Notice
Privacy Policy
This notice describes how the Hepcat mobile app ("the App") processes its users' personal data under Regulation (EU) 2016/679 ("GDPR"). The App is free, ad-free, and never sells your data.
I. Data controller
The data controller is Alessandro Di Già, reachable at info@hepcatapp.com.
II. Data we process
- Account data: email address, username, display name and, if you provide them, city, country, year you started dancing, dance role, bio and profile photo.
- Content you create: messages and photos in trip group chats, board announcements, bookings, polls, checklists, shared expenses, festival attendance and wishlists.
- Social relations: friendships, friend requests, blocked users and reports you submit.
- Push notification token: a technical device identifier required to deliver notifications.
- Location: if you grant permission, the App detects only your country code (e.g. "IT") directly on your device, to show nearby festivals. Coordinates are never sent to or stored on our servers. You can deny the permission and still use the App.
We collect no advertising data and use no third-party analytics tools.
Data about people who don't use Hepcat (guest partner)
Someone registering for a festival can register as a couple and bring along a person who doesn't have Hepcat. In that case we process that person's name, email address and dancing role, and we receive them from whoever registers them, not from them.
- Why: to hold the registration, to let them into the event, and to tell them they have been registered. Legal basis: legitimate interest in allowing couple registration (Art. 6.1.f GDPR), balanced by the notice we send them and by their ability to cancel on their own.
- What they receive: an email telling them who registered them, for which event, what data we hold and how to opt out. This is the notice required by Art. 14 GDPR for data not obtained from the data subject, and it reaches them at the first suitable opportunity.
- How they opt out: from that same email, through a personal link that lets them cancel the registration without creating any account. No account, no profile, no further communications.
- Who sees it: the festival organiser, as for every attendee, and the person who registered them.
Whoever registers someone else declares they are entitled to do so. If you receive one of these emails and don't want to appear, the link in the email settles it in one click; alternatively, write to privacy@hepcatapp.com.
III. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the service: account, profile, content, chat, notifications | Performance of a contract (Art. 6.1.b GDPR) |
| Showing festivals based on your detected country | Consent (Art. 6.1.a GDPR), revocable in your device settings |
| Security, moderation of reported content, abuse prevention | Legitimate interest (Art. 6.1.f GDPR) |
| Legal compliance | Legal obligation (Art. 6.1.c GDPR) |
IV. Where your data lives and who processes it
Data is hosted on Supabase infrastructure (database, authentication and file storage) in the European Union — Frankfurt, Germany (AWS eu-central-1) region. Push notifications are delivered through Expo (Expo Push Service), Google (Firebase Cloud Messaging, Android devices) and Apple (Apple Push Notification service, iOS devices). These providers act as processors under agreements compliant with Art. 28 GDPR.
Service emails are sent through Resend: delivery may originate from European servers, but email metadata and logs — including recipient addresses — are stored in the United States. Automatic translation of organiser-published content (descriptions, schedule, announcements) is performed by Cloudflare (Workers AI): that text may incidentally contain personal data, such as teachers' names. Processing takes place on Cloudflare's global network, and Cloudflare does not publish the location of its inference servers; Cloudflare states that it does not use customer content to train models. These providers likewise act as processors under Art. 28 GDPR.
For festival registration payments we rely on Stripe (Stripe Payments Europe, Ltd., Ireland, with Stripe, Inc. in the United States). Stripe processes the dancer's payment data and — for organizers who charge for passes in the app — the identity and tax data required for the anti-money-laundering (KYC) checks on their account. We use Standard connected accounts with direct charges: with respect to the payment, the organizer, not Hepcat, is the controller toward Stripe and responsible for the transaction; Hepcat only receives the outcome. Stripe acts as an independent processor/controller under its own privacy policy.
When you register for a festival through the App, that event's organizer sees your name, your username, the dance role you declared, the pass you chose and the status of your registration — not your email, your contacts or your friendships. The organizer can also add their own questions to the registration (for example dance level, T-shirt size, dietary needs, housing requests, membership number, consent to the code of conduct or to photography): your answers are visible to them and serve the running of the event. With respect to this data the organizer is an independent controller. Questions only allow short answers, predefined choices or checkboxes: attaching documents or uploading files is not possible. Answers that reveal special category data (Art. 9 GDPR) — such as health-related dietary needs — are optional and are processed on the basis of your explicit consent, which you may withhold without losing your registration.
Any transfers to third countries rely on Standard Contractual Clauses or adequacy decisions (including the EU-U.S. Data Privacy Framework, where applicable). Your data is never sold or shared with third parties for marketing purposes.
We apply appropriate technical measures (Art. 32 GDPR): data is transmitted over encrypted connections (TLS/HTTPS) and stored encrypted at rest by the infrastructure. Chat messages are not end-to-end encrypted: they remain accessible to the controller for security, moderation and notification delivery purposes.
V. Who can see your content
- Board announcements and social activity are visible only to your accepted friends.
- Chat messages and photos are visible only to the members of the trip group.
- Your profile (name, username, photo, dance styles) is visible to other registered users of the App.
- To festival staff, at the door: whoever runs check-in with the App sees your name, the pass type you bought and — if the organiser has declared them necessary at entry — some of the answers you gave in the registration form (for example your t-shirt size, if the pass includes one). No other answer leaves the organiser: the choice is made question by question, it is off by default, and staff have no access to the list of registrants — they see one person at a time, and only after scanning that person's code.
VI. Retention and deletion
Data is kept for as long as your account is active. You can delete your account at any time from the App (Profile → menu → Delete account): your profile, friendships, announcements, photos and all other personal data are permanently deleted. Messages already sent in group chats remain visible to other members but are anonymised (no author).
VII. Your rights
Under Arts. 15–22 GDPR you may exercise your rights of access, rectification, erasure, restriction, portability and objection by writing to the email address above. You also have the right to lodge a complaint with your supervisory authority (in Italy, the Garante: garanteprivacy.it).
VIII. Minimum age
The App is intended for users aged 14 or older, the digital consent age in Italy under Legislative Decree 101/2018.
IX. Changes
Material changes to this notice will be communicated through the App. The current version is always available on this page.