In effect since 2026-08-09

Privacy

What we collect, why we collect it, who else sees it, and how to get it back or have it deleted. Written to be read, not to be survived.

Who we are

Stoop is operated by 1294630 BC LTD, a company registered in British Columbia, Canada. We are the organisation responsible for the personal information described here. You can reach a person at hello@stoop.place, or by mail at 7184 120th Street, Surrey BC V3W 0M6.

We handle personal information under Canada's federal privacy law (PIPEDA), British Columbia's Personal Information Protection Act, and — for any commercial email — Canada's anti-spam legislation (CASL).

What we collect, and why

Two stages, because the product has two stages.

When you join the waitlist, we collect your email address, the city you entered, your answers to the short questionnaire, and the activities you picked. You may optionally tell us your gender and which genders you would like to meet. We use this to work out whether enough people near you want the same thing, and to build a circle from real answers rather than guesses.

When you create an account, we also collect a display name, your birth year, your gender and who you are open to meeting, a short description of where you are in life, anything you write in your bio, and your city. If you allow it, we store approximate coordinates so we can tell how far apart people are. From then on we hold what you do here: messages you send, meetups you say you are attending, attendance after the fact, reports you file, and people you block.

Circles are assembled from your life stage, interests and availability. We also ask for gender and birth year. Neither is shown as a public profile field for browsing, because there is no browsing of people.

Verification photos

If you verify yourself with a photo, that photo is reviewed by a person and then deleted — whether you are approved or rejected, with no waiting period. What remains is the outcome and, if you were rejected, the note explaining what to change. The photo itself is gone.

We say this plainly because the site promises it on the front page, and a promise like that is either enforced in code or it is decoration. Deletion happens as part of the review itself, and if a deletion ever failed we would still be holding a photo we said we had removed — so the system is built to make exactly that situation countable and findable rather than silent.

What we do not do

  • We do not sell or rent personal information. Not to advertisers, not to data brokers, not to anyone.
  • We do not run advertising or third-party tracking. There is no advertising pixel, no analytics SDK, and no cross-site tracker on this site.
  • Members never pay us, so we never hold your card details. Venues pay, and their billing runs through a separate payment processor that members never touch.
  • We do not show anyone a map of where people are. Coordinates are used to measure distance, never to plot a person.

How we measure the site

We record a small number of events — that a page was viewed, that a step of the questionnaire was reached — to understand whether the site works. Those records contain the name of the event, which step it was, and when it happened. They contain no account identifier, no session identifier and no IP address, so they cannot be traced back to a person, including by us.

To be straightforward about the limit of that: the companies that host this site and deliver it to your browser necessarily see your IP address in order to answer the request, the way every website works. We do not join that to anything above.

Cookies

One cookie, set only after you sign in, holding your session so you stay signed in between pages. It cannot be read by scripts, it is sent only to this site, and it expires. There are no advertising cookies and no analytics cookies, which is why there is no cookie banner asking you to accept any.

Who else handles your information

We use a small number of service providers to run the product. They act on our instructions, and each sees only what its job requires.

  • Vercel — hosts the site and stores verification photos until they are deleted.
  • Neon — hosts the database.
  • Resend — delivers our email. It handles your address and the contents of the message.
  • Stripe — payments from venues only. If you are a member, Stripe holds nothing of yours.
  • Google — only if you choose to add a meetup pass to a phone wallet.
  • OpenStreetMap — supplies the background tiles for the city map on the momentum page. Loading that map sends your IP address to their servers, as loading any image from another site does.

Some of these providers operate infrastructure outside Canada, which means your information may be stored or processed in another country and be subject to the laws there.

How long we keep it

We would rather tell you what actually happens than quote a retention schedule we do not enforce. Each period below is deleted by a scheduled job, not by good intentions.

  • Verification photos — deleted at review. This one is immediate and automatic.
  • Waitlist sign-ups that were never confirmed — deleted after 12 months. If you started to join and never clicked the confirmation link, you never finished agreeing to anything, so we do not keep the record indefinitely. Confirmed sign-ups stay until you ask us to remove them.
  • The measurement records described above — deleted after 24 months. They contain nothing that identifies anyone, and they still expire.
  • Sign-in links and sessions — stored only as a scrambled fingerprint, never the link itself, and they expire.
  • Everything else — your account, your profile, your messages — kept for as long as your account exists, or until you ask us to remove it. We do not put a timer on those, because deleting the conversation you are in the middle of would be a strange thing to do to you.

If you unsubscribe from our email, we keep the record of the unsubscribe so that we do not email you again, and so a link you click later still works.

Your choices, and how to use them

You can ask for a copy of what we hold about you, ask us to correct it, ask us to delete it, or withdraw a consent you gave. There is no form. Email hello@stoop.place from the address on your account and say which one you want.

Deleting your account is handled by email, not by a button. We would rather say that than describe a self-serve control that does not exist yet. Some records may be kept after a deletion where we are required to — for example, a safety report someone else filed is their record of what happened, not yours to erase.

Every marketing email carries a one-click unsubscribe that needs no login. Email about something you are actually part of — a meetup being confirmed, an introduction — is not marketing, and you control that from your account settings.

If you think we have handled your information badly, tell us first and we will answer. You can also complain to the Office of the Privacy Commissioner of Canada, or to the Office of the Information and Privacy Commissioner for British Columbia.

Keeping it safe

Sign-in links and sessions are stored as scrambled fingerprints rather than as the values themselves, so the database does not hold anything that could be replayed to log in as you. Access to member data is limited to what running the product requires. No system is perfect, and we will not pretend otherwise — if something happens that puts your information at real risk, we will tell you and the relevant regulator.

Children

Stoop is for adults. It is not intended for anyone under 18, and we do not knowingly collect information from anyone under 18. If you believe a minor has an account, email us and we will remove it.

Changes

If we change this page in a way that matters, we will update the date at the top and, where the change affects how we use information you have already given us, tell you directly rather than relying on you to re-read it.

Related: Terms, Community guidelines, Contact.