Privacy Policy
Effective date: 13 August 2026 Last updated: 1 September 2026
This Privacy Policy explains how UniPulse, a general partnership (vennootschap onder firma) registered in the Netherlands with the Chamber of Commerce under number 42133276, with its registered office at Bosboom-Toussaintplein 261, 2624 DR Delft ("UniPulse," "we," "us," or "our"), collects, uses, and shares personal data when you use the UniPulse mobile application, website, and related services (the "Service").
We are the controller of the personal data described in this Policy. If you have any questions, contact us at info@unipulse.nl.
This Policy should be read together with our Terms of Service. Terms in bold have the meaning given to them there.
1. Summary
- We collect the data needed to run the Service: your account details, your date
of birth, the events you register for or host, your activity and rewards, the content you post, and — if you allow notifications — a push token for your device. We do not track your location. The one time your coordinates reach us is when you check yourself in at an event that works that way, and then only to confirm you are there — we compare them to the event's address and keep no record of where you were.
- Your date of birth is used only to check you meet a minimum age, is kept apart
from the rest of your profile, and is never shown to other users.
- Ticket payments are handled by a licensed payment provider. We do not
store your full card or bank details.
- We rely on the General Data Protection Regulation (“GDPR”) legal bases of
contract, consent, legitimate interests, and legal obligation, depending on the data.
- You have rights over your data, including access, correction, deletion,
and the right to complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
2. What Data We Collect
a) Account and profile data. Your first and last name, email address, password (stored only as a hash by our authentication provider), the institution you chose when signing up, and your faculty. "Institution" here means the university or hogeschool you study at. We do not derive it from your email address: you select the institution first, and we then check that the address you enter ends in that institution's email domain. You can update your profile, change your faculty, or leave your institution at any time.
b) Date of birth and age. When you create an account we ask for your date of birth. We use it for two things: to check that you are at least 16 — the age from which, under the GDPR as implemented in the Netherlands, you may consent to the processing of your own personal data — and to tell you whether you meet the minimum age an Organizer has set for a particular event, such as an event restricted to attendees of 18 and over where alcohol is served.
Because it is needed for nothing else, your date of birth is held separately from the rest of your profile, in a restricted record that only you and the Service itself can read. It is not shown on your profile and is not visible to other users or to Organizers. When you open an event with a minimum age, the app tells you and the Organizer only whether you meet it — never your date of birth and never your age.
Your age for an event is calculated on the date of that event, not on the day you look at it: someone who turns 18 the week before an 18+ event meets its requirement.
We do not otherwise verify your age. The date you enter is a declaration you make yourself; we do not ask for identity documents, and Organizers still check identification at the door.
When you create an account you also confirm that you have read and accept the Terms of Service and this Policy. We store those confirmations against your account, together with the version of each document you accepted and the time you accepted it, so that we can demonstrate that consent was given and ask you again if either document changes materially.
c) Event and ticket data. The events you view, save, register for, host, or manage; your tickets and QR check-in codes; check-in status; and, for events you host, the registration and attendance data of your attendees.
d) Payment-related data. When you buy or sell a ticket, Stripe processes the payment. We do not receive or store your card number or bank credentials, and we never see them: they are entered on Stripe's own screens.
What we do store for each purchase is: a transaction identifier, the amount, the status, which kind of payment method was used (for example "iDEAL" or "card"), the email address your receipt was sent to, and a record of exactly what you were shown before you paid — the seller's identity, the price breakdown, and the notice that no 14-day withdrawal right applies.
That last item exists because Dutch consumer law requires us to be able to demonstrate what a buyer was told before they were bound. It is evidence about our own disclosure, not profiling of you, and it is never used for anything else.
For communities receiving payouts we additionally store the organisation's registered name, KvK number, VAT number, registered address, and the last four digits of the payout bank account. Stripe collects the full identity and bank details directly for its own "Know Your Customer" checks; we never see them.
For communities receiving payouts, the payment provider collects identity and bank details directly for verification ("Know Your Customer") purposes. Of those we store only the last four digits of the payout account, so a community's treasurer can confirm on the payouts screen that the money is going where they expect.
e) Location data. Your device asks for permission the first time either of the two features below needs it, and you can withdraw that permission at any time in your device settings. Nothing runs in the background: we never ask for your location while the app is closed, and we do not track your movements.
The map's "My location" button. Your device works out where you are and the app centres the map on it. Those coordinates stay on your device — they are not sent to us, not stored, and not shared with anyone. If you decline, the rest of the map works exactly as before.
Self check-in. Some Organizers run an event without scanning tickets at the door, and let you check yourself in from your own ticket instead. When you press that button, your device reads your coordinates once and sends them to us with that single request. We compare them to the address the Organizer gave for the event, to establish that you are actually there, and answer yes or no.
We do not keep them. The coordinates exist only for the moment that comparison takes; nothing is written to any record. What we do store is the outcome — that you checked in, and at what time — which is the same thing we store when an Organizer scans your ticket at the door, and it says nothing about where you were. Checking in is what unlocks the attendance reward and the ability to review the event; if you would rather not share your location, you can simply not press it, and everything else about the event stays as it is.
Events themselves appear on the map at the address the Organizer entered for them, which involves no location data of yours at all.
f) Content you submit ("User Content"). Photos, timeline memories, reviews, messages, event updates, questions, and poll responses. Photos are stored in our media storage. Content may be visible to other users as described in Section 5.
g) Rewards and activity data. Your pulses, activity streaks, collectible cards, and related activity used to operate the gamification features.
h) Notifications. If you enable push notifications, we store a push token so we can send you notifications about events, questions, polls, and community activity. You can disable notifications in your device settings.
i) Technical and usage data. Device type, operating system, app version, approximate region, log data, and diagnostic information, used to operate, secure, and improve the Service.
j) Website data. If you visit our website, we may process limited technical data and, where required, use cookies or similar technologies as described in Section 11.
3. How and Why We Use Your Data (Legal Bases)
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and manage your account | Account, profile | Performance of a contract (Art. 6(1)(b)) |
| Check you meet the minimum age for the Service | Date of birth | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |
| Check you meet the minimum age an Organizer set for an event | Date of birth | Performance of a contract (Art. 6(1)(b)) |
| Let you discover, register for, and attend events | Event, ticket, check-in | Performance of a contract (Art. 6(1)(b)) |
| Process ticket payments and payouts | Payment-related | Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) |
| Show nearby events on the map | Location | Consent (Art. 6(1)(a)) |
| Confirm you are at an event when you check yourself in | Location, at that moment only | Consent (Art. 6(1)(a)) |
| Send push notifications | Push token | Consent (Art. 6(1)(a)) |
| Display content you post to relevant users | User Content | Performance of a contract; legitimate interests (Art. 6(1)(f)) |
| Operate rewards, streaks, and collectibles | Rewards/activity | Performance of a contract; legitimate interests |
| Secure the Service and prevent abuse/fraud | Technical, usage, account | Legitimate interests (Art. 6(1)(f)) |
| Comply with legal, tax, and accounting duties | Account, payment | Legal obligation (Art. 6(1)(c)) |
| Improve the Service | Usage, diagnostics | Legitimate interests (Art. 6(1)(f)) |
| Marketing communications (if any) | Contact details | Consent (Art. 6(1)(a)) |
Where we rely on consent, you may withdraw it at any time (for example by turning off location or notifications), without affecting processing already carried out. Where we rely on legitimate interests, we have balanced those interests against your rights; you may object as described in Section 8.
4. Data of Attendees Shared with Organizers
If you register for an event, the hosting community and that event's Organizers can see what they need in order to run it: your name, your faculty, which ticket and any ticket options you chose, your check-in status, and anything you post to that event such as a question or a poll answer. A review you write is shown to that event's Organizer and counted in the event's rating. Organizers act as independent controllers for how they use attendee data outside the Service and must comply with applicable data-protection law. If you host events, you are responsible for handling your attendees' data lawfully.
5. Visibility of Your Data to Other Users
Depending on the feature, some data is visible to other users:
- your profile is visible to other signed-in users — including your name,
avatar, institution and faculty, your Campus Collector trading username, and app activity such as your pulse balance, login streak, and the event preferences you set for recommendations;
- a review you write is shown to that event's Organizer and counted in the
event's rating, not to other attendees;
- a question you ask is private between you and that event's Organizers, who
see it together with your name. It becomes visible to other attendees only if an Organizer chooses to publish it, which is a deliberate act on their part and not something answering it does by itself. A published question is shown to everyone else without your name — you appear only as "Questioner";
- the memories, photos, and notes you add to your personal timeline are
visible only to you;
- content you post in a community or event is visible to the relevant
members and Organizers.
Do not post content you do not wish to be seen by the relevant audience.
6. Who We Share Data With
We share personal data only as needed to run the Service:
- Payment provider — Stripe Payments Europe, Limited, to process payments and
payouts.
- Hosting and database provider — Supabase, Inc., which stores our data and
media on our behalf.
- Push-notification providers — the operating-system notification services
(Apple Push Notification service and/or Firebase Cloud Messaging) and our notification tooling.
- Mapping provider — Apple Maps on iOS and Google Maps on Android render
the event map and receive the map requests your device makes in order to do so.
- Organizers and communities — as described in Section 4.
- Professional advisers and authorities — where required by law, to
comply with a legal obligation, or to protect our rights, users, or the public.
- In a business transfer — if we are involved in a merger, acquisition,
or sale of assets, subject to this Policy.
We do not sell your personal data. We may produce aggregated, anonymised statistics that cannot be traced back to you or to any other individual — for example how many students attended a category of event in a given city — and we may publish, share, or commercially exploit those. Such statistics are no longer personal data, so this Policy does not restrict their use.
7. International Transfers
Our database, file storage, and authentication run on Supabase infrastructure hosted in the European Union (Ireland, eu-west-1), so the core of your data does not leave the EEA. Some of the other providers listed in Section 6 do process data outside the EEA. Where that happens we rely on a transfer mechanism — the safeguard the GDPR requires before personal data may leave the EEA — meaning either a European Commission adequacy decision covering the receiving country (such as the EU–US Data Privacy Framework) or the Commission's Standard Contractual Clauses agreed with that provider.
8. Your Rights
Under the GDPR, you have the right to:
- access the personal data we hold about you;
- rectify inaccurate or incomplete data;
- erase your data ("right to be forgotten"), subject to legal retention
duties;
- restrict or object to certain processing, including processing
based on legitimate interests and direct marketing;
- data portability — receive certain data in a structured, machine-
readable format;
- withdraw consent at any time where processing is based on consent.
You can exercise most of these rights in the app (for example, editing your profile or deleting your account) or by contacting us at info@unipulse.nl. We will respond within one month of receiving your request. If a request is particularly complex, or if you have made several, we may extend that by up to two further months — in which case we will tell you within the first month, and why (Article 12(3) GDPR). Exercising these rights is free; we may charge a reasonable fee only for a request that is manifestly unfounded or excessive. You also have the right to lodge a complaint with the Autoriteit Persoonsgegevens (the Dutch Data Protection Authority, autoriteitpersoonsgegevens.nl) or your local supervisory authority.
9. Data Retention
We keep personal data only as long as necessary for the purposes described in this Policy:
- account and profile data — while your account exists. When you delete your
account, this is deleted immediately, not after a waiting period. There is no grace period and no way for us to restore it, so please be certain before you confirm;
- User Content — deleted with your account, at the same moment, except where it
has become part of something shared. What is shared stays with the community or event it was written for, and is shown without your name from the moment your account goes: a review you left stays with the event it rates; a question you asked stays under its event, as does any answer or update you wrote as an Organizer; and a post or announcement you wrote for a community, and any image you uploaded to a community or event page, stay with that community or event. Your private timeline — its photos, memories and notes — is not shared with anyone and is deleted outright;
- your registration for an event — the record that a ticket was issued and
checked in remains with the event, because the Organizer needs to be able to account for who attended. It is disconnected from you when your account goes, so it no longer identifies you;
- payment records — for seven years, counted from the end of the financial year
they fall in. This is not our choice: Article 52 of the Dutch General Tax Act (Algemene wet inzake rijksbelastingen) requires it of every business, and it overrides a deletion request for these records specifically. They consist of the transaction, its amount, and the event it paid for. The email address your receipt was sent to is removed from them when you delete your account; the receipt itself has already been delivered to you by then;
- a keyed fingerprint of a deleted account's email address — for twelve months
after the deletion. New accounts start with a small welcome reward, and inviting a friend earns one too; without this, deleting an account and creating it again would collect both a second time. The fingerprint is a one-way code made with a secret key held only inside our database, so it cannot be turned back into your address and cannot be matched against one without that key. It is kept for nothing else, and is the only trace of a deleted account we hold (legitimate interests, Article 6(1)(f));
- a community that asks to be closed — its page, membership and roles are
removed, but the records of what it sold are not, for the seven-year period and the reasons set out in Section 4.1 of the Terms of Service. Those records concern the transaction rather than the buyer's profile, and the buyer's own account is unaffected by them;
- the coordinates sent for a self check-in — not retained at all. They are
used for one comparison inside the request that carries them and are never written down, so there is nothing to delete afterwards. The check-in itself (that it happened, and when) is kept with the registration described above;
- technical and log data — up to 90 days, for security and diagnostics. The
same period applies to notifications: a notification sent to another user that mentions you by name (for example that you sent them a card) is removed 90 days after it was sent.
Deleting your account does not withdraw it from our provider's routine backups immediately. Those are kept for disaster recovery, are not readable as ordinary data, and roll over within 30 days, after which no copy remains.
10. Children
The Service is not intended for children under 16, and we do not knowingly collect personal data from anyone under 16. Creating an account requires you to enter your date of birth, and an account cannot be created if it shows you are under 16. If you believe a child has provided us with personal data, contact us at info@unipulse.nl. We will investigate and delete the data where we establish that it belongs to someone under 16.
We should be straightforward about the limits of that check. The date of birth on an account is something the account holder typed, and someone determined to get in can type a different one; we do not ask for identity documents, which would be a heavier intrusion than the risk warrants for a student events app. So a report is weighed against what the account itself shows and anything else we can reasonably see, and we may ask the account holder about it. What we do not do is delete an account on an anonymous report alone — otherwise a report would be a way to have someone else's account erased.
11. Cookies and Similar Technologies
The mobile app uses local storage on your device to keep you signed in and to remember your preferences. This is strictly necessary to provide the Service and is not used to track you.
Our website sets no cookies, and uses no analytics, advertising, or tracking tools. That is why you are not asked to accept cookies when you visit it.
Two things on the website do involve someone else. The site loads its typefaces from Google Fonts, which means your browser requests them from Google's servers and Google receives your IP address in the process. And if you send us a message through the contact form, that message is passed to our hosting provider (see Section 6) and delivered to us by email. Nothing else on the website leaves your device.
12. Security
We take reasonable technical and organizational measures to protect personal data. Traffic between the app and our servers is encrypted in transit with TLS (HTTPS); data stored with our hosting provider is encrypted at rest; passwords are stored only as hashes by our authentication provider; and access to data is constrained by row-level security rules in the database, so one account cannot read another account's private data. Securing the Service is our responsibility, and nothing in this Policy shifts that responsibility to you. What is yours is keeping your own credentials and device secure: please do not share or reuse your password, and tell us promptly if you think someone else has access to your account. No system is completely secure, and we cannot guarantee absolute security.
13. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will notify you through the app or by email before they take effect. The "Last updated" date at the top shows when this Policy was last revised.
14. Contact
For any privacy question or to exercise your rights, contact:
UniPulse
Bosboom-Toussaintplein 261, 2624 DR Delft
Email: info@unipulse.nl
We have not appointed a Data Protection Officer. We are not a public authority, and our core activities do not consist of large-scale regular monitoring of individuals or large-scale processing of special categories of data, so Article 37 GDPR does not require one. We are established in the Netherlands, so no EU representative under Article 27 is required either.
You also have the right to lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).