Privacy policy
Last updated 23 July 2026.
This policy explains, in plain language, what personal data Good Company collects, why, and the rights you have over it. We aim to be a genuinely safe, respectful place, and that starts with handling your data carefully.
Who is responsible for your data (the controller)
The data controller is Good Company. You can reach us about anything in this policy — including to access, correct, or delete your data — at hello@goodcompanyfriends.com.
What we collect
- Account details: your name, email address, and password (stored only as a secure hash).
- Profile: your city, a short bio, an optional business/link, and an optional face photo.
- Date of birth: to confirm you are 18+. We store the full date privately but only ever show your day and month to other members — never the year.
- Optional government ID: only if you choose to verify your identity (see below).
- Basic activity: when you were last active.
- Server visit logs: like most websites, our server keeps a standard visit log of pages viewed — the page, the time, the referring site (how you found us), your browser/device type, and your IP address (from which we derive an approximate city/country). We use this only to understand our own traffic. We set no tracking cookies for logged-out visitors and we do not sell or share this data. For anonymous visitors this technical data is not linked to any name or email. These logs are kept for 90 days and then automatically deleted.
Why we use it (lawful basis)
We rely on:
- Legitimate interests — keeping the community safe and running it (vetting, preventing abuse, showing approved members to one another).
- Consent — for your face photo and your government ID, which you actively agree to at upload and can withdraw at any time by deleting them.
- Contract — to provide the membership you signed up for.
Your ID document
If you verify your identity, your ID is uploaded to a private store (never on the public web) and is seen only by our founder to confirm you are who you say. For verified members it is then kept securely — encrypted at rest, access strictly limited to the founder and logged — for as long as you remain a member. It is deleted straight away if your application is declined, and erased when you leave or ask us to delete it. It is never shown to other members and never appears in the directory.
Who can see your profile
Your photo, name, city, and bio are visible only to signed-in, approved members — never to the public web, and member pages are not indexed by search engines. We do not sell your data, and we do not share your personal information beyond the profile you choose to publish inside the community.
How long we keep it
We keep your profile for as long as you have an account. When you delete your account, your profile and photo are removed straight away. If you choose to add a government ID for a Verified badge, it is kept securely — encrypted at rest, with access strictly limited to the founder and logged — for as long as you remain a member; it is deleted straight away if your application is declined, and erased when you leave or ask us to delete it. Voluntary contribution records are kept for accounting, with your personal link removed when you delete your account.
Your rights
You have the right to access your data, correct it, delete it (erasure), receive a portable copy, and object to or restrict certain processing. You can exercise most of these yourself, any time, from your profile:
- Access & portability: "Download my data" gives you a JSON copy of your profile.
- Rectification: "Edit my profile" lets you correct your details.
- Erasure: "Delete my account" permanently removes your profile, photo, and any ID on file.
- Objection / anything else: email hello@goodcompanyfriends.com and we'll help.
Where your data is held (international transfers)
Our servers are hosted in the European Union (Germany). If you access Good Company from elsewhere, your data may be transferred to and stored there. We take care to work with reputable infrastructure providers.
If something goes wrong (breach response)
We keep personal data to a minimum and protect it with access controls. In the unlikely event of a data breach that risks your rights, we will investigate promptly and notify affected members and the relevant authority without undue delay.
Complaints
If you're unhappy with how we've handled your data, please contact us first at hello@goodcompanyfriends.com so we can put it right. You also have the right to complain to your local data-protection supervisory authority (for EU/UK residents, your national supervisory authority or the ICO; elsewhere, your country's data-protection regulator).
Contact
Privacy questions or requests: hello@goodcompanyfriends.com