Privacy Policy
Version: v3.2
Effective date: 1 October 2026
1. Who we are
Havra is an activity-first social platform operated from Sydney, New South Wales, Australia. This policy applies to havra.social, related Havra domains, web/mobile applications and services.
2. Information Havra may collect
| Category | Examples |
|---|---|
| Account and profile | Display name, email address, date of birth for age eligibility, required home city, optional profile photo or Havra avatar, gender field, optional age band, country of origin, languages, interests and privacy preferences. |
| Authentication | Passwordless email sign-in events and identifiers from supported Google, Apple or personal Microsoft sign-in. Havra does not store a member password. |
| Participation | Save/Interested/Confirmed/Waitlisted states, cancellations, event tickets, QR-verified attendance, host roles, group membership, feedback and rewards. |
| Communications | Event threads, group discussions, connection/direct messages where enabled, support requests and moderation reports. |
| Location | Home city; optional session location for Near Me; momentary host/geolocation proof for eligible event operations. Havra does not use continuous location tracking for ordinary event attendance. |
| Usage and device | IP address, browser/app/device information, pages/features used, diagnostics, security events and limited analytics. |
| Billing | Provider/customer/subscription identifiers, entitlement state and transaction references needed to operate membership. Havra does not store raw card numbers or CVV. |
| Admin/safety | Audit logs, moderation records, reports, fraud/abuse signals and security events. |
3. Why Havra uses information
- Create and secure accounts;
- Show relevant activities and city discovery;
- Operate event confirmation, capacity, waitlists, protected meeting details and check-in;
- Operate groups, connections and messaging;
- Calculate private attendance/reward state and limited host planning context;
- Send transactional notifications and optional discovery/marketing communications;
- Process membership entitlements and reconcile payment-provider state;
- Prevent abuse, investigate reports, enforce rules and protect platform security;
- Measure product performance and improve Havra;
- Comply with legal obligations.
4. Authentication
Havra uses passwordless email sign-in and supported identity providers. Havra does not create or store a Havra password for members. If you use Google, Apple or a personal Microsoft account, the provider authenticates you and Havra receives the information authorised for sign-in/profile setup.
5. What other members and hosts can see
- Public/signed-out pages show only public-safe activity/group information and broad location information.
- Member profiles are not intended to be indexed as public web pages.
- Confirmed attendees may see eligible host/attendee profile context according to Havra’s privacy rules.
- Hosts may see operational RSVP/check-in status and limited attendance-planning context. Hosts do not receive raw member email lists, date of birth, billing information, private platform reports or Havra internal trust scores.
- Exact meeting details are protected and shown only to eligible users according to the event state.
6. Attendance reliability and trust
Havra records factual event outcomes and may derive a private Attendance Reliability status from recent Confirmed-event outcomes. This is not a public numeric score or public no-show count. Hosts may receive limited, neutral planning context where needed. Havra keeps detailed anti-abuse and trust signals private to protect members and prevent gaming.
7. Groups
Group Owners, Admins and Moderators receive only information and actions needed for their granted group permissions. Private group content and member-only events are access-controlled. Group membership does not give an administrator access to private direct messages or Havra platform moderation records.
8. External activities and third-party links
Havra may publish factual activity information derived from trusted external sources and link to official organisers, venues, councils or ticketing providers. If you follow an external link, that third party’s privacy practices apply to information you provide there.
9. Service providers
Havra uses service providers for functions such as hosting/database, authentication, email delivery, analytics, maps, security and payment processing. Providers may process personal information only to the extent needed for those services and subject to applicable contracts and safeguards. The provider list may change as Havra develops.
10. Overseas processing
Some providers may process or store data outside Australia depending on their infrastructure and selected region. Havra will take reasonable steps required by applicable Australian privacy law when disclosing personal information overseas and will update this policy as the production vendor/region list is finalised.
11. Cookies and analytics
Havra may use necessary cookies/local storage for authentication, security and preferences, and optional analytics technologies to understand product use. Where consent is required, optional analytics/marketing technologies will be controlled through the applicable consent mechanism. Havra does not sell personal information to advertisers.
12. Security
- TLS/HTTPS in transit and provider-managed encryption at rest where supported;
- Row-level/access controls and least-privilege authorization;
- Private storage/signed access for protected media;
- Server-side validation for uploads and URLs;
- Verified provider webhooks for payment state;
- Audit logging for privileged actions;
- Monitoring, backups and incident response.
13. Retention
Havra keeps information only as long as reasonably needed for product operation, safety, fraud prevention, legal obligations and legitimate recordkeeping. Different data types have different retention periods. Precise host-location proof and short-lived QR secrets are retained for much shorter periods than account, safety or financial records. Backups expire on provider schedules.
14. Account deletion
Members can request account deletion through Account Settings. Havra may provide a short recovery period before final deletion. After finalisation, profile data is removed or de-identified where reasonably possible, while limited safety, fraud, legal, financial, audit or shared-event records may be retained where necessary. Deleting and recreating an account does not restore forfeited rewards or prior referral attribution.
15. Access and correction
Where the Australian Privacy Principles apply, individuals generally have rights to request access to personal information and correction of information that is inaccurate, out of date, incomplete, irrelevant or misleading, subject to permitted exceptions. Havra also intends to provide practical self-service correction and may voluntarily offer exports/deletion beyond minimum statutory requirements.
16. Direct marketing
Optional marketing/discovery communications can be unsubscribed from. Essential security, billing, safety and material event communications may still be sent where necessary to provide the service or meet legal obligations.
17. Data breaches
Havra will assess suspected eligible data breaches and, where required by the Notifiable Data Breaches scheme or other applicable law, notify affected individuals and the relevant regulator. Notifications will explain what happened, the kinds of information affected and recommended protective steps.
18. Adults only
Havra membership is for adults aged 18 and over. If Havra discovers an underage account, it may restrict/remove the account and handle associated information according to safety and legal requirements.
19. Contact and complaints
Privacy questions or requests can be sent to privacy@havra.social. If an Australian privacy complaint is not resolved directly with Havra, eligible individuals may be able to complain to the Office of the Australian Information Commissioner (OAIC).
20. Changes to this policy
Havra may update this policy as the product, vendors or law change. The current version and last-updated date will be published, and material changes may be notified through appropriate channels.