Privacy policy
This policy covers the GRLS Do iPhone app and grlsdo.com. We collect the minimum we need to run the service, and social visibility is always your choice.
Last updated 30 September 2026
Who we are
GRLS Do, London, United Kingdom, is the data controller for personal data processed through GRLS Do. Contact us at privacy@grlsdo.com.
What we collect
You give us
- Account: email address, or your Apple ID relay email if you use Sign in with Apple.
- Profile: first name, date of birth (to confirm you are 18+; never shown to others), general London area, interests, and optionally a short bio and photo.
- Social choices: whether you are open to connecting, per-event visibility, and whether you are coming solo.
- Messages: connection requests, direct messages and event chat messages you send.
- Reports: information you give us when you report a person, event or host.
- Hosts: organiser name, contact details, event information and payout details (held by Stripe).
Created when you use GRLS Do
- Bookings: tickets, orders, amounts, refund status and check-in time. Card details are handled by Stripe; we never see or store your full card number.
- Saved events and events you view, to personalise what you see.
- Diagnostics: crash reports and performance data, to fix problems.
- Usage: which screens and features are used, to improve the product. This is not used for advertising.
- Device: a push notification token if you allow notifications.
We do not collect your precise location. We do not sell your data or use it for third-party advertising, and we do not track you across other companies' apps or websites.
Why we use it (and our lawful basis)
- To provide the service: accounts, bookings, tickets, messaging and support (contract).
- To confirm you're 18+ and keep the community safe: moderation, fraud prevention, enforcing our rules (legitimate interests; legal obligation where applicable).
- To show you relevant events based on your interests, area, saves and bookings (legitimate interests).
- To process payments and refunds and keep financial records (contract; legal obligation).
- To send notifications about bookings, messages and reminders (contract; you can turn these off).
- Marketing emails only if you opt in (consent; withdraw any time).
What other people can see
Nothing, by default. If you opt in for an event, other opted-in attendees of that event can see your first name, general area, interests and, if you choose, your age band. Hosts see the names of people who booked their event and check-in status, so they can run it. Hosts cannot see your social settings or messages.
Who we share it with
We use trusted service providers who process data on our instructions:
- Supabase: database, authentication and file storage.
- Stripe: payments, refunds and host payouts.
- Apple: Sign in with Apple and push notifications.
- Expo: app updates and push notification delivery.
- Sentry: crash and error reporting.
- PostHog: product analytics.
- Vercel: website hosting.
- Email provider: sign-in codes and booking emails.
We share booking information with the host of an event you book. We may disclose information if required by law or to protect someone's safety. Some providers process data outside the UK; where they do, we rely on UK adequacy regulations or the UK International Data Transfer Addendum.
How long we keep it
- Account and profile data: while your account is open, then deleted within 30 days of you deleting it.
- Messages: while your account is open; deleted with your account, except where kept as part of a safety report.
- Booking and payment records: 6 years, as required for tax and accounting.
- Safety reports and moderation records: up to 2 years after the case is closed, longer if needed for legal claims.
- Diagnostics and analytics: up to 12 months.
Your rights
Under UK data protection law you can ask to access, correct, delete or receive a copy of your data, object to or restrict how we use it, and withdraw consent. See Privacy choices or email privacy@grlsdo.com. We respond within one month. You can also complain to the Information Commissioner's Office at ico.org.uk.
Age
GRLS Do is only for people aged 18 and over. If we learn an account belongs to someone under 18, we delete it.
Changes
If we make significant changes we'll tell you in the app or by email before they take effect.