General template — not reviewed by a lawyer
This document is a general-purpose template prepared for Coopc's launch. It has not been reviewed by a qualified lawyer and is not legal advice. The operating entity behind Coopc, the governing law and the dispute-resolution forum are not yet fixed, and will be added here once they are. If you need certainty about your own legal position, please take independent advice.
This policy explains what personal data Coopc (coopc.one) collects, why we collect it, who processes it on our behalf, and the choices you have. It covers the Coopc website and the accounts, profiles, projects and messages inside it.
1. Data we collect
- Account data — your email address, display name, and a password that our authentication provider stores only as a hash. If you sign in with GitHub or Google, we receive the account identifier, email address, display name and avatar that provider shares. We never receive your GitHub or Google password.
- Profile data — username, avatar image, bio, identity type, location, timezone, availability status, skills, what you can do, what you are looking for, external links, and your language preference.
- Content you publish — projects, open-role listings, descriptions, screenshots and links you upload, applications and their messages, team memberships, saved items, ratings and comments.
- Notifications and email — the in-product notifications we generate for you, and the transactional emails we send, for example when an application is accepted or not accepted.
- Usage events — a first-party analytics record of actions in the product: the event name, the page URL, a timestamp, an anonymous session identifier stored in your browser, and your account ID if you are signed in. We do not use third-party advertising or cross-site tracking.
- Technical data — our hosting and database providers process standard connection data such as IP address, browser user agent and request logs in order to deliver and secure the service.
- Cookies and local storage — an authentication session cookie set when you sign in, a coopc_lang cookie holding your language choice, and an anonymous session identifier kept in your browser's local storage for analytics. We do not use advertising cookies.
2. How we use your data
We use the data above:
- to create and run your account and to authenticate you;
- to show your profile, projects, roles and public activity to other users, according to the visibility you chose;
- to deliver core features: applications, acceptances, team membership, favourites, ratings and notifications;
- to send transactional email you would expect — application results, and account or security messages;
- to understand which features are used, and to improve the product;
- to detect, investigate and prevent fraud, abuse, spam and security incidents;
- to meet legal obligations and to enforce our Terms of Service.
We do not sell your personal data, and we do not share it with advertisers.
3. Legal bases (users in the EEA and the UK)
Where the GDPR applies, we rely on: performance of a contract (running your account and the features you ask for); our legitimate interests (keeping the service secure, understanding usage, improving the product); your consent, where we ask for it; and legal obligation, where the law requires us to keep or disclose data. You can withdraw consent at any time.
4. What other people can see
- Public projects and role listings, along with your name, username, avatar, bio and profile details, are visible to anyone on the internet, including search engines.
- Projects you mark as private are visible only to you.
- When you apply to a role, the project owner can see your application message and your profile.
- Your email address is not shown on your public profile. It is used for account, notification and transactional purposes.
5. Service providers who process data for us
- Supabase — database, file storage and authentication. Your account, profile and published content are stored here.
- Vercel — hosting, content delivery and application logs for the website.
- Resend — sending transactional email, such as application status updates.
- GitHub and Google — only if you choose to sign in with them; they authenticate you and share basic profile data with us.
These providers process data on our instructions and are not permitted to use it for their own purposes. They may run infrastructure or support operations in other countries.
6. Where your data is stored
Our Supabase project — database, file storage and authentication data — is hosted in the Singapore region (ap-southeast-1). The website itself is served through Vercel's global network, so a request may be processed in a region close to you. If you are located outside Singapore, using Coopc involves an international transfer of your data.
7. How long we keep data
- Account and profile data: for as long as your account exists.
- Content you publish: until you delete it, or delete your account. Content is first marked as deleted so it disappears from the product, then removed from active storage.
- Deleting your account removes your profile and personal data from the live service. Copies may remain in encrypted backups for a limited period, until those backups expire on their normal cycle.
- Usage events may be kept in aggregated or de-identified form for product analytics after an account is deleted.
- We keep records for longer only where the law requires it, or where we need them to resolve a dispute or enforce our Terms.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to withdraw consent, and to receive a copy of the data you gave us in a portable form.
- Access and correction — most of your data can be viewed and edited directly in Settings.
- Deletion — schedule account deletion in Settings. A 14-day cooling-off period applies; signing in again before the deadline cancels the request. After deletion, public profile and authored public content are removed from public views, while minimum collaboration history may be retained for the people involved.
- Other requests, including a copy of your data — email report@coopc.one from the address on your account.
We aim to respond within 30 days. If you are in the EEA or the UK, you also have the right to complain to your local data protection authority.
9. Security
- Traffic between your browser and Coopc is encrypted with HTTPS.
- Passwords are stored only as hashes by our authentication provider; we never see them.
- Database access is restricted by row-level security rules, so private data is not returned to users who should not see it.
- No online service can be completely secure. If we become aware of a breach affecting your personal data, we will notify affected users and any regulator as required by law.
10. Children
Coopc is not intended for children. You must be at least 13 years old to create an account, or older if your country sets a higher minimum age for consenting to online services. We do not knowingly collect data from children below that age; if we learn that we have, we will delete the account and its data.
11. Changes to this policy
We will update this page when our data practices change, and update the effective date at the top. For significant changes we will make a reasonable effort to notify you in the product or by email.
12. Contact and reporting
For privacy questions, data requests, or to report misuse of personal data on Coopc, email report@coopc.one. This is currently the single contact address for Coopc; a dedicated privacy address will be published here once it exists.
Report a project, profile or message
If you see something on Coopc that looks like fraud, impersonation, harassment, infringement, or a scam open-role listing, tell us. Send the page link, what you believe is wrong, and any evidence. We review every report and may remove content or suspend accounts.
Email report@coopc.one