Privacy Policy
Last updated: 1 August 2026
This policy explains how Nookyard (“we”, “us”) handles your personal data when you apply for and use membership. We aim to collect only what we need to run the club.
1. Who is responsible (controller)
The data controller is VPG Concept Studio SRL, Strada Radu Boiangiu, Nr. 4-6, Bloc 42S, Sc. B, Et. 1, Ap. 31, București, Sector 1, VAT/fiscal code (CUI) RO36592698. For any privacy question or to exercise your rights, contact privacy@nookyard.club.
2. What we collect
- Application data: your name, email, and the answer you submit when applying.
- Account & profile: email, display name, Google profile photo (shown to you and admins), bio, LinkedIn/website links, and, for founders/guests, a phone number.
- Coffee preferences: your drink, milk, and preferred time (operational, for the counter).
- Activity: reservations (day & slot), venue check-ins/presence (when you scan at the venue), and no-show records derived from reservations vs. presence.
- Billing & payments: your payment status, plan and price, billing cycle, subscription period dates, and your Stripe customer, payment and subscription identifiers. For day passes, we also record the visit date you select and the amount paid. For a payment we cannot match automatically, we also process the email address we receive from Stripe, solely to match the payment to a membership or day pass. Your card details never reach us, they are handled entirely by Stripe (see §5).
- Billing details (invoice identity): before a membership payment can go ahead we ask who is being billed. If that is you as an individual, we collect your full name and a Romanian address (county, city, street address, postcode). If it is a company, we collect the company name, its CUI/fiscal code, whether it is VAT-registered, its trade-register number and the same address. We do not ask for your CNP, an identity-card number or any bank/IBAN details, and we have no reason to.
- Technical: standard security signals from Firebase App Check / Google reCAPTCHA (see §5), and, only with your consent, analytics data (see §4).
- Anti-abuse (application form): when you submit the application form we store a hashed (pseudonymised) form of your IP address, never your raw IP, solely to rate-limit submissions and prevent spam/abuse (see §3 and §6).
3. Why we use it & legal bases
- To provide membership (accounts, reservations, check-in, the member directory shown to other members), performance of a contract (GDPR Art. 6(1)(b)).
- To take payment (identifying who is being billed, completing the checkout you asked for, and correcting billing mistakes), performance of a contract or steps taken at your request before one (Art. 6(1)(b)).
- To keep the evidence a payment needs — matching and reconciling payments, and being able to show what was charged and to whom. Where a particular record must be kept to satisfy an accounting or tax obligation, we rely on that legal obligation (Art. 6(1)(c)) for that record and for as long as the obligation lasts; where we keep something to resolve a payment dispute or to establish or defend a legal claim, we rely on our legitimate interests (Art. 6(1)(f)). Not every field we hold is an accounting document, and we do not treat it as one.
- To run and protect the club (capacity, the no-show policy, anti-abuse/security, including rate-limiting the application form using a hashed IP address), our legitimate interests (Art. 6(1)(f)).
- Analytics (Microsoft Clarity, Google Analytics 4), your consent (Art. 6(1)(a)); you can withdraw it anytime.
When billing details are needed, and when they are not. We ask for them when a membership payment is about to happen: starting a membership subscription, reserving a membership whose first charge is scheduled for a later date, or upgrading from a day pass to membership. Buying or using an ordinary day pass does not require billing details — you can book, pay for and use a day pass without ever filling that form in. If you are a day-pass guest who wants to become a member, you may provide them voluntarily as part of that upgrade.
How we keep them. Your billing details are stored separately from your member profile, are not part of the profile other members or staff can see, and cannot be read by the app directly — only specific authorised server functions can reach them. What we pass on to Stripe is the name and address needed to bill you; the fiscal identifiers of a company (CUI, VAT status, trade-register number) stay with us.
Why an old record does not change when you edit. When a payment actually happens, we keep a copy of the billing details as they stood at that moment, attached to that transaction. Later edits do not rewrite it — otherwise a record of a past payment would silently start describing a different customer. For the same reason, once a payment has been made against your details the ordinary edit form closes. Your details are still yours to correct: if they change — you move, you rename, your VAT registration changes, or something was entered wrongly — you can update them from your settings. We ask what changed, record that you made the change and when, and limit how often it can be done. The updated details apply to future invoices only; the record kept with a past payment is not rewritten. If a correction cannot wait, write to privacy@nookyard.club and an administrator can help — and nobody at Nookyard can change your card or payment method.
What we do not do with them. We do not use billing details for marketing, advertising, profiling, credit or eligibility scoring, or to decide who appears in the member directory. Collecting them is also not, by itself, Romanian fiscal invoicing: we do not currently issue numbered invoices automatically, compute VAT, or send anything to e-Factura or an external accounting provider.
4. Cookies & analytics
Essential storage (keeping you signed in, and remembering your cookie choice) is always active and needed for the site to work. Non-essential analytics load only after you accept in the cookie banner, you can change or withdraw your choice anytime via “Cookie settings” in the footer.
Microsoft Clarity includes session recording: with your consent it captures interactions (clicks, scrolls, mouse movement, page navigation) to produce heatmaps and replays that help us improve the site. It does not capture your passwords. Google Analytics 4 measures aggregate usage; we run it with Google Consent Mode (default denied, granted only on your acceptance) and IP anonymisation.
| Category | Purpose | Basis |
|---|---|---|
| Essential (auth/session, consent choice) | Sign-in, security, remember your cookie choice | Necessary / legitimate interest |
| Microsoft Clarity | Session replay & heatmaps | Consent |
| Google Analytics 4 | Aggregate usage analytics | Consent |
5. Who we share data with (processors)
We don’t sell your data. We use a small set of providers who process it on our behalf:
- Google Firebase (Authentication, Firestore, Hosting), core platform. Our database and functions run in europe-west1 (EU, Belgium). Google is a US company; international transfers rely on standard safeguards (EU Standard Contractual Clauses).
- Google reCAPTCHA (via Firebase App Check), security/anti-abuse, applied separately from analytics consent as a legitimate-interest security measure.
- Resend, sending transactional emails (e.g. your approval/first-login invite).
- Microsoft Clarity, analytics/session replay (only with consent).
- Google Analytics 4, analytics (only with consent).
- Stripe, payment processing for paid memberships (including founding memberships) and day passes. Stripe processes your card and billing details on its own infrastructure, we receive payment confirmations and the billing data described in §2, never your card number.
6. Retention & deletion
You can delete your account anytime from Settings. When you delete, we free your seat, cancel your upcoming reservations, and remove your personal profile data(name, profile email, phone, links, coffee preferences) and your sign-in account. For integrity we keep a minimal anonymised record (a “tombstone”) and your past activity is retained as anonymised history rather than erased instantly. Billing details and records of payments you already made are treated differently — see the list below.
How long we keep things:
- Active members: for as long as your membership is active.
- Deleted accounts: the minimal tombstone is kept for up to 90 days, then hard-purged. This hard-purge is currently performed manually by an administrator on a periodic basis, there is no automated job yet.
- Applications not approved: kept until we’ve made the intake decision plus a short period, and removed within 90 days of that decision.
- Anti-abuse (rate-limiting) data: the hashed IP used to limit application submissions is transient, it applies within a short rolling window (about an hour for network-level limiting, 24 hours per email) and the underlying counters are cleared periodically (currently manually). We never store your raw IP address.
- Billing details and transaction evidence: deleting your account does not automatically delete all billing records or the evidence attached to payments you already made. Some of it may be kept after your account closes, but only so far and for as long as it is genuinely needed — to meet legal, accounting or tax obligations, to resolve a payment or subscription problem, or to establish or defend a legal claim. Different records can have different periods, because the obligation behind each one differs. Where none of those purposes still applies, the information should not be kept. Deleting your account stops future billing; it does not erase the record of a payment that already happened.
- Payment review records: the limited technical records we keep to match and reconcile individual payment events are automatically deleted after 90 days. That period applies to those event records only, not to your billing details or to the evidence kept with a payment.
If you have an active paid subscription, deletion takes effect at the end of your current subscription period, and you keep access until then.
7. Your rights
Under the GDPR you can request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interests; where we rely on consent, you can withdraw it anytime (without affecting prior processing). Email privacy@nookyard.club. You may also lodge a complaint with the Romanian supervisory authority (ANSPDCP).
One limit worth stating plainly: a request to delete can be narrower than it sounds. We will delete your account and community data as described in §6, but where a billing or transaction record must still be kept for a legal, accounting or tax obligation, or to resolve a payment issue or a legal claim, we keep that record for as long as the reason lasts and no longer. If that applies to you we will say so when we answer, and which purpose it rests on.
8. Changes
We may update this policy; material changes will be reflected here with a new date.