Coming soon · Amsterdam

Privacy

Privacy policy

Last updated 9 August 2026

1. Who we are

1.1

Conriso, registered in Amsterdam, the Netherlands, Chamber of Commerce (KvK) number 42115223, is the controller of the personal data described in this policy. We decide what is collected and why.

1.2

This policy explains how we handle personal data under the General Data Protection Regulation (GDPR) and the Dutch Uitvoeringswet AVG. It forms part of our Terms of Service.

1.3

We do not sell personal data, and we do not share it for advertising.

1.4

For any privacy question or request, write to hello@conriso.com.

2. What we collect

2.1

Account. Your email address and a password, which is stored only as a hash by our authentication provider and is never visible to us.

2.2

Profile. Completing a profile is required before you can join or host, and we ask for:

  • your first and last name;
  • your date of birth, which we use to confirm you are over 18 and to display your age rather than your birthday;
  • your telephone number;
  • your gender, which also determines whether women-only Tables are available to you;
  • your city and country;
  • a photograph of yourself; and
  • what you write about yourself: a short description, who you hope to meet, conversation topics, interests, cuisines, dietary requirements, languages, and any social links you choose to add.
2.3

Tables. The Tables you publish or join, any note you send with a request, whether a request was approved or declined, whether you attended, and any feedback given afterwards.

2.4

Messages. Messages sent through the Platform between a Host and their joiners, including the subject and body.

2.5

Reports. If you report another User, we record who reported whom, in relation to which Table, and what you told us.

2.6

Reliability. A record of late cancellations and non-attendance, and any suspension that follows from them.

2.7

Payments. The identifier of the Stripe checkout session, the amount, and the times at which a Seat Fee was paid or refunded. Card details are handled by Stripe and never reach us.

2.8

Usage. A record of certain actions on the Platform, held against your account: opening Discover, opening a Table, completing a share, and editing a Table. We use these to understand where people stop, not to build a profile of you.

2.9

Technical. Standard server and analytics information such as IP address, browser and pages visited. See clause 8.

3. How we use it

3.1

We use personal data to:

  • create and run your account;
  • publish Tables and show them to the people who may join;
  • let a Host decide on a request, and let attendees see who else is coming;
  • take and refund Seat Fees;
  • send you messages, notifications and emails about your seats, cancellations and refunds;
  • investigate reports and enforce our Terms, including suspending accounts;
  • understand how the Platform is used, and improve it; and
  • meet our legal obligations, including Dutch tax record-keeping.
3.2

Your profile is shown to other Users when it is relevant to a shared Table: your name, photograph and what you have written about yourself. Your email address, telephone number and date of birth are never shown to other Users.

5. Who else sees it

5.1

Other Users. People at the same Table see your name, your photograph and what you have written on your profile. A Host sees the same for anyone requesting a seat, along with any note sent with the request. Nobody sees your email address, telephone number or date of birth.

5.2

Processors. Companies that handle data on our instructions, each under a data processing agreement and each receiving only what it needs:

  • Supabase: database, authentication and storage of profile photographs;
  • Stripe: payment processing;
  • Resend: transactional email, such as seat confirmations and notifications;
  • Vercel: hosting of the Platform, and privacy-friendly traffic measurement;
  • Google: Analytics on our public pages (see clause 8), and the venue search used when a Host chooses where to meet.
5.3

Authorities. We disclose personal data where we are legally required to, or where it is necessary to protect someone's safety.

6. How long we keep it

6.1

We keep personal data no longer than we need it:

  • account and profile data, for as long as your account exists, and for two years afterwards so that a dispute or a safety question can still be answered;
  • records of Tables, seats and payments, for seven years, as Dutch tax law requires;
  • messages, for two years after they are sent;
  • reports and the record of any suspension, for three years, since the point of that record is to recognise a pattern;
  • notifications, for ninety days, after which they are deleted automatically;
  • usage records, for two years.
6.2

When you ask us to delete your account, we delete your profile, your photograph and your messages, and we retain only what the periods above require us to keep.

7. Your rights

7.1

Under the GDPR you have the right to:

  • obtain a copy of the personal data we hold about you;
  • have inaccurate or incomplete data corrected;
  • have your data erased, subject to what we must keep by law;
  • restrict how we process your data in certain circumstances;
  • receive your data in a structured, commonly used, machine-readable format;
  • object to processing based on our legitimate interests, including any profiling; and
  • withdraw consent at any time where processing rests on consent.
7.2

Write to hello@conriso.com to exercise any of these. We shall acknowledge within five working days and respond in full within one month, which we may extend by a further two months for a complex request, telling you if we do.

7.3

You also have the right to complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

8. Cookies and analytics

8.1

We use storage that is strictly necessary for the Platform to work: keeping you signed in, remembering your light or dark preference, and recording the choice you make below. These cannot be switched off, and no consent is required for them.

8.2

We measure traffic on our pages using Vercel Analytics, which sets no cookies and does not identify you.

8.3

We use Google Analytics to understand how people find us and how our pages are used. It sets cookies, it is not strictly necessary, and it therefore runs only if you accept it. Until you do, the Google Analytics script is not loaded and no request is made to Google.

8.4

You are asked once, and your answer is remembered on that device. You may change it at any time through the Cookie settings link at the foot of any public page, which is as straightforward as giving consent was. If you withdraw it, we delete the cookies Google Analytics has set and stop collecting through it.

9. Security

9.1

We protect personal data with:

  • encryption in transit;
  • row-level access rules in the database, so one User's data is not reachable by another;
  • passwords stored only as hashes, never in a form we can read;
  • profile photographs served through short-lived signed links rather than public addresses; and
  • restricted administrative access.
9.2

If a breach occurs that presents a risk to you, we shall notify the Autoriteit Persoonsgegevens within 72 hours as Article 33 requires, and tell you directly where Article 34 requires it.

9.3

Please use a password you do not use elsewhere, and tell us at hello@conriso.com if you believe someone else has reached your account.

10. Transfers outside the EU

10.1

Your account, your profile, your photograph and the record of your Tables are stored in the European Union. Our database, authentication and file storage run on Supabase infrastructure in Frankfurt, Germany, and personal data of that kind does not leave the European Economic Area in the ordinary course of running the Platform.

10.2

Some of our other processors are established in the United States, among them Stripe, Vercel, Resend and Google. Where personal data reaches them, it is protected by an adequacy decision, by the EU-US Data Privacy Framework where the processor is certified under it, or by Standard Contractual Clauses approved by the European Commission.

10.3

You may ask us at hello@conriso.com which safeguard applies to a particular processor.

11. Children

11.1

Conriso is for adults. You must be 18 or older to hold an account, and we do not knowingly collect data from anyone younger. If we learn that we have, we delete it. If you believe a minor holds an account, tell us at hello@conriso.com.

12. Automated decisions

12.1

One decision on the Platform is automated. Repeated late cancellations or non-attendance suspend an account for a fixed period, cancel any free join credits, and cancel that account's upcoming Tables. This follows a fixed rule applied to your own record, not a judgement about you.

12.2

You may ask a person to review any suspension by writing to hello@conriso.com within thirty days, as clause 10 of the Terms provides. Nothing else on the Platform makes decisions about you automatically.

13. Changes to this policy

13.1

Where a change is material, such as a new category of data, a new processor, or a change affecting your rights, we shall give at least fourteen (14) days' notice by email or through the Platform and say what has changed. Corrections that do not alter the substance may be made without notice.

13.2

The date at the head of this page always shows when it was last amended.

14. Contact

14.1

Conriso, Amsterdam, the Netherlands. Chamber of Commerce (KvK) number 42115223. Email hello@conriso.com. We have not appointed a data protection officer, as we are not required to.