Back to The Reader's Hangout

Legal

Privacy Policy

Last updated: 14 June 2026

This Privacy Policy explains how The Reader's Hangout (“the Service”, “we”, “us”) collects, uses, and protects your personal data when you use this bookclub scheduling app. The Service is operated by [Operator / Organisation name], the data controller, which you can reach at [contact email].

Information we collect

  • Account information. Your email address (required to sign in and receive notices) and, optionally, a display name and profile image if you provide one.
  • Authentication data. Passwordless “magic link” sign-in tokens and session cookies used to keep you signed in.
  • Participation data. Your RSVPs, waitlist position and join time, seat confirmations and cancellations, attendance and no-show records, and the resulting attendance and penalty counts.
  • Content you submit. Book proposals (title, author, and a cover image URL) and the votes you cast.
  • Notifications. In-app messages we generate for you (for example, when a seat opens up) and whether you have read them.
  • Technical data. Collected automatically — see “Cookies” and “Analytics” below. Our hosting provider may log technical information such as your IP address and browser type for security and reliability.

How we use your data

  • To authenticate you and keep your session secure.
  • To run the bookclub: seating, the waitlist, seat confirmations, and book voting.
  • To send transactional emails (magic-link sign-in and waitlist-promotion notices).
  • To apply club rules, including no-show penalties and waitlist ordering.
  • To maintain meeting and attendance records for organisers.
  • To secure, debug, and improve the Service.

Legal bases (EEA/UK)

Where the EU/UK GDPR applies, we process your data on the basis of: performance of a contract (providing the Service to you), our legitimate interests (operating and securing the club fairly), your consent where required, and compliance with legal obligations. You may object to processing based on legitimate interests at any time.

Cookies

  • Essential cookies. Authentication and CSRF-protection cookies set by our sign-in system. These are required to sign in and use the Service.
  • Functional cookies. A short-lived cookie (about one minute) used to show status messages after an action.

We do not use advertising or cross-site tracking cookies.

Analytics

We use Vercel Web Analytics and Vercel Speed Insights to understand aggregate usage and page performance. These tools are designed to be privacy-friendly and do not build advertising profiles of you. Vercel acts as our processor for this data.

Emails

We send you magic-link sign-in emails and waitlist-promotion notices. These are delivered through Resend, our email processor, which handles your email address and message content solely to deliver these messages.

Service providers

We share data with the following processors, only as needed to run the Service:

  • Vercel — application hosting, analytics, and performance monitoring.
  • Resend — delivery of transactional email.
  • [Database hosting provider] — storage of the application database.

We do not sell your personal data.

Who can see your data

Organisers (admins) of the club can view members' contact details, attendance and penalty records, waitlist order, and book proposals, and can manage approvals and roles. Vote totals are hidden from members until results are revealed.

International transfers

Our providers may process data in countries outside your own. Where required, such transfers are covered by appropriate safeguards (for example, Standard Contractual Clauses). [Confirm the regions and safeguards that apply to your deployment.]

Data retention

We keep your account and participation data while your account is active and for as long as needed to maintain club records. You can request deletion of your account and associated personal data by contacting us at [contact email]; some records may be retained where we have a legal basis to do so.

Your rights

Depending on your location, you may have the right to access, correct, delete, or export your data, to restrict or object to processing, and to withdraw consent. To exercise any of these rights, contact [contact email]. If you are in the EEA or UK, you also have the right to lodge a complaint with your local data protection authority.

Security

We protect your data with passwordless authentication, encrypted connections, and role-based access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

Children

The Service is not directed to children under 16, and we do not knowingly collect their personal data. [Adjust the age to your jurisdiction.]

Changes to this policy

We may update this policy from time to time. We will revise the “Last updated” date above when we do, and significant changes may be communicated in-app.

Contact

Questions about this policy or your data? Contact [Operator / Organisation name] at [contact email].

Terms & Conditions·Privacy Policy