Find Me After
This is a first draft and is pending review by a lawyer. It is provided for transparency and does not constitute final legal advice. Some details (marked [TODO]) still need to be completed before launch.

Privacy Policy

Last updated: 28 July 2026

Your privacy is central to how Find Me After works — the product is private by default. This policy explains what personal data we process, why, on what legal basis, who processes it on our behalf, how long we keep it, and the rights you have under the EU General Data Protection Regulation (GDPR / DSGVO).

1. Controller

The controller responsible for processing your personal data is Hudsonly LLC ([TODO: legal entity address]), contactable at hello@hudsonly.com.

Data protection contact: privacy@hudsonly.com. [TODO: appoint and name a data protection officer if required under Art. 37 GDPR.]

2. What data we process, why, and the legal basis

Profile data and photos

When you create a profile we process the details you provide (such as your display name, age confirmation, bio, preferences, and the photos you upload). This is used to display your private profile to a person you hand a card to. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). Photos may reveal information some consider sensitive; you provide them voluntarily and by uploading them you consent to their processing for this purpose (Art. 9(2)(a) GDPR where applicable).

Card scans

When someone scans one of your cards, we record the scan event (including a coarse timestamp and technical data such as IP address and user agent) so we can show the right profile, protect against abuse, and operate the single-use card logic. Legal basis: performance of a contract and our legitimate interest in a secure, functioning service (Art. 6(1)(b) and (f) GDPR).

Chat messages (connections and messages)

When a scanner starts a conversation with you, we process the messages exchanged and the connection between the two of you, including anything you choose to share in the chat. Messages are stored so the conversation persists across devices and sessions. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). We also process reports and blocks to keep the platform safe (Art. 6(1)(f) GDPR).

Approximate location (coarse)

If you explicitly allow it, we store a coarse, rounded approximation of where a card was scanned to power the "scanned near …" memory. We never store a precise coordinate. Legal basis: your consent (Art. 6(1)(a) GDPR), which you can decline or withdraw at any time.

Waitlist email

If you join our pre-launch waitlist, we process your email address (and optionally your city and the language you used) to send you a confirmation email and, once you confirm, a single notification at launch. We use a double opt-in and record the time, IP address, and browser of your signup and confirmation as proof of consent. Legal basis: your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time via the link or contact address in every email.

Payments

When you order physical cards, payment is handled by our payment processor (Stripe). We do not receive or store your full card number. We process order and limited billing/shipping data needed to fulfil and account for your order. Legal basis: performance of a contract and compliance with legal (tax/accounting) obligations (Art. 6(1)(b) and (c) GDPR).

Technical and usage data

To operate and secure the service we process technical data such as IP address, device/browser information, and event logs. Legal basis: our legitimate interest in a secure, reliable service (Art. 6(1)(f) GDPR).

3. Processors and third parties

We use carefully selected service providers who process personal data on our behalf under data processing agreements (Art. 28 GDPR). We do not sell your personal data. The main processors are:

  • Stripe — payment processing for card orders (Stripe Payments Europe / Stripe, Inc.).
  • Gelato — on-demand printing and shipping of your physical cards; receives the print file and the shipping address for your order.
  • Google Cloud Storage — secure storage of uploaded photos and generated card PDFs.
  • Resend — delivery of transactional and waitlist emails; receives your email address and message content.
  • Cloudflare — DNS, CDN, and protection against abuse; processes technical connection data (e.g. IP address).
  • Google Kubernetes Engine (GKE) — the cloud infrastructure that hosts the application and database.

A current, complete list of processors is available on request at privacy@hudsonly.com. [TODO: confirm each processor and its hosting region before launch.]

4. International transfers

Some of our processors are based in, or may process data in, countries outside the European Economic Area (for example the United States). Where that happens, transfers are safeguarded by appropriate measures such as the EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework. [TODO: confirm the specific transfer mechanism for each processor.]

5. How long we keep your data

  • Profile, photos, and chats: for as long as your account is active; deleted (or anonymised) after you delete your account or profile, subject to short technical backup retention.
  • Card scans and coarse location: kept only as long as needed for the feature and abuse prevention, then deleted or anonymised.
  • Waitlist email: until you unsubscribe/withdraw consent, or shortly after launch if the list is no longer needed.
  • Order and payment records: retained as required by tax and commercial law (typically up to 10 years under German law).

6. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you (Art. 15).
  • Rectify inaccurate or incomplete data (Art. 16).
  • Erase your data ("right to be forgotten", Art. 17).
  • Restrict processing (Art. 18) and object to processing based on legitimate interests (Art. 21).
  • Data portability — receive your data in a machine-readable format (Art. 20).
  • Withdraw consent at any time, without affecting processing already carried out (Art. 7(3)).

To exercise any of these rights, contact privacy@hudsonly.com. You also have the right to lodge a complaint with a supervisory authority — for the Berlin launch this is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).

7. Cookies and tracking

We keep cookies to a minimum. We use only what is necessary to run the service (for example a session cookie so a scanner is recognised as the same person on reload, and a security token). We do not use third-party advertising trackers. [TODO: if any analytics or non-essential cookies are added, add a consent banner and update this section.]

8. Adults only (18+)

Find Me After is intended solely for adults aged 18 and over. We do not knowingly process the data of minors. If you believe a minor is using the service, please contact us and we will act promptly.

9. Changes to this policy

We may update this policy as the product and our processing evolve. The current version is always available here, with the "last updated" date shown above.