The Group. Back

Legal

Privacy Policy.

Version 1.0.0 · Effective July 20, 2026

This Privacy Policy describes how The Group ("we", "us", "our") collects, uses, shares, and protects personal information when you use checkthegroup.com, the web app, the iOS and Android apps, and related services (the "Service"). Short version: we collect what the planner needs to work, we don't sell it, and we don't do ads.

1. What we collect

  • Account & profile: first name, last name (optional), email address, phone number (optional, for group texts), and avatar. Passwords don't exist here - sign-in is by emailed magic link, handled by our authentication provider.
  • Group content: plans and their details, RSVPs, availability votes, messages, and photos you post - visible to the members of the group you post them in.
  • Calendar data (optional): if you connect your calendar, we read busy/free times only - not event titles, attendees, or details - to power availability features, and we add events you RSVP to.
  • Billing: payments are processed by Stripe. We store your group's Stripe customer and subscription identifiers; we never see or store card numbers.
  • Usage & device data: message delivery records (email/SMS/push), monthly usage counts against your plan's limits, push subscription tokens, and standard technical logs (IP address, user agent, timestamps) kept by our infrastructure providers.

We do not knowingly collect biometric data, precise geolocation, or special-category data. Locations you type into a plan (like "Dave's place" or a restaurant) are group content, visible to your group.

2. How we use it

  • Run the planner: show plans to your group, sync calendars, collect RSVPs.
  • Send notifications you can control per channel in Settings: email, text, and push for new plans, invitations, changes, and host blasts.
  • Process subscription payments and enforce plan limits.
  • Keep the Service secure, prevent abuse, and debug problems.
  • Comply with legal obligations.

We do not use your information for targeted advertising, and we do not build advertising profiles. Ever.

3. Legal basis (GDPR)

If you're in the EEA, UK, or Switzerland: we process data to perform our contract with you (running the Service), to meet legal obligations (tax and accounting records), for legitimate interests (security, abuse prevention, product quality - you may object at info@checkthegroup.com), and with your consent for optional features like calendar sync and text messages, which you can withdraw at any time.

4. Who we share it with

We share personal information only with the service providers that run the product, each bound to confidentiality and security terms:

  • Supabase - database, authentication, file storage, and server functions.
  • Stripe - subscription payments.
  • Resend - email delivery.
  • HighLevel (LeadConnector) - text-message delivery and our support contact records (name, email, phone, group membership).
  • Composio & Google - the optional calendar connection (busy/free reads, RSVP event creation) and location search when adding a place to a plan.

We do not sell personal information and we do not share it for cross-context behavioral advertising or third-party marketing. We may disclose information if required by law or to protect the rights, property, or safety of The Group, our users, or the public.

5. Cookies

We use strictly necessary cookies and local storage for sign-in sessions and remembering things like your active group. No third-party advertising cookies, no cross-site tracking. Because there is no accepted standard, we do not respond to "Do Not Track" signals - but we don't do the tracking DNT is meant to prevent.

6. Retention

  • Account and profile data: for as long as your account exists.
  • Billing records: seven (7) years, as tax rules require.
  • Message delivery logs and usage counts: kept for operations; delivery detail ages out after ninety (90) days.
  • When you delete your account: your profile, phone number, RSVPs, calendar link, and notification settings are deleted, and we request deletion of your contact record from our SMS provider. Plans and messages you posted stay with the group with your name removed.

7. Your rights

Depending on where you live, you may have rights to access, correct, delete, export, or restrict processing of your personal information, and to withdraw consent. Most of this is self-serve: edit your profile in Settings, turn notification channels on or off, disconnect your calendar, or delete your account entirely (Settings → Danger zone). For anything else, email info@checkthegroup.com - we verify identity, respond within thirty (30) days for GDPR requests and forty-five (45) days for CCPA/CPRA requests, and never discriminate against you for exercising your rights.

8. California residents

Under the CCPA/CPRA you have the rights to know, delete, correct, and to opt out of sale or sharing. We do not sell or share (as the CCPA defines those terms) personal information, so there is nothing to opt out of. In the last twelve (12) months we collected the categories in Section 1 and disclosed them only to the providers in Section 4 for the purposes in Section 2.

9. Children

The Service is not directed to children under thirteen (13), and we do not knowingly collect personal information from them. If you believe a child under 13 has an account, contact info@checkthegroup.com and we will delete it promptly.

10. Text messages & mobile information

Text messages are sent only to members who have added a phone number to their profile - the field is optional and never required to use the Service. Messages are service-related: plan invitations, changes, cancellations, RSVP prompts, and messages your group's host sends to the group. Frequency varies with group activity; message and data rates may apply.

Opt out anytime: reply STOP to any message, turn off text notifications in Settings, or remove your phone number. Reply HELP or email info@checkthegroup.com for assistance. No mobile information is shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third parties, except the aggregators and providers of text messaging services required to deliver the messages. Carriers are not liable for delayed or undelivered messages.

11. Security

Data is encrypted in transit (TLS) and at rest, access is controlled by row-level security and role-based rules, and sign-in uses one-time email links instead of passwords. No system is perfectly secure; if a breach affects your personal information, we will notify you as applicable law requires.

12. International transfers

We are based in the United States and process data there. If you use the Service from elsewhere, your information is transferred to the U.S. Where required, we rely on Standard Contractual Clauses and equivalent safeguards.

13. Changes & contact

We may revise this Policy; the version number above changes when we do. Material changes (new data categories, new purposes, new recipients) will be announced by email at least thirty (30) days before taking effect. Questions and privacy requests: info@checkthegroup.com. See also our Terms of Service.