Privacy Policy
Last updated: 17 August 2026
This policy explains how Nookyard (“we”, “us”) handles your personal data when you apply for and use membership. We aim to collect only what we need to run the club.
1. Who is responsible (controller)
The data controller is VPG Concept Studio SRL, Strada Radu Boiangiu, Nr. 4-6, Bloc 42S, Sc. B, Et. 1, Ap. 31, București, Sector 1, VAT/fiscal code (CUI) RO36592698. For any privacy question or to exercise your rights, contact privacy@nookyard.club.
2. What we collect
- Application data: your name, email, and the answer you submit when applying.
- Account & profile: email, display name, optional sign-in provider or uploaded profile photo, bio, LinkedIn/website links, and, for founders/guests, a phone number. Your email, bio and website are shown only to you and admins. Your display name and profile photo are shown to you and admins, and to other eligible Nookyard members alongside your reservations only if you turn that on — see §2a.
- 2a. Community visibility (your choice): by default, other members cannot see who you are when you reserve. If you choose to make your reservation presence visible, other eligible Nookyard members may see your display name and profile photo next to the days you have reserved. Your LinkedIn profile is shown only if you separately enable that second option. Either way, the number of members expected on a day may include you — that count never identifies anyone who has not chosen to be visible. You can change this preference at any time in Settings, and it takes effect immediately.
- 2b. The Nookyard member community (members only): the club runs a members-only community inside the app. It has three parts: a member directory, a member profilefor each member, and a Feed — a noticeboard where members post what they are working on or what they need help with, and reply to each other.
- Your community profile. It shows your display name, profile photo, and the things you have chosen to write about yourself in Settings — what you do, your domain, a short bio, what you are looking for, what you can help with, and your LinkedIn or website if you added them. It is visible by default to other eligible Nookyard members. It is not visible on the open internet and it is not visible to guests, to day-pass holders, or to anyone who is not a current member. You can set it to private at any time in Settings, and that takes effect immediately.
- A private profile is not an anonymous account. If you set your profile to private, other members can no longer open it or find you in the directory — but anything you choose to publish in the Feed still carries your display name and photo, because that is what publishing something to the club means. Hiding your profile hides the page about you; it does not make the things you say unattributed.
- The Feed. Posts, comments, and “I can help” responses are visible to eligible members only, and to no one else. What you write is your own text and we do not use it for anything other than showing it to the members it was addressed to.
- Reporting and moderation. Any member can report a post or a comment. A report records who reported what, and is readable only by Nookyard staff — never by the person who was reported. If staff remove something, the author is told that it was removed and why, from a fixed list of reasons, and can ask for the decision to be reviewed by a person. A review request records what you write in it, and staff can see it. Neither the author nor anyone else is ever told who reported them.
- Notifications. Community activity that concerns you — a reply to your post, someone offering help, a moderation decision, the outcome of a review — is written to your in-app inbox.
- No ranking, no profiling, no AI. The Feed is in chronological order and nothing else. There is no algorithm deciding what you see, no scoring of members, no matching or recommendation of people to each other, and no artificial intelligence used anywhere in the community — not to rank, not to moderate, not to select who may join, and not to generate content.
- These are four different questions. Whether your name appears beside your reservations (§2a), whether other members can open your community profile (this section), what you choose to publish in the Feed, and whether you have a public page on the open internet (§2c) are four separate choices. Answering one never changes another.
- 2c. Your public page (off by default): separately from everything above, you may choose to publish a page about yourself on the public internet at nookyard.club. That is an explicit opt-in, it is off unless you turn it on, and it is the only one of these settings that shows anything to people who are not members. You can unpublish it at any time and it stops being served immediately.
- Coffee preferences: your drink, milk, and preferred time (operational, for the counter).
- Activity: reservations (day & slot), venue check-ins/presence (when you scan at the venue), and no-show records derived from reservations vs. presence.
- Billing & payments: your payment status, plan and price, billing cycle, subscription period dates, and your Stripe customer, payment and subscription identifiers. For day passes, we also record the visit date you select and the amount paid. For a payment we cannot match automatically, we also process the email address we receive from Stripe, solely to match the payment to a membership or day pass. Your card details never reach us, they are handled entirely by Stripe (see §5).
- Billing details (invoice identity): before a membership payment can go ahead we ask who is being billed, and in which country. We invoice in Romania and Italy, and the country decides which fields apply. If you are billed as an individual, we collect your full name and a billing address: street address, city and postcode in both countries, and the county as well for a Romanian address. If you are billed as a company, we collect the company name, whether it is VAT-registered, and the company’s tax identifier, which is the CUI/fiscal code in Romania and the VAT number (Partita IVA) in Italy. For a Romanian company we also collect the trade-register number and the form of organisation you declare, neither of which exists for an Italian company, so for an Italian company neither is asked for nor stored. We do not ask for your CNP, an Italian codice fiscale or any other national identity number, an identity-card number, or any bank/IBAN details, and we have no reason to.
- Technical: standard security signals from Firebase App Check / Google reCAPTCHA (see §5), and, only with your consent, analytics data (see §4).
- Anti-abuse (application form): when you submit the application form we store a hashed (pseudonymised) form of your IP address, never your raw IP, solely to rate-limit submissions and prevent spam/abuse (see §3 and §6).
3. Why we use it & legal bases
- To provide membership (accounts, reservations, check-in, the member directory shown to other members), performance of a contract (GDPR Art. 6(1)(b)).
- To take payment (identifying who is being billed, completing the checkout you asked for, and correcting billing mistakes), performance of a contract or steps taken at your request before one (Art. 6(1)(b)).
- To keep the evidence a payment needs — matching and reconciling payments, and being able to show what was charged and to whom. Where a particular record must be kept to satisfy an accounting or tax obligation, we rely on that legal obligation (Art. 6(1)(c)) for that record and for as long as the obligation lasts; where we keep something to resolve a payment dispute or to establish or defend a legal claim, we rely on our legitimate interests (Art. 6(1)(f)). Not every field we hold is an accounting document, and we do not treat it as one.
- To run and protect the club (capacity, the no-show policy, anti-abuse/security, including rate-limiting the application form using a hashed IP address), our legitimate interests (Art. 6(1)(f)).
- Analytics (Microsoft Clarity, Google Analytics 4), your consent (Art. 6(1)(a)); you can withdraw it anytime.
When billing details are needed, and when they are not. We ask for them when a membership payment is about to happen: starting a membership subscription, reserving a membership whose first charge is scheduled for a later date, or upgrading from a day pass to membership. Buying or using an ordinary day pass does not require billing details — you can book, pay for and use a day pass without ever filling that form in. If you are a day-pass guest who wants to become a member, you may provide them voluntarily as part of that upgrade.
How we keep them. Your billing details are stored separately from your member profile, are not part of the profile other members or staff can see, and cannot be read by the app directly — only specific authorised server functions can reach them. What we pass on to Stripe is the name and address needed to bill you; a company’s fiscal identifiers stay with us, in either country. For a Romanian company those are the CUI, the VAT status, the trade-register number and the declared form of organisation; for an Italian company they are the VAT number and the VAT status.
Why an old record does not change when you edit. When a payment actually happens, we keep a copy of the billing details as they stood at that moment, attached to that transaction. Later edits do not rewrite it — otherwise a record of a past payment would silently start describing a different customer. For the same reason, once a payment has been made against your details the ordinary edit form closes. Your details are still yours to correct: if they change — you move, you rename, your VAT registration changes, or something was entered wrongly — you can update them from your settings. We ask what changed, record that you made the change and when, and limit how often it can be done. The updated details apply to future invoices only; the record kept with a past payment is not rewritten. If a correction cannot wait, write to privacy@nookyard.club and an administrator can help — and nobody at Nookyard can change your card or payment method.
What we do not do with them. We do not use billing details for marketing, advertising, profiling, credit or eligibility scoring, or to decide who appears in the member directory. Collecting them is also not, by itself, Romanian fiscal invoicing: we do not currently issue numbered invoices automatically, compute VAT, or send anything to e-Factura or an external accounting provider.
4. Cookies & analytics
One security cookie loads before you choose, and it is not analytics. Every page of this site is protected by Google reCAPTCHA through Firebase App Check, which is what stops automated abuse of the application form, the sign-in and the club’s data. It sets a _GRECAPTCHA cookie from google.com, and it does so before the cookie banner is answered, because it is a security measure for a service you asked for rather than a measurement of you. It is not used to profile you, it is not shared with us as a browsing history, and it is not used for advertising. Nothing analytics-related — no Microsoft Clarity, no Google Analytics — loads until you accept.
Essential storage (keeping you signed in, and remembering your cookie choice) is always active and needed for the site to work. Non-essential analytics load only after you accept in the cookie banner, you can change or withdraw your choice anytime via “Cookie settings” in the footer.
Microsoft Clarity includes session recording: with your consent it captures interactions (clicks, scrolls, mouse movement, page navigation) to produce heatmaps and replays that help us improve the site. It does not capture your passwords. Google Analytics 4 measures aggregate usage; we run it with Google Consent Mode (default denied, granted only on your acceptance) and IP anonymisation.
| Category | Purpose | Basis |
|---|---|---|
| Essential (auth/session, consent choice) | Sign-in, security, remember your cookie choice | Necessary / legitimate interest |
Security (Google reCAPTCHA / Firebase App Check, _GRECAPTCHA) | Abuse and bot protection for forms, sign-in and data access | Necessary / legitimate interest |
| Microsoft Clarity | Session replay & heatmaps | Consent |
| Google Analytics 4 | Aggregate usage analytics | Consent |
5. Who we share data with (processors)
We don’t sell your data. We use a small set of providers who process it on our behalf:
- Google Firebase (Authentication, Firestore, Hosting), core platform. Our database and functions run in europe-west1 (EU, Belgium). Google is a US company; international transfers rely on standard safeguards (EU Standard Contractual Clauses).
- Google reCAPTCHA (via Firebase App Check), security/anti-abuse, applied separately from analytics consent as a legitimate-interest security measure.
- Resend, sending transactional emails (e.g. your approval/first-login invite).
- Microsoft Clarity, analytics/session replay (only with consent).
- Google Analytics 4, analytics (only with consent).
- Stripe, payment processing for paid memberships (including founding memberships) and day passes. Stripe processes your card and billing details on its own infrastructure, we receive payment confirmations and the billing data described in §2, never your card number.
6. Retention & deletion
You can delete your account anytime from Settings. When you delete, we free your seat, cancel your upcoming reservations, and remove your personal profile data(name, profile email, phone, links, coffee preferences) and your sign-in account. For integrity we keep a minimal anonymised record (a “tombstone”) and your past activity is retained as anonymised history rather than erased instantly. Billing details and records of payments you already made are treated differently — see the list below.
How long we keep things:
- Active members: for as long as your membership is active.
- Deleted accounts: the minimal tombstone is kept for up to 90 days, then hard-purged. This hard-purge is currently performed manually by an administrator on a periodic basis, there is no automated job yet.
- Applications not approved: kept until we’ve made the intake decision plus a short period, and removed within 90 days of that decision.
- Anti-abuse (rate-limiting) data: the hashed IP used to limit application submissions is transient, it applies within a short rolling window (about an hour for network-level limiting, 24 hours per email) and the underlying counters are cleared periodically (currently manually). We never store your raw IP address.
- Billing details and transaction evidence: deleting your account does not automatically delete all billing records or the evidence attached to payments you already made. Some of it may be kept after your account closes, but only so far and for as long as it is genuinely needed — to meet legal, accounting or tax obligations, to resolve a payment or subscription problem, or to establish or defend a legal claim. Different records can have different periods, because the obligation behind each one differs. Where none of those purposes still applies, the information should not be kept. Deleting your account stops future billing; it does not erase the record of a payment that already happened.
- Payment review records: the limited technical records we keep to match and reconcile individual payment events are automatically deleted after 90 days. That period applies to those event records only, not to your billing details or to the evidence kept with a payment.
- The member community, when you delete your account:
- Your community profile is deleted, and you disappear from the member directory immediately.
- Your Feed posts and comments have their text and any link removed, and they stop being shown to members. The empty row is kept only so that replies other members wrote underneath are not destroyed along with your account; your name is replaced by “Former member” and the identifier linking your posts to each other is removed, so what is left cannot be traced back to you or joined together.
- Your “I can help” responses are deleted outright.
- Reports you filed are deleted. Reports other people filed about your content may be kept where they explain a moderation decision that still stands, but they no longer identify you.
- Your in-app notifications are deleted.
If you have an active paid subscription, deletion takes effect at the end of your current subscription period, and you keep access until then.
7. Your rights
Under the GDPR you can request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interests; where we rely on consent, you can withdraw it anytime (without affecting prior processing). Email privacy@nookyard.club. You may also lodge a complaint with the Romanian supervisory authority (ANSPDCP).
One limit worth stating plainly: a request to delete can be narrower than it sounds. We will delete your account and community data as described in §6, but where a billing or transaction record must still be kept for a legal, accounting or tax obligation, or to resolve a payment issue or a legal claim, we keep that record for as long as the reason lasts and no longer. If that applies to you we will say so when we answer, and which purpose it rests on.
8. Changes
We may update this policy; material changes will be reflected here with a new date.