Legal
Privacy Policy
Last updated: October 4, 2026
This Privacy Policy explains how meetstack ("we", "us", "our") collects, uses, and protects personal data when you use our platform to book or host consultant video calls. We are subject to the EU General Data Protection Regulation (GDPR) because we offer our services to residents of the European Union.
1. Data controller
The data controller is Uptide Group Limited, a company registered in England and Wales (company no. 09257622), with registered address at Faversham House, Wirral International Business Park, Old Hall Road, Wirral, CH62 3NX.
Privacy contact: privacy@meetstack.io
2. Information we collect
We collect only what we need to run the service:
- Account data: name, email address, hashed password, role (client or consultant), and preferred language.
- Organisation data (consultants): organisation name, slug, and billing currency.
- Profile data (consultants and moderators): bio, areas of consultantise, spoken languages, profile photo.
- Booking and call data: rooms created, scheduled date and time, duration, parties involved, join tokens, and call status.
- Payment data: card payments are processed directly by Stripe; we store only a Stripe customer ID as a reference and never see or store card numbers. Consultant payout data (bank details, identity documents) is collected and held by Stripe as an independent controller — we store only the Stripe Connect account ID and have no access to connected account financial data.
- Call metadata: call start and end timestamps, technical quality indicators, and a per-participant attendance record for each call — the display name and email address of each person who joined, when they joined and left, and why the connection ended. Video and audio content is never recorded, transcribed or streamed. This is enforced technically, not merely by policy: every access token the platform issues disables recording, transcription and live streaming outright, so no participant — including the consultant — is able to turn them on.
- Support data: messages you send us through the support form.
- Device and usage data: IP address, browser type, operating system, and basic server access logs used for security and debugging.
3. How we use your data
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the booking, video, and billing features | Art. 6(1)(b) — contract performance |
| Consultant payout processing via Stripe Connect | Art. 6(1)(b) — contract performance |
| Sending transactional emails (confirmations, reminders, receipts, moderator change notices) | Art. 6(1)(b) — contract performance |
| Security, fraud prevention, and abuse detection | Art. 6(1)(f) — legitimate interests |
| Platform reliability and technical debugging | Art. 6(1)(f) — legitimate interests |
| Compliance with tax, accounting, and legal obligations | Art. 6(1)(c) — legal obligation |
Where we rely on legitimate interests, we have balanced those interests against your rights and concluded they do not override them. You may object to legitimate-interest processing at any time (see Section 8).
We do not use automated decision-making or profiling that produces legal or similarly significant effects on you (GDPR Article 22).
4. Sub-processors and data locations
We share data only with the service providers below, all under data processing agreements. We do not sell personal data.
| Provider | Purpose | Location |
|---|---|---|
| Northflank | Application hosting (CMS and frontend) | US East region, United States 🇺🇸 — transfers covered by EU Standard Contractual Clauses. |
| 8x8, Inc. (JaaS) | Video call infrastructure (Jitsi as a Service), a GDPR-compliant video provider | USA 🇺🇸 (8x8, Inc.). Call media is routed via 8x8's global infrastructure by default, or its EU (Frankfurt 🇪🇺) region for calls where the consultant has enabled EU routing. As 8x8, Inc. is US-established, transfers are covered by EU Standard Contractual Clauses either way. |
| DigitalOcean Spaces | File and media storage (profile photos, assets) | ric1 — Richmond, United States 🇺🇸 — transfers covered by EU Standard Contractual Clauses. |
| Stripe, Inc. |
Buyer payments: Stripe processes card data on our behalf as a payment processor. We store only a Stripe customer ID — no card numbers or CVVs ever pass through our systems. Consultant payouts (Stripe Connect): Consultants onboard directly with Stripe, which collects and controls their bank account details, identity documents, and KYC data independently. We have no access to this data and store only the Stripe Connect account ID as a reference. Stripe is the data controller for this processing — see Stripe's Privacy Policy. |
USA 🇺🇸 — transfers covered by EU Standard Contractual Clauses. |
| AhaSend B.V. | Transactional email delivery | Netherlands 🇳🇱 (EU) |
We also share the name and profile information of the consultant or moderator with the client (and vice versa) as necessary to conduct a booked call. No other sharing occurs without your explicit consent or a legal requirement.
5. International transfers
Our application servers (Northflank) and our file storage (DigitalOcean Spaces) are located in the United States. Video calls are delivered via 8x8, Inc. (JaaS), and payments are processed by Stripe, Inc. — both also established outside the EU. Video-call media is routed via 8x8's global infrastructure by default, or via 8x8's EU (Frankfurt) region for calls where the consultant has enabled EU routing; in either case 8x8, Inc. remains a US-established processor. All of these transfers of personal data outside the EU/UK are governed by Standard Contractual Clauses (SCCs) pursuant to GDPR Article 46(2)(c), which we have entered into with each provider. Consultant financial and KYC data never leaves Stripe's systems and is not transferred to us.
As the data controller, Uptide Group Limited (England and Wales) may access personal data held on our infrastructure providers' servers for operational and support purposes, wherever those servers are located. Such access, and the underlying transfer of personal data to providers outside the EU/UK, is covered by the SCCs referenced above.
6. Retention
- Account and booking data: retained for the lifetime of your account and for seven years after closure to comply with UK and EU tax and accounting law.
- Call metadata, including per-participant attendance records: retained for 12 months for debugging and dispute resolution, then deleted.
- Support messages: retained for 24 months then deleted.
- Server access logs: retained for 90 days then deleted.
- Payment tokens: retained until you close your account or request deletion; card data is never stored by us.
7. Security
Video calls are delivered via 8x8 JaaS (Jitsi as a Service), a GDPR-compliant video provider operating under Standard Contractual Clauses. Video and audio streams are encrypted in transit. Data stored on our servers is encrypted at rest. All connections to the platform use TLS 1.2 or higher. Access to production systems is restricted to authorised staff using two-factor authentication and audited access logs.
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected individuals without undue delay.
8. Your rights
Under GDPR you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your data ("right to be forgotten") where no overriding legal obligation requires us to keep it.
- Restrict processing while a dispute is resolved.
- Object to processing based on legitimate interests.
- Port your data to another service in a machine-readable format.
- Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, email privacy@meetstack.io. We will respond within one month. You also have the right to lodge a complaint with the supervisory authority in your country of residence — in Germany, for example, that is the relevant state DPA; in Austria the Datenschutzbehörde (dsb.gv.at).
9. Children
meetstack is not intended for users under 18. We do not knowingly collect personal data from children. If you believe a child has registered, please contact us immediately and we will delete the account.
10. Changes to this policy
If we make material changes to this policy we will notify you by email and update the "last updated" date at the top of this page at least 30 days before the changes take effect. Continued use of the platform after that date constitutes acceptance.
This document is published in several languages, and the English text governs. If a translation and the English text differ in meaning, the English text prevails.
11. Contact
Privacy questions: privacy@meetstack.io
Uptide Group Limited, registered in England and Wales, company no. 09257622
Registered office: Faversham House, Wirral International Business Park, Old Hall Road, Wirral, CH62 3NX
Office: 4th Floor, Silverstream House, 45 Fitzroy Street, Fitzrovia, W1T 6EB London