Privacy by design

Your dance life is
not our advertising inventory.

SocialDancing.eu collects only what an active feature needs, explains why it is needed, and gives account holders practical control over it.

Open your privacy controls →

THE ACCOUNT BETA

Only the data each role needs.

01

Account and role data

We store your email, display name, role, security credentials, acceptance records and a required main dance city and country. Dance styles remain optional. The main dance area is private and is used to localize the service; it does not subscribe you to email.

02

Private saved plans

Signed-in saved-event identifiers synchronize privately to your account. Anonymous bookmarks remain in the browser until sign-in and can be exported or erased separately.

03

Marketing stays off

Registration never subscribes you. Saved-event reminders, dance digests and organizer promotions have separate choices and withdrawal records. Digest and promotion locations are selected separately, and organizers see only privacy-protected aggregate eligibility.

04

Verified Passport visits

If you join an organizer’s Dance Passport, we store its accepted terms version, stamp ledger, reward state and verified event check-ins. Door staff see a display name and event eligibility, never your email. Short-lived QR values are stored only as hashes and are not included in exports.

Our implementation rules

Privacy is part of the architecture.

Minimum necessary

Your main dance area is required to provide a local service, but is not a street address or live location. Phone number, birth date and similar information are not requested without a real purpose. An organizer may choose a venue pin for an event.

Private by default

Saved events, main dance area, notification locations, preferences and attendance are private. Verified teachers must explicitly publish a directory profile, can hide it again, and never expose their account email.

Separate consent

Accounts, service messages, dance digests, organizer promotions and analytics receive separate controls and legal-basis decisions. Optional mail includes category-specific one-click unsubscribe.

Controlled campaigns

A location campaign must be anchored to the organizer’s published event. Consent, location relevance, role access, review, release limits and weekly pressure caps are checked again before delivery.

Defined deletion

Account erasure removes live account data immediately. Delivery evidence is minimized and database backups expire on the documented operational schedule.

Restricted access

Organizer and admin access uses least privilege, strong authentication boundaries and audit logs.

Map services

Public map tiles come from OpenStreetMap. Address searches are sent from our server to Nominatim only when an approved organizer or administrator presses the search button; searches are rate-limited and cached.

Optional website analytics

When enabled, our privacy banner asks before optional analytics starts. You do not need an account. Accepting lets us measure public-page visits, approximate country, device category and broad referral source. Rejecting does not affect your access, account or newsletter choices. Change this browser’s privacy settings at any time.

We remember the choice and its policy version in the first-party sd_analytics_consent cookie for up to 180 days without a unique identifier. After acceptance, a separate random, signed sd_analytics_browser cookie lasts up to 30 days. It is not your login cookie. A visit ends after 30 minutes of inactivity. We store only a keyed hash of the optional browser identifier, consent version/time/source and the minimized measurements on our server. We do not connect analytics to your account, email, attendance or saved events.

The server uses the connection IP temporarily for a local country lookup and abuse prevention; analytics does not retain the raw IP address or send it to an external lookup provider. Keyed abuse-prevention counters are kept separately for up to one day. Country is approximate and VPNs may affect it. We retain broad device and referral categories, not raw user agents or referring URLs. Private pages, query strings and URL fragments are excluded. No advertising pixels, cross-site tracking or fingerprinting are used for this feature.

Measurements and browser consent records expire within 30 days; automated cleanup removes expired records. Existing backups rotate after 14 days and restored analytics must be purged before use. Withdrawal stops future optional measurement and clears the optional browser cookie; previously collected measurements expire on this schedule. Necessary service/security processing continues separately. Do Not Track and Global Privacy Control signals disable optional measurement.

Reports describe consenting browsers, not all visitors or exact people. Site-wide reports are administrator-only. Country data uses IP Geolocation by DB-IP, Lite database under CC BY 4.0, held locally. This disclosure does not change the closed-beta legal/operator launch requirements.

ACCOUNT RIGHTS

Access. Correct. Export. Delete.

Signed-in users can immediately export their account data, including location choices, and permanently erase the account. Correction, restriction, objection and human-reviewed requests are handled through the privacy contact.

Closed-beta notice

The product now has technical privacy controls, but it is not legally ready for unrestricted public registration. Before open launch, this notice must identify the controller/operator, postal contact, establishment country, supervisory authority, processors, transfer safeguards and confirmed retention periods.