Privacy policy
Last updated 6 July 2026
GetTAGether is a meetup space for women, built with privacy as a founding principle. This policy describes what personal data we process, why, and the rights you have under the GDPR.
The essentials: your tags are always private and are never
shown to anyone else — not even the person you tagged. We never sell your data.
Everything is stored within the EU.
Data controller
GetTAGether, Stockholm. Contact: support@gettagether.se.
Data we process
- Account: phone number (sign-in by SMS code), first name, date of birth (your age is shown on your profile), postcode (determines your district — no exact address is stored), optional email address (alternative sign-in).
- Profile: profile photo, bio, and the attributes you choose to show. Photos are always stripped of location data (EXIF) before being stored.
- Private tags: the labels you put on other members. They are visible only to you, are used only to target your invites, and the tagged person never learns which tag invited her.
- Events and messages: events you create or respond to, event album photos (visible only to the guest list), chat and direct messages.
- Verification (optional): a selfie reviewed by a moderator and deleted immediately at decision (at most after 30 days). Only the outcome is kept.
- Contact matching (optional): if you choose to find friends through your contact list, phone numbers (never names) are sent to the server, matched against existing members, and immediately discarded — the numbers are never stored. Only the count of submitted numbers is logged, as abuse protection. Members who have paused their visibility are never matched.
- Technical: push notification tokens and IP addresses (used to protect the service from abuse, such as SMS bombing).
- Launch list: if you sign up on gettagether.se, your email is stored only for the launch notice and deleted afterwards.
Legal bases
- Contract — providing the service (account, events, messages).
- Legitimate interest — security, abuse protection, and moderation.
- Consent — optional verification and the launch list. You can withdraw at any time.
Who we share with
We never sell personal data and show no advertising. We use the following processors to run the service:
- Hetzner (hosting, EU) — all storage.
- 46elks (Sweden) — SMS code delivery.
- one.com — email code delivery.
- Google — place search when you pick an event location (only the search text is sent).
- Apple and Google — push notifications to your device.
Beyond that, data is disclosed only where the law requires it.
Retention
- Account data is kept until you delete your account. On deletion the account is hidden immediately and permanently anonymized after 14 days (the grace period — sign in again to restore it).
- Backups rotate within 14 days.
- Verification selfies are deleted at decision, at most after 30 days.
Your rights
- Access and export: download all your data directly in the app (Profile → Download my data).
- Rectification: edit your details yourself in your profile.
- Erasure: delete your account directly in the app.
- Objection and restriction: contact us and we'll help.
- Complaints: you can always contact the Swedish Authority for Privacy Protection (imy.se).
Changes
If this policy changes materially, we'll notify you in the app before the change takes effect.