Switch to Suomi

Privacy policy

Version 2.7 · updated September 29, 2026

This policy describes how the Hoodly app processes data. Hoodly brings a neighborhood's deals together in a single view. Browsing deals requires no account; claiming a deal requires signing in.

1. Controller

The controller is Tuomo Suortti. For matters concerning data protection you can contact tuki@hoodly.fi.

2. What data we process

Browsing. Browsing deals requires no account. While you browse, we process the approximate location of your device if you give permission for it; see section 3 for details.

Account data. When you sign in to claim a deal, we process the email address returned by the sign-in and an identifier created for your account. Signing in takes place through Google, Apple (in the iOS app only), and our authentication service (Supabase Auth).

Claims. When you claim a deal, we store which deal you claimed, the claim code you show at the location, and the times of the event. These are linked to your account.

Pseudonymous event log. Claims produce a separate event log in which a business sees the completed transaction only through a pseudonym (a random identifier), not your name or your email address. This log is immutable and is not edited afterwards.

Error and server data. For stability and error monitoring we use Sentry. The data collected is technical error data (for example the error message, the app version, and the device type), to which no user or device identifier is attached; the storage of IP addresses is switched off in Sentry. Technical request data, such as an IP address, may be stored briefly in server logs. To prevent abuse of the business contact form we count submissions per IP address; the counter is deleted within a day.

Days of use. We follow the use of the app in two ways. Openings accumulate as a per-day total that carries no identifier at all and cannot be connected to an individual person or device. While you are signed in, we additionally store the fact that you used the app on that day. This record is bound to your account and is removed with it; it carries no time of day, no location, and no device data, and it is not connected to the pseudonym in the event log.

Deal images. The illustrations for deals are created with the help of AI before publication. No personal data of users is used to create the images.

Messages. When you write to us from the app's conversation while signed in, we store your message and the answer given to it, linked to your account. You choose what a message contains, so do not write anything into it that you do not want us to process. Every message is also relayed to our team's internal messaging tool (Slack) so that we can answer what the bot cannot; where needed, we answer by email.

The bot that answers. Your message is answered by a bot named Naali, which reads your message, the earlier messages in the conversation, and your own claims in order to answer questions about them; it sees no other data of your account. The answer is produced with the language model of the provider named in section 6, in the EU region, and your messages are not used to train models.

Business contact request. When you ask us to get in touch as a business, we process the business name, contact name, email address, city or area, and any description you provide of quiet hours or a deal idea. We use the data only to contact you and assess whether the service fits.

3. Location

The app asks permission to use your location so that deals can be ordered by walking distance and so that the distance and an estimated walking time can be shown with each deal.

Location is not stored. The device coarsens your location to an accuracy of about 100 meters before it is sent, so we do not receive an address-accurate location. The location is used only to order that one search: it is not stored in the database, it is not linked to your account, and no movement history is formed from it. Location is removed from error reports before they are sent; a coarsened location may remain briefly in server request logs, like the other technical request data described in section 2.

Giving permission is voluntary. You can refuse the permission or withdraw it from your device's settings at any time. Without location the app works normally: deals are ordered by whichever claim window ends first, and distances are not shown.

4. Legal bases for processing

The processing of your account and your claims is based on the performance of a contract (Article 6(1)(b) of the General Data Protection Regulation): without this data you cannot sign in or claim a deal.

The processing of location is based on consent (Article 6(1)(a)): the app works without location, so processing it is not necessary in order to provide the service. You give consent by allowing location, and you can withdraw it from your device's settings.

The processing of messages is based on legitimate interests (Article 6(1)(f)): answering the questions and feedback you write, and developing the service on the basis of what is not working in it. You can object to the processing as described in section 8; without your message, however, we cannot answer it.

The processing of a business contact request is based on legitimate interests (Article 6(1)(f)): making the contact you asked for and assessing whether the service fits. You can object to the processing as described in section 8; without contact details, however, we cannot answer the request.

The processing of the pseudonymous event log, the error and server data, and the days of use is based on legitimate interests (Article 6(1)(f)): ensuring the stability and security of the service, giving businesses the ability to see the realized use of their deals without identifying an individual person, and developing the service on the basis of how many people actually use it.

5. Cookies and browser storage

The browser version stores on your device only what the operation of the service requires. We do not use analytics, advertising, or tracking cookies, and we do not share the stored data with third parties. This is also why the site does not ask for cookie consent: everything listed below is necessary in order to deliver the service you asked for.

  • Signing in — the identifier of your session, so that you stay signed in and do not have to authenticate again on every page.
  • Sign-in return address — the page from which you started signing in, so that you return there rather than to the front page. Deleted immediately after the return.
  • Location permission memory — the fact that you have given location permission, so that deals can be ordered correctly right away and the view does not reorder itself after loading. Does not contain your location.
  • Appearance — the light or dark theme you chose.

You can delete these at any time from your browser's settings. Deleting the sign-in identifier signs you out; the others are set again when needed.

6. Disclosure of data and service providers

We do not sell data and we do not use it for marketing. For the technical operation of the app we use service providers that process data on our behalf:

  • Google and Apple — signing in. We use these to authenticate your account when you sign in. Apple is available in the iOS app only.
  • Google Cloud — AI-assisted creation of deal images before publication. No personal data of users is sent to the service.
  • Google Cloud (Vertex AI) — the language model of the bot that answers your message. Your message, the earlier messages in the conversation, and your claims are processed in the EU region and are not used to train models.
  • Supabase — authentication and database in the EU region (Stockholm). Your account, your claims, your conversation, and the content of deals are located here.
  • Vercel — the platform for the backend service, in whose logs technical request data may be stored briefly.
  • Sentry — error and stability monitoring in the EU region, as described in section 2.
  • Slack — our team's internal messaging tool, to which your messages are relayed as described in section 2.

Other data is processed in the EU region. Slack processes the messages relayed to it in the United States; the transfer relies on the standard contractual clauses approved by the European Commission.

7. Retention and deletion of data

You can delete your account at any time from the app. Deletion removes your account and the personal data linked to it, such as your claims, and severs the connection between you as a person and the pseudonym in the event log.

The event log described in section 2 is immutable, so it remains after the account is deleted, but only as a pseudonym with no connection to you. Data may remain in backups for a limited time, until the copies expire.

Your conversation is removed with your account. We also delete the messages we relayed to Slack. A note a team member wrote into the same conversation is not something we can delete from the app, so it remains in Slack for the period set by the workspace's retention setting and is removed with it.

Days of use accumulated while you are signed in are retained for at most 13 months, after which they are deleted. The anonymous per-day count of openings is not personal data, so it is retained for the time being.

We delete a resolved business contact request 12 months after its resolution. An unresolved request is retained so that we can answer it.

Error data is retained in Sentry for at most 90 days, after which it is deleted automatically; location is removed from it before it is sent. Location is not stored in the database at all: it is used to order the search and then forgotten.

8. Your rights

You have the rights provided by data protection legislation: the right to access your data, to rectify it, to erase it (for example by deleting your account), and to restrict and object to processing. Your rights concern the data we can connect to you; after your account is deleted, we can no longer connect the remaining pseudonymous log to you as a person.

You can exercise your rights by contacting tuki@hoodly.fi. You also have the right to lodge a complaint with the data protection authority (the Office of the Data Protection Ombudsman).

9. Changes

As the service develops, this policy is updated. We announce significant changes in the app.