Legal Stuff

Privacy Policy

Jathikka Oy

Effective date: 17 September 2026

1. Who we are

g3t club is operated by Jathikka Oy, a Finnish private limited company, Business ID 3435622-4, with its registered address at Kirjurinkuja 3 B 11, 02600 Espoo, Finland.

Jathikka Oy is the controller of the personal data described in this Privacy Policy. You can contact us about privacy at kevin@g3t.club or +358 41 721 6394.

Jathikka Oy has not appointed a Data Protection Officer.

2. Scope and sources of personal data

This Privacy Policy explains how Jathikka Oy collects and uses personal data when you use the g3t website, application process, mobile or web applications, Membership, profiles, Clubs, chat, bookings, g3t-hosted Hangouts, community-hosted Hangouts, hosting tools, research, support, safety features and marketing.

It applies to website visitors, Applicants, Members, Hosts, research participants and anyone who contacts g3t.

We receive personal data directly from you, automatically from your browser or device when you use g3t, and where relevant from payment and platform providers, other Members or Hosts, venues, professional advisers, public authorities or emergency services.

Third parties such as payment providers, app stores and venues may also process personal data for their own purposes under their own privacy notices.

3. Personal data we collect

The personal data we collect depends on how you use g3t.

3.1 Application data

When you apply to join a g3t group, we may collect your name, email, telephone or WhatsApp number, preferred contact method, age information, when you moved to Paris, student status, intention to stay, postcode or nearest métro stop, preferred area and travel time, availability, activity interests, Clubs, languages, application answers, hosting interest, referral information, marketing choice and application, waitlist or invitation status.

We may also keep notes and outcomes from application or onboarding conversations that are relevant to reviewing your application and arranging Membership.

3.2 Account, profile and Membership data

If you are offered a place, we may collect account and login information, telephone number, preferred first name, profile photograph, optional pronouns, languages, former city, interests, profile answers, postcode or nearest métro stop, preferred area, availability, Clubs joined, hosting interest and notification settings.

We also process your Membership plan and status, bookings, requests, confirmations, waitlists, cancellations, cancellation reasons, no-shows, check-ins and attendance; Hangouts created or hosted; post-Hangout feedback and connection choices; and reports, blocks, restrictions, warnings, suspensions, appeals and account status.

3.3 Identity verification

For identity verification, g3t may compare a profile photograph with a valid government-issued identity document and confirm the Member’s age or date of birth. Accepted documents include a national identity card, driving licence or passport. Verification is optional for ordinary Members and mandatory for Hosts.

Identity verification is reviewed internally by an authorised g3t reviewer who is subject to confidentiality obligations. g3t does not use facial-recognition or biometric technology for identity verification.

We use the identity document only to complete the verification and delete it after the check is completed. We retain the verification result, date, method and verified age or date-of-birth information while the Member’s account remains active. Access to verification records is limited to authorised g3t staff.

If verification is successful, other Members may see a verified badge or verification status. They do not see the identity document or the information contained in it. If verification is unsuccessful, the Member may try again or contact g3t support at kevin@g3t.club.

3.4 Location information

For applications and group planning, g3t may use information such as postcode, district, neighbourhood, nearest métro stop, preferred area, stated travel time and map-search information.

If you enable a location-based feature, g3t may use live or background GPS, precise coordinates or location history where the required device permission and legal basis are in place. We do not require a full home address for group formation or display a home address to other Members. A payment provider may separately process a billing address where needed.

3.5 Payments

Stripe processes g3t payments and subscriptions. g3t may receive your Membership plan, amount, currency, billing details, payment status, transaction reference, refund status, chargeback information and limited payment-method information. g3t does not normally receive or store your full card number.

3.6 Messages, support, safety and calls

We process in-app messages, Club chat, event descriptions, support emails, reports, feedback and communications with g3t.

g3t’s in-app chat is operated through g3t systems hosted on Google Cloud. Messages are not end-to-end encrypted. Authorised g3t staff may access messages only when necessary for support, safety, moderation, security or legal compliance.

Onboarding, research or support calls may be recorded after we tell you at the beginning of the call. We may also keep call notes and, where used, transcripts. Call recordings and transcripts are retained for up to 2 years.

Where a call is recorded using Otter.ai, Otter.ai processes the recording and any resulting transcript in the EU.

Safety and moderation records may include the identity of reporting and reported people, relevant messages, Host observations, dates, evidence, investigation notes, actions taken, appeals and communications with authorities.

3.7 Sensitive and special-category information

g3t does not ask for racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, health information, sex life, sexual orientation or other special-category personal data as part of the standard application, account or profile process.

A person may nevertheless choose to disclose sensitive or special-category information in an open-text answer, message, support request, report or call. If this happens, we use only what is reasonably necessary for the relevant purpose and restrict access to authorised people who need it.

Where necessary, we process such information only where an additional legal condition applies, for example with explicit consent, where necessary to establish, exercise or defend legal claims, or in an emergency to protect someone’s vital interests where the person concerned cannot give consent.

g3t does not use voluntarily disclosed special-category information to decide whether to accept an Applicant, form local groups or recommend Clubs or Hangouts unless that use has been specifically explained and is permitted by applicable law.

3.8 Device, analytics, marketing and media data

We may collect IP address, device and browser type, operating system, app version, language, time zone, login and security logs, crash information, cookie or SDK identifiers, consent choices and feature or analytics events.

Marketing data may include subscription choice, campaign or referral source, message delivery, clicks, unsubscribe status and suppression records. If a photograph, recording or testimonial is created for promotion, we may process the media, event details and permission record. Promotional use is optional and handled separately from Membership.

4. How we use personal data and our legal bases

We process personal data only where we have a legal basis to do so. Depending on the purpose, we use personal data:

  • to receive and assess applications, arrange onboarding and communicate about an invitation or Membership, as steps requested before entering into a contract;
  • to create and manage your account and provide Membership, Clubs, chat, bookings, Hangouts, reminders, feedback and support, to perform our contract with you;
  • to use your area, availability, interests, activity choices and booking information to place you in a local group and provide or recommend Clubs and Hangouts, as part of providing the Membership service;
  • to process payments, refunds and other charges, to perform our contract with you;
  • to keep tax, accounting and other legally required records, to comply with legal obligations;
  • to send essential Service communications such as booking changes, reminders, receipts, safety notices and account messages, to provide the Service or comply with legal obligations;
  • to investigate reports, moderate the Service, prevent fraud, enforce our rules and secure accounts and systems, based on our legitimate interests in operating a safe and trustworthy Service;
  • to establish, exercise or defend legal claims, based on our legitimate interests and applicable law;
  • to compare attendance records and analyse how g3t is used, including whether Members have opportunities to meet the same people again, based on our legitimate interests in understanding and improving the Service;
  • to conduct optional research, surveys and usability testing, on the basis explained when you are invited to participate; and
  • to send marketing or use promotional photographs, recordings or testimonials, with consent where required or another lawful basis that is explained to you.

Where we rely on legitimate interests, we consider the impact on your privacy and use personal data only where our interests are not overridden by your rights and interests. Where we rely on consent, you may withdraw it at any time without affecting processing that was lawful before withdrawal.

5. Group formation, recommendations and repeated encounters

g3t may use service area, estimated travel time, availability, interests, activity choices, capacity and prior attendance to review applications, form local groups and plan or recommend Clubs and Hangouts.

Software may help organise this information, but g3t does not accept or reject an Applicant, impose a material safety restriction or make another similarly significant decision solely through an automated system. A person reviews material decisions. You may ask us to correct inaccurate information or review a material decision.

We may compare attendance records to identify whether two Members attended more than one of the same Hangouts. This is used to measure opportunities for repeated encounters. It does not mean that the Members spoke, became friends or want further contact.

6. Who can see or receive your data

We limit access to personal data according to what each person or organisation needs to provide the Service.

  • Members may see profile fields made visible within their local group, Clubs, connections or Hangouts, messages addressed to them and participation information needed for the feature.
  • Before a g3t-hosted Hangout, attendee identities are not shown to Members. Members may see only how many attendees are new faces and how many are familiar faces from earlier Hangouts.
  • For a community-hosted Hangout, Members can see who is joining before they join.
  • A g3t Host may see accepted attendee names, profiles, booking status and information reasonably needed to run the Hangout or respond to a safety need.
  • A community Host receives only the minimum attendee name, profile and booking information needed for that Hangout. Community Hosts do not receive full applications, onboarding notes, unrestricted phone exports or unrelated safety information.
  • Venues receive only information needed for a booking or another agreed operational need.
  • Authorised g3t staff and contractors receive information needed for their role and are subject to access controls and confidentiality obligations.
  • Service providers receive information needed to provide hosting, authentication, payments, communications, notifications, support, security or other contracted services.
  • Advisers, insurers, authorities or emergency services may receive information where disclosure is legally required or reasonably necessary for legal claims, safety or an emergency.

We do not show a Member’s exact home address, full application, onboarding notes, private reports or sensitive personal circumstances to other Members or community Hosts.

7. Service providers and international data transfers

We use third-party service providers where needed to operate g3t. Our current production providers include:

  • Google Cloud — server, database and in-app chat hosting. The configured hosting region is St. Ghislain, Belgium. Data hosted there is encrypted in transit and at rest; chat is encrypted in transit.
  • Google and Apple OAuth2 — account authentication and authorisation. g3t does not store plaintext passwords for OAuth-authenticated accounts.
  • Stripe — payments and subscriptions. The current configured processing region is Europe.
  • Apple App Store and Google Play — app distribution, installs and updates. The current operating region is Europe.
  • Resend — transactional email, including invitations and Hangout, cohort and payment updates. The current configured region is Europe.
  • Firebase Cloud Messaging — push notifications for Hangout, cohort and chat updates.
  • Otter.ai — call recording and transcription for onboarding, research or support calls. The configured processing region is the EU.

Google Analytics and Sentry are not currently used in production. If we introduce additional analytics, crash reporting or other providers, we will update this Policy where required.

For g3t’s current use of Google and Apple OAuth2 and Firebase Cloud Messaging, the processing region is the EU.

Some providers act only on g3t’s instructions. Others, such as payment or platform providers, may process personal data for their own purposes under their own privacy notices.

Where personal data is transferred outside the European Economic Area and the destination is not covered by an adequacy decision, g3t uses an appropriate transfer mechanism and supplementary safeguards where required. You may contact us for more information about the safeguards used for a particular transfer.

8. Cookies, device permissions and marketing

We may use cookies and similar technologies to operate and secure the website and app. Non-essential cookies or trackers are used only where permitted and, where required, with your consent.

At the date of this Policy, Google Analytics and Sentry are not used in production. If non-essential analytics or tracking tools are introduced, we will update the relevant notices and obtain consent where required.

The app may request access to device features such as location, camera or photographs, and notifications when they are needed for a feature. You can manage device permissions through your device settings.

Audience-measurement cookies or trackers are retained for up to 6 months and other cookies or trackers for up to 13 months.

Marketing communications are optional. You can unsubscribe at any time. This does not affect essential messages about your Membership, bookings, payments, account or safety.

9. Data retention and account deletion

We keep personal data only for as long as needed for the purpose for which it was collected, legal obligations, safety, fraud prevention and legal claims.

Unless a longer period is required by law or reasonably needed for a legal claim, we apply the following retention periods:

  • active accounts and profiles: for the duration of the account;
  • inactive accounts: up to 2 years of inactivity, after which g3t may contact the Member about reactivation and delete the personal data if there is no response;
  • selected service records retained for proof or legal claims: up to 5 years after the relevant relationship or event;
  • login and account-access logs: up to 1 year;
  • applications that do not result in Membership, including rejected or incomplete applications: up to 3 years from the last meaningful contact, unless the Applicant asks for deletion earlier or a legal reason requires retention;
  • waitlisted Applicants: while the request to be considered for a future group remains active, and no longer than 3 years from the last meaningful contact without renewed contact;
  • payment, invoice and accounting records: up to 10 years where required for accounting or tax purposes;
  • product analytics and service-improvement data: up to 2 years from collection;
  • marketing data for Members: for the duration of the relationship and up to 3 years after it ends;
  • marketing data for people who never become Members: up to 3 years from the last contact;
  • identity documents used for verification: only for the time necessary to complete the identity check;
  • identity-verification result, date, method and verified age or date of birth: for the duration of the Member’s active account;
  • call recordings and transcripts: up to 2 years;
  • safety reports, investigation records and minimum records needed to enforce a safety restriction or exclusion: up to 10 years;
  • promotional photographs, recordings, testimonials and permission records: up to 5 years;
  • audience-measurement cookies or trackers: up to 6 months;
  • other cookies or trackers: up to 13 months; and
  • backup copies following deletion: up to 13 months before they expire or are overwritten.

You may request account deletion through the in-app deletion option or by contacting kevin@g3t.club. Account deletion and Membership cancellation are separate. Deleting an account does not by itself create a refund or remove an existing payment obligation.

When an account is deleted, active profile information is deleted or anonymised immediately, except information that g3t must or may retain for accounting, fraud prevention, safety, legal claims, backups or the rights of other people. Where a provider processes personal data on our behalf, we instruct the provider to delete or return the data in accordance with our retention schedule. Messages already delivered to another Member may remain in that Member’s account.

10. Security and personal-data breaches

We use technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse or disclosure. g3t’s core hosting and database infrastructure is hosted on Google Cloud in St. Ghislain, Belgium. Data hosted there is encrypted in transit and at rest. In-app chat is encrypted in transit. Access to personal data is restricted according to role and operational need, and g3t does not store plaintext passwords for OAuth-authenticated accounts.

No online service can be guaranteed to be completely secure. We assess suspected personal-data breaches and notify supervisory authorities and affected people where the law requires it.

11. Your privacy rights and complaints

Subject to applicable conditions and exceptions, you may ask us to:

  • confirm whether we process your personal data and give you access to it;
  • correct inaccurate or incomplete data;
  • erase personal data;
  • restrict processing;
  • provide eligible data in a portable format;
  • object to processing based on legitimate interests;
  • object to direct marketing;
  • withdraw consent; and
  • request human review of a qualifying material decision.

Send a request to kevin@g3t.club. We may ask for information reasonably needed to verify your identity. We normally respond within one month, subject to a lawful extension where a request is complex or numerous.

You may complain to the data-protection authority in your habitual residence, place of work or the place of an alleged infringement. Because Jathikka Oy is established in Finland, you may contact the Office of the Data Protection Ombudsman in Finland. People in France may also contact the Commission Nationale de l’Informatique et des Libertés (CNIL).

12. Children and changes to this Policy

g3t is not directed to children. You must be at least 18 years old to create an account. If we learn that an ineligible minor submitted personal data, we will take reasonable steps to delete it, subject to legal retention requirements.

We may update this Privacy Policy when g3t, our service providers, applicable law or our data-processing practices change. We will update the date above and give reasonable notice of material changes. Where a new use of personal data requires consent, we will ask for consent rather than treating continued use as consent.

13. Contact us

For privacy questions, data-protection requests, account deletion or other privacy concerns, contact:

Jathikka Oy / g3t club

Kirjurinkuja 3 B 11

02600 Espoo

Finland

Email: kevin@g3t.club

Telephone: +358 41 721 6394

Back to g3tTerms & Conditions