Skip to main content
Urban Gather

Privacy Policy

This Policy explains how personal data is processed when you use UrbanGather, attend or organize events, volunteer, or contact support.

Document version
Version 2026-08-17
Effective date
Effective August 17, 2026
Document owner
Document owner: UrbanGather Platform Operations

1. Scope and responsibility

This Policy applies to the UrbanGather web platform, accounts, public pages, events, registrations, tickets, reviews, volunteer features, recommendations, notifications, and support.

UrbanGather controls data used to operate the platform, security, accounts, recommendations, and support. An organizer receives only permitted attendee data for their own event and is independently responsible for any further collection or use outside UrbanGather.

2. Data we process

We collect data you provide, records of your actions in the service, and the minimum technical data needed for safe operation. We do not sell personal data or use advertising trackers in the current version.

For password recovery, we process the normalized email, keyed digests of the email and one-time code, a technical operation identifier, issue/expiry times, failed-verification count, and security outcome. The eight-digit code is valid for 10 minutes and becomes invalid after successful use; the address and code are stored only in encrypted delivery queues and are wiped from the Identity outbox when delivery reaches a terminal state.

  • Account data: email, cryptographic password hash, role, name, username, optional profile and contact fields, avatar, language, and settings.
  • Participation data: saved events, followed organizers, interest categories, recommendation signals, registrations, waitlist status, optional attendee note, tickets, check-ins, and reviews.
  • Organizer and volunteer data: events, locations, images, translations, applications, skills, availability, statuses, and related audit records.
  • Support data: name, reply email, category, message, consent, policy version, technical operation identifier, and privacy-safe abuse-prevention signals.
  • Technical data: session cookie, locale cookie, locally stored theme preference, request times and outcomes, bounded security logs, and pseudonymous rate-limit keys.
  • Browser geolocation: only after your explicit permission to show a current map position, plan a route, or choose venue coordinates. It is sent onward only at your direction, such as when opening an external route.

3. Why we use data

Data is used only for specified and compatible purposes needed to provide and protect UrbanGather.

  • Creating and protecting accounts, authentication, role management, and session management.
  • Event discovery, recommendation personalization, preference storage, and interface localization.
  • Registration, waitlists, ticket issuance and verification, check-in, reviews, and volunteer applications.
  • Providing organizer and admin tools within role and ownership boundaries, moderating content, and handling support cases.
  • Detecting fraud and abuse, rate limiting, auditing critical operations, diagnosing incidents, and restoring service.
  • Complying with law, protecting users’ rights, and resolving disputes.

4. Legal bases

Depending on the feature, we process data to perform the Terms of Use and provide a requested service, with your consent, to meet a legal obligation, or for legitimate interests in security, abuse prevention, and service improvement. Legitimate interests apply only when they are not overridden by your rights.

You may withdraw consent for future processing. Withdrawal does not make earlier processing unlawful and may limit a feature that objectively requires the data.

5. Public visibility and organizer access

Published events, locations, organizer profiles, images, and public reviews are visible to others and may be indexed by search engines. Draft translations, private account pages, applications, tickets, and support cases are not public.

An organizer can view bounded registration records for their own events, including status and a voluntary attendee note, only to administer the event. Do not place sensitive data or another person’s personal data in the note unless it is necessary.

6. Who may receive data

Access follows least-privilege rules. We do not share data for sale or independent targeted advertising.

  • Organizers receive only attendee data and aggregates needed to register, communicate with, and host participants in their events.
  • Authorized administrators and support staff receive access for moderation, security, account operations, and support-case handling.
  • Infrastructure, hosting, storage, or future delivery providers receive data only under contract, on UrbanGather’s instructions, and after the relevant capability is activated.
  • Authorities or other parties may receive data when required by law, a valid request, or the need to protect rights, safety, and platform integrity.
  • At your direction, control may pass to an external map, Telegram, or another third-party service; its own policy governs subsequent processing.

7. Cookies and local storage

The current UrbanGather version uses only necessary technologies: an HttpOnly session cookie for sign-in, a locale cookie for routing, and localStorage for theme selection. The session cookie lasts up to 30 days and the locale cookie up to one year. Disabling necessary cookies may prevent sign-in or language persistence.

The current version does not use advertising pixels or cross-site tracking. If optional analytics or advertising is introduced, this Policy and cookie-choice controls will be updated before activation.

8. Retention and deletion

We retain data no longer than needed for its feature, security, proof of operations, and legal requirements. Deletion may be logical or physical depending on the domain contract, backups, and unresolved disputes.

  • A support case and its personal data are retained for up to 365 days; PII is then deleted while a minimal non-personal audit record may remain.
  • A session cookie lasts up to 30 days or until sign-out or revocation; security keys and command evidence remain only within bounded operational retention.
  • Inbox notifications follow bounded Notification configuration; the current default is up to 400 days. Temporary payloads are removed sooner after delivery or terminal failure.
  • Account, profile, and settings data remain while the account is active or are needed for security and contract performance; deactivation ends access but does not instantly erase every domain record.
  • Registrations, tickets, check-ins, reviews, organizer and volunteer records, and audit evidence remain as needed for the event, record integrity, disputes, and legal duties, and are then deleted or de-identified.
  • Files are removed after all permitted references end and the protected cleanup process completes.

9. Security

UrbanGather uses role-based and owner-scoped access, HttpOnly cookies, cryptographic password hashes, signed internal requests, least-privilege database roles, request size and rate limits, critical-command audit, and private caching. Raw passwords, session tokens, and recovery tokens must not enter logs or public responses.

No system can guarantee absolute security. Users are responsible for a unique password, control of their device, and promptly reporting suspicious access.

10. Your rights and choices

Subject to applicable law, you may request information about processing, access or a copy, correction, deletion, restriction, objection, data portability, and withdrawal of consent. You may also complain to the Ukrainian Parliament Commissioner for Human Rights or another competent supervisory authority.

We may refuse or limit a request if we cannot safely verify identity, it harms another person’s rights, conflicts with law, or the data is required to protect rights or record integrity. We will explain the reason where legally permitted.

11. Minors and international processing

UrbanGather is not intended for independent use by a person who lacks legal capacity to accept these Terms. A minor must act with a legal representative’s involvement and consent where required by law or the event’s conditions.

Infrastructure or providers may process data in other countries. Contractual, technical, and organizational safeguards required by Ukrainian law and, where applicable, the GDPR apply to such transfers.

12. Policy changes and contact

We update the date and version when this Policy changes. Material changes affecting rights or introducing new processing purposes will receive prominent notice before taking effect, and fresh consent will be requested where required.

The official channel for privacy requests, complaints, and questions is the UrbanGather contact form. Platform Operations owns this Policy’s content; every revision must match actual data flows and service retention.

Questions, requests, and complaints

UrbanGather accepts requests for access, correction, deletion, restriction, objections, and complaints through the contact form. Include your case number for support-related requests when available. We may verify your identity without collecting excessive data before fulfilling a request.