Privacy policy
Last updated: 28-09-2026
Paragliding Events is a free, community-driven calendar of paragliding events. We keep as little personal data as we can, never sell it, and don’t show ads. This page explains what we keep, why, for how long, and what you can do about it.
Who we are
Paragliding Events is run by the team behind Paragliding Events, who is responsible for your personal data on this site (the “controller” under the EU General Data Protection Regulation, GDPR). For anything about your data, use the contact form and choose My personal data.
What we keep and why
Your account. Your email address, username and password (stored only as a secure hash, never readable). We need these to let you log in, and use your email address for the emails described below. If you set up two-factor authentication, we keep the key your authenticator app uses.
Your profile, all optional except the pilot type: picture, description, date of birth, country, pilot type, license, languages, social media usernames, and your connections to organisations, brands and events. We use them to show your profile and to find relevant events. Your date of birth and email address are never shown to others. Your profile is only visible to others once you’re connected to an event, organisation or brand (see Who can see my profile?).
What you add to the site: events, organisations and brands, and the changes you make to them. They’re public, as sharing them is the point of the site. We keep a change log with who changed what, to be able to undo mistakes and misuse.
Your settings: your email alerts (filters and how often), notification settings, preferred currency and whether your profile is hidden.
Messages and reports. What you write in the contact form (with your name if you give it, and your email address to reply) and in Report this event (with your username when you’re logged in, or an email address if you choose to leave one).
Anonymous statistics. Which pages are viewed, for how long, from which kind of device, from which website visitors came, and clicks on links to other websites and on Add to calendar. These are linked to a random number that only lasts while your browser tab is open, not to you: we don’t store your IP address, your account or any cookie for this. Administrators of organisations and brands see totals for their own pages and events.
Security and errors. To stop abuse (like someone sending hundreds of messages), we count requests per visitor using a scrambled, one-way version of the IP address, which we delete after a day. When a page shows an error, we record the error, the page and the type of browser, to fix it.
The legal basis is our agreement with you when you create an account and use its features (GDPR article 6(1)(b)), and our legitimate interest in running a safe, working site for the community (article 6(1)(f)) for the change log, reports, security and anonymous statistics.
Emails
We only email you about things you asked for or need to know: confirming your address and resetting your password, the alerts you set up, and, if you manage an organisation or brand, events that need your approval (you choose which under Settings > Notifications). Every alert email has a link to unsubscribe from it straight away. We don’t send newsletters or advertising.
Cookies and storage in your browser
We don’t use cookies for tracking or advertising. Your browser keeps your login (so you stay logged in) and the random number for the anonymous statistics (only while the tab is open). These are needed for the site to work and aren’t shared with anyone.
Services we use
We use a few services to run the site. They only process data on our behalf, under data processing agreements, and not for their own purposes:
- Supabase: the database, logins and uploaded pictures.
- Vercel: hosting the website.
- Resend: sending emails.
Some parts of a page load directly from other services, which then see your IP address like any website you visit: map tiles from OpenStreetMap, and place names from Open-Meteo when you search for a city in a form. Links to Google Calendar, Outlook, WhatsApp, Facebook and other sites only send information to them when you click them.
Some of these services may process data outside the European Economic Area; where they do, they’re bound by the EU’s standard contractual clauses or an adequacy decision.
How long we keep it
- Your account, profile and settings: until you delete your account.
- Events, organisations and brands you added: they stay on the site after you delete your account, without your name.
- Anonymous statistics: 13 months.
- Scrambled IP addresses for abuse protection: 1 day.
- Error reports: until fixed, and then 90 days.
- Contact messages and event reports: as long as needed to handle them, and at most 2 years.
Your rights
You can see and change most of your data yourself under Settings, and delete your account there (Settings > Configuration), which removes your profile, your alerts and your connections straight away. You also have the right to get a copy of your data, to have it corrected or deleted, to object to or restrict how we use it, and to take it with you. Ask us through the contact form; we’ll answer within a month.
Not happy with how we handle your data? You can also complain to the data protection authority in your country.
Children
The site is meant for people aged 16 and over. If you’re younger, please don’t create an account.
Changes
If we change this policy in a way that matters, we’ll update the date at the top and, for important changes, tell account holders by email.