HostHive

Template: have these terms reviewed by a lawyer before launch.

Text in [square brackets] is a placeholder to fill in. Last updated: 25 September 2026.

Privacy Policy

This policy explains which personal data HostHive processes, why, who can see it and which rights you have under the EU General Data Protection Regulation (GDPR).

1. Controller

The controller responsible for your data is [Company name], [Legal form], [Address], email [Email], phone [Phone]. [If a data protection officer is appointed: name and contact.]

2. Data we process

Account data (all users)

  • email address and password (stored only as a secure hash by our authentication provider);
  • full name, your role (host or client) and, if you add one, a phone number and profile picture;
  • the time you accepted the Terms of Service and Privacy Policy and which version you accepted;
  • technical sign-in data: session tokens, sign-in times and security logs.

Host profiles

  • headline, biography, city, country, hourly rate and currency, headshot, intro video link, years of experience, skills, languages and industries;
  • whether the profile is published, and the rating calculated from reviews;
  • days you block in your calendar, with an optional note.

Client (company) profiles

  • company name, website, logo and industry.

Bookings and reviews

  • booking requests: event name, location, start and end time, offer and currency, your message and the status (pending, accepted, declined, cancelled, completed);
  • reviews: the star rating, the comment and the date, linked to the booking.

Visitors

  • when you visit the site, our hosting provider processes your IP address, the page requested, the time and your browser’s user agent in server logs.
  • if you sign in, a session cookie keeps you signed in (see the Cookie Policy). We use no analytics or advertising cookies.

3. Purposes and legal bases

PurposeLegal basis
Creating and running your account, signing you inContract, Art. 6(1)(b) GDPR
Showing a published host profile to clients and on public pagesContract, Art. 6(1)(b) GDPR (the host chooses to publish)
Sending, answering and cancelling booking requests; showing a host’s busy daysContract, Art. 6(1)(b) GDPR
Reviews and the public rating of hostsContract, Art. 6(1)(b) GDPR, and our legitimate interest in a trustworthy marketplace, Art. 6(1)(f) GDPR
Security, preventing spam and abuse (for example limits on requests), server logsLegitimate interest, Art. 6(1)(f) GDPR
Service emails (confirming your email address, password reset)Contract, Art. 6(1)(b) GDPR
Keeping records we are legally required to keepLegal obligation, Art. 6(1)(c) GDPR

We do not sell personal data and do not use it for advertising or automated decisions.

4. Who can see your data

  • Everyone, including search engines: a published host profile, that is the host’s name, headshot or profile picture, headline, biography, city, country, rate, intro video, years of experience, skills, languages, industries, rating and reviews. Public reviews show the rating, comment and date, but never the client who wrote them. An unpublished profile is not public.
  • Your booking counterparties: when a client and a host have a booking request between them (in any status), each can see the other’s name, profile picture and phone number, and the host can see the client’s company details. A client can also see the profile of a host they booked even after it is unpublished.
  • Only the two participants: the booking itself (event details, times, offer and message) and the full review record.
  • Only the host: the days the host blocked and their notes. A client sending a request sees only which days the host is busy, not why.
  • Nobody else: your email address and phone number are never shown on public pages, and other users cannot see your account unless you have a booking with them.

5. Processors and other recipients

  • Supabase (Supabase, Inc.) hosts our database, authentication and file storage, and sends our service emails [or: our email provider, [SMTP provider]]. Data region: [region].
  • [Hosting provider] runs the website and processes the server logs described above.
  • Video providers: if a host adds an intro video, their profile embeds a player from YouTube (in privacy enhanced mode, youtube-nocookie.com), Vimeo or Loom. The player loads from that provider when you view the profile, which then receives your IP address and may set its own cookies under its own privacy policy.

We have data processing agreements with our processors (Art. 28 GDPR). We disclose data to authorities only where the law requires it.

6. International transfers

Some providers are based in, or may access data from, countries outside the European Economic Area, such as the United States. Where this happens we rely on an adequacy decision (for example the EU-US Data Privacy Framework for certified companies) or on the European Commission’s Standard Contractual Clauses. [Confirm the mechanism for each provider.]

7. How long we keep data

  • Account and profile data: until you delete your account, then within [30] days.
  • Bookings and reviews: for as long as either participant’s account exists, and afterwards only as long as needed for legal claims or legal retention duties [period].
  • Server logs: [7] days, unless needed to investigate a security incident.
  • Backups: overwritten within [period].

8. Your rights

You have the right to:

  • access the personal data we hold about you (Art. 15 GDPR);
  • have incorrect data corrected (Art. 16);
  • have your data erased (Art. 17);
  • restrict processing (Art. 18);
  • receive your data in a portable format (Art. 20);
  • object at any time to processing based on our legitimate interests, for reasons arising from your particular situation (Art. 21);
  • lodge a complaint with a data protection supervisory authority, in particular in the country where you live or work, or with the authority responsible for us: [Supervisory authority].

You can edit most of your data yourself in your dashboard. For everything else, write to [Email].

9. Security

Data is sent over encrypted connections. Access to data in our database is restricted by row level security rules, so each user can read only what section 4 describes.

10. Changes

We update this policy when our processing changes. The date at the top shows the current version.

11. Contact

Questions about privacy: [Email], [Address].