The legal bit
Privacy policy
You're handing us your name, your email and a bit about yourself. Here's exactly what happens to it, in plain language.
Last updated 16 September 2026
Who’s responsible
The Link is a social club based in Rotterdam, the Netherlands. We are the data controller for everything described on this page, which means we decide what is collected and what happens to it.
The quickest way to reach us about anything on this page is thelink.rotterdam@gmail.com.
What we collect
Only what the club actually needs to run. There is no profiling, no advertising, and we never sell or rent your data to anyone.
- Your membership
- Your name and email address, and — only if you choose to answer — your age bracket, the city you're in, what you like doing at weekends, and what you're hoping to get out of the club. You pick these from the join form; every one of them is optional except your name and email.
- Whether you want club news
- If you unsubscribe from our newsletter we record that you did, so we don't email you again by mistake. Nothing else changes — you keep your membership, your stamps and every email about events you've booked.
- Your password
- Stored only as a scrypt hash, never as text. We cannot read your password, and neither can anyone who might get hold of the database.
- Events you book
- Which events you've booked, whether you paid, whether you turned up, your Link Stamps, and any free event you've unlocked or redeemed. Also the events you've favourited.
- Payments
- You pay for events by Tikkie, or by arrangement with us directly. We never see or store your bank or card details — those stay with your own bank or payment app. All we keep is a record of whether a booking has been paid, so we can confirm your place and refund you if we need to.
- Messages you send us
- If you use the contact form or enquire about a private event, we keep what you wrote along with your name, email, and anything else you told us — so we can reply and pick the thread back up later.
- Guests you bring
- If you bring a friend who isn't a member, we keep her name — and her email only if you give it to us — so we know who to expect at the door. She gets no account, no Link Stamps and no newsletter: a guest is never added to our mailing list, and we won't email her at all unless you've asked us to send her the details. Her record is removed with the booking it belongs to, and if you're the guest and you'd rather we held nothing, write to us and we'll delete it.
- Photos from events
- We take photos at events and some end up in the gallery on this site or on our Instagram. You may be recognisable in them.
Why we’re allowed to
The GDPR asks us to name a lawful basis for each thing we do. Ours:
Running your membership and your bookings
Performance of a contract
We can't give you a place at an event without knowing who's coming.
Sending you booking confirmations and account emails
Performance of a contract
Activation links, password resets, and the confirmation after you pay.
Answering your messages
Legitimate interests
You wrote to us and would like a reply.
Holding the name of a guest a member brings
Legitimate interests
We need to know who to expect at an event we're responsible for. It's the minimum — a name, and an email only if we were given one. Guests are never added to the mailing list.
Keeping records of payments
Legal obligation
Dutch tax and accounting rules require us to retain these.
Photos of events, on this site and Instagram
Legitimate interests
Showing what the club is actually like. You can object at any time and we'll take a photo down — see below.
Emailing you news about upcoming club events
Legitimate interests
You joined a social club, so we tell you what the club is doing. Every one of those emails has an unsubscribe link, and opting out never affects emails about events you've booked.
Counting anonymous page views
Legitimate interests
Knowing which pages are used helps us run the club. No cookies, and nothing that identifies you.
Keeping you logged in
Strictly necessary
One cookie. No consent needed and none asked for.
Cookies
One cookie, called link_session. It keeps you logged in and does nothing else. It lasts 60 days, it can’t be read by JavaScript, and it isn’t shared with anyone.
That’s the whole list. We do count page views, so we can see which parts of the site people use — but that is done without cookies, without storing anything on your device, and without anything that identifies you or follows you to other websites. No advertising trackers, no third-party pixels, no session recording. That is why this site has never shown you a cookie banner — a strictly necessary cookie doesn’t need consent, and we don’t set any other kind.
Who else sees it
A handful of service providers, each doing one job for us under a data processing agreement. They may not use your data for their own purposes.
Supabase
Hosts the database that holds everything above.
EU region
Vercel
Hosts and serves this website, and counts anonymous page views so we can see which pages people actually use.
EU region, US company
Resend
Sends our transactional email — activation, resets, confirmations.
US company
Some of these are US companies. Where your data reaches the United States, the transfer is covered by the EU–US Data Privacy Framework or by the European Commission’s standard contractual clauses.
How long we keep it
Your membership data stays for as long as you’re a member. Ask us to delete your account and we’ll remove it, along with your bookings, stamps and favourites.
Two exceptions. Records of payments are kept for seven years, because Dutch tax law requires it. And messages you’ve sent us are kept for two years, so we have the history if you write again.
Photos at events
We photograph events and post some of them here and on Instagram. If you’d rather not be in them, tell whoever’s holding the camera on the night — no explanation needed, and it won’t be awkward.
If a photo of you is already up and you want it gone, email us and we’ll remove it. We won’t ask why.
Your rights
Under the GDPR you can ask us to do any of the following, free of charge. We’ll respond within one month.
- See it
- Ask for a copy of everything we hold about you.
- Fix it
- Correct anything that's wrong — most of it you can edit yourself in your dashboard.
- Delete it
- Ask us to erase your account and the data attached to it.
- Take it
- Get your data in a portable, machine-readable form.
- Limit it
- Ask us to pause what we do with it while something is being sorted out.
- Object
- Tell us to stop processing anything we do on the basis of legitimate interests — including photos.
Email thelink.rotterdam@gmail.com and we’ll sort it.
Keeping it safe
Passwords are hashed, never stored as text. The database is locked down so that nothing can be read from a browser — every request goes through our server, which checks who you are first. Card details never touch our systems at all.
Changes to this policy
If we change how we handle your data, we’ll update this page and move the date at the top. If it’s a significant change, we’ll email members rather than hope you notice.
Questions about any of this? Come and ask.

