Privacy Policy

Last updated: 28 June 2026

This Privacy Policy explains how Groxo collects, uses, and protects your personal data when you use our platform. We are committed to handling your data responsibly and transparently, in compliance with the General Data Protection Regulation (GDPR) and applicable Hungarian data protection law.

Data controller: Kovács Milán Barnabás e.v., registered address 1204 Budapest, Berzsenyi Dániel utca 3., Hungary, registration no. 62257785, tax no. 92020948-1-43. For any privacy matter you can contact the controller at hello@groxo.app.

1. Data we collect

We collect the following categories of data:

  • Account data: email address, display name, and password (stored as a secure hash) when you sign up.
  • Profile data: nickname, city, country, phone number (organisers), profile photo, biography, sport preferences, and social media links — provided voluntarily.
  • Event interaction data: events you register for, favourites you save, and tickets you purchase.
  • Organiser data: business or club name, contact email, event listings, and identity verification documents submitted during the verification process.
  • Usage data: pages visited, search queries, filter selections, and timestamps — collected automatically to improve the platform.
  • Device data: browser type, operating system, and IP address — collected automatically for security and analytics purposes.

2. How we use your data and our lawful basis

We use your data for the purposes below. For each purpose we state the lawful basis under Article 6 of the GDPR on which we rely:

  • Provide and operate the Groxo platform, including account creation and management, event discovery, registration, and ticket purchases. Lawful basis: performance of our contract with you (Article 6(1)(b) GDPR).
  • Send the transactional emails you need to use the service, such as registration and ticket-purchase confirmations, ticket QR codes, and essential account notifications. Lawful basis: performance of our contract with you (Article 6(1)(b) GDPR).
  • Send optional event-notification emails about organisers, cities, or sports you have chosen to follow, where you have switched these notifications on. Lawful basis: your consent, given through the email-notification toggle in your settings, which you can withdraw at any time (Article 6(1)(a) GDPR).
  • Verify organiser identities and keep the platform safe, secure, and free of fraud and abuse. Lawful basis: our legitimate interest in protecting the integrity and security of the platform (Article 6(1)(f) GDPR).
  • Improve the platform through aggregated usage and device analytics. Lawful basis: our legitimate interest in understanding and improving how the platform is used (Article 6(1)(f) GDPR).
  • Meet our legal obligations, including tax, accounting, and record-keeping requirements. Lawful basis: compliance with a legal obligation (Article 6(1)(c) GDPR).

We do not use your data for automated profiling that produces legal or similarly significant effects.

3. How we share your data

We do not sell your personal data to third parties. We may share data with:

  • Event organisers: when you register for or buy a ticket to an event, the organiser receives the information necessary to process your registration (name, email, and any details you provided). Where an event has a linked co-organiser (an "away" organiser) or where the organiser has authorised check-in staff to scan tickets at the event, those parties may also access the attendee information needed to run the event.
  • Infrastructure providers: Groxo uses Supabase as its backend infrastructure provider. Data is stored on Supabase-managed servers in the European Union. Supabase processes data on our behalf and is bound by appropriate data processing agreements.
  • Email provider: Groxo uses Resend to deliver transactional and notification emails. Resend processes your email address and the contents of those messages on our behalf under a data processing agreement.
  • Payment processors: when you purchase a ticket, payment is handled by Stripe (contracting entity Stripe Payments Europe, Ltd., based in Ireland). Groxo does not receive or store your full payment card details. Because the event organiser is the merchant of record for ticket sales, Stripe also makes the transaction information available to the organiser as needed to process and account for the payment.
  • Legal authorities: if required by law, court order, or to protect the safety of users.

Some of our processors are based outside the European Economic Area (EEA) — in particular Resend, and Stripe's parent company, in the United States. Where personal data is transferred outside the EEA, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework. Personal data held in our own database remains hosted within the EEA.

4. Cookies and local storage

Groxo uses browser local storage to maintain your session and remember your preferences (such as your selected filters). We do not use third-party advertising cookies. Essential session cookies may be set by our infrastructure provider (Supabase) to authenticate your account.

5. Data retention

We retain your account data for as long as your account is active. If you delete your account, your personal profile data will be removed within 30 days. Some data may be retained for longer where required by law or for legitimate business purposes (e.g. records of financial transactions).

6. Your rights

Under the GDPR and Hungarian data protection law, you have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your data ("right to be forgotten").
  • Object to or restrict certain types of processing.
  • Data portability — receive a copy of your data in a machine-readable format.
  • Withdraw your consent at any time, where our processing is based on consent (such as the optional event-notification emails). Withdrawing consent does not affect the lawfulness of any processing we carried out before you withdrew it. You can withdraw by switching off the relevant toggle in your settings, or by contacting us.
  • Lodge a complaint with the Hungarian data protection supervisory authority, the NAIH (Nemzeti Adatvédelmi és Információszabadság Hatóság) at naih.hu.

To exercise any of these rights, contact us at hello@groxo.app. We will respond within 30 days.

7. Security

We use industry-standard security measures including encrypted connections (HTTPS), server-side authentication, and access controls. Identity documents submitted for organiser verification are stored in a private, access-controlled storage bucket and are not publicly accessible.

8. Children's privacy

Groxo is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has registered, please contact us at hello@groxo.app.

9. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or an in-app notice. The "last updated" date at the top of this page reflects the most recent revision.

10. Contact

For privacy-related enquiries, email hello@groxo.app. For general support, see our page.