Privacy Policy

Last updated: August 24, 2026

This privacy policy describes how Hamak collects, uses and protects the personal data of application users, in accordance with the General Data Protection Regulation (GDPR) and applicable French data protection law.

Data controller

The data controller is [TO BE COMPLETED: publisher name / company name], reachable at: [TO BE COMPLETED: GDPR contact email].

Data collected

Depending on how you use Hamak, we may collect the following data:

  • Email address, when you create an account via magic link or Google sign-in (name, email and profile picture provided by Google).
  • An anonymous identifier stored in your browser (localStorage / cookie) allowing us to recognize you as a participant in a trip, without creating an account.
  • The information you enter or share when organizing a trip: proposed dates, lodgings, votes, comments, messages, participant first name and color.
  • Technical browsing data (IP address, browser type, pages visited) if an audience measurement tool is enabled (see the "Google Tag Manager" section).

Purposes of processing

Your data is used to:

  • Authenticate you and secure access to your account and your trips.
  • Enable the service to function: creating and managing trips, voting on dates and lodgings, exchanging messages between participants.
  • Send you transactional emails necessary for the service (sign-in link, trip invitations, notifications related to your trip).
  • Improve the service and ensure its security (anonymized audience measurement, where applicable).

Legal basis

The processing of your data is based on the performance of the service you request from us (providing the trip-planning tool), on your consent (for example for audience-measurement cookies) and, where applicable, on our legitimate interest in ensuring the security and proper functioning of the application.

Recipients and processors

Your data may be shared with the following providers, who act as data processors strictly within the purposes described above:

  • [TO BE COMPLETED: Neon / Supabase]: hosting of the application database.
  • Resend: sending transactional emails (sign-in link, invitations).
  • Google: authentication via Google OAuth, when you choose this sign-in method.
  • Google Tag Manager: only if enabled, for anonymized audience measurement of the site.

These providers only use your data for the purposes of the services they provide us, and in compliance with applicable regulations.

Data retention period

Your data is kept for as long as necessary to fulfill the purposes described above, in particular for the entire lifetime of your account or your active trips. Trip data may be deleted at the request of its organizer. You can request the deletion of your account and your data at any time (see "Your rights" below).

Your rights

In accordance with the GDPR, you have the following rights over your personal data:

  • Right of access: obtain confirmation that your data is being processed and obtain a copy of it.
  • Right of rectification: correct inaccurate or incomplete data.
  • Right to erasure: request deletion of your data, within the limits provided by law.
  • Right to portability: receive your data in a structured, commonly used format.
  • Right to object and to restrict processing, in cases provided for by the regulations.

To exercise these rights, contact us at: [TO BE COMPLETED: GDPR contact email]. You also have the right to lodge a complaint with your national data protection authority (in France, the CNIL).

Cookies and local storage

Hamak uses cookies and your browser's local storage (localStorage) to operate the service: maintaining your session, remembering your identity as a trip participant when you are not signed in, and remembering your language and theme (light/dark) preferences. These elements are strictly necessary for the application to function. If an audience-measurement tool (Google Tag Manager) is enabled, audience-measurement cookies may also be set, subject to your consent where required.

Data security

We implement reasonable technical and organizational measures to protect your data against unauthorized access, loss or alteration. As no system is completely infallible, we invite you to report any potential vulnerability to the contact address above.

Changes to this policy

This privacy policy may be updated at any time, in particular to comply with any regulatory, case-law or technical developments. The last-updated date appears at the top of this page.