Who we are
datezero operates this service from Helsinki, Finland. For privacy questions or requests, email hello@datezero.io.
A host decides why an event is run and who may attend. For attendee data used to deliver that event, the host is normally the controller and datezero processes the data on the host's instructions. datezero is independently responsible for customer and host accounts, pack entitlements, service security, reliability, and its own legal obligations.
Data we process
Hosts
A prospective host application includes the applicant's name, email address, city or community, relevant hosting or community background, and description of the event they want to create. We store the review status, reviewer, timing, and a private decision note so access can be granted consistently and audited.
We receive the account identifier, email address, and basic profile information needed for host sign-in from Google and Supabase Auth. We also store event titles, start times, capacity, status, selected experience configuration, and operational audit records.
Customers
A customer may create an optional account to keep purchased or granted conversation packs in the My packs section of Account. We receive the account identifier, email address, and basic profile information needed for Google or email sign-in. A customer may add an optional display name. We store the stable Pack licensed to the account, the exact version recorded when access was granted, its entitlement status, source and audit reference, and grant or revocation timestamps.
When paid checkout is enabled, Stripe collects payment details on its hosted checkout page. datezero creates the records needed to prepare, fulfil, and reconcile the purchase, including the checkout and provider identifiers, amount, currency, tax, consent and legal- document versions, immutable order confirmation, acquisition grants, refunds, disputes, and withdrawal requests. datezero does not receive or store the full payment-card number or security code.
Attendees
Attendees do not create accounts and do not provide an email address. For each event we store a display name, self-described gender, join and activity timestamps, event status, and an opaque guest identifier. Gender is used only for gender-aware group balancing. Events with private matching also require your phone number and a name unique within that event. Phone numbers are supplied by attendees and are not verified. We check their format, store them encrypted, and record which phone-use notice was shown. Joining does not enable private matching. If you choose to send a like, we separately record your matching consent and private selections.
Venue context and event feedback
After joining, attendees give two required yes-or-no venue-context answers: whether they came specifically for the datezero event and whether it is their first visit to the venue. When the guided journeys finish, attendees give four required multiple-choice outboarding answers about return intent, instruction clarity, social comfort, and connection intent. They may also leave one optional note of up to 240 characters. We do not ask who an attendee connected with, or ask for a name or contact details in either response flow.
Venue context and outboarding feedback are stored in separate event-level response streams without a guest identifier. Each stream uses a separate one-time claim so the same guest session cannot submit twice; the one-time claims and answer rows are not linked to each other. We do not promise that these responses are anonymous: timing or optional text could make a response recognizable.
Sessions and operations
Guest session tokens are stored as one-way hashes. Strictly necessary session cookies keep a customer or host signed in or let an attendee resume the same event. Security and reliability systems may process route names, status codes, timings, and aggregate counts; names, emails, gender, tokens, request bodies, and user identifiers are removed before external error-monitoring events are stored.
During outboarding, the browser may keep completed answers, the optional note, and a submitted or technical-failure status in session storage for up to eight hours. This bounded local state is separated by an opaque server-derived session namespace and contains no raw guest ID, session token, name, selected person, or contact detail. The namespace is never accepted as authentication, and the local state expires with the session window.
Why we use data
We process personal data only to:
- authenticate customers and restore their licensed packs in Account across browsers;
- deliver the current reviewed version of only the Packs an account is licensed to play;
- authenticate hosts and protect host-only event controls;
- review prospective hosts and grant workspace access only after approval;
- let attendees join, resume, and participate in one specific event;
- build and rotate balanced groups during the guided experience;
- enforce capacity, repair reconnects, and keep live state authoritative;
- use venue context and outboarding feedback to improve the event, explain instructions more clearly, and understand venue visits;
- collect attendee-supplied phone numbers and exchange contact details for mutual likes at matching events;
- prevent abuse, investigate failures, and secure the service; and
- meet legal, accounting, and incident-response obligations.
Customer-account, entitlement, and host-account processing is necessary to provide Account, owned-pack play, and host services requested by the user. Security and reliability processing is based on datezero's legitimate interests in operating a safe, dependable service. Event attendee processing follows the host's documented purpose and lawful basis. We do not use event data for advertising, sell it, or build attendee marketing profiles.
Private matching uses your explicit consent, requested once per event when you first choose “Agree & like”. Choosing “Not now” saves no like or matching consent and you can continue playing. Entering your phone number supports the event's contact exchange facility; it is not recorded as permission to share your number. Your likes are visible only to you. You may remove them until the host ends the event. Only reciprocal likes exchange names and the phone numbers entered by SMS. Match results are not shown in the app. A number already sent cannot be recalled or erased from another person's device by datezero.
Automated grouping
datezero uses attendee gender and current participation state to place people into balanced small groups and rotate those groups through an event. This automation does not make legal, employment, credit, eligibility, or similarly significant decisions. The host controls the event, and an attendee may leave at any time.
Providers and processing regions
Core event data is stored and processed in the European Union. Supabase provides EU database and authentication services. Hetzner infrastructure in Finland runs the web, live engine, and temporary Valkey state through Coolify. If error monitoring is enabled, Sentry's Germany ingest region receives only scrubbed operational metadata.
Google processes customer or host sign-in information under its own privacy terms. Attendee names, gender, group assignments, and event sessions are not sent to Google. We do not use advertising networks or third-party analytics in the MVP.
When paid checkout is enabled, Stripe processes the customer's payment information and returns payment, tax, refund, and dispute status needed to fulfil the exact purchase and maintain accounting and support records.
When matching SMS is enabled, 46elks and the receiving mobile operators process the phone numbers and message content needed to deliver mutual-match texts. We request that message text is not stored in the provider's message history. Provider and carrier processing, including any required traffic-record retention, is separate from deletion in datezero and must be configured for the approved event deployment.
How long we keep data
- Matching phone numbers are deleted from the application after the SMS handoff finishes, or within one hour after the event ends if sending cannot complete. An automated cleanup runs every minute. If an event never ends, matching contact data expires within 24 hours of matching onboarding starting. Existing database backups and carrier records follow their separate retention periods.
- Attendee display names and gender are automatically purged 24 hours after an event is finished or cancelled.
- Guest sessions expire and can be revoked; only token hashes are stored in the database.
- Venue-context and feedback one-time claims are deleted when attendee display names and gender are purged.
- Venue-context and feedback responses, including the optional note, are automatically deleted 90 days after submission.
- Temporary live state has bounded expiry and is removed after the event lifecycle.
- Pending, approved, and declined host applications are kept while the host network is being operated and then only as long as needed for review history, security, or legal obligations. An applicant may ask us to delete an application unless we must retain it.
- Host accounts and host-created event records remain while the host service is active, then only as long as needed for closure, security, or legal obligations.
- Customer profiles and owned-pack access remain while the customer account is active. Pack-license, version-at-grant, and support records are retained only as needed to provide access, resolve disputes, prevent fraud, or meet legal and accounting obligations.
- Scrubbed operational records are retained only for the configured security and incident- response period.
Your rights
Depending on the circumstances, you may ask for access, correction, deletion, restriction, or portability of your personal data, or object to processing based on legitimate interests. Where processing relies on consent, consent can be withdrawn at any time without affecting earlier lawful processing.
Send a request to hello@datezero.io. We may need to verify your identity and coordinate attendee requests with the event host. You may also complain to the Finnish Data Protection Ombudsman or your local supervisory authority.
Changes to this notice
We will update this notice when the service, providers, or data practices materially change. The effective date at the top identifies the current version.