Notice

Privacy Policy

Last updated: August 1, 2026 · Version 1.6 · Courtesy translation — the Italian version prevails

This notice describes how the Hepcat mobile app ("the App") processes its users' personal data under Regulation (EU) 2016/679 ("GDPR"). The App is free, ad-free, and never sells your data.

I. Data controller

The data controller is Alessandro Di Già, reachable at info@hepcatapp.com.

II. Data we process

We collect no advertising data and use no third-party analytics tools.

Data about people who don't use Hepcat (guest partner)

Someone registering for a festival can register as a couple and bring along a person who doesn't have Hepcat. In that case we process that person's name, email address and dancing role, and we receive them from whoever registers them, not from them.

Whoever registers someone else declares they are entitled to do so. If you receive one of these emails and don't want to appear, the link in the email settles it in one click; alternatively, write to privacy@hepcatapp.com.

III. Purposes and legal bases

PurposeLegal basis
Providing the service: account, profile, content, chat, notificationsPerformance of a contract (Art. 6.1.b GDPR)
Showing festivals based on your detected countryConsent (Art. 6.1.a GDPR), revocable in your device settings
Security, moderation of reported content, abuse preventionLegitimate interest (Art. 6.1.f GDPR)
Legal complianceLegal obligation (Art. 6.1.c GDPR)

IV. Where your data lives and who processes it

Data is hosted on Supabase infrastructure (database, authentication and file storage) in the European Union — Frankfurt, Germany (AWS eu-central-1) region. Push notifications are delivered through Expo (Expo Push Service), Google (Firebase Cloud Messaging, Android devices) and Apple (Apple Push Notification service, iOS devices). These providers act as processors under agreements compliant with Art. 28 GDPR.

Service emails are sent through Resend: delivery may originate from European servers, but email metadata and logs — including recipient addresses — are stored in the United States. Automatic translation of organiser-published content (descriptions, schedule, announcements) is performed by Cloudflare (Workers AI): that text may incidentally contain personal data, such as teachers' names. Processing takes place on Cloudflare's global network, and Cloudflare does not publish the location of its inference servers; Cloudflare states that it does not use customer content to train models. These providers likewise act as processors under Art. 28 GDPR.

For festival registration payments we rely on Stripe (Stripe Payments Europe, Ltd., Ireland, with Stripe, Inc. in the United States). Stripe processes the dancer's payment data and — for organizers who charge for passes in the app — the identity and tax data required for the anti-money-laundering (KYC) checks on their account. We use Standard connected accounts with direct charges: with respect to the payment, the organizer, not Hepcat, is the controller toward Stripe and responsible for the transaction; Hepcat only receives the outcome. Stripe acts as an independent processor/controller under its own privacy policy.

When you register for a festival through the App, that event's organizer sees your name, your username, the dance role you declared, the pass you chose and the status of your registration — not your email, your contacts or your friendships. The organizer can also add their own questions to the registration (for example dance level, T-shirt size, dietary needs, housing requests, membership number, consent to the code of conduct or to photography): your answers are visible to them and serve the running of the event. With respect to this data the organizer is an independent controller. Questions only allow short answers, predefined choices or checkboxes: attaching documents or uploading files is not possible. Answers that reveal special category data (Art. 9 GDPR) — such as health-related dietary needs — are optional and are processed on the basis of your explicit consent, which you may withhold without losing your registration.

Any transfers to third countries rely on Standard Contractual Clauses or adequacy decisions (including the EU-U.S. Data Privacy Framework, where applicable). Your data is never sold or shared with third parties for marketing purposes.

We apply appropriate technical measures (Art. 32 GDPR): data is transmitted over encrypted connections (TLS/HTTPS) and stored encrypted at rest by the infrastructure. Chat messages are not end-to-end encrypted: they remain accessible to the controller for security, moderation and notification delivery purposes.

V. Who can see your content

VI. Retention and deletion

Data is kept for as long as your account is active. You can delete your account at any time from the App (Profile → menu → Delete account): your profile, friendships, announcements, photos and all other personal data are permanently deleted. Messages already sent in group chats remain visible to other members but are anonymised (no author).

VII. Your rights

Under Arts. 15–22 GDPR you may exercise your rights of access, rectification, erasure, restriction, portability and objection by writing to the email address above. You also have the right to lodge a complaint with your supervisory authority (in Italy, the Garante: garanteprivacy.it).

VIII. Minimum age

The App is intended for users aged 14 or older, the digital consent age in Italy under Legislative Decree 101/2018.

IX. Changes

Material changes to this notice will be communicated through the App. The current version is always available on this page.