Privacy Policy
Last updated 29 July 2026
1. Who we are
PlayTribes (“we”, “us”) is the data controller for the personal data described in this policy.
[Company legal name, registered address, and company number to be added here.]
Contact: see our support page
2. Who this app is for
PlayTribes is designed to be used by parents and legal guardians on behalf of their children. Children do not create their own accounts, do not log in, and are never asked to provide their own personal data directly — everything about a child is entered and controlled by the parent who added them.
3. Information we collect
About you (the parent/guardian): name, email address, mobile number, optional home address, profile photo, and your notification and privacy preferences.
About your child: first name, last name (optional), date of birth, gender (optional), school (optional), interests, allergies, medical notes, emergency contact details, and a photo if you choose to add one.
Usage data: the circles, events, RSVPs, invitations and connections you create, so the app can function — plus basic technical logs (timestamps, error logs) needed to keep the service reliable and secure.
4. Allergies and medical notes are special category data
Information about a child's allergies or medical conditions is “special category data” under UK/EU GDPR, which requires a higher standard of protection. We only ask for it because it's genuinely useful for hosts and other parents to know before a playdate or party, and:
- These fields are always optional — you choose what to share.
- By entering this information you're giving explicit consent for us to store it and to share it only with parents you've invited to a specific event your child is attending.
- It is never visible to parents outside your accepted connections, and never used for advertising, profiling, or any purpose beyond helping families keep kids safe at events.
- You can edit or remove it at any time from your child's profile.
5. Why we process your data
We rely on the following legal bases:
- Performance of a contract— to provide the core PlayTribes service you've signed up for (accounts, circles, events, RSVPs, notifications).
- Consent — for special category data (allergies/medical notes) and for optional communications you opt into.
- Legitimate interests — to keep the service secure, prevent abuse, and improve reliability, balanced against your right to privacy.
6. Who we share data with
Other parents:a child's profile, circle membership, and event details are only ever visible to parents you've explicitly connected with through a mutual invitation — never publicly, and never searchable.
Service providers (processors): we use a small number of trusted providers to run PlayTribes, currently Supabase (database, authentication and file storage) and Resend (transactional email). They only process data on our instructions and under contract. We do not sell your data, and we do not share it with advertisers.
7. International data transfers
Depending on how our infrastructure is configured, your data may be processed in a country outside your own. Where that happens, we rely on our providers' standard contractual clauses or equivalent safeguards recognised under UK/EU GDPR. [Confirm and name the specific hosting region(s) once finalised.]
8. How long we keep your data
We keep your account and your children's data for as long as your account is active. If you delete your account, we delete your personal data within 30 days, except where we're required to keep limited records for legal or security purposes.
9. Your rights
Under UK/EU GDPR, you have the right to:
- Access the personal data we hold about you and your children
- Correct inaccurate data
- Request deletion of your data (“right to be forgotten”)
- Export your data in a portable format
- Object to or restrict certain processing
- Withdraw consent at any time, without affecting past processing
- Lodge a complaint with your national data protection authority (in the UK, the ICO)
To exercise any of these rights today, use our support pageand we'll action your request by hand — or use the self-service data export and account deletion options in Settings.
10. How we protect your data
Data is encrypted in transit and at rest. Access to every child's profile is enforced at the database level — the application code cannot bypass these rules, even if there were a bug elsewhere in the app. Access to our production systems is limited to authorised administrators only.
11. Cookies
We use only strictly necessary cookies required to keep you signed in and to keep the app working. We do not currently use advertising or analytics cookies. If that changes, we'll update this policy and ask for your consent first.
12. Changes to this policy
We'll update this page if how we handle data changes, and update the “last updated” date above. For material changes, we'll let you know directly.
13. Contact us
Questions about this policy or your data? Visit our support page.