The Good Company Club

Last updated: August 2026

Privacy Policy

Note for review, not for publication

Sections marked [NEEDS LEGAL REVIEW] or [NEEDS VERIFICATION] need completing or confirming before publication. This document has been cross-checked against the Terms of Service for consistency, but neither has been reviewed by a qualified lawyer. Review them together, not separately: the content licence in section 10 of the Terms has direct consequences here, particularly in sections 3, 4, 7, and 8.

Remove this note before publishing.

1. Who we are, and who this applies to

This policy explains how we collect, use, and protect your personal data. It applies to everyone who uses the platform, whether as a guest, a host, or a visitor.

  • Data controller: House of Sridharan
  • Organisation number: 932428024
  • Registered address: Trelastveien 10B, 1415 Oppegård
  • Contact for privacy matters: friends@thegoodcompany.club

We are based in Norway and subject to the General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act (personopplysningsloven).

2. What data we collect

When you create an account

  • Email address
  • Display name
  • Profile photo, if you upload one

When you become a host

  • Your bio and anything else you add to your host profile
  • Photos you upload for your experiences, up to five per experience
  • The address where your experiences take place. This is a home address in most cases. We do not ask for this when you sign up to host — we collect it when you create your first experience, not before
  • Your Stripe account identifier. Stripe collects your bank details, identity documents, and date of birth directly. We never see or store them

When you book or receive a booking

  • Booking details: which experience, the date, the number of seats
  • Any note you add to your booking
  • Payment status and Stripe transaction references. We do not store card numbers

When you use the platform

  • Basic technical information such as your browser and device type
  • Which pages you visit and actions you take, used to keep the platform working and improve it

People who are not platform users. Photos uploaded by hosts may show other people, including guests at past events. We ask hosts to only upload photos they have the right to share, but we do not review every photo before it is published. If you appear in a photo on the platform and you did not upload it, you can ask us to remove it at friends@thegoodcompany.club and we will.

3. Why we use your data, and our legal basis

GDPR requires us to have a lawful basis for each purpose. Ours are:

What we doWhyLegal basis
Create and manage your accountSo you can sign in and use the platformPerformance of a contract
Show your profile and experiences to other usersSo guests can find and trust hostsPerformance of a contract
Enable and manage bookingsSo the booking worksPerformance of a contract
Process payments through StripeSo hosts get paidPerformance of a contract
Send transactional emails: booking confirmations, cancellation notices, and similarSo you know what is happening with your bookingPerformance of a contract
Generate a draft event description from your host bio and event details using an AI serviceSo hosts have a starting point for their listing. See section 4Performance of a contract
Promote the platform and the experiences on it, using published event photos, host bios, and event descriptions: our website, our emails, our social media, and press or partner materialTo bring guests to experiences and grow the communityLegitimate interests
Keep the platform secure and prevent misuseTo protect users and the serviceLegitimate interests
Understand how the platform is used, and improve it, including anonymous usage analyticsTo make the product betterLegitimate interests
Keep records of transactionsBecause Norwegian bookkeeping law requires itLegal obligation
Collect a host's organisasjonsnummer, and report host earnings to Skatteetaten where requiredNorwegian tax law, and potentially DAC7 digital platform reporting rules. See the note in section 4 of our Terms of ServiceLegal obligation

On promotion. We do not sell your data, and we do not use it to show you third-party advertising. We do promote the platform and the experiences listed on it, and that can include event photos, host bios, and event descriptions you have published. It does not include your host profile photo: that continues to appear on the platform itself, but is not used in external marketing. Section 10 of our Terms of Service sets out the licence this relies on. You can object at any time and we will stop: see section 8 below.

[Needs legal review]Legitimate interests for promotion. Relying on legitimate interests requires a documented balancing test, which should be completed and retained. Separately, host profile photos are no longer used in external marketing, which resolves most of the risk under Norwegian image rights law (åndsverkloven § 104) for those photos. What remains: whether an event photo used in external marketing that shows an identifiable guest needs that guest's separate consent, or whether the requirement in Terms section 10 that hosts obtain a person's permission before uploading a photo showing them is sufficient on its own. A lawyer needs to confirm. This affects section 10 of the Terms of Service as well.

4. Who we share it with

We use the following providers to run the platform. Each processes personal data on our behalf, and only to the extent needed.

Stripe processes payments and host payouts, and collects host identity and bank details directly. Stripe's privacy policy applies to what it collects: stripe.com/privacy

Supabase hosts our database. Your account, profile, and booking data is stored there.

Resend sends our transactional emails.

Vercel hosts the platform and provides anonymous usage analytics (Vercel Web Analytics), so we can see aggregate traffic patterns. This does not identify you individually and sets no cookies. See section 9 for more on this.

Anthropic provides the AI model that generates draft event descriptions. When a host creates an experience, their bio and the event details they have entered are sent to Anthropic's API to produce a draft description. The host can edit or replace that draft before publishing. Anthropic's privacy policy: anthropic.com/legal/privacy

Brønnøysundregistrene, the Norwegian business register. When a host registers as a business, the organisasjonsnummer they provide is checked against Brønnøysundregistrene's public register to confirm it exists and to retrieve the registered business name.

Marketing and press. When we promote the platform, published event photos, host bios, and event descriptions may be shared with press, partners, or people who help us produce that material. This is limited to content covered by the licence in section 10 of our Terms of Service. It never includes host profile photos, email addresses, phone numbers, booking records, payment information, or private notes.

[Needs verification]Confirm this list matches what is actually running in production. If any analytics, error monitoring, or session recording tool is in use, it must be added here.

Apart from the above, we do not share your data with anyone else without your consent, unless we are legally required to.

5. What hosts and guests see about each other

This platform involves people meeting in private homes, so it is worth being specific.

Hosts see the display name of each guest who books, the number of seats they booked, and any note the guest added to their booking. Hosts do not see guest email addresses.

Guests see the host's display name, profile photo, and bio before booking. Once a booking is confirmed, the guest also sees the full address of the experience, which is usually the host's home address. This is necessary for the guest to attend, and hosts are told about it before they list.

We do not publish either party's email address or phone number to the other.

6. Where your data is processed

Most of our providers process data entirely inside the European Economic Area. Where that is the case, no international transfer safeguard is needed, and we say so plainly below rather than implying transfers are widespread.

  • Supabase — our database and file storage are hosted in the EEA (Ireland).
  • Vercel — our application is hosted in the EEA (Ireland).
  • Resend — our transactional email is sent from the EEA (Ireland).
  • Stripe — our contract for European merchants is with Stripe Payments Europe, Limited, a company incorporated in Ireland (EEA), which acts as the data processor. Providing the service also involves transferring some personal data to Stripe's US parent, Stripe, LLC. Stripe, LLC is self-certified under the EU-US Data Privacy Framework, which it relies on as the primary safeguard for that transfer, with the EEA Standard Contractual Clauses (Modules 1–3) applying as a fallback if that certification lapses. Source: Stripe's Data Processing Agreement and Data Transfers Addendum, stripe.com/legal/dpa and stripe.com/legal/dta.
  • Anthropic — based in the United States. Anthropic relies on Standard Contractual Clauses (Module 2, controller-to-processor, and Module 3, processor-to-processor) as the safeguard for transferring data out of the EEA, not the EU-US Data Privacy Framework. Source: Anthropic's Data Processing Addendum, anthropic.com/legal/data-processing-addendum.

[Needs verification]The positions above were checked against Stripe's and Anthropic's own published DPA and transfer-addendum documents current as of this policy's last-updated date. Both companies can and do change their certifications and contract terms; reconfirm before publication and periodically afterward.

7. How long we keep your data

We keep your account data for as long as your account is active.

If you delete your account, from your profile, the following happens immediately, not after a waiting period:

  • Your name, phone number, and email address are removed from your profile.
  • If you are a host, your bio, display name, address on file, business details, and profile photo are removed from your host profile, and the photo is deleted from storage.
  • Your sign-in record is kept, but with your email address replaced by a randomised placeholder, so your original email address is freed for you (or anyone else) to sign up with again. A new account created this way starts fresh and inherits nothing from the deleted one.

Some records are not removed, because we are required to keep them or because they belong to someone else's record too:

  • Your past bookings and, if you were a host, your past events, are retained as booking and event records — for example, which experience, the date, the seat count, and any note added at booking. They are no longer linked to your name, phone number, or email address once your account is deleted. We keep these for up to five years, in line with the Norwegian Bookkeeping Act (bokføringsloven).
  • For paid bookings, Stripe independently keeps its own payment record, including the payer's email address, as part of its own bookkeeping obligations. That record is Stripe's, not ours, and is not affected by deleting your account with us.
  • An event and its photos remain visible for as long as the event itself is kept, even if the host who created it has since deleted their account. Once anonymised, the event is shown as coming from an unnamed host. This includes the address where the experience took place: it was lawfully shared with guests once their booking was confirmed, and it stays part of that event's record for those guests, even after the host's account is deleted. You cannot delete your account while you have an upcoming published experience, so this only ever applies to past experiences.
  • Data already contained in a routine database backup remains in that backup until it is cycled out in the ordinary course of our backup schedule.

[Needs legal review]Whether retaining a booking or event record without an attached identity still satisfies the Bookkeeping Act's requirements needs a lawyer's or accountant's confirmation.

8. Your rights

Under GDPR you have the right to:

  • Access the personal data we hold about you
  • Correct anything inaccurate
  • Delete your data, subject to the retention obligations in section 7
  • Portability, meaning a copy of your data in a machine-readable format
  • Restrict how we use your data in certain circumstances

Deleting your account. You can delete your own account at any time from your profile — no need to email us. If you currently have an upcoming published experience as a host, or an upcoming confirmed booking as a guest, you will need to cancel it first; we ask for this so a booking is never left stranded by a deletion.

Objecting to marketing. You can tell us at any time to stop using your data to promote the platform, and we will stop. You do not need to give a reason. We will stop using your content in anything new and remove it from the channels we control. Write to friends@thegoodcompany.club.

Objecting to other uses. Where we rely on legitimate interests for something other than marketing, such as security or product improvement, you can object and we will stop unless we have compelling grounds to continue. We will explain our reasoning either way.

Withdrawing consent. Where we have asked for your consent for something, you can withdraw it at any time. We do not currently rely on consent for any of the processing in section 3, but this may change and we would ask you at the time.

To exercise any of these rights, email friends@thegoodcompany.club. We will respond within one month.

You can also complain to the Norwegian Data Protection Authority, Datatilsynet, at datatilsynet.no.

9. Cookies

We use only the cookies necessary to keep you signed in and to make the platform work. We do not use advertising cookies or tracking pixels.

We use Vercel Web Analytics to understand how the platform is used in aggregate: how many people visit, and which pages they view. It works without setting any cookies and does not identify you individually. This information is not shared for advertising, and is not combined with your account to build a profile of you.

If this changes, we will update this policy and ask for your consent where the law requires it.

10. Automated decisions

We do not make automated decisions about you that have legal or similarly significant effects, and we do not use your data for profiling.

The AI-generated event description mentioned in sections 3 and 4 produces draft text for a host to review and edit. It does not make any decision about you.

11. Security

We take reasonable technical and organisational measures to protect your data, including encrypted connections, access controls on our database, and role-based permissions limiting who can see what.

No system is completely secure. If a data breach occurs that is likely to affect your rights, we will notify Datatilsynet and, where required, you directly.

12. Children

The platform is not intended for anyone under 18. We do not knowingly collect data from children.

13. Changes to this policy

If we make significant changes, we will notify you by email. The date at the top of this page always shows when it was last updated.

14. Contact

For any privacy question, or to exercise your rights: friends@thegoodcompany.club