Privacy policy
Last updated: 26 September 2026
This privacy policy explains how RHUL Mobile ("we", "us", or "the app") collects, uses, stores, and protects your information when you use our mobile app and website. We believe in transparency and want you to understand exactly what data we handle.
Who we are
RHUL Mobile is an independent app built and run by SHACKSOLUTIONS LTD, a UK-registered software studio. It is not part of Royal Holloway or the Students' Union, and we are not affiliated with, endorsed by, sponsored by, or officially connected to Royal Holloway, University of London or Royal Holloway Students' Union.
The data controller for the personal data described in this policy is SHACKSOLUTIONS LTD (company number 13337279), England and Wales, registered with the Information Commissioner's Office. Contact privacy@shack.solutions.
Information we collect
We collect the minimum data needed to provide and improve RHUL Mobile. Here's what we collect:
Account information
When you create an account or sign in:
- Authentication data: If you sign in with Apple or Google, we receive your email address and name from these providers. We store your email for account management purposes. You can choose to hide your email when signing in with Apple.
- Profile information: Display name and profile picture that you optionally provide.
- Anonymous accounts: If you use the app without signing in, we create an account with a random identifier. We do not collect your name or email address, but we do process device, usage and push notification data linked to that identifier.
Device and technical information
When you use the app, we may collect technical details such as:
- Device model and platform
- Operating system version
- App version and build number
- Push notification token (if notifications are enabled)
- IP address, collected by PostHog and used for approximate geolocation (e.g. city-level) and analytics
Usage analytics
We use PostHog (EU-hosted) for product analytics and debugging:
- Which screens you view and features you use
- Content interactions (such as saves, shares, and marketplace actions)
- App performance and stability signals
- Crash reports
Analytics events and crash reports are linked to your account ID. When you open the app, it also sends PostHog your sign-in method, whether your account is anonymous and, if you are signed in, your email address and display name, so your PostHog profile carries them.
Session replay is switched off. Until September 2026 the app recorded a sample of sessions to help us find bugs. A recording captured what was on screen, including on-screen text such as other students' listings, unless that part of the screen was masked. Text you typed and images were masked, and the recording also included app logs and the web addresses of requests the app made. The website and partner dashboard recorded sessions with form inputs masked. We have switched session replay off in the app, on the website and in the partner dashboard, and recordings made before then are deleted when their 30-day retention period ends.
Timetable (withdrawn 17 September 2026)
From version 2.1.0 until 17 September 2026 the app offered an optional timetable. If you connected it, you signed in on the University's own timetable website inside the app, or pasted the personal calendar link that website provides, and we never saw your password. The app saved that link on your device. To show your timetable, the app sent that link to our server, which fetched your calendar from the University and passed it back to your device without storing it. Your schedule, module labels and reminders were kept on your device. Analytics recorded that the feature was used, but never the link, module titles, rooms or lecturer names. If your session was sampled for session replay while you used the timetable, the recording may show your timetable as it appeared on screen, and it is deleted when its 30-day retention period ends.
We withdrew the feature on 17 September 2026 at the University's request. Our server no longer contacts the University's timetable system, and current versions of the app erase the saved link, cached timetable and reminders from your device when they open. If you still have an older version, updating or deleting the app removes that data.
User-generated content
If you post on the marketplace, we store:
- Your post content (title, description, category, price if applicable)
- Images you upload
- The contact method you choose to share (phone number, email address, or Instagram handle)
- Any reports submitted about posts (reason/details) for moderation and safety
Important: Contact information you add to marketplace posts is visible to other users. Only share what you're comfortable making public.
Automated content moderation: OpenAI's moderation service checks marketplace post text, contact details and images, and profile display names and avatars, to detect content that may violate our content guidelines (for example illegal, harmful, or sexually explicit material). If the automated check flags content, it is rejected automatically. You can ask for a person to review any automated decision by emailing privacy@shack.solutions. See "International data transfers" below for how this data is safeguarded when sent outside the UK.
Saved items and preferences
We store your:
- Saved/bookmarked content (news articles, events, bus stops, societies, etc.)
- Event RSVPs (events you mark as "going")
- App preferences and settings
- Quick actions order customisation
- Home screen widget configuration (selected bus stops and laundry rooms)
Feedback and support data
If you send feedback or report a problem through the app, it goes to PostHog, our analytics provider, as a survey response and is copied into Linear, our issue tracker, so we can fix the problem and reply to you by push notification. It includes:
- Your message and the category you chose (bug, crash, feature request, etc.)
- Optional technical context (screen name and stack trace). Web addresses in a stack trace have their query strings removed on your device, and file paths are stripped of your username, before anything is sent
- Device context (platform, OS version, app version, model)
Turning analytics off in the app's settings stops reports being sent. If you have turned it off, the app will tell you the report could not be sent rather than sending it anyway.
Permissions and on-device data
The app may request optional permissions when you use specific features:
- Location: Used for "locate me" and campus walking directions. Location data stays on your device and is not transmitted to our servers. We do not continuously track or store your location history.
- Camera and photos: Used if you choose to upload an avatar or marketplace image.
- Notifications: Used for push notifications and local reminders (for example, laundry and bus alerts).
In-app purchases
The only in-app purchases are one-off marketplace bumps. There are no subscriptions. If you buy a bump:
- We do not collect or store your payment details. All payments are processed by Apple (App Store) or Google (Play Store).
- We use RevenueCat to validate purchases and manage entitlements. RevenueCat receives transaction identifiers associated with your app user ID.
- We store a record of your purchase (product type, duration, timestamp) to provide the service.
- If a purchase is refunded, we remove the related credit.
Your credit card number, billing address, and other payment details are handled entirely by Apple or Google and are never shared with us.
Home screen widgets
If you use iOS home screen or lock screen widgets (bus departures, laundry availability), the app fetches that data and stores it on your device. No additional personal data is collected through widgets.
Website cookies and local storage
On rhulmobile.com, website analytics through PostHog (page visits and clicks) only runs if you consent through the cookie banner. Without your consent, none of it runs. Your choice is stored in your browser's local storage.
The campus map page loads Apple MapKit, and the advertising enquiry form uses Cloudflare Turnstile to block spam. Both receive your IP address.
Email engagement
When we send you an email, our email provider (Amazon SES) records whether the message was delivered, whether it was opened, and whether you clicked a link inside it. Opens are measured using a small tracking image embedded in the message. Links are routed through a redirect that records the click before passing you on to the destination.
This tells us the recipient address, which message it was, the time, and the basic technical details your mail client sends when it loads the image or follows the link, such as IP address and mail client type. We use it to confirm our email is arriving and is worth sending. We do not use it to build a profile of you, and we do not share it with partners or advertisers.
Open tracking only works if your mail client loads remote images. Most clients let you switch that off, and some (including Apple Mail with Mail Privacy Protection) block or pre-load these images automatically, which makes open figures approximate at best. Blocking remote images stops open tracking and does not affect delivery of the email itself.
Marketing and product-update emails carry an unsubscribe link in the footer, which stops those emails entirely. Transactional emails such as sign-in links, moderation outcomes, and billing notices have no unsubscribe link because they form part of the service you asked for. You can object to engagement measurement at any time by emailing privacy@shack.solutions.
Public campus information
The news, events, societies, term dates, opening hours and bus information in the app are collected by automated means: our software regularly reads publicly accessible pages on the Royal Holloway, University of London and Students' Union websites, and other public sources such as OpenStreetMap and the bus operator's live service pages. We show that content as it was published and link back to the source. Where published content names a person, for example an event speaker or the author of a news story, it appears in the app as it does on the original page. To have something corrected or removed, email privacy@shack.solutions.
Information we do not collect
- Your academic records, grades, or student ID
- Your credit card numbers, billing address, or bank details (payments are handled by Apple/Google)
- Your contacts or existing personal calendar data
- Persistent precise-location history
- Official Royal Holloway academic or HESA records - we only hold what you voluntarily provide within the app
Advertising and partner content
Some content in the app is paid placement (the Deals tab, partner-pinned map locations, and any deal cards labelled "Ad"). We label these placements clearly so you can tell paid content from organic university content.
What this means for your data:
- We do not share your personal data with partners. Partners do not receive your name, email, account ID, contact details, location, browsing history, or anything that could identify you.
- We share aggregated counts only. Partners receive periodic reports of how many redemptions their deal received over a period - never individual user data.
- We do not sell your data to advertisers, and we do not run third-party ad networks (Google Ads, Meta, etc.) inside the app.
- Deal activity stays internal. When you view or redeem a deal, we record that event (deal ID, time, and your account) for fraud-prevention and partner reporting. The user_id on that record is set to NULL when you delete your account.
Full advertising terms - including labelling commitments and editorial separation - are in section 15 of the Terms of service.
How we use your information
- To provide the service: Syncing saved items, publishing your content, and delivering core app features.
- To improve reliability: Understanding usage patterns helps us prioritise features and fix issues.
- To keep the community safe: Moderating content (including automated screening of marketplace posts, avatars, and display names via OpenAI's moderation service), handling reports, and preventing abuse.
- To communicate: Sending service notifications and important product updates, and measuring whether those emails were delivered, opened, and clicked so we can tell whether they are working.
- To process purchases: Activating paid features and recording purchase outcomes.
Legal basis for processing
Under UK GDPR, we rely on the following legal bases to process your data:
- Account, marketplace, and saved-item features: Processed to perform our contract with you - providing the account, marketplace, and other core features you sign up to use.
- Content moderation: Display names, avatars, and marketplace post content are processed (including automated screening via OpenAI's moderation service) on the basis of our legitimate interest in keeping the platform safe, lawful, and free of abusive or harmful content.
- Push notifications: Service notifications (such as moderation outcomes and marketplace updates) are sent to perform our contract with you. Optional local reminders (for example, bus and laundry alerts) are based on your consent, given when you enable them.
- Analytics: Usage, device, and technical data processed via PostHog is based on our legitimate interest in understanding and improving the app. You can opt out at any time using the in-app analytics toggle - see "Opt-out" under Your rights.
- Website analytics: Analytics on rhulmobile.com is based on your consent, given through the cookie banner. It does not run unless you consent.
- Email engagement: Delivery, open, and click measurement on the emails we send is based on our legitimate interest in confirming that our email reaches students and is worth sending. You can object at any time by contacting us, unsubscribe from marketing and product-update emails using the footer link, or block remote images in your mail client to prevent open tracking.
Data storage and security
- Where: App data is stored using AWS, Cloudflare, and Neon infrastructure providers, primarily within the UK and EU.
- Encryption: Data is encrypted in transit (TLS). Storage protections are managed by our infrastructure providers.
- Access: Access is limited to authorised maintainers and service providers who need it to operate the service.
- Security: We apply reasonable technical and organisational safeguards, but no system is completely risk-free.
Third-party services
We use these trusted third-party services:
| Service | Purpose | Privacy policy |
|---|---|---|
| AWS | App and partner-dashboard hosting, email delivery and engagement measurement (delivery, opens, clicks), and scheduled tasks | aws.amazon.com/privacy |
| Cloudflare | Website hosting and security, Turnstile spam protection, image delivery, and storage of uploaded images (avatars, marketplace photos, partner logos) | cloudflare.com/privacypolicy |
| Neon | Database hosting | neon.tech/privacy |
| PostHog | Analytics and error tracking | posthog.com/privacy |
| Expo | Mobile app framework and push notifications | expo.dev/privacy |
| Apple Sign In | Authentication (if you choose) | apple.com/legal/privacy |
| Google Sign In | Authentication (if you choose) | policies.google.com/privacy |
| RevenueCat | In-app purchase management | revenuecat.com/privacy |
| Google Maps | Campus map rendering on Android | policies.google.com/privacy |
| Apple Maps (MapKit) | Campus map on iOS and the website | apple.com/legal/privacy |
| Google Firebase Cloud Messaging | Push notifications on Android | firebase.google.com/support/privacy |
| Slack | Internal alerts, including new sign-ups (with email), account deletion requests, and marketplace posts for review | slack.com/privacy-policy |
| OpenAI | Automated content moderation. Data sent: marketplace post text, contact details and images, profile display names, and avatars | openai.com/policies/privacy-policy |
| Linear | Bug report and feedback tracking | linear.app/privacy |
| Stripe | Partner billing | stripe.com/privacy |
Your rights
You have full control over your data:
- Access: View your profile and saved data any time in the app.
- Correction: Update your display name, avatar, and preferences in settings.
- Deletion: Delete your account from within the app, or ask for erasure by emailing privacy@shack.solutions. You're signed out immediately; if you sign back in within 30 days the deletion is cancelled. See "Data retention" for what is deleted and what we keep.
- Portability: Contact us to request an export of your data.
- Restriction and objection: You can ask us to restrict how we use your data, or object to processing based on our legitimate interests.
- Human review: You can ask for a person to review any automated moderation decision.
- Opt-out: You can use the app anonymously without creating a full account. In the app, you can turn analytics off at any time from the Analytics toggle in Settings, and website visitors can opt out of analytics cookies via the cookie preference banner. Marketing and product-update emails can be stopped with the unsubscribe link in the email footer, and blocking remote images in your mail client prevents email open tracking.
To exercise any of these rights, email privacy@shack.solutions. We will reply within one month. You also have the right to complain to the Information Commissioner's Office at ico.org.uk.
Data retention
- Active accounts: Data is retained while your account exists.
- Deleted accounts: When you delete your account you're signed out immediately and your account enters a 30-day recovery window. Signing back in during that window cancels the deletion. 30 days after you ask, we delete your account data from our database and file storage: your profile and sign-in records, saved items, event RSVPs, marketplace posts and bump history, the reports you made, and your avatar and marketplace images. Backups are overwritten within a further 30 days.
- What we keep after deletion: your email address on a do-not-email list if you unsubscribed, reports other users made about your content, and de-identified purchase and deal records.
- What the 30-day deletion does not reach: data held by other services. That is your PostHog profile, with the email address and name attached to it, and your analytics events, crash reports, feedback and any session replays there; the purchase history RevenueCat holds against your account ID; our internal Slack alerts, which include your email address for sign-ups and deletion requests; and bug reports in Linear. Account deletion does not remove these automatically; PostHog data follows the analytics and session replay periods below. To have them deleted too, email privacy@shack.solutions.
- Marketplace posts: Hidden after 30 days unless renewed, and deleted when you delete them or your account.
- Analytics logs: PostHog events are retained for approximately 12 months, after which they are deleted or fully anonymised.
- Feedback and problem reports: Held by PostHog as survey responses and retained on the same schedule as analytics events above.
- Session replays: no longer recorded. Recordings made before session replay was switched off are deleted 30 days after they were made.
- Server logs: 14 days.
- Email engagement: Delivery, open, and click metrics held by our email provider are retained for up to 15 months. We do not store per-recipient open or click records in our own database.
Children's privacy
RHUL Mobile is intended for university students and is not directed at children under 16. We do not knowingly collect information from anyone under 16. If you believe we have collected data from a child, please contact us immediately.
International data transfers
Some of our providers are based in the United States: Expo, RevenueCat, OpenAI, Slack, Linear, Cloudflare, Apple, and Google. Your data may be processed there when these providers handle it for us.
These transfers are protected by UK adequacy regulations or, where those do not apply, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, as applicable.
Changes to this policy
We may update this privacy policy from time to time. Significant changes will be announced through the app or website. The "Last updated" date at the top shows when this policy was last revised.
Contact us
Questions about this privacy policy or your data? Email us at privacy@shack.solutions.