top of page
Logo.png
KOM IGÅNG

Privacy Policy

SVENSKA

Version 1.0   Last updated 14 September 2026

This Privacy Policy explains how Studio Hamlin AB processes personal data in the Pantpolare app, website, support and administration.

Pantpolare uses personal data to create accounts, connect users who have invited each other, administer group collection campaigns, register deposit receipts, provide support and keep the service secure. We do not sell personal data or use children's data for personalised advertising.

Data controller

Studio Hamlin AB is the controller of the processing described in this policy.

Company Studio Hamlin AB

Company registration number 559071-7855

Postal address Friisgatan 9, 214 21 Malmö, Sweden

Email mikael@pantpolare.se

Website https://www.pantpolare.se

An association, school or other organisation may process its own participant or membership data outside Pantpolare for its own purposes. That organisation is responsible for such processing.

People covered by this policy

This policy applies to coordinators, adult account holders, collectors, donors, people who contact support and visitors to the Pantpolare website. Collectors may be minors. The service is directed at adults, and a minor uses a profile created and managed by an adult guardian or account holder.

Personal data we process

Account and contact data

  • name or display name, email address and, when needed for a coordinator, telephone number

  • team name, account role, account status, user ID and node ID in the product structure

  • protected login credentials, latest login, and the accepted terms version and time

  • invitation and handover email addresses for people who are invited or nominated

Pantpolare does not store a minor's birth year, age category or a separate record identifying the minor's guardian in V1.

Groups, pickups and communication

  • group, team, campaign, relationships, invitations and status

  • the donor's pickup address within the established relationship that needs the address

  • messages, times and status for planned or completed pickups

  • cases and reports concerning inappropriate contact, misuse or other safety matters

Pantpolare does not collect the home address of a minor collector and does not use continuous location data.

Deposits, images and financial records

  • profile images and images the user chooses to add to a case

  • receipt images, registered deposit amounts in whole Swedish kronor, campaign dates and deposit history

  • reconciliations, corrections, fee records, invoices and payment status for coordinators

Pantpolare does not receive or hold the group's deposit money and does not process users' bank accounts or card details for transfers within the group.

Technical data and permissions

  • IP address, date and time, session, device and app version, and necessary operational and security logs

  • push identifier and platform for delivering notifications

  • language preference in the pantpolare_locale cookie

  • camera or photo library access when the user chooses to add a profile, case or receipt image

  • notification permission for cases, messages and handovers

The app does not use location, contacts, microphone, calendar, Bluetooth, background location or App Tracking Transparency. Pantpolare does not use analytics, advertising, tracking or a separate crash-reporting service in V1.

Why we use the data

Contract We use necessary account, relationship, message, pickup, deposit and support data to create the account and provide the functions requested by the adult user.

Steps before a contract We use data submitted by a coordinator through a start or interest form to respond and help the person get started.

Legitimate interests We use necessary data for secure operation, support, fraud prevention, corrections, receipt checks and the adult-managed function that enables a minor to participate. The child's interests are given particular weight.

Legal obligation We process invoices and other information when required by accounting rules, public-authority decisions or other law.

Consent If we later introduce an optional function that requires consent, the user receives separate information and may withdraw consent. We do not use consent as a general basis for the service's necessary functions.

Who can see the data

Access depends on the user's role and established relationship. A coordinator sees the group and campaign information needed for administration. A collector, donor or adult account holder sees names, messages, images, amounts, addresses and status only when needed for the relevant relationship or case. Authorised staff may access data when needed for operation, support, security, receipt checks or invoicing.

Suppliers

  • Vercel for hosting the web app and necessary technical logs

  • Supabase for accounts and authentication, database, image storage, live updates, invitation email and password reset

  • Apple Push Notification service for push notifications to iOS devices

  • Google Firebase Cloud Messaging for push notifications to Android devices

  • Wix for the public website and web forms

  • Visma for necessary invoicing and accounting

Apple and Google receive the push identifier and notification text needed to deliver a notification. The app does not use Firebase Analytics, Firebase Crashlytics or advertising services. Suppliers processing data on Pantpolare's behalf may only use it under Pantpolare's instructions and applicable agreements. Pantpolare does not sell personal data.

Processing outside the EU and EEA

The suppliers' companies, infrastructure or subprocessors may involve processing outside the EU and EEA, including in the United States. When data is transferred outside the EU and EEA, Pantpolare relies on a permitted safeguard, such as an adequacy decision or the European Commission's standard contractual clauses together with necessary supplementary safeguards. Further information can be requested from mikael@pantpolare.se.

How long we retain the data

Pantpolare does not retain personal data for longer than needed for each purpose.

Active accounts and profiles are retained while the account or profile is in use. An account that has been inactive for 24 months may be closed after prior notice.

Relationships and pickup addresses are retained while needed for the active relationship. Access to the address ends when the relationship or account ends, unless the address is needed for a specific safety matter or legal claim.

Ordinary messages are retained for no more than 12 months after the message or the end of the relationship, whichever is later. Reported messages may be retained longer when needed for a safety investigation or legal claim.

Receipt images are normally retained for no more than 24 months after the end of the campaign so that the campaign, invoice, ordinary corrections and complaints can be handled.

Amounts and campaign history may be retained while the product structure needs the history. When an account is closed, the personal link is removed or anonymised when it is no longer needed.

Contract evidence and coordinator history are retained while the contract applies and afterwards for as long as needed for legal claims or accounting records.

Invoices and accounting records are retained for the period required by Swedish accounting law, normally seven years after the end of the calendar year in which the relevant financial year ended.

Support matters are normally retained for 24 months after the matter is closed. A safety matter may be retained longer when there is a documented need.

Activation data is retained while activation is in progress and normally for no more than 12 months after the latest activation activity. A minimal suppression record may be retained longer to honour a request not to receive further optional messages.

Technical and security logs are normally retained for no more than 12 months, unless a specific incident requires longer retention.

Backups may contain deleted data until it is overwritten through the supplier's normal backup rotation. The data must remain separate from ordinary use and must not be restored except when necessary for service recovery, after which the deletion is applied again. Images in active storage are deleted separately when they may no longer be retained.

Children's personal data

Pantpolare processes children's data with particular care. An adult guardian or account holder creates and manages the minor's profile. The child does not become a party to the contract and has no payment liability. We do not collect the child's home address, birth year, age category or a separate guardian-link field. Children's data is not used for personalised advertising.

A child may independently have the right to receive information, correct data or request deletion. Pantpolare considers the child's age, maturity and safety as well as the guardian's responsibility when handling such a request.

Delete an account

An account holder can initiate deletion in the app by selecting Settings, Delete account and Delete my account. A request can also be made without access to the app at:

https://www.pantpolare.se/delete-account

The user may first need to close open pickups or hand over a team or administrator role that would otherwise be left without a responsible person. The app explains the required steps.

When an account is deleted, Pantpolare removes the login, push identifiers, profile image and unnecessary direct personal data. Other personal links are deleted or anonymised. Vacant nodes in the group structure, amounts and group results may remain only when they can no longer reasonably be linked to the former user. Data needed for accounting, a specific safety matter or a legal claim is separated from ordinary use and retained only while the need remains.

Your rights

  • receive information about how your personal data is processed and obtain a copy

  • have inaccurate or incomplete data corrected

  • request deletion or restriction of processing

  • object to processing based on legitimate interests

  • receive certain data in a structured, commonly used and machine-readable format

  • withdraw consent without affecting processing that was lawful before withdrawal

  • lodge a complaint with the Swedish Authority for Privacy Protection

The right to deletion is not absolute. We may need to retain limited data to comply with accounting rules, handle a safety matter or establish, exercise or defend legal claims. Send a request to mikael@pantpolare.se. We may request proportionate information to ensure that data is not disclosed to or changed by the wrong person.

Automated decisions

Pantpolare does not make decisions based solely on automated processing that produce legal or similarly significant effects for the user. Technical checks may be used to identify errors, duplicates or suspected misuse, but a significant action against a user can be reviewed by a person.

Security

All app traffic is protected by HTTPS and TLS in transit. Pantpolare uses protected authentication, role- and relationship-based access, limited administrator access, and procedures for security events, data-subject requests and deletion. No digital service can guarantee complete security. Suspected unauthorised access or another incident can be reported to mikael@pantpolare.se.

Cookies, analytics and marketing

Cookies and similar technology on the website are described in Pantpolare's separate cookie information. Necessary technology is used to make the service function securely. Non-essential analytics, advertising or tracking is not activated unless the applicable information and consent requirements have been addressed. Pantpolare does not use children's data for personalised advertising.

Changes

Pantpolare may update this policy when the service, suppliers or legal requirements change. The current version is always available on the website with its revision date. Affected users are clearly informed before a material change takes effect when required.

bottom of page