Last updated: 2026-09-21

Version 2026-09-21

Privacy Policy

turkis Crew is a volunteer platform used to coordinate volunteers and create a community around cultural events and venues.

We collect as little information as possible and try to be clear about how it is used.

Who manages the data?

Det Turkise Telt / turkis is the data controller for turkis Crew. Privacy enquiries are handled by Zana Veliqi, volunteer coordinator.

Contact:
Zana Veliqi — Det Turkise Telt / turkis
Jægergårdsgade 154C, 1. tv., 8000 Aarhus C
CVR: 33339917
frivillig@detturkisetelt.dk
detturkisetelt.dk

What information is collected?

Required information:

  • Name, email address and phone number
  • Login credentials, confirmation that you are at least 18, and the date and version of the privacy notice you acknowledged

Optional information you may choose to provide:

  • Profile photo
  • Short biography/about text
  • Social links
  • Volunteer preferences
  • Notification preferences
  • Birthday and other profile details you decide to add
  • Application text, location, languages, pronouns, conversation topics and earlier volunteer history

The platform may also store:

  • A last-active timestamp, updated at most once an hour during foreground app use, and the date activity observation started; used by admins to review inactive accounts, without recording pages visited or keystrokes
  • Shift signups, cancellations, cancellation requests and waiting-list entries and offers
  • Event participation and guest-list requests, names, guest counts, notes and decisions
  • Chat messages related to events
  • Application decisions, role qualifications, coordinator notes and administrative activity history
  • Email delivery records, notification preferences, event mutes and device push subscriptions (delivery address, encryption keys, browser information and timestamps)
  • Technical request, security, error and performance information, such as IP addresses handled by hosting services, browser/device details and request times

Most information comes from you or your use of the app. Coordinators add application decisions, role qualifications and operational notes, and may add guest names directly. For a guest without an account, we record their name, event and guest count; the coordinator should share this notice with them. Additional guests are normally recorded as a count rather than individually named.

Why do we collect this information?

We only collect information needed to:

  • Coordinate volunteers
  • Manage events and shifts
  • Reach volunteers quickly about shift changes or on-the-night logistics
  • Let volunteers communicate
  • Help volunteers recognize and connect with each other
  • Send important notifications and updates
  • Improve the platform

We do not sell personal information.

GDPR and legal basis

turkis Crew is built to follow the principles of the EU General Data Protection Regulation (GDPR): collect only what is needed, use it for clear purposes, keep it reasonably secure, and give volunteers control over their own information.

We use the following legal basis for each purpose:

  • Our legitimate interests in organising volunteer activities (GDPR Article 6(1)(f)): reviewing applications, managing accounts, contacting crew, coordinating shifts, waiting lists and guest lists, and sending related service messages
  • Our legitimate interests in a functioning crew community (Article 6(1)(f)): showing crew profiles and participation history, optional details you choose to share, and event chat to the relevant crew
  • Our legitimate interests in operating a reliable and secure service (Article 6(1)(f)): access controls, administrative records, troubleshooting and limited error/performance monitoring

The signup checkbox confirms that you have read this notice; it is not blanket consent to processing. Optional profile fields can be left blank or removed. Name, email, phone and an 18+ confirmation are needed to create a volunteer account; without them we cannot process your application. We do not require your date of birth; the birthday field in your profile is optional. Please do not put health information or other sensitive personal details in profiles, application notes or chat.

We do not make decisions with legal or similarly significant effects about you solely through automated processing. Waiting-list ordering, capacity checks and notification scheduling are ordinary coordination functions. Contact the coordinator if you need a decision reviewed.

Who can see my information?

Crew pages require an approved account. Other approved volunteers can see:

  • Name
  • Profile photo
  • Optional profile information you choose to share
  • Past turkis events, shift roles and volunteer totals connected to your crew profile
  • Upcoming events or shifts you share with another volunteer
  • Your name, photo and role on published event shift rosters
  • Event chat messages, visible to the volunteers and admins connected to that event
  • Confirmed guest-list names and approved guest counts, visible to admins and volunteers booked on that event, and on the door list

Admins can access contact details, application text, coordinator notes, last-active timestamps and requests to coordinate volunteers. Email, phone and private notes are not shown in crew profiles. Event chat requires a shift booking for that event; admins also have access. Guest-list notes and replies are visible only to the person concerned and admins. Profile images require a signed-in account: you and admins can view your image, and approved crew can view images of other approved crew.

Third-party services

turkis Crew uses external services that process limited information:

  • Supabase — login, database, file storage and live chat updates; processes the account and platform records described above
  • Vercel — website hosting and request processing, including technical request/security logs
  • Resend — sends account and crew emails; processes recipient addresses, message content and delivery records. Event-chat emails can include the sender and message preview
  • Sentry — error and performance monitoring. We filter contact details, cookies and request bodies and do not enable session replay
  • Your browser/device push provider — delivers notifications when you enable them; receives the device subscription and encrypted notification. Chat push alerts use generic lock-screen text

These providers process information needed to deliver their services, not just temporary technical data. Our database is hosted in Stockholm and Sentry uses its EU region. Provider support, infrastructure and subprocessors can nevertheless involve processing outside the EU/EEA, including the United States. Resend stores email content and delivery records in the United States; selecting a European sending region does not change that storage location. Provider transfer terms describe safeguards such as EU Standard Contractual Clauses and, where applicable, an adequacy decision. Contact us for details or a copy of the safeguards applicable to your data.

Cookies and similar technologies

turkis Crew only uses cookies and similar browser storage that are needed for the platform to work or to remember choices you have made.

  • Supabase authentication cookies, used to keep you signed in and protect restricted pages. Their browser expiry is up to 400 days from renewal; signing out removes the login cookies, and the login itself can expire sooner
  • A Supabase code-verifier cookie, used during email confirmation, magic-link and password recovery. It is cleared when the flow consumes it; an abandoned flow can leave it until its browser expiry (up to 400 days) or you clear site data
  • tc_route, a short-lived signed routing cookie used to remember your approved role/status for a few minutes so the app does not need to repeat the same profile lookup on every page
  • turkis-locale, used to remember English or Danish for up to one year, renewed when set
  • turkis-theme and shift-checklist choices in local storage, kept on your device until changed or cleared
  • App caches, including recently loaded volunteer pages and a user identifier, for faster loading and limited offline use. Signing out clears the app's per-user page cache; clear site data to remove remaining device storage

We do not currently use advertising cookies, marketing pixels, or third-party tracking cookies. If we add non-essential cookies in the future, we will ask for consent before using them.

Email and phone notifications

You can change chat, broadcast and shift notification preferences in your profile and mute individual event chats. Push requires your browser's permission and can be disabled in the app or browser. Account/security emails, waiting-list offers you request and guest-list decisions may still be sent independently of those preferences. Phone notifications use Web Push, not SMS.

How long is information stored?

Account details and participation history are kept while you use the crew platform, including between events. Applications, requests and coordination records are retained while needed to decide the request, organise the event or resolve a related question or dispute. Optional profile details remain until you change or remove them, or close your account.

Admins can filter accounts with more than 30 days of recorded inactivity for manual review, once at least 30 days of observation are available. This does not automatically delete accounts. The app does not automatically delete rejected applications or old event records after a fixed period either. You can request removal using the contact below, or delete your account from your profile. An account that cannot access the profile page can still request deletion by email.

Provider logs, delivered emails, exports and backups have separate retention arrangements; they are not all removed by the account-deletion button. Retention depends on the purpose of the record, any unresolved issue and the provider's configured retention. Contact us for the arrangements that apply to a particular record.

Deleting your account and data

You can delete your account from the Privacy & data section of your profile. To avoid accidental deletion, the app asks you to confirm by typing DELETE.

Account deletion removes your stored profile images before removing your login and the linked records below from the active app database. Failed cleanup steps are retried. If deletion still cannot finish, the request stays saved and visible to admins for follow-up, and the app reports that it is incomplete. You can retry or contact us. Previously downloaded or cached copies may remain outside the app.

Account deletion removes:

  • Stored profile images, activity timestamps and saved deletion requests
  • In-app shift-email records linked to you, including coordinator notifications about your bookings
  • Your login account
  • Your volunteer profile, including name, email, phone number, profile-image link, profile details, role tags, and application information
  • Your shift signups and event participation records connected to your profile
  • Waiting-list entries/offers, cancellation requests and guest-list entries linked to your account, with their linked delivery records
  • Your event chat messages
  • Your notification preferences and push-notification device subscriptions
  • Broadcast-recipient rows that record that an email broadcast was sent to you
  • Older legacy-profile, legacy-signup, and legacy-message rows connected to your account, where those tables exist

The app removes your name/id references from activity-log actor and target fields, while keeping the coordination event. This does not guarantee that every mention of you is removed: messages written by others, shared files, manually entered guest names and copies of coordinator emails may still refer to you. Contact us to request review of those records.

Deletion cannot recall emails already delivered, printed/exported door lists or files another person has downloaded. Provider-held logs and backup copies follow their separate retention and deletion processes.

Your rights

You may request to:

  • Access your personal data and receive a copy
  • Correct inaccurate or incomplete information
  • Request erasure or restriction of processing, where the GDPR conditions apply
  • Object, for reasons relating to your situation, to processing based on legitimate interests; we must stop unless we can demonstrate overriding grounds or need the data for legal claims
  • Receive data in a portable format where processing is automated and based on consent or a contract
  • Withdraw consent at any time for any processing that relies on it, without affecting earlier lawful processing

Email the privacy contact below, or use Request my data in your profile. We normally respond within one month; if a complex or numerous request needs up to two additional months, we will explain why within the first month. We may ask for proportionate information to verify your identity. If a request cannot be granted, we will explain the reason and your complaint options.

frivillig@detturkisetelt.dk

You can complain to the Danish Data Protection Agency (Datatilsynet), including without contacting us first: Datatilsynet.

Changes

This policy may occasionally be updated as turkis Crew evolves.

Major changes will be communicated through the platform.