Privacy policy

Last updated: 4 July 2026

This privacy policy explains how RHUL Mobile ("we", "us", or "the app") collects, uses, stores, and protects your information when you use our mobile app and website. We believe in transparency and want you to understand exactly what data we handle.

Who we are

RHUL Mobile is an independent, student-built app. We are not affiliated with, endorsed by, or officially connected to Royal Holloway, University of London. We simply built a tool we wished existed as students.

The data controller for the personal data described in this policy is SHACKSOLUTIONS LTD (company number 13337279), England and Wales. Contact [email protected].

Information we collect

We collect the minimum data needed to provide and improve RHUL Mobile. Here's what we collect:

Account information

When you create an account or sign in:

  • Authentication data: If you sign in with Apple or Google, we receive your email address and name from these providers. We store your email for account management purposes. You can choose to hide your email when signing in with Apple.
  • Profile information: Display name and profile picture that you optionally provide.
  • Anonymous accounts: If you use the app without signing in, we create an anonymous account with a random identifier. No personal information is collected.
  • University verification: You may optionally verify your Royal Holloway email address to access certain features, such as posting on the marketplace.

Device and technical information

When you use the app, we may collect technical details such as:

  • Device model and platform
  • Operating system version
  • App version and build number
  • Push notification token (if notifications are enabled)
  • IP address, collected by PostHog and used for approximate geolocation (e.g. city-level) and analytics

Usage analytics

We use PostHog (EU-hosted) for product analytics and debugging:

  • Which screens you view and features you use
  • Content interactions (such as saves, shares, and marketplace actions)
  • App performance and stability signals
  • Session replay with text inputs and images masked

Session replay helps us identify bugs and UX issues. Your typed text and any photos on screen (such as marketplace listing photos or your profile picture) are masked before capture.

User-generated content

If you post on the marketplace, we store:

  • Your post content (title, description, category, price if applicable)
  • Images you upload
  • The contact method you choose to share (phone number, email address, or Instagram handle)
  • Any reports submitted about posts (reason/details) for moderation and safety

Important: Contact information you add to marketplace posts is visible to other users. Only share what you're comfortable making public.

Automated content moderation: Marketplace post text and images, and profile content (display name and avatar), are automatically screened by OpenAI's moderation service before publication to detect content that may violate our content guidelines (for example illegal, harmful, or sexually explicit material). See "International data transfers" below for how this data is safeguarded when sent outside the UK.

Saved items and preferences

We store your:

  • Saved/bookmarked content (news articles, events, bus stops, societies, etc.)
  • Event RSVPs (events you mark as "going")
  • App preferences and settings
  • Quick actions order customisation
  • Home screen widget configuration (selected bus stops and laundry rooms)

Feedback and support data

If you send feedback through the app, we store:

  • Your feedback message and category (bug, crash, feature request, etc.)
  • Optional technical context (screen name and stack trace)
  • Device context (platform, OS version, app version, model)
  • A PostHog identifier/session reference used for debugging

Permissions and on-device data

The app may request optional permissions when you use specific features:

  • Location: Used for "locate me" and campus walking directions. Location data stays on your device and is not transmitted to our servers. We do not continuously track or store your location history.
  • Camera and photos: Used if you choose to upload an avatar or marketplace image.
  • Notifications: Used for push notifications and local reminders (for example, laundry and bus alerts).
  • Face ID / biometrics: Used by the operating system to protect your authentication session stored in the device keychain. We do not receive or store biometric data.

In-app purchases

If you make in-app purchases (for example, marketplace bump credits or paid entitlements):

  • We do not collect or store your payment details. All payments are processed by Apple (App Store) or Google (Play Store).
  • We use RevenueCat to validate purchases and manage entitlements. RevenueCat receives transaction identifiers associated with your app user ID.
  • We store a record of your purchase (product type, duration, timestamp) to provide the service.

Your credit card number, billing address, and other payment details are handled entirely by Apple or Google and are never shared with us.

Home screen widgets

If you use iOS home screen or lock screen widgets (bus departures, laundry availability), the app fetches that data and stores it on your device. No additional personal data is collected through widgets.

Website cookies and local storage

On rhulmobile.com, we use cookies and local storage for analytics and consent preferences. We use a cookie banner so you can choose whether to allow analytics tracking.

If you opt out, we store that preference and disable PostHog capture for the site.

Information we do not collect

  • Your academic records, grades, or student ID
  • Your credit card numbers, billing address, or bank details (payments are handled by Apple/Google)
  • Your contacts or existing personal calendar data
  • Persistent precise-location history
  • Official Royal Holloway academic or HESA records - we only hold what you voluntarily provide within the app, such as your optional university email for verification

Advertising and partner content

Some content in the app is paid placement (the Deals tab, partner-pinned map locations, and any deal cards labelled "Ad"). We label these placements clearly so you can tell paid content from organic university content.

What this means for your data:

  • We do not share your personal data with partners. Partners do not receive your name, email, account ID, contact details, location, browsing history, or anything that could identify you.
  • We share aggregated counts only. Partners receive periodic reports of how many redemptions their deal received over a period - never individual user data.
  • We do not sell your data to advertisers, and we do not run third-party ad networks (Google Ads, Meta, etc.) inside the app.
  • Redemption telemetry stays internal. When you tap "Redeem" on a deal, we record that event (deal ID, timestamp, your account) for fraud-prevention and partner reporting. The user_id on that record is set to NULL when you delete your account.

Full advertising terms - including labelling commitments and editorial separation - are in section 15 of the Terms of service.

How we use your information

  • To provide the service: Syncing saved items, publishing your content, and delivering core app features.
  • To improve reliability: Understanding usage patterns helps us prioritise features and fix issues.
  • To keep the community safe: Moderating content (including automated screening of marketplace posts, avatars, and display names via OpenAI's moderation service), handling reports, and preventing abuse.
  • To communicate: Sending service notifications and important product updates.
  • To process purchases: Activating paid features and recording purchase outcomes.

Under UK GDPR, we rely on the following legal bases to process your data:

  • Account, marketplace, and saved-item features: Processed to perform our contract with you - providing the account, marketplace, and other core features you sign up to use.
  • Content moderation: Display names, avatars, and marketplace post content are processed (including automated screening via OpenAI's moderation service) on the basis of our legitimate interest in keeping the platform safe, lawful, and free of abusive or harmful content.
  • Push notifications: Service notifications (such as moderation outcomes and marketplace updates) are sent to perform our contract with you. Optional local reminders (for example, bus and laundry alerts) are based on your consent, given when you enable them.
  • Analytics: Usage, device, and technical data processed via PostHog is based on our legitimate interest in understanding and improving the app. You can opt out at any time using the in-app analytics toggle or, on the website, the cookie preference banner - see "Opt-out" under Your rights.

Data storage and security

  • Where: App data is stored using AWS, Cloudflare, and Neon infrastructure providers, primarily within the UK and EU.
  • Encryption: Data is encrypted in transit (TLS). Storage protections are managed by our infrastructure providers.
  • Access: Access is limited to authorised maintainers and service providers who need it to operate the service.
  • Security: We apply reasonable technical and organisational safeguards, but no system is completely risk-free.

Third-party services

We use these trusted third-party services:

ServicePurposePrivacy policy
AWSApp and partner-dashboard hosting, email delivery, and scheduled tasksaws.amazon.com/privacy
CloudflareWebsite hosting and security, image delivery, and storage of uploaded images (avatars, marketplace photos, partner logos)cloudflare.com/privacypolicy
NeonDatabase hostingneon.tech/privacy
PostHogAnalytics and session replayposthog.com/privacy
ExpoMobile app framework and push notificationsexpo.dev/privacy
Apple Sign InAuthentication (if you choose)apple.com/legal/privacy
Google Sign InAuthentication (if you choose)policies.google.com/privacy
RevenueCatIn-app purchase managementrevenuecat.com/privacy
Google MapsCampus map rendering on Androidpolicies.google.com/privacy
SlackInternal moderation and operational alerts (for example, marketplace report workflows)slack.com/privacy-policy
OpenAIAutomated content moderation of marketplace posts, avatars, and profile content. Data sent: marketplace post text and images, display names, and avatar imagesopenai.com/policies/privacy-policy

Your rights

You have full control over your data:

  • Access: View your profile and saved data any time in the app.
  • Correction: Update your display name, avatar, and preferences in settings.
  • Deletion: Delete your account from within the app. You're signed out immediately; if you sign back in within 30 days the deletion is cancelled and your account is restored exactly as it was.
  • Portability: Contact us to request an export of your data.
  • Opt-out: You can use the app anonymously without creating a full account. In the app, you can turn analytics off at any time from the Analytics toggle in Settings, and website visitors can opt out of analytics cookies via the cookie preference banner.

Data retention

  • Active accounts: Data is retained while your account exists.
  • Deleted accounts: When you delete your account you're signed out immediately and your account enters a 30-day recovery window. Signing back in during that window cancels the deletion and restores everything. If you don't sign back in, all personal information (email, name, avatar, push token, preferences, and uploaded files) is permanently and irreversibly deleted from all active systems within 30 days, in line with UK GDPR's right to erasure.
  • Marketplace posts: Automatically expire after 30 days unless renewed.
  • Analytics logs: PostHog events are retained for approximately 12 months, after which they are deleted or fully anonymised.
  • Feedback logs: Retained for approximately 24 months to support ongoing bug investigation, then deleted.

Children's privacy

RHUL Mobile is intended for university students and is not directed at children under 16. We do not knowingly collect information from anyone under 16. If you believe we have collected data from a child, please contact us immediately.

International data transfers

Your data may be processed in countries outside your residence, including through our third-party providers. Where a provider processes data outside the UK or EU, we rely on an approved transfer mechanism - typically the UK International Data Transfer Agreement or the EU Standard Contractual Clauses - to safeguard it.

In particular, when marketplace post content, images, avatars, and display names are sent to OpenAI (a US company) for automated content moderation, that transfer is safeguarded by Standard Contractual Clauses or an equivalent approved transfer mechanism.

Changes to this policy

We may update this privacy policy from time to time. Significant changes will be announced through the app or website. The "Last updated" date at the top shows when this policy was last revised.

Contact us

Questions about this privacy policy or your data? Email us at [email protected].