1. Controllers
This Privacy Policy applies to the coup mobile application and the related services (the “Platform”). Until a legal entity is formally incorporated, the joint controllers within the meaning of Art. 4(7) and Art. 26 GDPR are:
Henry Buchhalla, Sinan Ceviker and Tuan-Dai Do
acting as private individuals under the project name “coup”, based in Groningen, the Netherlands.
Central point of contact for all data protection matters: support@thecoup.app
This Policy has been prepared on the basis of Regulation (EU) 2016/679 (General Data Protection Regulation, “GDPR”) and the Dutch implementing act (Uitvoeringswet AVG). Once a legal entity has been incorporated, this Policy will be updated and the entity will be named as controller.
2. What Data We Process
2.1 Account Data
- Email address and profile name.
- Where you register with a password: your password, stored exclusively as a salted hash. We never store your password in plain text and cannot recover it.
- Where you register using Sign in with Google or Sign in with Apple: the user identifier assigned by the relevant provider, the email address transmitted to us by the provider and, where applicable, the name transmitted by the provider. We do not receive your password for that account. If you use Apple’s “Hide My Email” function, we receive only an anonymised relay address and not your actual email address.
- Profile picture, profile description and interests.
- The status of your email verification, the date on which your account was created and the date of your most recent sign-in.
2.2 Content and Activity Data
- Listings (title, description, photos, category).
- The approximate location of a Listing, for display on the map.
- The city you are in, derived once from your device’s location if you have allowed location access, so that we can show you what is nearby. It is shown in your profile and you can change or clear it at any time.
- Photos you upload. We automatically remove embedded metadata from uploaded images, in particular EXIF geodata, before the image is stored.
- Token balance and token transactions within the Platform.
- Messages exchanged with other users via the chat feature.
- Redemptions of Partner discounts (which discount, when, at which Partner).
- Ratings and reports.
2.3 Technical Data
- Device and access data (device type, operating system, app version, language, IP address, user agent, timestamps and error logs).
- Session data (identifiers of your session and refresh tokens, together with sign-in timestamps). This data keeps you signed in and allows you to end individual sessions.
- The device token for push notifications, issued by the Apple Push Notification service or by Firebase Cloud Messaging. We process this only if you have enabled push notifications.
- Security data for the prevention of abuse and fraud, in particular failed sign-in attempts, rate limit counters and indications of the operation of multiple accounts.
- App error and crash reports (technical error details, such as stack traces and the state of the app at the time of the error), processed via Sentry — see §5.
- Location data only if you actively grant location permission — exclusively to display offers near you. The permission can be revoked at any time in your device settings.
2.4 Usage and Interaction Data
To understand how the Platform is actually used and to decide what to improve next, we record certain actions you take in the app:
- which screens you open;
- the search terms you enter, and searches that return no results;
- which filters you apply;
- which listings and Partner offers were shown to you, and which of them you opened;
- where you begin but do not complete a multi-step process, such as creating a Listing, sending a request, or the initial setup of your account.
Each entry carries the time of the action, the version of the app, the operating system, a session identifier and your account identifier. We record only the actions on a fixed internal list; we do not record the content of your messages, and we do not follow you outside the app or across other providers’ services. This data is used solely to understand and improve how the Platform is used, and is stored on our existing database infrastructure (see §5, Supabase). You can switch it off at any time under Settings → Privacy.
We do not process any payment data, identity document data, or special categories of personal data within the meaning of Art. 9 GDPR. Please also refrain from including such data in listings, profiles or messages.
3. Purposes and Legal Bases
We process your data for the following purposes on the following legal bases:
- Provision of the Platform, account management, facilitation of exchanges and discounts, token system, chat: Art. 6(1)(b) GDPR (performance of the user agreement).
- Making a Listing available at a shareable public link, including the first name shown on that page, when you or another User shares it: Art. 6(1)(f) GDPR (legitimate interest in allowing members to pass on what they find, which is how the Platform reaches new members). The disclosure is limited to the fields listed in §4.2. You may object at any time under Art. 21 GDPR, by deleting the Listing or by contacting us at support@thecoup.app.
- Security and integrity of the Platform, abuse and fraud prevention (e.g. detection of multiple accounts), error analysis: Art. 6(1)(f) GDPR (legitimate interest in a secure, functioning operation).
- Handling of reports of illegal content and moderation decisions: Art. 6(1)(c) GDPR (legal obligation, in particular Regulation (EU) 2022/2065) and Art. 6(1)(f) GDPR.
- Communication regarding your account and material changes to the Platform: Art. 6(1)(b) GDPR.
- Product analytics, in particular understanding usage patterns such as failed searches, filter usage and abandoned Listing creation, in order to improve the Platform: Art. 6(1)(f) GDPR (legitimate interest in understanding and improving the Platform). We use this data only in aggregate for product decisions, never to assess an individual user; you may object at any time under Art. 21 GDPR, and switch the collection off directly under Settings → Privacy.
- Use of location, optional push notifications and any voluntary surveys: Art. 6(1)(a) GDPR (consent, revocable at any time).
- Anonymised or aggregated statistics for the further development of the Platform (e.g. number of redemptions per Partner): Art. 6(1)(f) GDPR; any personal reference is removed as early as possible.
We do not use your data for personalised advertising, do not sell it to third parties, and do not make automated individual decisions with legal effect within the meaning of Art. 22 GDPR.
4. Visibility to Other Users and Partners
coup is a community platform. Certain data is, by design, visible to others:
4.1 Inside the Platform
- Your profile name, profile picture, interests and your active listings are visible to other users.
- The approximate location of your active listings is visible to other users on the map; your exact position is not displayed to other users.
- Messages are visible only to the conversation participants involved.
- When a discount is redeemed, Partners see a confirmation of the redemption as well as aggregated, non-personal statistics on their offers (e.g. number of redemptions per day). Partners do not receive contact details or profile data of individual users from us.
- Your email address is never visible to other users or Partners.
4.2 Links Shared Outside the Platform
The Platform lets you share a Listing, a Partner, a Partner discount or a coup announcement as a link to our website (for example thecoup.nl/l/…). Anyone who receives such a link can open that page without an account and without signing in, and messaging services generate a preview of it automatically. Treat a link you share as public.
- A shared Listing page shows that Listing's title, photo, price in tokens, category and neighbourhood, together with the first name of the person offering it. It does not show a full name, a profile description, an email address or an exact location.
- A shared Partner, discount or announcement page shows business or editorial information only, and contains no personal data of Users.
- Nothing else about you is reachable through these links. Your messages, your redemptions, your token balance, your email address and your other listings are not shown on any public page, and there is no public page that collects a User's listings together.
- The Listing, discount and announcement pages instruct search engines not to index them. Partner pages are indexable, because a Partner is a business that has chosen to be publicly findable and its page shows business information only, with no personal data of Users. The major search engines respect an instruction not to index, but no such instruction can prevent someone who has the link from opening it or passing it on.
- When a Listing expires or you delete it, its page stops showing it.
5. Recipients and Processors
We share your data only to the extent necessary for operating the Platform:
- Supabase Inc., United States — database, authentication, file storage and application hosting (including Usage and Interaction Data, see §2), acting as a processor on the basis of an agreement pursuant to Art. 28 GDPR. All data is stored in the European Union, in the region eu-central-1 (Frankfurt), on infrastructure operated by Amazon Web Services as sub-processor.
- Functional Software, Inc. d/b/a Sentry, United States — error monitoring and crash reporting, used solely to detect and resolve technical issues in the app, acting as a processor on the basis of a data processing agreement pursuant to Art. 28 GDPR. Data storage location: Sentry’s EU region (Frankfurt, Germany).
- Google Ireland Limited and Google LLC — the “Sign in with Google” function, Firebase Cloud Messaging for the delivery of push notifications on Android devices, and — on the website thecoup.nl and only where you have consented — Google Analytics 4 (see §11).
- Apple Inc. — the “Sign in with Apple” function, and the Apple Push Notification service for the delivery of push notifications on iOS devices.
- 650 Industries, Inc. (“Expo”), United States — dispatch of push notifications. Our server does not address your device directly: it hands each notification to Expo’s push service, which forwards it to the systems of Google or Apple named above. The push token of the device the notification is addressed to, and the title and text of the notification itself, pass through that service.
- Strato — dispatch of transactional emails such as registration confirmations and password reset links.
- App store operators (Apple, Google) in the context of app distribution; their data processing is subject to their own privacy policies.
- Authorities or other third parties where we are legally obliged to do so or where this is necessary for the establishment, exercise or defence of legal claims.
Beyond this, your data is not sold, rented out or exchanged.
6. Third-Country Transfers
Your data is stored within the European Economic Area (EEA). However, some of our service providers are undertakings established in the United States, and access to data from the United States — for example in the course of support, maintenance or security operations — cannot be ruled out.
Transfers to Supabase Inc. take place on the basis of the standard contractual clauses of the European Commission pursuant to Art. 46(2)(c) GDPR, as concluded in the data processing agreement we have entered into with that provider.
Transfers to Functional Software, Inc. d/b/a Sentry take place on the basis of the standard contractual clauses of the European Commission pursuant to Art. 46(2)(c) GDPR, as well as Sentry’s self-certification under the EU-U.S. Data Privacy Framework, for the limited cases in which support, maintenance or security operations from the United States cannot be excluded. Core data storage takes place in Sentry’s EU data centre (Frankfurt, Germany).
Transfers to Apple Inc. and Google LLC in connection with authentication, push notifications and — subject to your consent — website analytics take place on the basis of the adequacy decision of the European Commission concerning the EU-US Data Privacy Framework, and, in addition, on the basis of standard contractual clauses.
Transfers to 650 Industries, Inc. (Expo) in connection with the dispatch of push notifications take place on the basis of the standard contractual clauses of the European Commission pursuant to Art. 46(2)(c) GDPR, as incorporated in that provider’s data processing addendum.
You may request a copy of the safeguards in place by writing to the contact address in §13.
7. Retention Periods
We store personal data only for as long as necessary for the stated purposes:
- Account data and content. For the duration of your account. When you delete your account, your profile, your listings and the associated images are anonymised or deleted without delay, and any residual copies contained in our encrypted backups are overwritten in the ordinary course of backup rotation within 30 days at the latest.
- Messages. The content of a conversation remains available to the other participant for as long as that participant’s account exists, so that they retain a record of an exchange they were part of. Once you delete your account, your profile name is replaced in that conversation by a neutral placeholder and can no longer be traced back to you by the other participant.
- Technical logs. A maximum of 90 days, unless a specific security incident requires longer retention in an individual case. Your account identifier is removed from log entries immediately upon deletion of your account. Error and crash reports processed via Sentry are subject to the same 90-day maximum.
- Usage and interaction data (§2.4). A maximum of 90 days, after which the individual entries are deleted or fully aggregated so that no personal reference remains. Search terms are the one exception worth naming: a term is kept beyond 90 days only where at least three different people searched for it on the same day, and it is then kept without any link to who searched for it. Your account identifier is removed from usage data immediately upon deletion of your account.
- Data relating to suspensions and serious violations. Up to 12 months after account deletion, in order to prevent circumvention of suspensions (legitimate interest, Art. 6(1)(f) GDPR). For this purpose we retain an irreversible cryptographic hash of your email address, which allows us to recognise a renewed registration but does not allow us to reconstruct the address itself, together with the reason for and date of the measure.
- Records of the user agreement. Records of the conclusion of the user agreement and of your acceptance of our Terms — comprising an account identifier, the version of the document accepted and the date of acceptance — are retained for 5 years from the end of the calendar year in which the account was deleted, in order to cover statutory limitation periods for contractual claims (verjaringstermijn under Dutch law).
Deletion runs on an automated schedule. Where full deletion is not technically possible at a given moment, we restrict processing of the data concerned in accordance with Art. 18 GDPR until deletion takes place.
8. Your Rights
Under the GDPR, you have the following rights:
- Access to the data processed about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR) — account deletion is available directly in the app
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR)
A copy of your data is also available directly in the app, under Settings → Privacy → “Download my data”. To exercise your rights beyond that, an informal email to support@thecoup.app is sufficient. We will respond without undue delay and in any event within one month of receipt of your request. Where a request is particularly complex, this period may be extended by up to two further months, in which case we will inform you of the extension and the reasons for it within the first month. In practice we aim to respond within five business days.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority is in particular the Dutch supervisory authority: Autoriteit Persoonsgegevens, Postbus 93374, 2509 AJ Den Haag, the Netherlands, www.autoriteitpersoonsgegevens.nl. You may also contact the supervisory authority of your country of residence.
9. Data Security
We take technical and organisational measures pursuant to Art. 32 GDPR to protect your data against loss, misuse and unauthorised access. These include in particular:
- encrypted transmission of all data between the app and our servers (TLS);
- storage of passwords exclusively as salted hashes, so that they cannot be reconstructed even by us;
- encryption of data at rest at the storage layer of our hosting provider;
- row-level access rules in the database, which enforce for each individual record which account is permitted to read or modify it;
- restriction of administrative access to the smallest possible number of persons, secured by multi-factor authentication;
- regular backups and monitoring of error and security events.
No system is completely secure. In the event of a personal data breach that is likely to result in a high risk to you, we will inform you and the competent supervisory authority in accordance with Arts. 33 and 34 GDPR.
10. Minimum Age
The Platform is directed at persons aged 18 or over. When registering, you confirm that you have reached the age of 18. Persons under 18 are not permitted to use the Platform. If we become aware that data of a person under 18 has been processed without a valid basis, we will delete it without delay. If you are a parent or guardian and believe that a person under 18 is using the Platform, please contact us at the address in §13.
11. Cookies, Analytics and Tracking
11.1 In the App
The app does not use any third-party advertising or tracking technologies. We do not create user profiles for advertising purposes, we do not pass any data to advertising networks, and we do not track you across other providers’ services.
The app uses Sentry for error monitoring and crash reporting, and records Usage and Interaction Data (such as search terms, filter usage and Listing-creation abandonment) in order to understand and improve how the Platform is used. The details are in §2.4, the legal basis in §3 and the retention period in §7. Apart from the error reports that go to Sentry, this measurement is carried out entirely on our own database infrastructure in the European Union (see §5); no analytics provider is involved. None of this data is shared with advertising networks, combined with advertising identifiers, or used to build advertising profiles. You can switch the usage measurement off at any time under Settings → Privacy.
Technically necessary local storage on your device — in particular the session token that keeps you signed in — is used exclusively to provide the app and is stored in the protected storage area of your operating system.
11.2 On the Website thecoup.nl
Since August 2026, our website uses Google Analytics 4, a web analytics service operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. We use it for one purpose only: to understand which pages are read and how visitors find us, so that we can improve the site. We do not use it for advertising, remarketing or profiling, and the advertising-related consent signals remain permanently switched off.
Where you consent, Google Analytics stores cookies on your device and transmits data about your visit to Google:
- the pages you view on thecoup.nl and the time of your visit;
- the approximate region derived from your IP address (Google does not store the IP address itself);
- the website or search engine you came from, and the campaign parameters in the link you followed, if any;
- technical information about your device, browser, operating system and screen size.
The cookies used are named _ga (a randomly generated identifier that distinguishes returning visits) and _ga_ followed by the identifier of our measurement stream (it holds the state of the current session). Both are stored for a maximum of 24 months.
Google acts as our processor under Art. 28 GDPR on the basis of the Google Ads Data Processing Terms. Data may be transferred to Google LLC in the United States; the safeguards for that transfer are described in §6.
11.3 Analytics Only With Your Consent
Google Analytics is switched off by default. Neither the Google Analytics script nor any analytics cookie is loaded before you have given your consent in the banner shown on your first visit — if you decline, no connection to Google's servers is established at all.
The legal basis for storing and reading information on your device is your consent under Art. 11.7a of the Dutch Telecommunications Act (Telecommunicatiewet), and for the subsequent processing of your data your consent under Art. 6(1)(a) GDPR.
You can withdraw your consent at any time with effect for the future, and just as easily as you gave it: select Cookie settings at the bottom of any page and choose “Decline”. Withdrawing your consent also deletes the Google Analytics cookies that have already been set on your device. The lawfulness of the processing carried out up to that point is not affected.
We ask again at the latest twelve months after your decision, so that a choice you made long ago does not simply continue indefinitely.
11.4 Storage That Does Not Require Consent
Your decision itself is stored in your browser under the name coup.consent, for up to twelve months. We need it in order to respect your choice and to avoid asking you the same question on every page. This storage is strictly necessary to provide a function you have expressly requested and therefore does not itself require consent. It contains no identifier and allows no conclusions about your person.
11.5 Sign-in With Google or Apple
If you sign in using Sign in with Google or Sign in with Apple, the sign-in process is carried out in a browser window provided by your operating system. In that window, the relevant provider may set cookies or comparable technologies of its own. This processing takes place under the responsibility of Google or Apple respectively and is governed by their privacy policies. We have no access to these cookies.
11.6 Future Analytics and Advertising Tools
Should we in future introduce analytics or advertising tools operated by third parties, we will update this Policy and obtain your prior consent before they are used. Neither of the two measurements described in §11.1 is such a tool: the error reports serve exclusively to find and fix technical faults, and the measurement of how our own app is used runs on our own infrastructure, is covered by §3, and can be switched off at any time under Settings → Privacy.
12. Changes to This Policy
We may update this Privacy Policy, for example in the event of new features, new service providers or changed legal requirements. We will inform you of material changes at least 14 days before they take effect, in the app or by email. The current version is available at any time in the app and at thecoup.nl/privacy; the date of the most recent change is shown at the top of this document.
13. Contact
For all questions and concerns regarding data protection:
coup — Data Protection Contact
Henry Buchhalla, Sinan Ceviker, Tuan-Dai Do (joint controllers)
Groningen, the Netherlands
Email: support@thecoup.app
Response time: within 5 business days
Languages of communication: Dutch, English, German