Privacy Policy
Last updated: July 2025
MakeTeams ("we", "us", "our") operates the website maketeams.app (the "Service"). This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our Service. We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR).
Who we are
MakeTeams is a service for teachers and educators to generate balanced teams from class rosters. We are the data controller for the personal data processed through this Service. For data protection inquiries, please contact us via the contact page.
What data we collect
We collect only the data necessary to provide you with our Service. Here is what we collect and why:
Account data
When you create an account, we collect your email address and an encrypted password. Your email is stored encrypted in our database using AES encryption. We also store your language preference.
Student and participant names
When you create class lists or use self-registration lobbies, first names or nicknames of students or participants are stored. Student names are encrypted at rest (AES-256). This data is entered by you (the teacher) or by participants themselves, is kept only for as long as you maintain your class lists, and is permanently deleted when you delete the relevant list or your account.
Payment data (Pro plan)
If you subscribe to a paid plan, payment processing is handled by Mollie, a EU-based payment provider. We never see or store your credit card or bank details. We retain records of transactions (amounts, dates, VAT) as required by law, but no payment instrument data.
Usage and security telemetry
We collect anonymized, aggregated usage statistics to improve our Service (for example, how many teams are generated). Separately, we keep a short-lived, user-linked record of security-relevant events — such as failed login attempts, rate-limit triggers, and bot-protection decisions — to detect and prevent abuse. This operational security data is tied to your account only as long as needed and is automatically deleted after 90 days. We do not build profiles of your behaviour for analytics or advertising.
Contact form messages
If you contact us through our contact form, we store your message, email address (encrypted), and name. Messages flagged as spam are deleted after 30 days; unverified messages after 24 hours; and handled messages after 90 days.
How we use your data
- To provide the Service — creating and managing your account, class lists, and generated teams
- To process payments — managing your subscription and issuing invoices
- To communicate with you — email verification, password resets, and responding to your inquiries
- To improve the Service — aggregated analytics help us understand how the Service is used
- To protect the Service — automated bot detection, rate limiting, and security monitoring
Legal basis for processing
We process your data only when we have a lawful basis to do so under the GDPR:
- Contract performance — to deliver the Service you signed up for (account, class lists, team generation)
- Legitimate interest — for security monitoring, abuse prevention, and product improvement
- Legal obligation — to retain financial records as required by tax and accounting laws
- Legitimate interest — when you contact us or when participants join a self-registration lobby; in both cases the data is minimal and kept only as long as needed
Data retention
| Data type | Retention period |
|---|---|
| Login sessions | 2 hours |
| Temporary class lists | 2 hours |
| Security logs (IP hashes) | 30 days |
| Security telemetry (abuse-prevention events, e.g. failed logins, rate-limit hits, bot detections) | 90 days |
| Admin audit logs | 1 year |
| Deleted accounts | Anonymized immediately, permanently deleted after 1 year |
| Payment records | Indefinite (required by law) |
| Aggregated statistics | Permanent (fully anonymized, not personal data) |
Cookies
Our Service uses a single encrypted session cookie that is essential for the website to function. It contains only a session identifier — no personal data is stored in the cookie. This cookie expires after 2 hours of inactivity.
Security measures
We apply the following technical and organisational measures to protect your personal data:
- Encryption at rest for sensitive fields — email addresses, contact-form sender emails, and student names are encrypted with AES-256 (Active Record Encryption).
- Passwords are never stored in plain text — they are hashed with bcrypt.
- All connections are encrypted in transit using TLS (HTTPS).
- IP addresses used for security are salted and one-way hashed, never stored in plain text.
- Automated bot protection, rate limiting, and session fingerprinting defend the Service against abuse.
Third-party services
Mollie
Payment processing. Based in the Netherlands (EU). Processes your name, email, and payment details during checkout. We never store your card or bank details. Mollie operates under its own privacy policy as a data processor.
Scaleway
Email delivery. Based in France (EU). Sends transactional emails on our behalf (email verification, password resets, contact form notifications). Your email address and email content pass through their servers.
ALTCHA
Bot protection widget. A small JavaScript file is loaded from jsDelivr CDN to perform a proof-of-work challenge in your browser. No personal data is sent to ALTCHA or jsDelivr.
Telegram
Internal alerting. We send system-generated notifications to our own administrators via Telegram (operated by Telegram FZ-LLC, based in the United Arab Emirates) — for example when a high-priority message arrives or a payment needs attention. To route these alerts, a notification may include the email address or name you gave us. Telegram never receives your password, your message body, or your payment details.
International data transfers
Your data is primarily processed within the European Union. Where data leaves the EU, we rely on the following safeguards:
- Payments (Mollie, Netherlands) and transactional email (Scaleway, France) stay within the EU — these countries are covered by the EU's own data-protection framework.
- Administrator alerts are sent to Telegram in the United Arab Emirates, a country without an EU adequacy decision. We transfer these only under the European Commission's Standard Contractual Clauses, after assessing that appropriate safeguards are in place, and we keep the transferred information to a minimum (see the Telegram card above).
Children's privacy
Our Service is designed for teachers who may enter student names into class lists. We take special care with this data:
- Only first names or nicknames are collected — no other identifying information about students
- Student data belongs to the class list that contains it and is deleted when the list or account is deleted
- Teachers are responsible for ensuring they have appropriate authority to process their students' names
Your rights under GDPR
Under the General Data Protection Regulation, you have the following rights regarding your personal data:
Deleting your account
You can delete your account at any time from your account settings. When you do, your email address, password, and all identifying information are immediately replaced with random data (anonymized). Your class lists, student names, and team configurations are permanently deleted. After 1 year, the anonymized record is completely removed from our database. Some data, such as payment records, may be retained longer as required by law.
How to contact us
If you have questions about this Privacy Policy or wish to exercise your data subject rights, please contact us through our contact form or send an email to our data protection contact.
Changes to this policy
We may update this Privacy Policy from time to time. The updated version will be indicated by the revised "Last updated" date. We encourage you to review this page periodically.
v0.8.1