves each request from the data center nearest you and can route or support traffic from elsewhere, including the United States. Cloudflare is certified under the EU-US Data Privacy Framework, and standard contractual clauses apply as well.
- Resend stores the emails it sends for us, and their delivery records, in the United States. Resend is certified under the EU-US Data Privacy Framework, and standard contractual clauses apply as well.
- Google Analytics data, if you say yes, may be processed by Google LLC in the United States. Google LLC is certified under the EU-US Data Privacy Framework, and standard contractual clauses apply as well.
- Push services are chosen by your browser's maker and may be in the United States. They only ever see encrypted messages.
- Infomaniak keeps our mailbox in Switzerland, which the European Commission recognizes as protecting personal data adequately. Polar, once premium exists, handles the payment in the United States as the seller.
You can ask for a copy of the safeguards for any transfer at info@pelipact.com.
9.How long we keep it
The table under “Why we use it” gives the period for each purpose. A few points need saying in full.
- Deleting your account deletes your account data straight away: your name, email address, password, passkeys, two-factor settings, sessions, notification devices and settings. Records the law makes us keep, such as purchase records, stay locked away until their period ends.
- Your tables keep their shared history for the other members: pacts, vouchers, Feed rows and memories. There you show as “Former member”, and nothing links it to your account any more. What you wrote into a shared pact, such as an item name, stays part of that history.
- Coins waiting in jars go back to where they came from, and your Gold goes back to thin air, so the table's coins still add up.
- An ended Duo, or a Den or Crew whose last member left, is archived rather than deleted, so its memories stay in its former members' archives.
- A guest seat lives in the browser you sat down in. To delete it, save your seat and then delete your account, or write to us. If you lose that browser before saving, we cannot tell that the seat is yours.
- Backups may hold a copy of deleted data for a short while, until they are replaced. We never restore data from a backup without deleting it again.
10.Your rights
The GDPR gives you these rights over your data. They cost nothing, and using them is never held against you.
- Access. Ask what we hold about you and get a copy.
- Correction. Ask us to fix what is wrong or incomplete. You can change most of it yourself in the app.
- Erasure. Ask us to delete your data, apart from records the law makes us keep. The shared history at your tables stays with the other members, with you shown as “Former member”.
- Restriction. Ask us to pause processing while we settle a question about accuracy or our legitimate interests.
- Portability. Get the data you gave us, and the data your use created, in a common machine-readable format, or have it sent to another service where that is possible.
- Objection. Object to anything we do on the basis of legitimate interests, including our security work. We stop unless we have compelling reasons that outweigh yours.
- Withdrawing consent. For analytics and notifications, at any time. It does not affect what happened before, and it never costs you access to Pelipact.
- No automated decisions. We make no decisions about you with legal or similarly significant effects by automated means, and we do not profile you. The Mystery Chest picks at random with the chances shown, which is not a decision about you.
11.How to use your rights
Write to info@pelipact.com, from the email address on your account if you have one, and tell us what you want. You do not need special words or a reason, except for an objection, where your situation helps us decide.
- We answer within one month. If a request is complicated we may take two more months, and we tell you within the first month if so.
- If we cannot be sure a request comes from you, we ask for something extra, such as a reply from your account's email address. We never ask for a copy of your passport.
- If we say no, we tell you why and how you can challenge it.
- You can also delete your account yourself in the app, which starts the erasure described above.
12.Complaints
If you think we handled your data badly, please tell us first at info@pelipact.com, because most things are quicker to fix directly. You do not have to, and it does not use up any other right.
You can complain to a supervisory authority. Ours is the Dutch data protection authority, the Autoriteit Persoonsgegevens, Postbus 93374, 2509 AJ Den Haag, the Netherlands, autoriteitpersoonsgegevens.nl. You can also go to the authority where you live or work, or where you think the problem happened, and you can always go to court.
13.How we protect it
No system is perfectly safe, and we will not pretend otherwise. These are the measures we actually take.
- Everything travels over HTTPS, with strict transport security and a content security policy. Our pages load no scripts, fonts or images from other companies, apart from Cloudflare's Turnstile check.
- Passwords are stored as salted hashes, so nobody at Pelipact can read yours. With a passkey, the private key never leaves your device.
- Two-factor authentication is available for accounts with a password, and its secrets are stored encrypted.
- Cloudflare Turnstile guards sign-up, sign-in, password resets and new guest seats, and we rate-limit sign-in attempts.
- Scripts cannot read the session cookie, and changing or resetting your password signs out every other device.
- Our API accepts traffic only through Cloudflare, private codes in links are kept out of our logs, and only the people who run Pelipact can reach live data.
- Notifications do not show what is in an offer unless you choose that, and you can hide item names in cash-in notifications too.
If a data breach is likely to put your rights at risk, we report it to the Autoriteit Persoonsgegevens within 72 hours. If the risk to you is high, we tell you directly, in plain words.
14.Children
Pelipact is only for people aged 16 and over. Everyone confirms their age when they sign up or take a seat. There are no child accounts, and a parent cannot sign up for a child.
If we learn that someone under 16 is using Pelipact, we delete their account. Parents and guardians can write to info@pelipact.com about this, and we treat it as urgent.
15.Changes to this policy
When Pelipact changes, this policy may change too. Every version shows the date it took effect, and you can ask us for an earlier one.
If a change matters to you, such as a new supplier, a new purpose or a new kind of data, we tell you in the app, and by email if we have your address, at least 30 days before it takes effect. If a change needs your consent, we ask again rather than assume it. Small fixes, such as a typo or a broken link, take effect when we publish them.