1. Data Collection
We collect information you provide directly to us, including your name, email, job title, and social media links. Payment information is processed securely via Stripe; we do not store full credit card details on our servers.
2. NFC & QR Technology
Your physical REACH. card contains a unique ID. When tapped or scanned, this ID communicates with our servers to display your profile. We track "Source Data" (NFC vs QR) to provide you with usage analytics. We do not track the identity of visitors to your profile unless they voluntarily submit a contact form.
3. Data Retention & Deletion
Under GDPR, you have the "Right to be Forgotten." You may delete your account at any time via the Dashboard. Upon deletion, all personal data is removed from our active database. Please note that physical cards in circulation will no longer function once the digital account is deleted.
4. Google Calendar Integration
If you choose to connect your Google Calendar, REACH requests permission to view and manage events on your calendar (the calendar.events scope). We use this access solely to:
- Read your busy times, so that slots when you are already booked are automatically hidden from your public booking page; and
- Create calendar events for new bookings made through REACH, so they appear in your calendar.
REACH's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We access only the calendar data necessary to provide the booking features described above.
- We do not sell your Google Calendar data, use it for advertising, or share it with third parties except as required to operate the service.
- We do not use your Google Calendar data to develop, improve, or train generalised artificial intelligence or machine learning models.
- We store only the access and refresh tokens required to maintain your connection, together with the minimum event timing data needed to display your availability.
You can disconnect your Google Calendar at any time using the Disconnect button on your REACH dashboard, or by revoking access in your Google Account permissions. Disconnecting immediately stops all further access and removes your stored tokens.
5. Video Calls
Some bookings may be conducted as video calls, which are powered by Jitsi Meet, an open-source video conferencing platform, hosted on the public meet.jit.si service operated by 8x8, Inc. When you join a REACH video call:
- All audio and video is encrypted in transit using the WebRTC standard DTLS-SRTP protocol.
- One-to-one calls are sent peer-to-peer and end-to-end encrypted directly between the two participants.
- For calls with three or more participants, media is routed via Jitsi's video bridge. It remains encrypted in transit; the bridge decrypts packets only momentarily in memory in order to route them, and call media is never written to persistent storage.
- REACH does not record, store, or have access to the content of your video calls. We do not retain audio, video, chat messages, or recordings.
- Each call uses a unique, unguessable room link tied to your booking. You should treat this link as private and share it only with your intended participant.
Your use of the video call feature is also subject to the Jitsi Meet security and privacy practices. For calls requiring the highest level of confidentiality, please arrange an alternative method, as the public meet.jit.si service relies on infrastructure operated by a third party.
6. Contact Information
For any data-related inquiries, please contact us at info@getworldreach.com. We are registered with the Information Commissioner's Office (ICO) in the United Kingdom.