← The Calendar 2027

Privacy Policy

Last updated: October 2026

1. Who we are

The Calendar 2027 (thecalendar2027.com) is an online platform that allows creators to claim and personalise individual days of the year 2027. References to "we", "us" or "our" refer to the operator of this platform.

2. Data we collect

We collect only the data you provide directly:

  • Name — your creator name, displayed publicly on your day.
  • Email address — used exclusively to send your login link and for order communications. Never displayed publicly.
  • Bio — a short description you write, displayed on your day.
  • Social links — Instagram, TikTok, website — displayed on your day if provided.
  • Media — images or videos you upload for your day.
  • Payment data — processed entirely by Stripe. We never store card numbers or payment credentials.

We also collect standard server logs (IP address, browser type, pages visited) for security and analytics purposes. We do not use third-party advertising trackers.

3. How we use your data

  • To reserve and confirm your slot on the calendar.
  • To send you a magic-link login so you can manage your day.
  • To display your public creator profile on the calendar.
  • To process payments via Stripe.
  • To send you service-related communications (receipt, slot confirmation).

We do not sell your data to third parties.

4. Third-party services

  • Supabase — database and authentication hosting.
  • Stripe — payment processing. Stripe's privacy policy applies to all payment data.
  • Vercel — website hosting and edge infrastructure.
  • Resend — transactional email delivery.

Each provider has their own privacy policy. We use these services solely to operate the platform.

5. Cookies

We use only functional cookies required for authentication (a session token set by Supabase Auth after you log in). We do not use advertising or tracking cookies.

6. Legal basis for processing (GDPR)

If you are located in the European Economic Area, we process your personal data on the following legal bases:

  • Contract performance (Art. 6(1)(b) GDPR) — processing your name, email, and slot data is necessary to fulfil your purchase and manage your slot.
  • Legal obligation (Art. 6(1)(c) GDPR) — retaining transaction records for tax and accounting purposes.
  • Legitimate interests (Art. 6(1)(f) GDPR) — security logging and fraud prevention.

The data controller is the operator of The Calendar 2027. Contact: hello@thecalendar2027.com.

7. Data processors

We use the following sub-processors, each bound by data processing agreements:

  • Supabase Inc. — database and authentication (EU data residency available).
  • Vercel Inc. — website hosting and CDN.
  • Stripe Inc. — payment processing (certified PCI DSS Level 1).
  • Resend Inc. — transactional email delivery.

8. Data retention

Your profile data is retained for as long as your slot is active on the calendar (through 31 December 2027) and for a reasonable period thereafter for legal and accounting purposes. You may request deletion at any time.

9. Your rights

You have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your data (subject to legal obligations).
  • Withdraw consent at any time (where processing is based on consent).
  • Data portability — receive your data in a structured, machine-readable format.
  • Lodge a complaint with your national data protection authority (e.g. the Italian Garante per la protezione dei dati personali).

To exercise any of these rights, contact us at the address below. We will respond within 30 days.

10. Contact

For any privacy-related questions or requests, email us at hello@thecalendar2027.com.