Privacy Policy

Last updated: 29 May 2026

1. Who we are

OurStreet (“we”, “us”, “our”) is a hyperlocal community platform for Ireland, accessible at ourstreet.ie. OurStreet connects residents with their neighbours and local community through neighbourhood-level identity verification.

For the purposes of the General Data Protection Regulation (GDPR) and the Data Protection Acts 2018, OurStreet is the Data Controller of your personal data.

Contact us at: privacy@ourstreet.ie

2. What data we collect and why

We only collect data that is necessary to provide the OurStreet service.

Account data

  • Email address: to create and secure your account, and to send you transactional messages (e.g. email confirmation, password reset).
  • Display name: shown to your neighbours on your profile.
  • Profile photo (optional): displayed on your public profile. You choose whether to upload one.
  • Password (hashed): we store a bcrypt hash of your password, never the password itself. If you sign in with Google, no password is stored.

Location data

  • Eircode: used to geocode your address and assign you to a neighbourhood. We store your Eircode on your profile.
  • Neighbourhood assignment: your Eircode is geocoded via the Nominatim API (OpenStreetMap) and matched to a neighbourhood polygon stored in our database using PostGIS. We do not store your precise GPS location.

Verification data

  • Verification level: your current trust tier (Member, Community Verified, or Verified Resident), how you were verified, and the date.
  • Postal address (postcard verification only): if you request a verification postcard, you provide a postal address. This is used solely to send the postcard and is deleted after your verification is completed.
  • Vouches: a record of which verified neighbours have vouched for you, or who you have vouched for.
  • Poster scan records: if you scan a QR poster to get Community Verified, a scan is recorded against the poster code (not linked to you individually beyond your verification event).

Technical data

  • IP address and user agent: collected automatically by our hosting provider (Vercel) and database provider (Supabase) for security, abuse prevention, and diagnostics. We do not use this for profiling.
  • Authentication tokens: stored in secure HTTP-only cookies to keep you signed in.

3. Legal basis for processing

We process your personal data on the following legal bases under GDPR Article 6:

  • Contract performance (Art. 6(1)(b)): processing your account data, Eircode, and neighbourhood assignment is necessary to provide the OurStreet service you signed up for.
  • Consent (Art. 6(1)(a)): uploading a profile photo is optional and based on your consent. You can remove it at any time in Settings.
  • Legitimate interests (Art. 6(1)(f)): we process technical/security data (IP address, logs) to protect the security and integrity of the platform, prevent fraud and abuse, and improve the service. We have assessed that these interests do not override your rights.
  • Legal obligation (Art. 6(1)(c)): we may retain certain data where required by Irish or EU law.

4. How we use your data

  • To create and manage your account.
  • To assign you to your neighbourhood using your Eircode.
  • To display your profile (name, photo, verification badge) to other members of your neighbourhood.
  • To send transactional emails: account confirmation, password resets, and postcard verification notifications. We do not send marketing emails.
  • To process verification requests (poster scans, vouches, postcard delivery).
  • To prevent abuse, fraudulent sign-ups, and misuse of the verification system.
  • To operate and improve OurStreet.

We do not sell your data. We do not use your data for advertising. We do not profile you for commercial purposes.

5. Who we share your data with

We use a small number of trusted third-party processors to operate OurStreet. Each is bound by a Data Processing Agreement and operates in compliance with GDPR.

ProcessorPurposeLocation
SupabaseDatabase, authentication, and file storageEU (Ireland: AWS eu-west-1)
VercelWeb hosting and serverless functionsEU edge / EU region
ResendTransactional email deliveryEU
Google (OAuth)Optional sign-in with GoogleGlobal (EU Standard Contractual Clauses)
Nominatim / OpenStreetMapGeocoding your Eircode to a map point. Only the Eircode is sent: no name or account data.EU

We do not share your personal data with any other third parties, including your neighbours. Other members can see your display name, profile photo, and verification badge: nothing else.

6. Data retention

  • Active accounts: your data is retained for as long as your account is active.
  • Deleted accounts: when you delete your account, your profile data (name, email, Eircode, avatar) is deleted within 30 days. Vouches and verification records are anonymised rather than deleted to preserve the integrity of other users' verification history.
  • Postal addresses (postcard verification): deleted within 7 days of your postcard verification being completed or expired.
  • Security logs: retained for up to 90 days by our hosting providers for security and abuse prevention.

7. Your rights under GDPR

As a resident of Ireland or the EU, you have the following rights regarding your personal data:

  • Right of access (Art. 15): you can request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16): you can correct inaccurate data. Most data (name, photo) can be updated directly in Settings.
  • Right to erasure (Art. 17): you can request deletion of your account and personal data, subject to legitimate retention obligations.
  • Right to data portability (Art. 20): you can request your data in a structured, machine-readable format.
  • Right to object (Art. 21): you can object to processing based on legitimate interests.
  • Right to restriction (Art. 18): you can request that we restrict processing of your data in certain circumstances.
  • Right to withdraw consent: where processing is based on consent (e.g. profile photo), you can withdraw it at any time with no effect on the lawfulness of prior processing.

To exercise any of these rights, email us at privacy@ourstreet.ie. We will respond within 30 days.

You also have the right to lodge a complaint with the Data Protection Commission (DPC): Ireland's supervisory authority: at dataprotection.ie.

8. Cookies

OurStreet uses only strictly necessary cookies: specifically, a session cookie used to keep you signed in. We do not use tracking cookies, analytics cookies, or advertising cookies. No cookie consent banner is required as we only use essential cookies.

9. Security

We take the security of your data seriously:

  • All data is transmitted over HTTPS/TLS.
  • Passwords are hashed using bcrypt (cost factor 10).
  • Verification codes are hashed using bcrypt before storage.
  • Database access is protected by Row Level Security (RLS): users can only read and write their own data.
  • Our service role key (which bypasses RLS) is never exposed to the browser and is only used in server-side code.
  • All data is stored in the EU (AWS eu-west-1 / Ireland).

If you discover a security vulnerability, please report it responsibly to privacy@ourstreet.ie.

10. Children

OurStreet is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has created an account, please contact us and we will delete it promptly.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this page. Continued use of OurStreet after a change constitutes acceptance of the updated policy. For significant changes, we will notify you by email.

12. Contact

For any privacy-related questions, requests, or concerns: