Legal
Privacy Policy
We built Socialhubbs to connect people — not to harvest their data. This policy explains exactly what we collect, why we collect it, and how you can control it. It is written to be read, not avoided.
1. Who We Are
Socialhubbs is operated by Socialhubbs Ltd, registered in England and Wales. We are the data controller for the personal data described in this policy — meaning we determine how and why it is processed.
Data protection contact: privacy@socialhubbs.com
This policy covers the Socialhubbs platform accessible at socialhubbs.com and any associated mobile applications.
2. What Personal Data We Collect
Information you give us directly
| Data | When collected |
|---|---|
| Email address | Registration (Step 1) |
| Password | Registration (Step 1) — stored as a one-way bcrypt hash only; we cannot see or recover your plaintext password |
| Display name | Onboarding (Step 2) |
| Date of birth | Onboarding (Step 2) — used to verify the 18+ age requirement |
| Intent | Onboarding (Step 3) — your stated purpose: dating, friendship, networking, or a combination |
| Profile content | Whenever you update your profile — photos, bio, interests (Phase 2) |
Information collected automatically
| Data | Purpose |
|---|---|
| Session cookie (PHPSESSID) | Keeps you logged in during your visit. This is a strictly necessary session cookie — it expires when you close your browser or log out. No consent required under UK PECR. |
| Server access logs | Your IP address, browser type, pages visited, and timestamps. Used for security monitoring, abuse detection and diagnosing errors. Retained for 90 days, then deleted. |
| Feature usage data | Which game features you use (trivia, challenges, icebreakers), XP earned and levels reached. Used to improve the product and personalise your experience. |
What we do not collect
- Payment card details — when paid subscriptions launch, payments will be handled entirely by a PCI-DSS compliant payment processor. We will never see or store your card number.
- Precise location data — we do not track your GPS or device location.
- Biometric data — no facial recognition, fingerprint data or similar.
- Data about children — Socialhubbs is strictly 18+. See Section 9.
3. How We Use Your Data (and Our Legal Basis)
UK GDPR requires us to have a lawful basis for every use of your personal data. Here is ours:
| Purpose | Legal basis |
|---|---|
| Creating and maintaining your account | Performance of a contract — you need an account to use the service |
| Operating the gamification system (XP, levels, matching) | Performance of a contract — these are core platform features |
| Verifying the 18+ age requirement | Legal obligation — we are required to ensure users are adults |
| Security, fraud prevention and abuse detection | Legitimate interests — protecting users and the platform |
| Sending transactional emails (account confirmation, password reset) | Performance of a contract |
| Product analytics and improvement | Legitimate interests — understanding how the platform is used helps us make it better for everyone |
| Marketing and promotional emails | Consent — we will only send marketing emails if you opt in; you can withdraw consent at any time via the unsubscribe link in any email or by contacting us |
| Compliance with legal obligations | Legal obligation |
4. Who We Share Your Data With
We do not sell, rent or trade your personal data.
Other users
Your display name, intent and any content you choose to make visible on your profile will be shown to other users of the platform as part of the matching and discovery experience. You control what appears on your profile.
Service providers (sub-processors)
We use a small number of trusted third-party providers to operate the platform — for example, hosting infrastructure and email delivery. All sub-processors are contractually required to process your data only on our instructions, to apply appropriate security measures, and to comply with UK GDPR.
Legal requirements
We may disclose personal data to law enforcement, regulators or courts where we are legally required to do so, or where necessary to protect the rights or safety of users or the public.
Business transfers
If Socialhubbs Ltd is acquired, merged or its assets are transferred, personal data may be transferred as part of that transaction. We will notify you before your data is transferred and becomes subject to a different privacy policy.
5. How Long We Keep Your Data
| Data type | Retention period |
|---|---|
| Account data (email, profile, intent) | Until you delete your account, plus 30 days grace period for recovery requests, then permanently deleted |
| Anonymised usage statistics | Retained indefinitely after anonymisation — no longer personal data |
| Server access logs | 90 days rolling, then deleted |
| Backup copies | Up to 90 days after the live data is deleted |
| Data retained for legal compliance | As required by applicable law (e.g. financial records: 7 years) |
6. Your Rights Under UK GDPR
You have the following rights regarding your personal data. To exercise any of them, contact us at privacy@socialhubbs.com. We will respond within 30 days.
| Right | What it means |
|---|---|
| Access | Request a copy of the personal data we hold about you (Subject Access Request) |
| Rectification | Ask us to correct inaccurate or incomplete data |
| Erasure | Ask us to delete your personal data ("right to be forgotten") in certain circumstances — including by deleting your account in settings |
| Restriction | Ask us to pause processing of your data while a dispute is resolved |
| Portability | Receive a copy of the data you provided to us in a structured, machine-readable format |
| Object | Object to processing based on legitimate interests, or to direct marketing at any time |
| Withdraw consent | Where processing is based on consent (e.g. marketing emails), withdraw it at any time without affecting the lawfulness of prior processing |
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
7. Cookies
We use one cookie: the PHP session cookie (PHPSESSID). It is strictly necessary for authentication — without it, you cannot stay logged in. It is a session cookie: it expires when you close your browser or log out.
We do not use advertising cookies, third-party tracking cookies, analytics cookies, or any cookie that tracks you across other websites.
When paid subscriptions launch, a payment processor may set its own cookies on the payment page. We will update this policy accordingly before that happens.
8. International Data Transfers
We store and process your data on servers located in the United Kingdom and/or the European Economic Area. If we engage sub-processors outside the UK/EEA, we will ensure appropriate safeguards are in place — such as UK adequacy regulations, Standard Contractual Clauses, or the International Data Transfer Agreement (IDTA).
9. Children
Socialhubbs is strictly for users aged 18 and over. We do not knowingly collect personal data from anyone under 18. If we become aware that we have inadvertently collected such data, we will delete it immediately.
If you believe we hold personal data about a minor, please contact us immediately at privacy@socialhubbs.com.
10. Security
We take the security of your data seriously. Measures include:
- Passwords stored as bcrypt hashes — we cannot see or recover your password in plaintext
- All data transmitted over HTTPS (TLS)
- Session cookies set with
HttpOnly,SecureandSameSite=Laxflags - Parameterised database queries throughout — no SQL injection risk
- Access to personal data limited to personnel who need it to operate or improve the service
No system is 100% secure. If you discover a security vulnerability, please disclose it responsibly to privacy@socialhubbs.com.
11. Changes to This Policy
We may update this Privacy Policy when our practices change or when the law requires it. When we make material changes, we will notify you by email and/or by a prominent notice in the app at least 14 days before the changes take effect.
The "last updated" date at the top of this page always reflects the current version.
12. Contact and Complaints
For any privacy-related question, request or concern:
Socialhubbs LtdEmail: privacy@socialhubbs.com
We aim to respond to all requests within 30 days. If you are not satisfied with our response, you may contact the ICO at ico.org.uk.