Privacy Policy

Last updated: July 2026

1. Controller

Jan Auras
Lenbachstr. 17
10115 Berlin
Germany
Email: hello@citreasurehunt.com

2. What this site does

CI Treasure Hunt is a non-commercial public directory of contact improvisation events and communities worldwide. We do not sell tickets, process payments, or organize events. We link to external organizer pages.

3. Hosting and server logs

This website is hosted by Vercel Inc. When you visit, technical data including IP address, browser type, requested pages, and access time may be logged by Vercel for security and stability purposes. We do not use these logs for profiling or tracking. See Vercel's privacy policy for details. Legal basis: Art. 6(1)(f) GDPR - legitimate interest in operating a stable website.

4. Analytics

This website uses Vercel Web Analytics (aggregate traffic: page views, referrers, top pages) and Vercel Speed Insights (Core Web Vitals: loading speed, layout stability, interactivity). Both tools are designed to be privacy-friendly: they do not use cookies or persistent identifiers and do not track visitors across sites. A short-lived hash derived from the visitor's IP address and user agent is used for unique visitor counting and is not stored. All data is aggregate only. It is processed by Vercel Inc. (US) under Standard Contractual Clauses. Legal basis: Art. 6(1)(f) GDPR — legitimate interest in understanding how the site is used and performs so we can improve it.

This website also uses Umami, a self-hosted, privacy-focused analytics tool (aggregate traffic: page views, referrers, visit duration). Like the tools above, Umami does not use cookies or persistent identifiers and does not track visitors across sites. Unlike Vercel's tools, Umami is self-hosted by us rather than run by a third-party processor, though no personally identifiable information is collected either way. Legal basis: Art. 6(1)(f) GDPR, legitimate interest in understanding how the site is used and performs so we can improve it.

5. Event data

Event listings are stored in a database provided by Supabase Inc. (US). This data is publicly displayed on the site. It consists of event details compiled from public sources and does not include personal data beyond organizer names and contact links that are already publicly available. Data transfers to Supabase are governed by Standard Contractual Clauses (SCCs) under Art. 46(2)(c) GDPR. See Supabase's privacy policy for details.

6. Newsletter

The newsletter signup form is embedded directly on this site and is provided by EmailOctopus (EmailOctopus Limited, UK). When you subscribe, your name and email address are transmitted to and stored by EmailOctopus. Their privacy policy governs that data. We do not store your email address on our own systems. Legal basis: Art. 6(1)(a) GDPR — your consent at the time of signup. You can unsubscribe at any time via the link in any newsletter email.

The signup form uses Google reCAPTCHA to prevent automated spam submissions. When the form loads, Google reCAPTCHA collects hardware and software information (including device and application data) and sends it to Google Inc. (US). This processing serves our legitimate interest in keeping the mailing list free from bots. Legal basis: Art. 6(1)(f) GDPR. See Google's privacy policy and terms of service.

7. Feedback form

The feedback form at /feedback is provided by Tally (Tally Solutions BV, Belgium) and is embedded via iframe. If you submit a response, the data you enter is received by Tally and forwarded to us. We use this data solely to improve the site and do not share it. Tally's privacy policy governs Tally's own processing. Legal basis: Art. 6(1)(f) GDPR — legitimate interest in improving the service.

9. Your rights

Under the GDPR you have the right to access, correct, or delete personal data we hold about you, to restrict or object to processing, and to data portability where applicable. To exercise these rights, contact us at hello@citreasurehunt.com.

You also have the right to lodge a complaint with the supervisory authority responsible for Berlin: Berliner Beauftragte für Datenschutz und Informationsfreiheit.

8. Event reports

When you submit a report via the report form on event, venue, or teacher pages, a daily-rotating hash of your IP address is stored to prevent abuse. This hash cannot be used to identify you and is not shared with third parties. Legal basis: Art. 6(1)(f) GDPR — legitimate interest in preventing spam and abuse.

10. Accounts and login

If you create an account to manage your events, we use Supabase Auth (Supabase Inc., US) to sign you in by magic link. We store your email address and an internal user identifier, and set a session cookie so you stay signed in. We do not use passwords — sign-in is by emailed link only. The session cookie is strictly necessary for login and is not used for tracking or profiling. Legal basis: Art. 6(1)(b) GDPR — processing necessary to provide the account and organizer tools you request. Data transfers to Supabase are governed by Standard Contractual Clauses (SCCs) under Art. 46(2)(c) GDPR. See Supabase's privacy policy.

11. Transactional email (magic links & notifications)

Emails such as your sign-in magic link, and notifications about your event submissions or profile claims, are delivered through Resend (Resend, Inc., US). Resend receives your email address and the message content in order to send these emails. We have configured Resend's EU sending region (Ireland, eu-west-1), so message delivery is processed within the EU; because Resend is a US-incorporated company, however, its staff may access data from the US, so transfers are governed by Standard Contractual Clauses (SCCs) under Art. 46(2)(c) GDPR. Legal basis: Art. 6(1)(b) GDPR for login emails (necessary to provide the account), and Art. 6(1)(f) GDPR — legitimate interest in operating the organizer tools — for related notifications. See Resend's privacy policy.

12. Community invite links

Some community pages hide their private Telegram/WhatsApp/Signal/LINE group link behind a "Request access" button, to keep it from being scraped. Before revealing the link, we run a Cloudflare Turnstile check: Turnstile collects technical data (such as browser and device signals, including your IP address) and sends it to Cloudflare, Inc. (US) to verify you're not a bot. We also store a daily-rotating hash of your IP address ourselves to rate-limit repeated requests; like the report-form hash in section 8, this cannot be used to identify you. Legal basis: Art. 6(1)(f) GDPR — legitimate interest in preventing these links from being scraped and spammed. See Cloudflare's privacy policy.

13. Profile photos

If you upload a profile photo, it is stored in our Supabase Storage (Supabase Inc., US) and is not publicly visible until we've reviewed and approved it. Approved photos are shown publicly on your teacher/organizer profile page, together with a photo credit if you provide one. You can replace or remove your photo at any time from your dashboard; a new upload is reviewed again before going live. Legal basis: Art. 6(1)(a) GDPR — your consent, given by choosing to upload a photo. Data transfers to Supabase are governed by Standard Contractual Clauses (SCCs) under Art. 46(2)(c) GDPR. See Supabase's privacy policy.

14. Changes to this policy

This policy will be updated when new features affecting data processing are added. The date at the top of this page reflects the most recent revision.