Collective

Privacy

Privacy notice

Last updated 10 July 2026.

1 · Who controls the data

Open Collective, operated from Ibiza, Spain, is the data controller for personal data processed through this platform (formal legal-entity details will be published here upon completion of incorporation). For privacy questions and to exercise any right described below, contact hello@example.com. A dedicated data-protection officer has not been appointed at this stage; the same address reaches the person responsible for data protection.

2 · What we collect

Depending on the flow: name, email, phone or WhatsApp, birthday, optional Instagram/social links, application answers, profile copy and photo, RSVP notes, dietary or allergy notes, stay-window details, internal admin notes, message delivery logs, and technical logs needed to run the service. Passwords are stored only as hashes. We do not run analytics or advertising trackers.

3 · Why we use it — and the legal basis

Under the GDPR (and UK GDPR), each use of your data rests on a legal basis:

Applications, screening calls, membership

Contract — Art. 6(1)(b)

Stays, events, RSVPs, waiting lists

Contract — Art. 6(1)(b)

Profile shown to other members

Consent — Art. 6(1)(a), given at onboarding

Dietary & allergy notes (health data)

Explicit consent — Art. 9(2)(a)

Birthday (greetings, house rituals)

Legitimate interest — Art. 6(1)(f)

Service emails & operational records

Legitimate interest — Art. 6(1)(f)

Safety, legal, and accounting records

Legal obligation — Art. 6(1)(c)

Where a use rests on consent you can withdraw it at any time — withdrawal doesn't affect what happened before. Public-event RSVP consent is recorded with the RSVP.

4 · Dietary and allergy information

Allergy and dietary notes are health data. You choose whether to share them; they are used only to keep you safe and fed at stays and events, visible only to operators and the staff who need them (kitchen, safety), never shown in the member directory, and deleted or anonymised when no longer needed for upcoming gatherings.

5 · Cookies

The platform uses only strictly necessary cookies: session cookies that keep you signed in and security cookies that protect forms. No analytics, advertising, or cross-site tracking cookies are set — which is why there is no cookie banner. If that ever changes, we will ask for consent first.

6 · Who can see it, and who processes it

Operators see operational records. Members see member-visible profile copy after onboarding. Guest RSVPs and private contact details are not shown in the member directory. Infrastructure is provided by processors under data-processing agreements (GDPR Art. 28), currently: Vercel (hosting), Supabase (database and storage), Resend (email delivery), and Google (Firebase phone verification and — where an operator connects it — Google Calendar scheduling). Villa owners and staff receive only what a specific stay or event requires.

7 · International transfers

Data is hosted in the EU where the provider offers it. Some providers are US-based; transfers to them rely on the EU–US Data Privacy Framework or Standard Contractual Clauses. You can request a copy of the relevant safeguards via the contact address.

8 · How long we keep it

Account & profile

Duration of membership + 2 years

Applications (not approved)

2 years from decision

Booking & stay records

7 years (tax and accounting)

Dietary / allergy notes

While relevant to upcoming stays, then removed

Email delivery logs

3 years (dispute resolution)

Guest-list RSVPs

2 years from the event

When a period ends we delete or anonymise. You can request earlier deletion at any time (see rights below).

9 · Your rights (EU/EEA & UK)

You may request access, rectification, erasure, restriction, portability (machine-readable export), object to legitimate-interest processing, and withdraw consent. Write to hello@example.com; we verify identity against the account details we hold, respond within one month (extendable by two for complex requests, with notice), and charge nothing unless a request is manifestly unfounded or excessive. You may also complain to a supervisory authority — in Spain the AEPD (aepd.es); in the UK the ICO (ico.org.uk).

10 · California and other US state rights

If you are a California resident, the CCPA/CPRA gives you the right to know what personal information we collect (sections 2–3 above), to access and correct it, to delete it, to limit use of sensitive personal information, and to not be discriminated against for exercising these rights. We do not sell personal information and do not share it for cross-context behavioral advertising — there is nothing to opt out of. Residents of Virginia, Colorado, Connecticut, Utah, and other states with comparable laws have equivalent access, correction, deletion, and portability rights, and may appeal a refusal by replying to our decision. Exercise any of these via hello@example.com; an authorised agent may act for you with written permission.

11 · No automated decisions

Membership, screening, and stay decisions are made by people — the founding circle — not by automated profiling. Waiting lists are handled personally, in order and in context.

12 · Children

The service is not directed at anyone under 18. We do not knowingly collect children's data; if we learn we hold any, we delete it. Parents or guardians can contact us at the address above.

13 · Security and breaches

We use authenticated operator access, server-side validation, password hashing, logged email delivery, and private admin tools. No online system is risk-free. If a breach is likely to put your rights at risk, we will notify you without undue delay and cooperate with the supervisory authority (GDPR Arts. 33–34).

14 · Changes and contact

We will update this notice as the Collective evolves; the date above always reflects the current version. For privacy questions or to exercise your rights, write to hello@example.com.