Back to Simply Dates

Privacy policy

Last updated: 11 September 2026

1. Controller

Matthias Neumann
Kastanienallee 4a, 44652 Herne, Deutschland
Email: matthiasn270404@gmail.com

2. What data does Simply Dates process?

When you register and sign in, we process your email address, display name, internal user ID, password hash, verification status and, where voluntarily used, your Apple or Google account identifier.

When you use the app, Couple Space data, invitations, date and travel ideas, preferences, home location, swipes, plans, calendar connections and events, memories, photos, notifications, device tokens for push notifications and savings goals may be stored.

Location and calendar data are processed only when you actively use the relevant feature. We do not continuously track your location.

Google Calendar data

When you voluntarily connect Google Calendar, Simply Dates reads events from your own primary Google Calendar. This can include the title, start and end time, location, description, Google event ID, version identifier and the private Simply Dates link. During synchronization, we store resulting ideas, plans and technical mappings in Simply Dates. Imported content is stored in your shared Couple Space and is visible to your partner there. Accepted Simply Dates plans can be written to your primary Google Calendar as new events.

The OAuth access and refresh tokens required for access are stored encrypted. Google Calendar data is not used for advertising, sold or used to train general-purpose AI models. It is shared only for the synchronization feature described and visible to you, with members of your Couple Space and with processors required to operate the service.

When you disconnect Google Calendar, we revoke Google access and delete the stored OAuth tokens and technical synchronization mappings. Ideas and plans already imported into the Couple Space and events previously created in Google Calendar remain until you delete them there. When you delete your account, we also revoke access and delete the Google connection data associated with your account.

Simply Dates’ use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google API Services User Data Policy

3. Purpose and legal basis

Processing provides and secures your account, shared Couple Space features, planning, and recommendations, emails and notifications you request. The legal bases are Article 6(1)(b) GDPR for providing the service, Article 6(1)(a) GDPR for optional features and Article 6(1)(f) GDPR for security, error analysis and reliable operation.

4. Service providers

  • Vercel for hosting and delivery.
  • Supabase for the PostgreSQL database and storage.
  • Resend for transactional emails such as email verification, password resets and email changes.
  • Google and Apple when you use their sign-in service or connect Google Calendar.
  • Google Places, OpenWeather and Duffel when you use the relevant place, weather or flight-price features.
  • Apple Push Notification Service when you enable push notifications.

5. Cookies and sessions

Simply Dates uses an HttpOnly session cookie and short-lived OAuth state cookies to secure sign-in and calendar connections. These cookies are necessary for operation and security.

6. Technical logs

Technically necessary server logs may be processed to operate the service. We do not use web analytics, advertising SDKs or cross-app or cross-site tracking.

7. Retention and deletion

Account and Couple Space data are generally stored while your account exists. After account deletion, we remove associated data unless legal retention obligations or the rights of other Couple Space members require otherwise. Short-lived verification and recovery tokens expire after their intended use. Technical backups may remain until the relevant backup cycle ends.

8. Security and international transfers

Data is transmitted using encryption. Passwords and recovery tokens are not stored in plain text. Where providers process data outside the European Economic Area, transfers rely on applicable safeguards, in particular adequacy decisions or EU Standard Contractual Clauses.

9. Your rights

In the app, you can request a data export, change optional consent choices and delete your account. Where the legal requirements are met, you also have rights of access, rectification, erasure, restriction, data portability and objection. You may lodge a complaint with a data protection authority, in particular the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia.

10. Contact

For privacy questions, contact matthiasn270404@gmail.com.