Privacy Policy
Last updated: July 28, 2026
This Privacy Policy explains how The Workaround Collective (“we,” “us,” the “Collective”) collects, uses, shares, and protects personal information about members of our community. Transparency is core to what we do, so we’ve tried to keep this plain.
Who we are. The Workaround Collective is a non-profit initiative currently in formation, registered and formed in the USA and managed from Germany by its founder. The Collective is the data controller for personal data processed through the platform. The platform is intended for adults (18+) in the United States. Because the Collective is managed from Germany, the GDPR applies to our processing activities. For privacy questions or requests, signed-in members can use the Privacy Center in their account (see Section 4); if you don’t have an account or can’t sign in, contact us.
1. Information we collect
You give us
- Account: your name, email, password (stored only as a salted hash), date of birth (to confirm you’re 18+), and US-residency confirmation.
- Profile: avatar, your “superpower” and headline, skills and industry, what you’re looking for, free-text answers, a public handle, and earned badges — much of which you choose to make public, partial, or private.
- Community content: hive memberships, discussion posts, buddy connections, the Buzz sessions you attend, and anything else you write in the community.
- Scheduling: the times you offer and the calls you book with mentors, creators, or peers.
- Feedback: messages you send our team through the in-app mailbox.
We generate or automatically collect
- Rewards: a token balance reflecting your participation (closed-loop points — see the Terms).
- Compliance records: your acceptance of these documents, and a pseudonymized log of any data request, kept as an audit trail.
Coming later. As we roll out grants and the Honeycomb Market, we’ll collect the information needed to run them — for example grant application details and, for the Market, order and transaction records — and we’ll update this policy before those features go live.
2. How we use your information
- To run your account, profile, community, scheduling, and rewards.
- To connect you with mentors, creators, and peers, according to your visibility settings.
- To keep the community safe (moderation, handling reports, preventing abuse).
- To respond to your feedback and support requests.
- To meet our legal and compliance obligations.
We do not sell or share (as defined under California’s CPRA) your personal information, and we do not use it to build third-party advertising profiles.
3. How your information is shared
- With other members: your profile and community activity are visible to others as you choose — public (visible to anyone, including search engines, which may cache your information), partial (only selected fields visible to other members), or private (members only). By choosing “public,” you consent to your profile being indexed by search engines; please note that cached copies may persist even after you change your settings.
- With service providers: vendors who help us run the platform (for example hosting, email delivery, and — in the future — video calls and payment processing), bound by data processing agreements that restrict them to processing your data strictly to provide the service on our behalf and prohibit them from using it for their own purposes.
- For legal and safety reasons: where required by law, or to protect the rights, safety, and security of members and the public.
4. Your controls & rights
The fastest way to exercise your rights is to do it yourself, in your account’s Privacy Center:
- Edit your details and visibility at any time (rectification).
- Export a copy of your data as JSON (portability).
- Delete your account (erasure). At your request, we soft-close your account for a 30-day restore window (in case you change your mind), then permanently purge your personal data. If you exercise a formal erasure right under the GDPR, we will act without undue delay. Community posts are anonymized to “Deleted user” to maintain discussion continuity.
Depending on where you live (including under the GDPR/UK GDPR and California’s CCPA/CPRA), you may also have the right to access, rectify, erase, restrict or object to processing, port your data, withdraw consent, opt out of the sale or sharing of your personal information, limit the use of sensitive personal information, and not be discriminated against for exercising your rights. The Privacy Center also lets you submit a formal access, correction, or deletion request that we log and action. If you can’t sign in, contact us; these requests require identity verification and are answered within the legal deadline (GDPR: one month; CCPA: 45 days). We do not make decisions with legal or similarly significant effects about you by solely automated means.
Complaints. In the EU/EEA you may complain to a data-protection supervisory authority; the authority competent for us is the LfDI Baden-Württemberg (Stuttgart, Germany). In the US you may contact your state attorney general or, in California, the California Privacy Protection Agency.
5. Legal bases for processing (GDPR)
- Contract (Art. 6(1)(b)) — creating and running your account, profile, community participation, and scheduling.
- Consent (Art. 6(1)(a)) — making your profile public, optional matching, and any optional communications. You can withdraw consent at any time.
- Legitimate interests (Art. 6(1)(f)) — keeping the platform safe and secure and preventing abuse, balanced against your rights.
- Legal obligation (Art. 6(1)(c)) — compliance, tax, and lawful requests.
We do not intentionally collect special-category data (Art. 9 GDPR), such as health information, racial or ethnic origin, or political opinions — please don’t include it in free-text fields. If you choose to provide such information voluntarily, you do so at your own risk and we will treat it in accordance with applicable law but disclaim any obligation beyond that required by law.
6. International transfers
The Collective is administered from Germany and serves members in the United States, so your data may be processed in the US and other countries. Where we transfer personal data out of the EEA/UK, we rely primarily on the European Commission’s Standard Contractual Clauses, together with supplementary technical and organizational measures where necessary. For providers certified under the EU-US Data Privacy Framework, we may also rely on that Framework as an additional basis; because its long-term status is subject to ongoing legal challenge, the Standard Contractual Clauses remain our primary safeguard. We require our providers to protect your data to a standard equivalent to GDPR.
7. Security & retention
We use reasonable technical and organizational measures to protect your data, including hashing passwords. In the event of a data breach that poses a risk to your rights, we will notify you and any applicable supervisory authority as required by law. We keep personal data while your account is active, then delete or anonymize it after the restore window — except limited records we must retain by law (for example financial or compliance records, kept in pseudonymized form).
8. Children
The platform is for adults 18 and older. We don’t knowingly collect data from anyone under 18; if you believe a minor has created an account, contact us and we’ll remove it.
9. Cookies
We use only strictly necessary cookies to run the service, such as a session cookie to keep you logged in. We do not use advertising or third-party tracking cookies. If we add analytics later, we’ll ask for consent where required.
10. Changes & contact
We’ll post updates here with a new “last updated” date. For material changes, we will notify you by email or in-app notification at least 30 days before the changes take effect and, where required, seek your renewed consent. For any privacy question or request, log in and use your account’s Privacy Center; if you don’t have an account or can’t access it, contact us here.