gadr.ing

Privacy policy

gadr.ing is a private event-coordination tool — the link is the invitation. This policy explains, in plain language, what personal data we collect, why, who we share it with, and the rights you have. It is honest and maps to what the product actually does.

Who we are

gadr.ing is operated by Johannes Andersson, based in Sweden, who is the data controller for the personal data described here. We do not have a Data Protection Officer — we are a small operation and one is not required at this scale. For anything in this policy, contact us at privacy@gadr.ing.

What we collect, and why

We only collect what we need to run the service. For each kind of data, the legal basis under the GDPR is noted in brackets.

  • Your account — your display name, email address, an optional profile photo, and your notification preferences. We use your email to sign you in (a one-time code, no password) and to send the messages you ask for. [Performance of our contract with you.]
  • Events and series you create — title, description, location, dates and times, cover image, and any questions you ask guests. A location is hidden from guests until they RSVP. [Performance of our contract with you.]
  • RSVPs — when you respond to an event, your name, your response, your optional email, and any answers to the organiser’s questions. You can respond without an account; if you do, a random token stored on your device lets you find and change your RSVP later. [Performance of our contract with you, and our legitimate interest in delivering the RSVP you asked to make.]
  • Comment-board notes — notes you post on an event’s private board are stored with your name and the time. [Performance of our contract with you.]
  • Push notifications — if you turn them on, your browser’s push subscription so we can deliver reminders and updates. [Your consent, which you can withdraw at any time by turning push off.]

Cookies and tracking

We use privacy-friendly, cookieless analytics to count page views and measure how quickly pages load. It uses no cookies, sets no persistent identifier, and never tracks you across other sites — so there is nothing to consent to and no tracking banner. We do not use advertising. The only cookies we set are strictly necessary: one that keeps you signed in after you log in, and one that remembers an anonymous guest’s device token so a returning guest can change their RSVP. These are required for the service you asked for and cannot be turned off without breaking it.

Who we share it with

We never sell, rent, or monetise your personal data, and we never use data you gave for one event to market unrelated events to you. We share data only with the service providers that make gadr.ing work, each acting on our instructions:

  • Infrastructure and hosting — running the app and securely storing its data, including your account, the events you create, and RSVPs.
  • Email delivery — sending transactional email such as your sign-in code, confirmations, and reminders.
  • Push delivery — delivering push notifications to your device, if you enable them.

Your event’s guest list is visible only to its organiser and any co-organisers — never to other guests beyond what the organiser chooses to show.

Sending data outside Europe

Some of these providers operate outside the European Economic Area, principally in the United States. Where your data is transferred outside the EEA, it is protected by appropriate safeguards — the European Commission’s Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

How long we keep it

We keep your data for as long as your account is active or as long as an event you are part of is live. When you delete your account, we anonymise rather than erase outright where a record must remain coherent for other people: we scrub your identifying details, remove pure personal data such as push subscriptions, and leave past events resolvable without your name. You can delete your account at any time from your privacy settings.

Your rights

Under the GDPR you have the right to access your data, correct it, erase it, restrict or object to how we use it, and receive a portable copy. You can withdraw consent for push notifications at any time. Where the processing is based on consent, withdrawing it does not affect what we did before.

You can export all of your data and delete your account yourself from your privacy settings. For anything else, email privacy@gadr.ing and we will help.

If you think we have handled your data wrongly, you have the right to complain to the Swedish Authority for Privacy Protection (IMY) — imy.se. We would rather you came to us first so we can put it right.

Automated decisions

We do not make any decisions about you by automated means, and we do not profile you.

Children

gadr.ing is not intended for children under 13. We do not knowingly collect data from them. If you believe a child has given us data, contact privacy@gadr.ing and we will remove it.

Administrative access

A site administrator may view limited account and event information, and may remove content or anonymise an account, where necessary for safety, moderation, or legal compliance. Administrators cannot see event locations unless a guest has already been granted access, and they cannot see payment or financial data (we hold none). Any administrative action on account data follows the same anonymisation process described in this policy — identifying details are scrubbed, not leaked.

Changes to this policy

If we change this policy we will update the date below, and for important changes we will let you know in the app. Continuing to use gadr.ing after a change means you accept the updated policy.