YourGroop Icon

YourGroop Privacy Policy

Last updated: 7th August 2026

1. Who we are

YourGroop ("we", "us", "our") operates the YourGroop platform, a group organisation and payments tool available at www.yourgroop.com. We are the data controller for the personal data described in this policy. You can contact us at hello@yourgroop.com, Bartle house, 9 Oxford Court, Manchester, M2 3WQ.

If you have questions about this policy or how we handle your data, contact our Data Protection Lead at hello@yourgroop.com.

2. What this policy covers

This policy applies to anyone who uses YourGroop, whether you're an organiser running a groop, a member joining one, or a visitor to our site. It explains what data we collect, why, how long we keep it, and what rights you have.

3. What personal data we collect

CategoryExamplesWho it applies to
Account dataName, email, password (hashed), profile photoAll users
Groop dataGroop names, descriptions, membership lists, sub-groop assignmentsOrganisers, members
Payment dataCard details (processed by Stripe — we never see or store full card numbers), billing name, transaction history, payout bank detailsOrganisers, paying members
Communications dataMessages sent via broadcast comms, Ask & Offer postsOrganisers, members
Technical dataIP address, device/browser type, log data, cookiesAll users
Usage dataPages visited, features used, groop activityAll users

We do not collect special category data (e.g. health, religion, sexual orientation) unless you choose to include it voluntarily in groop descriptions or communications — please avoid sharing this where possible, as we don't actively monitor for it.

4. How we collect it

  • Directly from you when you register, create or join a groop, make a payment, or contact us.
  • Automatically through cookies and similar technologies (see Section 10).
  • From Stripe, where they share limited information back to us (e.g. payment status, last 4 digits of a card) to allow us to display transaction records.

5. Why we use your data and our legal basis

PurposeLegal basis (UK GDPR Art. 6)
Creating and managing your accountPerformance of a contract
Processing payments and payouts via StripePerformance of a contract
Enabling groop and sub-groop functionalityPerformance of a contract
Sending essential service emails (e.g. payment confirmations, cancellation notices)Performance of a contract / Legal obligation
Sending broadcast comms you've opted intoPerformance of a contract / Consent
Fraud prevention and platform securityLegitimate interests
Improving the platform (aggregated analytics)Legitimate interests
Marketing communicationsConsent (you can withdraw anytime)
Complying with tax, accounting, and FCA-adjacent payment regulationsLegal obligation

6. Who we share your data with

  • Stripe: our payment processor, which handles all card data and payouts under its own role as a data controller for payment processing. Stripe is certified under UK adequacy/SCC arrangements where relevant. See Stripe's own privacy policy for details on their processing.
  • Other organisers/members: if you join a groop, the organiser can see your name, email, and membership/payment status for that groop. Sub-groop moves may share this data with a new organiser within the same groop structure.
  • Service providers: hosting, infrastructure, and technical support providers who process data on our behalf under data processing agreements.
  • Regulators or authorities: where required by law (e.g. tax authorities, law enforcement).
  • Business transfers: if YourGroop is acquired or merged, data may transfer to the new entity, subject to equivalent protections.

We do not sell your personal data.

7. International transfers

Where any of our service providers (including Stripe) process data outside the UK, we ensure appropriate safeguards are in place, such as the UK International Data Transfer Agreement (IDTA) or adequacy regulations.

8. How long we keep your data

  • Account data: retained while your account is active, and for 12 months after closure to handle disputes or legal claims.
  • Transaction/payment records: retained for at least 6 years to meet UK tax and accounting obligations.
  • Groop data: retained while the groop is active; closure flows determine onward retention or deletion as agreed during groop closure.
  • Marketing consent: retained until you withdraw consent, then suppressed to honour your opt-out.

9. Your rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request erasure ("right to be forgotten"), subject to our legal retention obligations (e.g. we can't delete transaction records required for tax purposes)
  • Restrict or object to certain processing
  • Data portability
  • Withdraw consent at any time where we rely on consent
  • Lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk

To exercise any of these rights, contact us at hello@yourgroop.com. We'll respond within one month as required by law.

10. Cookies

We use cookies and similar technologies for:

  • Essential functions (login sessions, security)
  • Analytics (understanding how the platform is used)
  • Preferences (remembering your settings)

11. Children

YourGroop is not intended for use by anyone under 16. We do not knowingly collect data from children.

12. Security

We use industry-standard measures (encryption in transit, access controls, and Stripe's PCI-compliant infrastructure for payment data) to protect your data. We encourage strong and unique passwords.

13. Changes to this policy

We may update this policy from time to time. We'll notify organisers and members of material changes via email or in-app notice before they take effect.

14. Contact us

YourGroop Ltd

Bartle House, 9 Oxford Court

Manchester, England, M2 3WQ

hello@yourgroop.com

ICO registration number: ZC209049