Privacy Policy
Effective Date: June 1, 2026
1. Information We Collect
We collect information you provide when joining, purchasing, creating an account, or contacting support. This may include name, email, account identifiers, and transaction metadata. We do not collect IP addresses, precise geolocation, or device fingerprints for tracking purposes.
2. Legal Basis for Processing
- We process your personal data under the following legal bases:
- Contract performance (GDPR Art. 6(1)(b)): To operate your membership, process payments, deliver program benefits, and provide member support.
- Legitimate interest (GDPR Art. 6(1)(f)): To prevent fraud, protect platform security, and improve service reliability. We balance these interests against your rights and freedoms.
- Consent (GDPR Art. 6(1)(a)): For optional features such as MessageBox communications and referral attribution. You may withdraw consent at any time.
- Legal obligation (GDPR Art. 6(1)(c)): To comply with tax, financial reporting, and dispute resolution requirements.
3. How We Use Information
We use personal data to operate membership access, process payments, deliver experiences, prevent fraud, and provide customer support. We also use limited analytics to improve product reliability. We do not sell personal data to third parties, and we do not use third-party advertising trackers or analytics pixels.
4. Data Sharing and Processors
- We share data only with service providers needed to run the platform, such as payment processors, hosting infrastructure, email delivery tools, and fraud prevention vendors.
- We maintain Data Processing Agreements (DPAs) with each processor in compliance with GDPR Article 28. Our processor categories include cloud infrastructure and CDN providers, payment processors, and email delivery services. A list of current sub-processors is available upon request by contacting privacy@heartbadge.com.
5. International Data Transfers
Your personal data may be processed in the United States and other countries where our service providers operate. Where data is transferred outside the European Economic Area, we rely on appropriate safeguards including Standard Contractual Clauses (SCCs) and adequacy decisions where available. Our primary infrastructure providers maintain their own GDPR compliance frameworks and data processing agreements.
6. Data Retention
- We retain personal data according to the following schedule:
- Membership records: For the life of your membership plus 7 years for tax and legal compliance.
- Transaction and payment data: 7 years from transaction date for financial reporting obligations.
- Session data: Automatically expired and purged after session timeout.
- Support communications: 3 years from last interaction.
- MessageBox data: For the duration of your MessageBox enrollment, or until you withdraw consent.
- Referral attribution (client-side): 30 days from capture, or until checkout completion.
- You may request earlier deletion where no legal retention obligation applies.
7. Security Controls
We use strong safeguards to protect personal data, including encryption in transit (TLS), secure session management, and access controls. No internet transmission is perfectly secure, but we continuously monitor and improve our protections.
8. MessageBox and Event Communications
- If you enable MessageBox, we may process information needed to provide secure communications linked to your HeartBadge identity. This may include your HeartBadge messaging identity, program and event associations, notification preferences, device or session data, delivery status information, and message or attachment data where supported.
- We use this information to:
- deliver program and event communications
- support event logistics and member notifications
- help deliver safety or operational notices
- protect members and the platform from misuse, fraud, or abuse
- improve reliability and performance of communications features
- We may use service providers and delivery partners to support MessageBox and related communications. Where a program uses MessageBox for operational or safety-related communications, we may share the minimum information necessary with authorized program operators, venues, or public safety partners as required for event operations, safety, fraud prevention, or legal compliance.
9. Your Data Rights
- Under applicable data protection law (including GDPR where it applies), you have the right to:
- Access (Art. 15): Request a copy of the personal data we hold about you.
- Rectification (Art. 16): Request correction of inaccurate personal data.
- Erasure (Art. 17): Request deletion of your personal data, subject to legal retention obligations.
- Restriction (Art. 18): Request that we limit how we process your data in certain circumstances.
- Portability (Art. 20): Request your data in a structured, machine-readable format.
- Object (Art. 21): Object to processing based on legitimate interest.
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- To exercise any of these rights, contact privacy@heartbadge.com. We will respond within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.
10. Data Breach Notification
In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours where required by applicable law, and will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
11. Contact for Privacy Requests
For privacy requests, data subject rights, or questions about how we handle your data, contact privacy@heartbadge.com. Please include the email associated with your account so we can verify your identity and process your request promptly.