YourGroop Privacy Policy
Last updated: 7th August 2026
1. Who we are
YourGroop ("we", "us", "our") operates the YourGroop platform, a group organisation and payments tool available at www.yourgroop.com. We are the data controller for the personal data described in this policy. You can contact us at hello@yourgroop.com, Bartle house, 9 Oxford Court, Manchester, M2 3WQ.
If you have questions about this policy or how we handle your data, contact our Data Protection Lead at hello@yourgroop.com.
2. What this policy covers
This policy applies to anyone who uses YourGroop, whether you're an organiser running a groop, a member joining one, or a visitor to our site. It explains what data we collect, why, how long we keep it, and what rights you have.
3. What personal data we collect
| Category | Examples | Who it applies to |
|---|---|---|
| Account data | Name, email, password (hashed), profile photo | All users |
| Groop data | Groop names, descriptions, membership lists, sub-groop assignments | Organisers, members |
| Payment data | Card details (processed by Stripe — we never see or store full card numbers), billing name, transaction history, payout bank details | Organisers, paying members |
| Communications data | Messages sent via broadcast comms, Ask & Offer posts | Organisers, members |
| Technical data | IP address, device/browser type, log data, cookies | All users |
| Usage data | Pages visited, features used, groop activity | All users |
We do not collect special category data (e.g. health, religion, sexual orientation) unless you choose to include it voluntarily in groop descriptions or communications — please avoid sharing this where possible, as we don't actively monitor for it.
4. How we collect it
- Directly from you when you register, create or join a groop, make a payment, or contact us.
- Automatically through cookies and similar technologies (see Section 10).
- From Stripe, where they share limited information back to us (e.g. payment status, last 4 digits of a card) to allow us to display transaction records.
5. Why we use your data and our legal basis
| Purpose | Legal basis (UK GDPR Art. 6) |
|---|---|
| Creating and managing your account | Performance of a contract |
| Processing payments and payouts via Stripe | Performance of a contract |
| Enabling groop and sub-groop functionality | Performance of a contract |
| Sending essential service emails (e.g. payment confirmations, cancellation notices) | Performance of a contract / Legal obligation |
| Sending broadcast comms you've opted into | Performance of a contract / Consent |
| Fraud prevention and platform security | Legitimate interests |
| Improving the platform (aggregated analytics) | Legitimate interests |
| Marketing communications | Consent (you can withdraw anytime) |
| Complying with tax, accounting, and FCA-adjacent payment regulations | Legal obligation |
6. Who we share your data with
- Stripe: our payment processor, which handles all card data and payouts under its own role as a data controller for payment processing. Stripe is certified under UK adequacy/SCC arrangements where relevant. See Stripe's own privacy policy for details on their processing.
- Other organisers/members: if you join a groop, the organiser can see your name, email, and membership/payment status for that groop. Sub-groop moves may share this data with a new organiser within the same groop structure.
- Service providers: hosting, infrastructure, and technical support providers who process data on our behalf under data processing agreements.
- Regulators or authorities: where required by law (e.g. tax authorities, law enforcement).
- Business transfers: if YourGroop is acquired or merged, data may transfer to the new entity, subject to equivalent protections.
We do not sell your personal data.
7. International transfers
Where any of our service providers (including Stripe) process data outside the UK, we ensure appropriate safeguards are in place, such as the UK International Data Transfer Agreement (IDTA) or adequacy regulations.
8. How long we keep your data
- Account data: retained while your account is active, and for 12 months after closure to handle disputes or legal claims.
- Transaction/payment records: retained for at least 6 years to meet UK tax and accounting obligations.
- Groop data: retained while the groop is active; closure flows determine onward retention or deletion as agreed during groop closure.
- Marketing consent: retained until you withdraw consent, then suppressed to honour your opt-out.
9. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request erasure ("right to be forgotten"), subject to our legal retention obligations (e.g. we can't delete transaction records required for tax purposes)
- Restrict or object to certain processing
- Data portability
- Withdraw consent at any time where we rely on consent
- Lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk
To exercise any of these rights, contact us at hello@yourgroop.com. We'll respond within one month as required by law.
10. Cookies
We use cookies and similar technologies for:
- Essential functions (login sessions, security)
- Analytics (understanding how the platform is used)
- Preferences (remembering your settings)
11. Children
YourGroop is not intended for use by anyone under 16. We do not knowingly collect data from children.
12. Security
We use industry-standard measures (encryption in transit, access controls, and Stripe's PCI-compliant infrastructure for payment data) to protect your data. We encourage strong and unique passwords.
13. Changes to this policy
We may update this policy from time to time. We'll notify organisers and members of material changes via email or in-app notice before they take effect.
14. Contact us
YourGroop Ltd
Bartle House, 9 Oxford Court
Manchester, England, M2 3WQ
hello@yourgroop.comICO registration number: ZC209049