Legal

Privacy Policy

This policy explains what personal data Hereabouts (hereabouts.ie) collects, why we collect it, and the rights you have over it. If you have any questions, contact [email protected].

Data We Collect

You can browse the public site without an account. We only collect personal data when you choose to use an account-based feature:

  • Account: your email address and a bcrypt hash of your password (we never store the plaintext). We also store email verification status, your plan tier, and your daily question count.
  • Email verification and password reset: short-lived tokens used to confirm your address or reset your password.
  • Subscription and billing: if you subscribe, we store your Stripe customer and subscription identifiers, subscription status and renewal date. Card and payment details are handled directly by Stripe and are never stored on our servers.
  • Ask Hereabouts chat: the questions you ask, the answers, and the queries used to generate them, stored so you can revisit your conversation history.
  • Newsletter: if you subscribe, your email address, whether it is verified or unsubscribed, the relevant timestamps, and a record of which issues were sent to you.
  • Technical data: server logs, including a client IP address derived from the request and a per-request identifier, used for security, rate limiting and diagnosing faults.

Why We Use It (Lawful Basis)

  • To provide the service you signed up for (contract): creating your account, serving chat answers, and managing your subscription.
  • With your consent: sending the newsletter. You can withdraw consent at any time using the unsubscribe link in every issue.
  • For our legitimate interests: keeping the service secure and available, preventing abuse, and rate-limiting requests. We balance these against your rights and only use the minimum data needed.

Cookies

We use a single strictly necessary cookie, access_token, to keep you signed in. It is set only after you log in, is httpOnly (not readable by scripts), and expires after up to 7 days. We do not use advertising, profiling or cross-site tracking cookies, and we do not run third-party analytics.

Sharing

We do not sell personal data. We share it only with the processors that run the service on our behalf, under contract: Stripe (payments), Resend (transactional and newsletter email), and our hosting provider. Some of these providers may process data outside the EEA; where they do, transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses.

Retention

We keep account and chat data while your account is active. Newsletter records are kept until you unsubscribe. Billing records are retained for as long as tax and accounting law requires. Server logs are kept for a short period and then deleted.

Your Rights

Under the GDPR you have the right to access, correct, delete or restrict your personal data, to object to processing based on legitimate interests, to data portability, and to withdraw consent. To exercise any of these, email [email protected]. You also have the right to complain to the Irish Data Protection Commission (dataprotection.ie).

Changes

We may update this policy as the service changes. Material changes will be posted on this page with a new date.

Last updated: October 2026