This Privacy Policy explains how Hospo Tech Limited collects, uses, shares and protects your personal data when you use the Hospo website, mobile apps, and any related services (together, "Hospo" or the "Service"). It applies to workers, venues, and any visitor of the Service. We follow the EU General Data Protection Regulation (GDPR), the Data Protection Acts 1988 to 2018, the ePrivacy Regulations (S.I. 336/2011), and applicable app marketplace privacy requirements.
1. Who we are
Hospo Tech Limited (CRO 757604), a company registered in Ireland, is the data controller for personal data collected through the Service. Our registered office is 16 Bawnouge View, Kilcock, Co. Kildare, W23 Y83K, Ireland.
For any privacy matter, including subject access requests, deletion requests, or complaints, contact us at privacy@hospo.dev. We respond within 30 days as required by GDPR Article 12.
Our supervisory authority is the Data Protection Commission of Ireland. You may lodge a complaint at any time at dataprotection.ie.
2. Scope
This policy covers the Hospo website, mobile apps, and any related backend services and emails sent from hospo.dev domains. It does not cover third-party sites or services that link to Hospo (for example, a venue's own website), which have their own privacy policies.
3. What data we collect
3.1 Workers
Identity: full name, date of birth (for age verification), profile photo.
Contact: email address, phone number, county of residence in Ireland.
Work profile: roles, skills, certifications, work history, languages, availability, desired hourly rate, professional summary.
CV documents: any CV or supporting documentation you upload. The content of these documents is processed by AI to populate your profile (see Section 9).
Identity and right-to-work documents: passport, visa, GNIB/IRP card or other documents you choose to upload for venue verification.
Shift activity: shifts you apply for, accept, cancel, complete, and check-in/check-out times.
Reviews and ratings you give and receive.
Messages exchanged with venues through the in-app messaging feature.
Payment-related metadata: net pay confirmations from venues. We do not collect or store PPS numbers, bank account details, or card details. Stripe holds payment instrument data; PPS numbers, where required for payroll, are exchanged directly between worker and venue outside the Service.
3.2 Venues / employers
Business identity: company name, CRO number, VAT number where applicable, registered address, venue trading name, venue type.
Contact: name of authorised user, email address, phone number.
Listings: shifts and jobs you post, including location, hours, hourly rate, role description, and venue images.
Payment metadata: Stripe customer ID, last 4 digits of card, subscription status, invoices, platform fee history. We do not store full card numbers.
Reviews and ratings you give and receive.
Messages exchanged with workers through the in-app messaging feature.
3.3 All users
Account credentials: email and password hash (we never see your password in plaintext), or OAuth identifiers if you sign in with Google or Apple.
Device and technical data: device type, operating system, browser type, IP address, language preference, session tokens, time zone.
Diagnostic data: crash logs and error reports generated by the Service. These do not include the content of your messages or documents.
Communication preferences: notification settings, email subscription state.
Consent records: which legal agreements you have accepted and when.
3.4 What we do not collect
We do not collect special category data (health, racial origin, political opinions, religious beliefs, sexual orientation, biometric data used for identification), and we do not knowingly process data of anyone under 18. We do not use the device microphone, contacts list, calendar, SMS messages, call logs, or device advertising identifiers.
4. Device permissions
The Hospo mobile apps request the following permissions. All are optional and you can change them at any time in your device settings.
- Camera — used to scan QR codes for venue check-in and to take a profile photo. Images are not retained by us beyond what you choose to save.
- Photo library — used to upload a CV, profile photo, or (for venues) venue hero images.
- Location (foreground only) — used for QR check-in and check-out verification where required by a shift. We do not use background location and we do not track your location when the app is closed.
- Notifications — used to alert you about new shift matches, application updates, messages, and payment events.
- Files / documents — used to attach a CV in supported formats.
The Hospo apps do not request access to your contacts, microphone, SMS, call logs, calendar, motion sensors, body sensors, Bluetooth, or device advertising identifiers.
5. How worker contact details are shared
This is the most important section for workers to read carefully.
When you sign up as a worker on Hospo, your contact details (name, email, and phone number) are stored securely and are not visible to venues by default. Your public profile shows your role, skills, and availability only.
When a venue decides you are a suitable match for a role they have posted, they may choose to unlock your contact details. During the beta period, this is free. From 1 June 2026, the venue pays a 10% introduction fee to do so.
At the moment your details are released, you will receive an in-app notification and email telling you which venue has been given your contact information. The legal basis for this disclosure is the contract between you and Hospo (Article 6(1)(b) GDPR), which you accept by creating an account.
If you do not wish your contact details ever to be shared, you must deactivate or delete your account (see Section 14).
6. Why we process your data and the legal basis
We process personal data only where we have a lawful basis under Article 6 of the GDPR. The legal basis depends on the purpose:
- Account creation, profile management, matching workers and venues, processing shift bookings, in-app messaging, payments — performance of the contract between you and Hospo (Art. 6(1)(b)).
- Verification of venues (CRO check) and workers (right-to-work documents you choose to upload) — our legitimate interest in maintaining a trustworthy platform and your protection (Art. 6(1)(f)).
- Fraud prevention, abuse detection, security logging — legitimate interest (Art. 6(1)(f)) and, where applicable, compliance with a legal obligation (Art. 6(1)(c)).
- Transactional emails about your account, shifts, payments, and required policy updates — contract (Art. 6(1)(b)).
- Marketing emails, product newsletters, push notifications you have opted into — your consent (Art. 6(1)(a)), which you can withdraw at any time.
- Tax, payroll evidence, financial records retained after account closure — compliance with a legal obligation under Irish tax and corporate law (Art. 6(1)(c)).
- Aggregated analytics about Service usage — legitimate interest in improving the Service (Art. 6(1)(f)), using privacy-friendly tools that do not identify you.
7. Sub-processors and third parties
To run the Service we rely on the following sub-processors. Each is bound by a data processing agreement and processes data only on our instructions, subject to GDPR-compliant safeguards.
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication, file storage, backend functions | EU (eu-west-1, Ireland) |
| Lovable | Application platform and web hosting | EU / global edge |
| Stripe | Payment processing, subscription billing | Ireland / USA |
| Resend | Transactional and outreach email delivery | USA |
| Lovable AI Gateway (Anthropic, OpenAI, Google) | CV parsing, lead-generation drafting, content classification | USA / EU |
| Mapbox | Map rendering and geocoding | USA |
| Google Maps Platform | Address autocomplete and geocoding | USA |
| Plausible Analytics | Privacy-friendly, cookie-less, aggregated usage analytics | EU |
| Platform notification services | Push notification delivery | USA |
We do not sell your personal data. We do not share your data with advertisers. We share personal data only with the sub-processors listed above, with venues or workers as needed for matching and shift fulfilment, and where required by law (for example, in response to a valid court order or a regulator's enforcement request).
8. International data transfers
Some of our sub-processors are located in or transfer data to countries outside the European Economic Area (EEA), notably the United States. Where this happens, we rely on:
- The European Commission's adequacy decision under the EU-US Data Privacy Framework (where the recipient is certified); and
- The European Commission's Standard Contractual Clauses (Module 2: Controller to Processor), supplemented by technical measures such as encryption in transit and at rest.
You can request a copy of the relevant transfer mechanism by emailing privacy@hospo.dev.
9. Automated processing and AI
Hospo uses artificial intelligence in two narrow ways:
CV parsing. When you upload a CV, we send the document to an AI model (provided by Anthropic, Google, or OpenAI via the Lovable AI Gateway) to extract structured information (name, roles, skills, certifications, work history) so we can pre-fill your profile. The extracted data is shown to you for review and editing before it is saved. The AI providers we use are contracted not to use this content to train their general-purpose models, and we do not use CV content for any purpose other than populating your profile.
Outreach email drafting (admin only). Our admin team uses AI to draft personalised outreach to potential venue leads. This processes only publicly available information about the venue and the admin's brief; it does not process worker data.
Hospo's worker-to-venue matching is a search and ranking system, not an automated decision with legal or similarly significant effects on you under Article 22 GDPR. A human at the venue always reviews and chooses which worker to unlock.
10. Tracking technologies, cookies and analytics
10.1 Web (hospo.dev)
We use a small number of strictly necessary cookies to keep you signed in, to maintain session security, and to remember your cookie preferences. We do not use advertising cookies and we do not use cross-site trackers. Details and controls are in our Cookie Policy.
10.2 Mobile apps
Native apps do not use browser cookies. Instead we use secure on-device storage for your session token and your in-app preferences. The apps do not use device advertising identifiers and they do not contain any third-party advertising SDKs.
10.3 Analytics
We use Plausible Analytics, a privacy-friendly EU-hosted analytics tool that does not set cookies, does not use cross-site identifiers, and does not collect personal data. Aggregated, non-identifying counts (page views, country, device type) help us understand product usage.
10.4 Apple App Tracking Transparency
Hospo does not track you across other companies' apps or websites and does not access the iOS advertising identifier. The App Tracking Transparency prompt is therefore not shown.
11. Push notifications
With your permission, we use platform push notification services to send notifications about shift matches, application updates, messages, and payment events. You can turn notifications off at any time in your device settings or in the notification preferences screen in the app. Push tokens are stored only to deliver notifications and are deleted when you uninstall the app or log out.
12. Age requirement
Hospo is an 18+ service. You must be at least 18 years of age to register as a worker or as a venue user, regardless of jurisdiction. We do not knowingly collect personal data from anyone under 18. If we discover that we have collected data from a user under 18, we will delete it promptly and close the account. If you believe a person under 18 has provided us with data, contact privacy@hospo.dev.
13. Data retention
| Data category | Retention period |
|---|---|
| Active account profile (worker or venue) | For as long as the account is active |
| Profile data after account deletion | Deleted within 30 days, except items below |
| Shift history, invoices, platform-fee records, tax-related records | 6 years (Section 886, Taxes Consolidation Act 1997) |
| Messages between workers and venues | 3 years after the related shift completes, then deleted |
| Security and access logs | 12 months |
| CV and uploaded documents | Until you delete them or close your account |
| Consent and policy-acceptance records | 7 years after account closure |
14. Your rights and how to exercise them
Under the GDPR you have the right to:
- Access a copy of the personal data we hold about you.
- Rectify inaccurate data — most fields are editable directly in your profile.
- Erase your data, subject to legal retention obligations (see Section 13).
- Restrict or object to certain processing, including profiling based on legitimate interest.
- Data portability — receive a copy of the data you provided in a structured, commonly used, machine-readable format.
- Withdraw consent at any time where processing is based on consent (e.g. marketing emails).
- Lodge a complaint with the Data Protection Commission of Ireland.
In-app account deletion. You can delete your account at any time inside the app: go to Profile → Settings → Delete Account. The deletion is initiated immediately and your personal data is removed within 30 days, subject to the retention exceptions in Section 13.
Web account deletion (no app install required). You can also request account deletion without installing the app by visiting hospo.dev/delete-account or by emailing privacy@hospo.dev with the subject "Account Deletion Request". We will verify your identity and complete the deletion within 30 days.
15. Security
We protect your data with measures appropriate to the risk, including:
- TLS 1.2+ encryption for all data in transit.
- Encryption at rest for the production database and file storage.
- Row-level security so that one user cannot read another user's private data through the backend.
- Hashed passwords using industry-standard algorithms; we never see your plaintext password.
- Principle-of-least-privilege access for our team and audit logging of administrative actions.
- Regular dependency security scanning and prompt patching of known vulnerabilities.
- Tokenised payment handling via Stripe; full card numbers never touch our servers.
16. Personal data breach notification
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Data Protection Commission within 72 hours of becoming aware of it, and we will notify affected users without undue delay, as required by Articles 33 and 34 of the GDPR.
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to the Service, our sub-processors, or the law. Material changes will be notified to you by email and via an in-app banner before they take effect. The "last updated" date at the top of this page is always current.
18. Contact
For any privacy query, request, or complaint, contact privacy@hospo.dev.
Postal address: Hospo Tech Limited, 16 Bawnouge View, Kilcock, Co. Kildare, W23 Y83K, Ireland.