Privacy Policy
Effective date: September 11, 2026
Last updated: September 11, 2026
Summit Software & People S.R.L.(“VillageLink,” “we,” “us,” or “our”) operates the VillageLink mobile application (the “App”). This Privacy Policy explains what information we collect, how we use it, and the choices you have.
It covers the App only. The villagelink.social website — the waiting list, the support form and its page-view counting — is described separately in the Website Privacy Notice.
By creating an account or using the App, you agree to the collection and use of information as described in this policy.
Table of Contents
1. Information We Collect
1.1 Account & Profile Information
When you create an account, we collect:
- Email address (required, used for login and account recovery)
- Full name
- Profile photo (optional — if you choose to upload one from your camera or photo library)
- Bio
- Dietary restrictions (optional, free text/tags)
- General care instructions / notes you choose to add to your profile
- Role(s) within the app (e.g., village owner, helper/contributor)
- The version of the Terms of Service you accepted, and when. The App shows the Terms before you create an account or sign in, and records which version was in force at the time.
1.2 Village & Community Information
- Village name, description, and a shareable invite link/slug
- Membership status (pending, active, declined, removed)
- Optional free-text notes describing how you know another member
- Whether you are a “lead villager” for a given village
1.3 Task / Help-Request Information
When you or others in your village create or interact with tasks (requests for help), we collect:
- Task title, description, category, and requested date/time window
- Task status (open, claimed, done, failed)
- The identity of the person who created the task and the person who claims it
- A note sent to the village owner by the helper when a task could not be completed
- “Gratitude” reactions and optional thank-you notes sent between village members after a task is completed
1.4 Referral / Invitation Information (“Vouches”)
If you invite someone to your village who does not yet have an account, we collect the name and email address you provide for that person so we can extend an invitation on your behalf. The invited person can decline or ignore this invitation at any time. If you received an invitation and do not want us to hold your details, write to contact@villagelink.social and we will remove them.
1.5 Reports and Moderation Records
If you report content, or someone reports content of yours, we collect:
- The reason chosen, and any detail added by the person reporting
- A copy of the reported content, kept so the report stays reviewable after the original is edited or deleted
- The decision we reach, any internal note recording why, and the notice we send to the person affected
- Whether an account is suspended, until when, and on what grounds
Blocking another member also files a report automatically, so that we can see that it happened.
1.6 Technical & Diagnostic Information
We use Sentry for crash reporting and performance monitoring. This may include device type, operating system version, app version, and error/stack trace data. We use Mailtrap to deliver sign-in codes, confirmation and password-reset email, which means it receives your email address and the contents of those messages. The App is configured not to send personal identifiers to Sentry: reports are stripped of your name, email address and IP, console output is discarded, and content you have typed is removed before a report leaves your device.
1.7 Locally Stored Data
The App caches some data on your device so it loads quickly and works briefly offline. This local cache is not a separate data collection — it mirrors data already described above. It is not cleared when you sign out: cached entries expire after at most seven days, and removing the App removes them immediately.
1.8 Information We Do NOT Collect
The App does not access or collect:
- Your device's precise or approximate location
- Your contacts
- Advertising identifiers, and we do not serve third-party ads
- Push notification tokens (the App does not currently send push notifications)
1.9 Free-Text Fields
Nothing in the App asks you for health, medical, religious or disability information, and there is no field for any of it.
But your bio, care instructions, dietary notes, village description, task titles and descriptions, failed-task notes and thank-you notes are all free text. You decide what goes in them, and in an app for coordinating care people naturally describe a condition, a recovery, a household routine or an address.
So these fields can end up holding information that data protection law treats as sensitive. That is why our App Store privacy labels declare health information as collected: not because we ask for it, but because we cannot rule out that you have typed it, and we would rather over-declare than understate what the App may hold.
Please put in these fields only what you are comfortable with the members of your village reading, and leave out details about anyone who has not agreed to being described there.
2. How We Use Your Information
We use the information described above to:
- Create and maintain your account
- Let you form, join, and manage “villages” (support networks)
- Let you post, claim, and coordinate help requests (“tasks”)
- Pass on a helper's note when a task could not be completed, and the gratitude reactions and thank-you notes members send after one is done
- Send village invitations on your behalf when you invite someone
- Review reports, decide what to do about them, tell the person affected what we did and why, and handle appeals
- Diagnose crashes and improve app stability and performance
- Communicate with you about your account (e.g., password resets)
We do not sell your personal information, and we do not use your data for third-party advertising.
2.1 The legal bases we rely on
Data protection law requires us to say not only what we do with your data but why we are allowed to:
- To provide the service you asked for (Article 6(1)(b), contract): creating and authenticating your account; villages and join requests; posting, claiming, completing and failing tasks; failed-task notes and thank-you notes; showing your profile to your village; holding dietary needs and care instructions so that helpers can act on them; and sending sign-in, confirmation and password-reset email.
- To keep members safe, and because the law requires it (Article 6(1)(c), legal obligation, together with Article 6(1)(f), legitimate interests): receiving and acting on reports, blocking, removing content, issuing warnings, suspending and terminating accounts, and screening submissions against a list of prohibited terms. The Digital Services Act obliges us to handle reports and to explain our decisions; acting before anyone reports something is our own interest in a platform that is safe to use.
- Because we have a legitimate interest (Article 6(1)(f)): sending an invitation to someone a member proposes, since that person is not the one who gave us their details; recording which version of the Terms you accepted; and crash and performance monitoring.
- Because the law requires it (Article 6(1)(c)): deleting an account and its data when you ask us to.
- Keeping moderation records after an erasure request rests on Article 17(3) — see section 4.
We do not rely on your consent for anything today. We do not profile you, and we do not make automated decisions about you: a moderation decision is made by a person.
3. How Information Is Shared
- Within your village: your name, bio, and task activity are visible to other members of villages you belong to.
- Your profile photo: stored at a web address derived from your account identifier and served without a sign-in, so anyone who has or finds that address can open it. Treat your photo as public rather than private. Replacing it does not change the address — the new image replaces the old one in place. Deleting your account deletes the photo, and the address stops working.
- Service providers: we use Supabase to host our database, authentication, and file storage, Sentry for crash/performance monitoring, and Mailtrap to deliver authentication email. These providers process data on our behalf and are contractually restricted from using it for other purposes.
- Legal requirements: we may disclose information if required by law or to protect the rights, safety, or property of VillageLink, our users, or others. Where content suggests a threat to someone's life or safety, we may report it to law enforcement.
- We do not share your personal information with third parties for their own marketing purposes.
4. Data Retention
Most of what we hold lasts exactly as long as your account. Deleting your account from Profile → Delete Accountremoves your profile, photo, village memberships, tasks, task messages and thank-you notes. If you host a village, it also deletes that village and everything in it, including other members' contributions.
Three things outlast an account, and we would rather say so plainly:
- Reports and moderation decisions. These survive the accounts involved, with the names removed, so that a record of the decision remains. A report also keeps its copy of the content it concerned. We keep these because Articles 16 and 17 of the Digital Services Act require us to handle reports and explain our decisions, and because a member should not be able to erase the record against them by deleting their account.
- An invitation you sent to someone who never joined. This lasts until you delete your account, or until that person asks us to remove it.
- Backups.Deleted data persists in our provider's backups for a limited period before they are overwritten.
Crash reports are kept for a limited period set by our monitoring provider. A suspension lapses on its own at the date it was set to end.
5. Your Choices & Rights
- Access & correction: you can view and edit most of your profile information directly in the App.
- Deletion: you can delete your own account and associated personal data directly in the App, at any time, without contacting support: go to Profile → Delete Account. You'll be asked to confirm your identity (with your password, or a one-time code emailed to you) before the deletion is processed.
- Optional data: profile photo, bio, dietary restrictions, and care instructions are optional — you may use the App without providing them.
5.1 If you are in the EEA or the UK
You have the right to access the personal data we hold about you, to have it corrected, to have it deleted, to receive a copy in a portable form, and to object to or restrict certain processing. Where we rely on your consent, you may withdraw it at any time. Write to contact@villagelink.social and we will respond within one month. You may also complain to your local data protection authority; in Romania that is the ANSPDCP.
An erasure request does not clear the moderation records described in section 4. We rely on Article 17(3) of the GDPR for that, and we will tell you so, and what remains, when we answer.
5.2 If you are in California
You have the right to know what personal information we collect and how we use it, to request a copy of it, to have it corrected, and to have it deleted, and we will not treat you differently for asking. Write to contact@villagelink.social.
We do not sell or share your personal information, and we have not done so. We do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit — we do not use it to infer characteristics about you. The categories we collect are the ones listed in section 1; our sources are you, and other members of your village who post about a task you are part of.
6. Children's Privacy
Our Terms of Service set the minimum age at 13, or higher where the age of digital consent in your country is higher — in the European Union that is generally 16. If you are under 18, you may only use the App with the involvement of a parent or legal guardian. The App asks you to confirm both of these before you create an account or sign in.
VillageLink is not directed to children, and we do not knowingly collect personal information from anyone below the applicable minimum age. Care-coordination tasks involving children (e.g., childcare-related help requests) are entered by adult users about their own family circumstances, not by children themselves. If you believe a child below that age has given us personal information, contact us at contact@villagelink.social so we can remove it.
7. Security
We use reasonable administrative, technical, and physical safeguards to protect your information, including encrypted transport (HTTPS) and access-controlled database policies. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
8. International Data Transfers
Our database, authentication and file storage are hosted in the European Union, in Ireland.
Some of our providers are established outside the European Economic Area, and some process data outside it. This applies to Supabase, which we contract with outside the EEA even though your data is stored in Ireland, and to Mailtrap and Sentry. Where a transfer outside the EEA takes place, it is covered by the Standard Contractual Clauses approved by the European Commission, which form part of our agreement with each of them.
9. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the App or by other means before the changes take effect. The “Last updated” date at the top reflects the most recent revision.
10. Contact Us
If you have questions about this Privacy Policy or how we handle your information, contact us at:
Summit Software & People S.R.L.
Cluj-Napoca, Cluj, Romania
Email: contact@villagelink.social
Online: villagelink.social/support