Privacy Policy
Last updated: September 27, 2026
This Privacy Policy explains how The Workaround Collective (“we,” “us,” the “Collective”) collects, uses, shares, and protects personal information about members of our community. Transparency is core to what we do, so we’ve tried to keep this plain.
Who we are. The Workaround Collective is a 501(c)(3) tax-exempt nonprofit organization, registered and formed in the USA and managed from Germany by its founder. The Collective is the data controller for personal data processed through the platform. The platform is intended for adults (18+) in the United States. Because the Collective is managed from Germany, the GDPR applies to our processing activities. For privacy questions or requests, signed-in members can use the Privacy Center in their account (see Section 4); if you don’t have an account or can’t sign in, contact us.
1. Information we collect
You give us
- Account: your name, email, password (stored only as a salted hash), date of birth (to confirm you’re 18+), and US-residency confirmation.
- Profile: avatar, your “superpower” and headline, skills and industry, what you’re looking for, free-text answers, a public handle, and earned badges — much of which you choose to make public, partial, or private.
- Community content: hive memberships, discussion posts, buddy connections, the Buzz sessions you attend, and anything else you write in the community.
- Scheduling: the times you offer and the calls you book with mentors, creators, or peers.
- Feedback: messages you send our team through the in-app mailbox.
We generate or automatically collect
- Rewards: a token balance reflecting your participation (closed-loop points — see the Terms).
- Compliance records: your acceptance of these documents, and a pseudonymized log of any data request, kept as an audit trail.
Coming later. As we roll out grants and the Honeycomb Market, we’ll collect the information needed to run them — for example grant application details and, for the Market, order and transaction records — and we’ll update this policy before those features go live.
2. How we use your information
- To run your account, profile, community, scheduling, and rewards.
- To connect you with mentors, creators, and peers, according to your visibility settings.
- To keep the community safe (moderation, handling reports, preventing abuse).
- To respond to your feedback and support requests.
- To meet our legal and compliance obligations.
We do not sell or share (as defined under California’s CPRA) your personal information, and we do not use it to build third-party advertising profiles.
3. How your information is shared
- With other members: your profile and community activity are visible to others as you choose — public (visible to anyone, including search engines, which may cache your information), partial (only selected fields visible to other members), or private (members only). By choosing “public,” you consent to your profile being indexed by search engines; please note that cached copies may persist even after you change your settings.
- With service providers: vendors who help us run the platform (for example hosting, email delivery, video calls, optional calendar sync, and — in the future — payment processing), bound by data processing agreements that restrict them to processing your data strictly to provide the service on our behalf and prohibit them from using it for their own purposes.
- For legal and safety reasons: where required by law, or to protect the rights, safety, and security of members and the public.
4. Your controls & rights
The fastest way to exercise your rights is to do it yourself, in your account’s Privacy Center:
- Edit your details and visibility at any time (rectification).
- Export a copy of your data as JSON (portability).
- Delete your account (erasure). At your request, we soft-close your account for a 30-day restore window (in case you change your mind), then permanently purge your personal data. If you exercise a formal erasure right under the GDPR, we will act without undue delay. Community posts are anonymized to “Deleted user” to maintain discussion continuity.
Depending on where you live (including under the GDPR/UK GDPR and California’s CCPA/CPRA), you may also have the right to access, rectify, erase, restrict or object to processing, port your data, withdraw consent, opt out of the sale or sharing of your personal information, limit the use of sensitive personal information, and not be discriminated against for exercising your rights. The Privacy Center also lets you submit a formal access, correction, or deletion request that we log and action. If you can’t sign in, contact us; these requests require identity verification and are answered within the legal deadline (GDPR: one month; CCPA: 45 days). We do not make decisions with legal or similarly significant effects about you by solely automated means.
Complaints. In the EU/EEA you may complain to a data-protection supervisory authority; the authority competent for us is the LfDI Baden-Württemberg (Stuttgart, Germany). In the US you may contact your state attorney general or, in California, the California Privacy Protection Agency.
5. Legal bases for processing (GDPR)
- Contract (Art. 6(1)(b)) — creating and running your account, profile, community participation, and scheduling.
- Consent (Art. 6(1)(a)) — making your profile public, optional matching, and any optional communications. You can withdraw consent at any time.
- Legitimate interests (Art. 6(1)(f)) — keeping the platform safe and secure and preventing abuse, balanced against your rights.
- Legal obligation (Art. 6(1)(c)) — compliance, tax, and lawful requests.
We do not intentionally collect special-category data (Art. 9 GDPR), such as health information, racial or ethnic origin, or political opinions — please don’t include it in free-text fields. If you choose to provide such information voluntarily, you do so at your own risk and we will treat it in accordance with applicable law but disclaim any obligation beyond that required by law.
6. International transfers
The Collective is administered from Germany and serves members in the United States, so your data may be processed in the US and other countries. Where we transfer personal data out of the EEA/UK, we rely primarily on the European Commission’s Standard Contractual Clauses, together with supplementary technical and organizational measures where necessary. For providers certified under the EU-US Data Privacy Framework, we may also rely on that Framework as an additional basis; because its long-term status is subject to ongoing legal challenge, the Standard Contractual Clauses remain our primary safeguard. We require our providers to protect your data to a standard equivalent to GDPR.
7. Security & retention
We use reasonable technical and organizational measures to protect your data, including hashing passwords. In the event of a data breach that poses a risk to your rights, we will notify you and any applicable supervisory authority as required by law. We keep personal data while your account is active, then delete or anonymize it after the restore window — except limited records we must retain by law (for example financial or compliance records, kept in pseudonymized form).
8. Children
The platform is for adults 18 and older. We don’t knowingly collect data from anyone under 18; if you believe a minor has created an account, contact us and we’ll remove it.
9. Events, webinars & recordings
We co-host the Candid Conversations webinar series with Personally LLC. When you register for a session, your name and email are collected through Zoom, acting as our processor, to manage your attendance; you can separately opt in to hear about future events. Sessions are recorded, and a recording may include a speaker’s name, voice, and image and — where we publish audience questions asked in the chat — the content of those questions. We publish recordings to third-party platforms such as YouTube (and may add podcast platforms later). We do not embed third-party video or audio players on our event pages, and those pages use no third-party cookies or trackers— links to a recording open on the external platform, where that platform’s own privacy policy and cookies apply. We rely on consent (Art. 6(1)(a)) for registration and optional communications, and on our and the speakers’ legitimate interests (Art. 6(1)(f)) to produce and share the recordings.
10. Google Calendar sync (mentors & creators)
Mentors and content creators can choose to connect their own Google Calendar from the My availability page. If you do, we ask Google for two permissions: read-only access to your free/busy information, and permission to manage events that the Collective creates on your calendar. We use free/busy data only to hide any open booking time that clashes with something already on your calendar, and we use event access only to add a confirmed call to your calendar and to remove it if the call is cancelled or rescheduled. We do not read the contents of your existing events (titles, descriptions, attendees or locations), and we do not change or delete events we didn’t create. An event we add shows the session type, time and the other member’s display name (for example “Jane D.”); we never add the other member as an attendee or share their email, and we don’t create Google Meet links (calls happen in our own private video rooms). We store only your Google account email (shown to you as a label), your access tokens (encrypted at rest) and the IDs of events we created. You can disconnect at any time from My availability, which revokes our access at Google and deletes the stored tokens; you can also remove access from your Google Account settings. We rely on your consent (Art. 6(1)(a)) for this processing. We never sell calendar data or use it for advertising.
The Collective’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
11. Cookies
We use only strictly necessary cookies to run the service, such as a session cookie to keep you logged in. We do not use advertising or third-party tracking cookies. If we add analytics later, we’ll ask for consent where required.
12. Changes & contact
We’ll post updates here with a new “last updated” date. For material changes, we will notify you by email or in-app notification at least 30 days before the changes take effect and, where required, seek your renewed consent. For any privacy question or request, log in and use your account’s Privacy Center; if you don’t have an account or can’t access it, contact us here.