Privacy policy
Last updated —
On this page
The short version
We built Stitch to help you keep track of the people you actually want to see. That works better when we hold less about you, not more.
So, plainly: we ask for your phone number because it is how we know it is you and how invites reach you. We do not run analytics or advertising trackers, we have no tracking pixels, and we have never sold personal data and do not intend to. Your data lives on servers in Ireland. The people who can see your profile and your RSVPs are other Stitch users, and this policy explains exactly which ones.
The rest of this page is the detailed version, which we are required to give you and which you are entitled to hold us to.
1. Who we are
Stitch is operated by [COMPANY LEGAL NAME] (“Stitch”, “we”, “us”), a company registered in England and Wales under company number [COMPANY NUMBER], with its registered office at [REGISTERED ADDRESS].
For the purposes of the UK GDPR and the EU GDPR, we are the controller of the personal data described here.
If you have a question about this policy, or want to exercise any of the rights in section 11, email [privacy@YOURDOMAIN]. We aim to reply within five working days and are required to respond substantively within one month.
2. What we collect
Information you give us
Your phone number. Required. It is your account identifier and how we verify it is you. We send a one-time code by SMS to confirm it.
Your name. We ask new users for a first name after verification, so other guests know who has replied. A surname is optional.
Optional profile details. A username, an email address, a short bio, a gender, and a profile photo. All of these are optional, and you can remove any of them at any time from your profile settings. We ask for gender only to help disambiguate people with similar names in guest lists and search results, and you can leave it blank.
Events you create. The name, description, date and time, time zone, poster image, capacity, cost per person if you state one, and the venue. Where you pick a venue from our search, we store its name, address, place identifier and coordinates so we can show it on a map and let guests find it.
Your responses. Whether you replied yes, no or maybe, how many guests you are bringing, and whether a host has approved you.
What you post. Comments and emoji reactions on events, poll votes, group names and group photos, and anything else you type into the app.
Information we create about you
Your social graph. Who you are friends with on Stitch, which groups you belong to, who invited you to what, and whether the invitation came from a host, another guest or a shared link.
Your activity. An event history, notifications addressed to you, and timestamps for when your account was created, last updated, and last active.
Information we collect automatically
Session data. When you sign in we set a session cookie so you stay signed in. It lasts 30 days.
Technical data. Your IP address and basic request information, which reach our servers as an unavoidable part of how the internet works, and which we use for security, rate limiting and abuse prevention. We pass your IP address to our SMS provider when sending a verification code, purely so they can rate limit and block fraud.
What we do not collect. We want to be specific, because most apps in this category do collect these. We do not read your address book or phone contacts. We do not request your device location. We do not use analytics, session replay, advertising or attribution tools. There is no Meta Pixel, no Google Analytics, and no advertising identifier in Stitch.
3. Why we use it, and our lawful basis
Under the UK GDPR we have to have a specific lawful basis for each use. Ours are:
| What we do | Data used | Lawful basis |
|---|---|---|
| Create and run your account, verify your phone number, keep you signed in | Phone, name, session data | Performance of a contract with you |
| Show your events, RSVPs, comments and profile to the people entitled to see them | Profile, event and RSVP data, social graph | Performance of a contract with you |
| Send you service notifications about events you host or are invited to | Phone, name, notification data | Performance of a contract with you |
| Prevent fraud, spam and abuse, and keep the service secure | Phone, IP address, technical data | Our legitimate interest in running a safe service |
| Fix bugs, diagnose faults and improve how Stitch works | Technical data, error logs | Our legitimate interest in improving our product |
| Send you marketing about Stitch, if you have asked for it | Phone or email | Your consent, which you can withdraw at any time |
| Meet legal obligations and respond to lawful requests | Whatever is relevant | Compliance with a legal obligation |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and you can object to that processing at any time using the contact details above.
4. Who can see what, inside Stitch
This is the part of a privacy policy that most affects you day to day, so we have set it out in full.
Your profile. Your name, username and profile photo are visible to other Stitch users who can find you, which means people you are friends with, people in your groups, and other guests at events you have said yes to. Your bio is visible in the same way. Your phone number is never displayed to other users. Your email address is never displayed to other users.
Your RSVPs. When you respond to an event, the host and co-hosts see your name, profile photo, your answer, and the number of guests you are bringing. Other guests can see the same, unless the host has limited the guest list. If the host requires approval, they see your response while it is pending.
Hosts do not get your phone number. A host cannot see, export or download the phone numbers or email addresses of their guests through Stitch. This is deliberate. It also means hosts cannot add you to a mailing list off the back of an RSVP.
Groups. Members of a group can see the other members, the group’s events, and anything posted in it.
Events with a public or link visibility setting. If a host sets an event so that anyone with the link can see it, then anyone with that link can see the event details and, depending on the host’s settings, the guest list. Bear that in mind before saying yes to something you would rather not be listed on.
Your own control. You can edit or delete your profile fields, delete your comments, change or withdraw an RSVP, and leave a group at any time.
5. Who we share it with
We share personal data with a small number of service providers who process it on our instructions and are contractually barred from using it for their own purposes:
- Amazon Web Services (AWS), our hosting, database, file storage and content delivery provider. Data is stored in the AWS Ireland region (
eu-west-1). - Twilio, which delivers the SMS verification code when you sign in. Twilio receives your phone number and your IP address for that purpose.
- AWS Location Service, which returns venue suggestions when a host searches for a place. It receives the search text, not your identity.
Beyond those, we will disclose personal data only where we are legally required to, where it is necessary to establish or defend a legal claim, where it is needed to protect someone’s vital interests or prevent serious harm, or to a buyer if our business is sold, in which case we will tell you before your data is transferred and this policy will continue to apply until it is replaced.
We do not sell personal data. We do not share it for cross-context behavioural advertising. We do not disclose it to data brokers or advertising networks.
6. Where your data is stored, and international transfers
Our servers, databases and file storage are all in Ireland, within the European Economic Area. Our content delivery network serves static files such as images from locations around the world.
Twilio is a US company and processes your phone number in the United States. That transfer is covered by the UK International Data Transfer Addendum to the European Commission’s standard contractual clauses, together with Twilio’s own supplementary safeguards. You can ask us for details of the safeguards in place.
7. Cookies and local storage
We do not use advertising, analytics or tracking cookies, so Stitch has no cookie consent banner. What we do use is:
| What | Type | Purpose | How long |
|---|---|---|---|
| Session cookie | Cookie | Keeps you signed in | 30 days |
| Session record | Local storage | Holds your signed-in identity in the browser | Until you sign out |
| Theme preference | Local storage | Remembers light or dark mode | Until you clear it |
| Recent searches | Local storage | Shows what you last searched for | Until you clear it |
| Event view state | Local storage and session storage | Remembers where you were on an event page | Until you clear it or close the tab |
The session cookie and session record are strictly necessary to provide a service you have asked for, so they do not require consent. Theme preference and recent searches are conveniences that store nothing beyond your own choices on your own device, and you can clear them at any time by clearing site data in your browser. If we ever add analytics, we will ask for your consent before it runs, and we will update this table.
8. How long we keep things
- Your account and profile: until you delete your account.
- After you delete your account: we remove your profile, phone number and personal details within 30 days. Events you hosted, and comments you posted, may remain visible to other users in a de-identified form so that other people’s records of their own social lives are not damaged by your departure. Tell us if you want your past content removed as well and we will do it.
- Session cookies and records: 30 days from sign-in.
- Notifications: 90 days, then automatically deleted.
- Security and abuse logs: up to 12 months.
- Anything we are legally required to keep: for as long as the law requires.
9. How we protect it
Traffic is encrypted in transit. Data is encrypted at rest by our hosting provider. Access to production systems is limited to people who need it. Uploaded files are stored with size limits and restricted, time-bound upload permissions rather than open write access.
We are a small team and we will not pretend that any service is impossible to breach. If a breach happens that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office within 72 hours and tell you directly where the law requires it.
10. Age
Stitch is for people aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has an account, email us and we will delete it.
11. Your rights
If you are in the UK or the EEA, you have the right to:
- Access the personal data we hold about you, and get a copy.
- Rectify anything inaccurate, most of which you can do yourself in the app.
- Erase your data, subject to the retention points in section 8.
- Restrict or object to processing, including any processing based on our legitimate interests.
- Portability, meaning a copy of the data you gave us in a machine-readable format.
- Withdraw consent at any time where we relied on it, without affecting what came before.
To exercise any of these, email [privacy@YOURDOMAIN]. We will not charge you or make you justify the request. You can also delete your account yourself in the app, which triggers the erasure process in section 8.
Complaints. If you think we have handled your data badly, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office, the UK regulator, at ico.org.uk or on 0303 123 1113. If you are in the EEA, you can complain to your own national supervisory authority.
12. If you are in the United States
Stitch is operated from the United Kingdom, and UK law governs how we handle your data. Some US states give their residents additional rights, and we extend the following to all US users regardless of state:
- Notice of collection. The categories we collect are identifiers (phone number, name, username, email, IP address), personal records (profile photo, bio), commercial information about events you attend, internet activity limited to your use of Stitch, and approximate coarse location only in so far as an event venue you choose reveals one. We collect them for the purposes in section 3 and keep them for the periods in section 8.
- No sale, no sharing. We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined under the California Consumer Privacy Act and similar state laws. We have not done so in the preceding 12 months. Because we do not, there is nothing to opt out of, and we honour Global Privacy Control signals as a matter of course.
- No sensitive information use. We do not use or disclose sensitive personal information for any purpose that would require an opt-out.
- Your rights. You may request access, deletion, correction, and a portable copy, using the contact details above. We will not discriminate against you for exercising any of them. You may use an authorised agent, and we may ask you to verify the request through the phone number on your account.
13. Changes to this policy
If we change this policy materially, we will tell you in the app or by message before the change takes effect, and update the date at the top. Continued use after that means the new version applies. Older versions are available on request.
14. Contact us
[COMPANY LEGAL NAME] [REGISTERED ADDRESS] [privacy@YOURDOMAIN]