Legal
Privacy Policy
Last updated: 2026-10-09. This notice covers pre-registration, private beta, and features available after launch.
1. Who is responsible
Operator identification is incomplete. HurryHome is the service name, not an identified legal entity. The operator must publish their verified legal identity and contact details before collecting public registrations. Free pre-registration does not remove this requirement.
For privacy requests, contact [email protected].
2. Information we process
| Category | Information and use |
|---|---|
| Account and pre-registration | Email, password hash, preferred contact name, registration date, Terms acceptance, access status, and any first-50 offer reservation or redemption. No document or payment is required to pre-register. |
| Student eligibility | Stated name for comparison, study/graduation dates, verification outcome, expiry, and a temporary document for authorised human review. The comparison last name is cleared after the decision. Do not upload unnecessary identity numbers or unrelated sensitive information. |
| Housing search | Search centre and coordinates, radius, budget, dates, property preferences, occupancy, student requirements, and optional commute destination/modes. These determine matches, not credit or tenancy decisions. |
| Matches and alerts | Results, saved/interested/applied/hidden state, notifications, delivery records, preferences, optional Discord identifiers, and browser push subscriptions. |
| Community | Posts, titles, tags, text, links, category fields, images, comments, votes, saves, reports, moderation outcomes, and timestamps. Published hub contributions are visible to other members; a private profile does not make those contributions private. |
| Social profiles | Handle, chosen display name, bio, optional city, avatar/banner, visibility choices, follows, requests, and blocks. Private profiles still have a discoverable handle, bio, avatar and banner preview. Restricted activity requires the relevant permission or an approved follow. |
| Private messages | Self-hosted Matrix stores encrypted events and metadata: opaque account/device identifiers, room membership, timestamps, and read/unread state. Encryption keys and decrypted text are handled in your browser. Remaining metadata is not anonymous. |
| Support, billing and security | Support requests, reports, Stripe references when billing is enabled, security events, relevant IP addresses, and operational logs. HurryHome does not store full payment card details. |
| Contact form | Your email, optional name, selected topic, and message are forwarded to [email protected] so the team can respond. Form submissions are not saved in the application database. Do not send passwords, payment details, or identity documents. |
3. Purposes and lawful bases
The intended bases below require the operator's documented assessment; this draft is not a certification of legal compliance.
- Providing your requested service (Article 6(1)(b)): account/pre-registration administration, offer reservations, eligibility checks, matching, community, social relationships, requested messaging, and subscription administration where necessary for that service.
- Your consent (Article 6(1)(a)): optional external listing alerts through enabled channels. Withdraw this in Alerts & delivery, disconnect Discord, or revoke browser push. Account-security and requested password-reset emails are service communications, not marketing consent.
- Legitimate interests (Article 6(1)(f)): proportionate security, moderation, abuse/fraud prevention and troubleshooting, subject to a documented necessity and rights-balancing assessment. You can object.
- Legal obligations (Article 6(1)(c)): records or disclosures required by identified accounting, tax, privacy or other obligations, not an indefinite blanket exemption.
Matching uses your stated filters. Automated moderation can flag or block unsafe content. Enabled Ollama moderation receives post/comment content, not private-message plaintext. Contact support for review of a disputed eligibility or moderation decision. Do not post other people's confidential or sensitive data.
4. Recipients and transfers
We do not sell personal data. Recipients depend on the feature used:
- Netcup: VPS hosting of the application, databases, uploaded files and backups. Self-hosted Matrix, routing and moderation run within the configured hosting environment.
- Cloudflare: DNS, proxy/tunnel, security and Turnstile where enabled. It processes connection/request data and IP addresses and can process HTTP content at the proxy boundary. Matrix message content is already encrypted in the browser.
- Email: Google (Gmail SMTP) handles recipients and outgoing service emails and enabled alerts. Cloudflare DNS for an email domain does not itself identify the outbound provider.
- Contact enquiries: the outgoing email provider delivers the message to [email protected]; Cloudflare Email Routing forwards it to the monitored support inbox. Your address is included as Reply-To, not used for marketing.
- Discord and browser push services: when enabled, Discord handles requested alerts and your browser/platform's push service handles subscription identifiers and delivery. Delivered copies may remain in those services or on recipient devices.
- Stripe: payments and billing when enabled. It can also act in its own legal role for payment, fraud and regulatory obligations.
- Geographic services: address queries can be sent to the Dutch PDOK location service. Street-map tiles are requested through HurryHome's proxy from OpenFreeMap; tile coordinates identify the viewed area without forwarding your account cookie. Google commute routing is not currently configured; self-hosted routing is used when available.
- Other members: receive the profile information, published content or encrypted messages you share according to access rules.
Some providers may process data outside the EEA. The operator must verify provider terms, subprocessors and applicable transfer safeguards, such as adequacy decisions or Standard Contractual Clauses with any necessary supplementary measures. Details can be requested from the privacy contact. Processor agreements and transfer assessments are not yet represented as verified for this beta.
5. Retention and deletion
Most account-linked records remain while the account exists. Delete your account in Privacy & data or request erasure from the privacy contact. A subscription or a settings cooldown does not remove statutory privacy rights; billing-related erasure, correction, restriction and objections can also be requested through that contact.
Account erasure removes live account records and uploaded files, replaces authored posts/comments with deleted placeholders, removes copied native room listings, and clears linked notification copies. Other people's replies can remain. Matrix deactivates/erases your identity, but shared encrypted room history and previously received copies cannot necessarily be recalled.
Reviewed verification files expire after 7 days plus the next daily cleanup. Pending files await review or withdrawal; a maximum pending-review period still needs to be established. Minimal outcome and eligibility dates remain for the account lifecycle.
Security audit records normally expire after 90 days plus the next daily maintenance run. Incident evidence may require separately justified, restricted retention. Operational container logs are size-rotated; a time-based maximum remains under review.
Encrypted backups include databases and uploaded files, so deleted files may remain in an older backup. Rotation targets 30 days; legacy archives and retention are still being reviewed. Private random erasure markers are kept for 37 days to reapply deletions before restored data is served. Older archives must not be restored without reconciling later erasures.
Disabling delivery stops future alerts but does not immediately erase every delivery or inactive device record. Contact us for the relevant erasure request. Recipients such as Stripe may keep records for their own identified legal purposes.
Contact-form messages are forwarded rather than stored in the application database. Copies can remain in mail-provider systems and support correspondence. Inbox retention must be managed by the operator, and relevant correspondence can be requested for access or erasure through the published contact.
6. Cookies and browser storage
The application uses an essential signed session cookie and form CSRF tokens. Before login, an essential random security cookie binds forms to your browser for up to eight hours; it contains no account information and is not used for advertising. Functional local storage remembers theme/device settings; messaging uses browser storage, including IndexedDB, for encryption/device state. A service worker caches application assets. Clearing messaging storage may make older messages unreadable without usable key recovery.
The application does not intentionally add advertising trackers. Cloudflare security features and dashboard-enabled analytics need separate assessment. Tracking or storage requiring consent must not run before that consent; strictly necessary storage does not require a tracking-consent banner.
7. Your rights
Subject to applicable conditions, you can request access, correction, erasure, restriction, portability, or object to processing, and withdraw consent without affecting earlier lawful processing. The Privacy & data JSON export includes account/search records, social relationships and your authored community activity. Document/media copies, relevant security records and separately held Matrix data may need an additional request. The server cannot supply browser-only decryption keys or plaintext history.
Send requests to [email protected]. Responses are normally due within one month. A permitted extension of up to two further months requires an explanation within the first month. Identity checks must be proportionate; an unredacted identity document is not routinely required.
You may complain to the Dutch Autoriteit Persoonsgegevens or your competent supervisory authority.
8. Security and changes
Passwords are hashed, sessions are signed, private uploads are access-controlled, and the public deployment uses HTTPS with private backend services. These controls reduce risk, not eliminate it. The update date changes when this notice changes; significant changes will be communicated as appropriate.