Data Controller
SocietyPopUp is a development project (MVP) without commercial activity.
The controller of personal data collected on this site is the publication director.
GDPR Contact: contact@societypopup.com
Important note: This site is a technical demonstration. No payment data is collected. No real financial transactions are processed.
Data Collected
As part of this MVP, we only collect data necessary for the demonstration's functionality:
Identity Data
Surname, first name, email address (collected when creating an account via Firebase Authentication).
Profile picture and optional information you choose to share.
Navigation Data
Technical cookies, IP address, browser type and version.
Search history, listing views, and booking simulations.
Messages exchanged between users via the messaging functionality.
⚠️ No payment data is collected (no credit cards, no IBAN, no identity documents).
Legal Basis for Processing
In accordance with GDPR Article 6, we process your data on the following legal bases:
- Service execution: account creation, booking simulations, user communication via messaging.
- Legitimate interest: platform improvement, feature testing, anonymized statistical analysis.
- Consent: use of non-essential analytics cookies, browsing preferences.
Your Rights
- Right of access: obtain a copy of your personal data.
- Right of rectification: correct your data from your personal space.
- Right to erasure: request deletion of your account and data.
- Right to object: object to direct marketing via unsubscribe link.
- Right to portability: receive your data in a structured format.
- Right to lodge a complaint: with the CNIL (www.cnil.fr) or your local data protection authority.
Data Retention
As an MVP project, we apply limited retention periods:
Account data: retained during active service use.
Activity data (searches, booking simulations): retained during the test project.
Messages between users: retained while the account is active.
Account deletion: your data is permanently deleted within 30 days maximum.
You can request immediate deletion of all your data at any time.
Data Security
- SSL/TLS encryption of all communications between your browser and our servers.
- Restricted access to personal data, limited to authorized personnel.
- Regular and secure backups of our databases.
- Data breach notification procedure within 72 hours in compliance with GDPR.