Privacy Policy
Last updated: October 2, 2026
Welcome to Hantes ("we", "us", "our"). We are committed to protecting your privacy and providing a transparent experience. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our website and services (collectively, the "Service"). It also describes your privacy rights and how the law protects you.
The site does not use tracking cookies for audience analytics, advertising or advertising profiles. Sign-in and payment features may use cookies or other technical data needed for their operation, security and fraud prevention.
This policy explains the processing associated with the Service. Reading it does not constitute acceptance of sales terms or consent to optional processing.
1. Who We Are (Data Controller)
For the purposes of data protection laws, including the General Data Protection Regulation (GDPR), the data controller is:
Aurélien CoppéeRue du Grand Pré, 6560 Hantes-Wihéries, Belgique
If you have any questions about this Privacy Policy, our privacy practices, or if you wish to exercise your rights, please contact us at: contact@hantes.be.
2. The Information We Collect and How
We collect information in different ways: information you provide to us directly, information from third-party services when you use them to log in, and some information automatically for essential service functions.
a. Information You Provide Directly
Communications and favorites:When you contact us, we may collect your name, email address and message. When you are signed in, the identifiers of your favorite events and your favorites calendar subscription settings are stored with your account so you can access your selection across your devices. Favorites selected in the browser without an account are added to your account favorites when you sign in.
Purchase and payment data:When you make a purchase, we process your contact or billing details, order reference, amounts and payment status. Information entered in the payment form is sent to the payment provider; we do not store your full card number or security code in the site’s database.
b. Information from Third-Party Login Services
You may choose to register and log in to our Service using third-party authentication providers. By doing so, we may receive personal information from that provider, which may include:
- Your full name
- Your primary email address
- Your profile picture URL
- A unique identifier assigned by the provider
The information we receive depends on your privacy settings with that third-party service, and we do not receive or store your password for those services. Your interaction with these third-party services is governed by their respective privacy policies, not this one.
c. Information We Collect Automatically
Usage and Device Data:Like most websites, our servers may automatically record standard information, such as your IP address, browser type, and operating system. This information is used for legitimate security, system administration, fraud prevention purposes, and to ensure the proper functioning of our Service.
Storage in your browser:Local storage keeps your display preferences and favorites selected without an account. Once signed in, it also keeps a copy of account favorites and pending changes. Signing out or switching accounts removes these local copies and changes for the previous account; unsynced changes are lost. Clearing browser data does not delete favorites already saved to your account. To suggest creating an account, Hantes also keeps a visit counter capped at three, the time of your last visit and the state of this suggestion only in your browser. These data expire after 90 days without another visit and are not sent to analytics.
Our Stance on Cookies and Tracking:This site uses no tracking cookies for analytics, advertising, or profiling purposes. We are committed to providing a private browsing experience and do not use third-party services like Google Analytics to monitor your web behavior.
Anonymous audience and advertising measurement:We count qualified page views, viewable advertising impressions, and clicks as aggregate totals. Only the page path and language and, for an advertisement, its id, slot, and contextual targeting level are counted. We collect no URL query, referrer, user identifier, or coordinates. No individual journey or unique visitor is created. A non-reversible network-address digest, renewed hourly, is used only to limit abuse and is deleted within two hours. Global Privacy Control and Do Not Track signals are honored.
3. How and Why We Use Your Information
We use the information we collect for various purposes, and we ensure we have a legal basis for each processing activity under GDPR.
| Purpose of Processing | Categories of Data | Legal Basis (GDPR) | Retention Period |
|---|---|---|---|
| Providing and maintaining our Service | Account Info, Third-Party Info | Performance of a contract | Duration of account existence |
| Managing your account | Account Info, Third-Party Info | Performance of a contract | Duration of account existence |
| Communicating with you | Data (Name, Email) | Legitimate interest | 2 years after last contact |
| Storing your preferences | Local Preferences (Theme) | Consent (User action) | Until manually cleared |
| Security and fraud prevention | Device Data (IP) | Legitimate interest (Security) | Duration necessary for security |
| Measure audience and advertising performance | Anonymous totals by day, page, language, and advertisement | Legitimate interest (measuring and improving the Service) | 25 months for aggregates; 2 hours for abuse throttling |
4. Data Sharing and Disclosure
We do not sell your personal information. If you activate your favorites calendar subscription, your calendar application and anyone who has its URL can view your selection of public events; the calendar contains neither your name nor your email address. Keep this URL personal. You can revoke access in your account settings; this does not erase copies already retrieved by an application or recipient. Other sharing is limited to the circumstances described below:
- Service Providers:The providers below support the listed features when you use them. The data shared depends on the service concerned.
- Website hosting: Google Firebase. Delivery of the site’s pages and files; processing of technical request data needed for delivery and service security. Google Firebase privacy information
- Authentication: Supabase. Management of the account, email address, sign-in identifiers and sessions; access verification and account security. Supabase privacy information
- Database: Supabase. Storage of account data, favorite event identifiers and their calendar subscription settings, along with data you entrust to the service and order references, amounts and statuses when you make a purchase. Supabase privacy information
- Sign-in and security emails: Resend. Delivery of account messages using the recipient address, subject and content supplied by the authentication service, including confirmation links or codes. Resend privacy information
- Commercial emails related to a request: Resend. When a quote or order follow-up message is sent to you, delivery of the recipient address, subject and commercial content needed for that message. Resend privacy information
- Payments and invoices: Stripe. When an online payment or invoice is offered, processing of billing details, the order reference and amounts, payment information and technical data needed for security and fraud prevention. The service returns payment status and references to us. Stripe privacy information
- Legal Compliance:We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court or a government agency).
- To Protect Our Rights:We may disclose your information when we believe it is necessary to investigate, prevent, or take action regarding potential violations of our policies, suspected fraud, situations involving potential threats to the safety of any person.
5. International Data Transfers
Storage and processing locations depend on each provider and the service configuration. Pages may be delivered through a global network.
A hosting region for the site or database does not mean all processing is limited to that region: page delivery, email delivery, payments and support may involve other countries, including outside the European Economic Area.
The provider links above explain their privacy and transfer practices. You can contact us for details about the services used for your account or order.
6. Security and Data Retention
Security:We use administrative, technical, and physical security measures (HTTPS encryption/at rest) to help protect your personal information.
Retention:Account favorites are kept until you remove them or delete the account. Revoking or replacing the link deletes the old subscription from the active database, without retaining a link history. Deleting the account removes its favorites and subscription from the active database. These actions do not remove copies already obtained by your calendar app or another recipient. To request access, an export or erasure of your data, use the contact in the “Your rights” section.
7. Your Data Protection Rights
Depending on your location (GDPR), you may have the following rights:
- Right to Access:Request copies of your personal data.
- Right to Rectification:Correct inaccurate information.
- Right to Erasure:Request the deletion of your data.
- Right to Restrict Processing:Limit the use of your data.
- Right to Object:Object to processing based on legitimate interests.
- Right to Portability:Receive your data in a structured format.
- Withdraw Consent:Withdraw your consent at any time.
- Non-discrimination:No penalty for exercising your rights.
To exercise these rights, please contact us at: contact@hantes.be. You also have the right to lodge a complaint with a data protection authority.
8. California Residents (CCPA/CPRA)
This section applies to California residents.
Categories Collected:
Identifiers (Name, Email, IP) and Internet Activity (Browser).
- Identifiers
- Network Activity
Sale/Sharing:
We do not "sell" or "share" your personal information (as defined by CCPA).
Sensitive Data:
We do not collect sensitive personal information.
Shine the Light:
We do not disclose personal information to third parties for direct marketing purposes.
9. Children's Privacy
Our Service is not intended for children under 13 (or 16 in the EEA).
10. Changes
We may update this policy. Check the "Last updated" date.
11. Contact Us
If you have any questions: contact@hantes.be.
Event listings and moderation records
To manage listings, Hantes stores their content, the link to your account identifier, their status and their revision in Supabase. Creation and claim records support daily and monthly limits. New submissions await moderation; management data is accessible only to the relevant account and authorized people.
Creating, claiming or editing an event sends a notification to a private Discord channel for the moderation team. It includes the action, event name and identifier, its public link when published, the technical account identifier (UUID), status, revision and notification reference. The account email address and complete form contents are not sent in this notification. The technical identifier can link the action to an account, so this information is not anonymous.
Discord receives this information to provide the notification service. Its privacy policy is available at https://discord.com/privacy. To exercise your rights regarding a listing or these records, write to contact@hantes.be with the relevant event reference.