← Back

Privacy Policy

Last updated: July 14, 2026

1. Who we are

PlusOne is operated by PlusOneHUB OÜ, a company registered in Estonia.

We are the data controller for the personal data described in this policy. That means we decide why and how your data is used, and we are responsible for protecting it.

2. What data we collect

2.1 Data you give us

DataWhy we need itRequired?
Email addressTo create your account and log you inYes
Password (encrypted)To secure your accountYes
NameSo others know who they're meetingYes
Birth yearTo confirm you are 18+ and show your approximate ageYes
GenderTo help others find suitable companionsOptional ("Prefer not to say")
Location (city, country)To show you people and events near youYes
BioTo help others get to know youOptional
Interests (up to 10)To match you with relevant people and eventsYes
"Looking for"To show what kind of company you wantYes
Photos (up to 5)To help build trustOptional
Social media linksTo help others verify you're realOptional
Language preferenceTo show the app in your languageYes

2.2 Data you create by using PlusOne

  • Plans you post (including Skill Swap posts)
  • Invitations you send and receive
  • Messages you send in conversations
  • Events you mark as "Interested" (private — only you can see these)
  • Reports and blocks you submit

2.3 Data we collect automatically

  • Log data: IP address, browser type, device type, timestamps. Used for security and to prevent abuse.
  • Profile views: ONLY recorded if you have switched on "Share profile views". If that setting is off, we do not record them at all.

2.4 Payment data

If you subscribe to PlusOne Plus, payments are processed by Stripe. We never see or store your card details. Stripe sends us only your subscription status. See Stripe's privacy policy.

2.5 What we do NOT collect

We deliberately do not collect:

  • Your national identity number (isikukood) or equivalent
  • Your exact GPS location or movement history
  • Criminal record or background check data
  • Special category data (health, religion, political views, sexual orientation, ethnicity) — please do not put such information in your bio

3. Why we use your data (legal bases under GDPR Art. 6)

What we doWhyLegal basis
Show your profile to other membersTo let people find companionsContract (Art. 6(1)(b)) — this is the service you signed up for
Deliver your messages and invitesCore serviceContract
Match you with relevant eventsCore serviceContract
Process your subscription paymentTo provide PlusContract
Review reports, block abusive users, moderate contentTo keep members safeLegitimate interest (Art. 6(1)(f)) and legal obligation (DSA)
Detect fraud and abusePlatform securityLegitimate interest
Record profile viewsOptional featureConsent (Art. 6(1)(a)) — off by default, you switch it on
Send you marketing emailsTo tell you about PlusOneConsent — opt-in only, unsubscribe anytime
Keep records of reports and legal requestsTo comply with the lawLegal obligation (Art. 6(1)(c))

4. Who can see your data

4.1 Other PlusOne members

  • If your profile is Public: your name, age, city, photo, interests and "looking for" are visible to all signed-in members. Your bio is visible when they open your profile.
  • If your profile is Private: you do not appear in the People tab for strangers. Only people you have already connected with can see you.
  • Your messages are visible only to the people in that conversation.
  • Events you mark "Interested" are visible to nobody but you.
  • Plans you post are public to all signed-in members — that's the point of posting them.

4.2 Service providers (data processors)

We share data only with providers who help us run PlusOne. They are contractually bound (GDPR Art. 28) and cannot use your data for their own purposes.

ProviderWhat they doWhereSafeguard
SupabaseDatabase and file storageEUGDPR Art. 28 Data Processing Agreement
StripePayment processingEU / USAEU Standard Contractual Clauses
LovableApp hostingEUGDPR Art. 28 Data Processing Agreement
Email providerSending transactional and notification emailsEUGDPR Art. 28 Data Processing Agreement

4.3 Authorities

We may disclose data to police or authorities where legally required, or where we believe in good faith that there is a serious risk to someone's life or safety (DSA Art. 18).

4.4 We never sell your data

We do not sell, rent or trade your personal data. We do not run behavioural advertising.

5. How long we keep your data

DataRetention
Your profile and contentUntil you delete your account
MessagesUntil you delete your account, or the conversation is deleted
Reports and blocks2 years after resolution — needed for safety and legal defence
Account deletion records30 days — to prevent immediate re-registration by banned users
Payment and invoice records7 years (Estonian accounting law)
Log data90 days

When you delete your account, we permanently remove your profile, photos, plans, invites, messages and saved events. Some records may be kept where the law requires it (see above).

6. Your rights (GDPR Chapter 3)

You have the right to:

  • Access — get a copy of the data we hold about you
  • Rectify — correct anything that's wrong (you can edit your profile directly)
  • Erase — delete your account and data ("right to be forgotten")
  • Restrict — ask us to pause processing while a dispute is resolved
  • Port — get your data in a machine-readable format to take elsewhere
  • Object — object to processing based on legitimate interest
  • Withdraw consent — at any time, for anything based on consent
  • Not be subject to automated decisions — we do not make automated decisions with legal effects about you

How to exercise these rights: Email privacy@plusone.ee. We will respond within one month (GDPR Art. 12(3)).

You can delete your account yourself at any time from the You tab.

Right to complain: If you're unhappy with how we handle your data, you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) — www.aki.ee — or the authority in your own country.

7. How we protect your data

  • Passwords are hashed, never stored in plain text
  • All traffic is encrypted (HTTPS/TLS)
  • Database access is controlled by row-level security — members can only read data they're allowed to see
  • Discount codes and admin functions are protected at the database level
  • Access to production data is limited to authorised personnel

No system is perfectly secure. If a data breach occurs that puts you at risk, we will notify the supervisory authority within 72 hours and inform you without undue delay (GDPR Arts. 33–34).

8. Cookies and tracking

PlusOne uses only essential cookies and local storage needed to keep you logged in and remember your language choice. We do not use advertising or third-party tracking cookies.

9. Children

PlusOne is strictly for adults aged 18 and over. We do not knowingly collect data from anyone under 18. If we discover that a user is under 18, we will delete the account immediately.

If you believe a minor is using PlusOne, please report it to safety@plusone.ee.

10. Changes to this policy

If we make material changes, we will notify you in the app and by email at least 30 days before they take effect. Continuing to use PlusOne after that means you accept the new policy.

11. Contact

Questions? Email privacy@plusone.ee for privacy matters, or info@plusone.ee for anything else.