1. Introduction
This Privacy Policy explains how Meetup ("we," "us," or "our") collects, uses, discloses, and protects your information when you use our event coordination and scheduling platform ("Service"). We are committed to protecting your privacy and ensuring transparency about our data practices.
By using the Service, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the Service.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address — for authentication and communications
- Password — stored securely using industry-standard encryption (hashed, never in plain text)
- Display name — optional, shown to other event participants
- Profile photo — optional, stored securely in our cloud storage
- Third-party login data — if you sign in with a social login provider
2.2 Event and Participation Data
When you create or participate in events, we collect:
- Event details — titles, descriptions, locations, time slots, emojis
- Availability selections — your indicated availability for event time slots
- RSVP responses — your confirmation or decline of events
- Location data — physical addresses, place identifiers, and coordinates when you set event locations
- Custom content — invitation designs, uploaded logos, and event branding
- Event tool data — Secret Santa assignments, potluck signups, menu items, etc.
2.3 Calendar Data
When you connect calendar integrations, we access:
- Calendar events — titles, start/end times, and free/busy status for conflict checking
- Calendar names — to let you select which calendars to use
- OAuth tokens — stored securely to maintain calendar access
Important: Calendar event data is accessed in real-time for conflict detection and is not permanently stored on our servers. Only the connection tokens and your calendar preferences are stored.
2.4 Payment Information
When you subscribe to a paid plan:
- Payment details — processed entirely by our payment processor; we never see or store your full credit card number
- Customer identifiers — customer ID, subscription ID, and billing status
- Subscription metadata — plan type, billing interval, period dates
2.5 Automatically Collected Information
- Device information — browser type, operating system, device type
- Log data — IP address, pages visited, access times, referring URLs
- Usage analytics — feature usage, interactions, and navigation patterns
- Performance data — page load times and application metrics
2.6 Saved Contacts
When you send event invitations, we may save recipient email addresses and names to provide autocomplete suggestions for future invitations. This data is stored in your account and is not shared.
2.7 Chat and Messaging Data
When you use the event chat feature, we collect:
- Message content — the text of messages you send in event chats
- Message metadata — timestamps, edit history, and reply references
- Typing indicators — temporary signals showing when you're typing (not stored permanently)
- Moderation data — reports submitted for inappropriate content
Important: Chat messages are visible to all participants in the event. Event organizers have additional moderation capabilities including the ability to delete any message.
3. How We Use Your Information
We use collected information to:
- Provide the Service — create accounts, manage events, process availability, send confirmations
- Enable integrations — connect with calendars, video conferencing, and payment processing
- Send communications — verification emails, event notifications, RSVP confirmations, and invitations
- Process payments — manage subscriptions and billing through Stripe
- Improve the Service — analyze usage patterns, fix bugs, and enhance features
- Ensure security — detect fraud, enforce rate limits, and protect against abuse
- Comply with legal obligations — respond to lawful requests and enforce our terms
4. Information Sharing and Visibility
4.1 With Other Event Participants
When you participate in events, other participants can see:
- Your display name
- Your profile photo (if set)
- Your availability selections
- Your RSVP status
- Your event tool contributions (potluck signups, etc.)
4.2 With Event Creators
Event creators can additionally see:
- Email addresses of waitlisted users (if provided)
- Detailed attendance and response data
- Exported CSV data (Pro feature) including names, availability, and timestamps
4.3 With Third-Party Service Providers
We share information with trusted third-party service providers to operate the platform, including:
- Infrastructure providers — for authentication, database, storage, and hosting
- Payment processors — for secure payment and subscription management
- Email delivery services — for sending notifications, invitations, and transactional emails
- Calendar integration providers — for syncing with your calendar services
- Video conferencing services — for virtual meeting integrations
- Analytics providers — for understanding usage patterns and improving the Service
- Image providers — for invitation and event imagery
All third-party providers are contractually obligated to protect your data and use it only for the purposes specified.
4.4 Legal Requirements
We may disclose information if required by law, court order, or to:
- Comply with legal process
- Protect our rights, property, or safety
- Investigate potential violations of our terms
- Respond to lawful government requests
4.5 Business Transfers
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your data is subject to a different privacy policy.
5. Data Security
We implement robust security measures to protect your information:
- Encryption in transit — all data transmitted using HTTPS/TLS
- Encryption at rest — data stored in our database is encrypted at rest using industry-standard AES-256 encryption
- Secure authorization — OAuth 2.0 for third-party integrations
- Access controls — granular access controls on database and storage with role-based permissions
- Webhook verification — cryptographic signature validation for external services
- Rate limiting — protection against brute-force and abuse
- Real-time data security — chat messages and real-time updates are transmitted over secure WebSocket connections with authentication
5.1 Chat Security
For the event chat feature specifically:
- Messages are transmitted over encrypted connections (TLS 1.2+)
- Messages are stored encrypted at rest in our database
- Only authenticated event participants can access chat messages
- Event organizers have moderation controls to remove inappropriate content
- Reported messages are automatically hidden when they receive multiple reports
- Chat is not end-to-end encrypted; messages are accessible to event participants and may be reviewed for moderation purposes
While we strive to protect your information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
6. Data Retention
- Account data — retained until you delete your account
- Event data — retained until the event is deleted by the creator
- Chat messages — retained until the event is deleted or the organizer deletes individual messages; soft-deleted messages are retained for 30 days before permanent removal
- Chat typing indicators — automatically cleared after 3 seconds of inactivity
- Message reports — retained as long as the associated message exists for moderation purposes
- Email verification codes — automatically expire after 10 minutes
- Analytics data — retained per our analytics provider's default policies (typically 14 months)
- Backup data — may be retained in backups for a limited period after deletion
When you delete your account, we will delete or anonymize your personal information, except where retention is required by law or for legitimate business purposes.
7. Cookies and Local Storage
7.1 Cookies
We use cookies for:
- Authentication — maintaining your logged-in session
- Preferences — remembering your settings
- Analytics — understanding usage patterns
7.2 Local Storage
We use browser local storage for:
- PWA install prompt preferences
- Theme preferences
7.3 Session Storage
We use session storage for:
- OAuth state tokens during authentication flows
- Temporary signup data during email verification
You can control cookies through your browser settings, but disabling cookies may affect Service functionality.
8. Your Privacy Rights
Depending on your location, you may have the following rights:
- Access — request a copy of your personal data
- Correction — request correction of inaccurate data
- Deletion — request deletion of your personal data
- Data portability — receive your data in a structured format (available via CSV export for Pro users)
- Withdraw consent — revoke consent for data processing
- Object — object to certain processing activities
- Restriction — request restricted processing of your data
To exercise these rights, please contact us at privacy@meetuptimes.app. We will respond within 30 days (or as required by applicable law).
8.1 California Privacy Rights (CCPA)
California residents have additional rights:
- Right to know what personal information is collected and how it's used
- Right to delete personal information
- Right to opt-out of the "sale" of personal information (we do not sell personal information)
- Right to non-discrimination for exercising privacy rights
8.2 European Privacy Rights (GDPR)
If you are in the European Economic Area, you have rights under GDPR including:
- All rights listed above
- Right to lodge a complaint with a supervisory authority
- Right to withdraw consent at any time
Our legal bases for processing your data include: consent, contract performance, legitimate interests, and legal compliance.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have different data protection laws.
Our service providers operate globally. By using the Service, you consent to the transfer of your information to these locations.
We rely on appropriate safeguards for international transfers, including Standard Contractual Clauses where applicable.
10. Children's Privacy
The Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@meetuptimes.app, and we will delete such information.
11. Third-Party Links and Services
The Service may contain links to third-party websites and integrations. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you interact with through our platform.
Third-party services we integrate with have their own privacy policies governing their collection and use of your information.
12. PWA and Offline Features
The Service is available as a Progressive Web App (PWA) that can be installed on your device. When installed:
- App icons and assets are cached locally on your device
- Certain data may be stored locally for offline access
- You can uninstall the PWA at any time through your device settings
13. Email Communications
We send the following types of emails:
- Transactional — account verification, password resets, security alerts (cannot be disabled)
- Event-related — confirmations, invitations, RSVP notifications, waitlist updates
- Promotional — if any, will include unsubscribe options
You can manage email notification preferences in your account settings.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last updated" date at the top of this page. For significant changes, we may also notify you via email.
Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.
15. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us:
- Email: info@meetuptimes.app
- Website: https://meetuptimes.app
For data protection inquiries in the EU, you may also contact your local data protection authority.