Privacy Policy
Last updated: 16 July 2026
This policy explains what personal data Händer (“we”, “us”, the “Service”) collects when you use our Stockholm event-discovery service at vad-hander.com, why we collect it, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR) and applicable Swedish data-protection law.
1. Who is responsible for your data
The Service is operated by its two founders, who are establishing it as a business that is currently in the process of incorporation as a Swedish private limited company (aktiebolag). The registration application is in progress and the company is not yet registered.
Because the company is not yet formed, the two founders act as joint data controllers in their personal capacity for the purposes of Article 26 GDPR. Once incorporation is complete and the company is registered, the registered company will become the data controller and this policy will be updated to reflect its statutory name, organisation number and registered address. The change of controller will not reduce the protections described in this policy.
Contact for privacy matters: privacy@vad-hander.com. You can use this address for any question about this policy or to exercise the rights set out in Section 9.
2. Our commitment to protecting your data
We are an early-stage service and, as explained above, not yet an incorporated company. That early stage does not mean a lower standard of care. We hold ourselves to the same data-protection principles expected of a large, established organisation, and we have built those principles into how the Service works rather than bolting them on afterwards:
- Data minimisation. We collect only what the Service actually needs — your account details and the preferences that power event recommendations. We do not collect data we have no use for.
- Your personal data is stored in the EU — in Stockholm. Your account, profile and activity data are held within the European Union, in the Stockholm (Sweden) region, through our database provider (Supabase), inside the scope of the GDPR.
- Analytics never contain personal identifiers. Our usage analytics measure how the Service is used in aggregate only. We never send your name, email address or account identifier to any analytics tool — only coarse, non-identifying attributes — and only after you have given consent.
- Consent-first by default. No non-essential cookies or analytics run until you actively accept them. Using Google Consent Mode, everything non-essential is denied by default for every visitor, in the EEA and everywhere else.
- Security enforced at the database, not just the perimeter. Access to your data is enforced at the database row level (row-level security), so one user can never read another user’s records. Data is encrypted in transit (HTTPS) and at rest, and passwords are salted and hashed by our authentication provider — we never see or store them in plain text.
- We never sell your data. We do not sell personal data, and we never share individual user records or email addresses with third parties for their own purposes.
- You stay in control. You can withdraw analytics consent at any time, and you can ask us to access, correct or delete your data — handled within 30 days (see Sections 8 and 9).
3. The data we collect
Account and profile data
When you create an account we collect the information you provide: your first name, last name, email address, and a password (stored only in hashed form by our authentication provider — we never see or store it in plain text). During sign-up you may optionally tell us your age range, gender, neighbourhood, and whether you prefer events solo or with friends. We use this to personalise the events we show you.
Your activity in the app
To power our event recommendations we record which events you mark as “interested” or “not interested.” These signals are used to match you to events you are likely to enjoy. We do not use this data to identify you to any third party.
Usage and analytics data (only with your consent)
If you accept analytics cookies, we collect information about how you use the Service — for example which pages, filters and events you view — together with standard technical data such as your browser type, device, and an approximate location derived from your IP address. This is collected through Google Analytics 4 (see Section 6). None of this is collected until you give consent, it never includes your name, email or account identifier, and you can withdraw consent at any time.
4. Cookies and similar technologies
We use a small number of cookies and browser-storage entries. You control the non-essential ones through our cookie banner.
| Type | Purpose | Consent needed? |
|---|---|---|
| Strictly necessary | Keep you signed in (authentication session) and remember your cookie choice. | No — exempt under the ePrivacy rules |
Analytics (e.g. _ga, _ga_*) |
Help us understand how the Service is used so we can improve it. | Yes — set only after you accept |
You can review or change your choice at any time:
5. Why we use your data and our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Creating and running your account; providing the Service | Performance of a contract (Art. 6(1)(b)) |
| Personalised event recommendations | Performance of a contract / our legitimate interest in providing a useful service (Art. 6(1)(b)/(f)) |
| Analytics cookies and usage measurement | Your consent (Art. 6(1)(a)) and the ePrivacy rules |
| Security, fraud prevention and keeping the Service working | Our legitimate interest (Art. 6(1)(f)) |
6. Who we share data with
We do not sell your personal data and we never share individual user records or email addresses with third parties for their own marketing. We use the following service providers (“processors”) to run the Service. Each processes data on our instructions under a data processing agreement.
| Provider | Role | Notes |
|---|---|---|
| Supabase | Database, authentication and backend hosting | Stores your account, profile and activity data, within the European Union (Stockholm, Sweden region). |
| Netlify | Hosting / delivery of the website | Processes technical request data (e.g. IP) to serve the site. |
| Google (Tag Manager & Analytics 4) | Tag management and analytics | Analytics only, after consent, and without personal identifiers. May involve transfer to the USA. |
| MapTiler | Map tiles and geocoding | Processes technical request data to render maps. |
| Google Fonts & jsDelivr (CDN) | Delivery of fonts and code libraries | May log your IP address as part of serving these assets. |
7. Transfers outside the EEA
Your account, profile and activity data are stored within the EU/EEA (Stockholm, Sweden). Some of our supporting providers (notably Google, for consented analytics) may process certain data in the United States. Where that happens, the transfer is protected by an appropriate legal mechanism such as the EU–US Data Privacy Framework and/or the European Commission’s Standard Contractual Clauses.
8. How long we keep your data
We keep your account and profile data for as long as your account exists. If you ask us to delete your account, we remove your personal data within 30 days of the request. Consented analytics data is retained in line with the retention period configured in Google Analytics 4 (up to 14 months).
9. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased (“right to be forgotten”);
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw consent for analytics at any time (via Cookie settings) — this does not affect processing done before you withdrew it.
To exercise any of these, contact us at privacy@vad-hander.com.
You also have the right to lodge a complaint with the Swedish supervisory authority, the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), at imy.se.
10. Children
The Service is not directed at children under 13, and we do not knowingly collect the personal data of children under that age.
11. Changes to this policy
We may update this policy from time to time. When we make material changes we will update the “Last updated” date above and, where appropriate, notify you in the app.