MakeTeams is in preview. Paid plans are not yet open — create a free account and start generating teams right away.

Privacy Policy

Last updated: July 2025

MakeTeams ("we", "us", "our") operates the website maketeams.app (the "Service"). This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our Service. We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR).

Who we are

MakeTeams is a service for teachers and educators to generate balanced teams from class rosters. We are the data controller for the personal data processed through this Service. For data protection inquiries, please contact us via the contact page.

What data we collect

We collect only the data necessary to provide you with our Service. Here is what we collect and why:

Account data

When you create an account, we collect your email address and an encrypted password. Your email is stored encrypted in our database using AES encryption. We also store your language preference.

Student and participant names

When you create class lists or use self-registration lobbies, first names or nicknames of students or participants are stored. Student names are encrypted at rest (AES-256). This data is entered by you (the teacher) or by participants themselves, is kept only for as long as you maintain your class lists, and is permanently deleted when you delete the relevant list or your account.

Payment data (Pro plan)

If you subscribe to a paid plan, payment processing is handled by Mollie, a EU-based payment provider. We never see or store your credit card or bank details. We retain records of transactions (amounts, dates, VAT) as required by law, but no payment instrument data.

Usage and security telemetry

We collect anonymized, aggregated usage statistics to improve our Service (for example, how many teams are generated). Separately, we keep a short-lived, user-linked record of security-relevant events — such as failed login attempts, rate-limit triggers, and bot-protection decisions — to detect and prevent abuse. This operational security data is tied to your account only as long as needed and is automatically deleted after 90 days. We do not build profiles of your behaviour for analytics or advertising.

Contact form messages

If you contact us through our contact form, we store your message, email address (encrypted), and name. Messages flagged as spam are deleted after 30 days; unverified messages after 24 hours; and handled messages after 90 days.

How we use your data

  • To provide the Service — creating and managing your account, class lists, and generated teams
  • To process payments — managing your subscription and issuing invoices
  • To communicate with you — email verification, password resets, and responding to your inquiries
  • To improve the Service — aggregated analytics help us understand how the Service is used
  • To protect the Service — automated bot detection, rate limiting, and security monitoring

Legal basis for processing

We process your data only when we have a lawful basis to do so under the GDPR:

  • Contract performance — to deliver the Service you signed up for (account, class lists, team generation)
  • Legitimate interest — for security monitoring, abuse prevention, and product improvement
  • Legal obligation — to retain financial records as required by tax and accounting laws
  • Legitimate interest — when you contact us or when participants join a self-registration lobby; in both cases the data is minimal and kept only as long as needed
MakeTeams does not rely on your consent for any processing. You will never see a consent dialog, consent checkboxes, or a cookie banner. Every use of your data is justified by contract, legal obligation, or legitimate interest.

Data retention

Data type Retention period
Login sessions2 hours
Temporary class lists2 hours
Security logs (IP hashes)30 days
Security telemetry (abuse-prevention events, e.g. failed logins, rate-limit hits, bot detections)90 days
Admin audit logs1 year
Deleted accountsAnonymized immediately, permanently deleted after 1 year
Payment recordsIndefinite (required by law)
Aggregated statisticsPermanent (fully anonymized, not personal data)

Cookies

Our Service uses a single encrypted session cookie that is essential for the website to function. It contains only a session identifier — no personal data is stored in the cookie. This cookie expires after 2 hours of inactivity.

We do not use Google Analytics, advertising cookies, tracking pixels, or any third-party tracking. Because the only cookie we set is strictly necessary for the Service, no cookie banner or consent is required.

Security measures

We apply the following technical and organisational measures to protect your personal data:

  • Encryption at rest for sensitive fields — email addresses, contact-form sender emails, and student names are encrypted with AES-256 (Active Record Encryption).
  • Passwords are never stored in plain text — they are hashed with bcrypt.
  • All connections are encrypted in transit using TLS (HTTPS).
  • IP addresses used for security are salted and one-way hashed, never stored in plain text.
  • Automated bot protection, rate limiting, and session fingerprinting defend the Service against abuse.

Third-party services

Mollie

Payment processing. Based in the Netherlands (EU). Processes your name, email, and payment details during checkout. We never store your card or bank details. Mollie operates under its own privacy policy as a data processor.

Scaleway

Email delivery. Based in France (EU). Sends transactional emails on our behalf (email verification, password resets, contact form notifications). Your email address and email content pass through their servers.

ALTCHA

Bot protection widget. A small JavaScript file is loaded from jsDelivr CDN to perform a proof-of-work challenge in your browser. No personal data is sent to ALTCHA or jsDelivr.

Telegram

Internal alerting. We send system-generated notifications to our own administrators via Telegram (operated by Telegram FZ-LLC, based in the United Arab Emirates) — for example when a high-priority message arrives or a payment needs attention. To route these alerts, a notification may include the email address or name you gave us. Telegram never receives your password, your message body, or your payment details.

International data transfers

Your data is primarily processed within the European Union. Where data leaves the EU, we rely on the following safeguards:

  • Payments (Mollie, Netherlands) and transactional email (Scaleway, France) stay within the EU — these countries are covered by the EU's own data-protection framework.
  • Administrator alerts are sent to Telegram in the United Arab Emirates, a country without an EU adequacy decision. We transfer these only under the European Commission's Standard Contractual Clauses, after assessing that appropriate safeguards are in place, and we keep the transferred information to a minimum (see the Telegram card above).

Children's privacy

Our Service is designed for teachers who may enter student names into class lists. We take special care with this data:

  • Only first names or nicknames are collected — no other identifying information about students
  • Student data belongs to the class list that contains it and is deleted when the list or account is deleted
  • Teachers are responsible for ensuring they have appropriate authority to process their students' names

Your rights under GDPR

Under the General Data Protection Regulation, you have the following rights regarding your personal data:

Access:You can view all your data at any time from your account settings page.
Rectification:You can update your email address, password, and language preference at any time.
Erasure:You can delete your account at any time. Your data is anonymized immediately and permanently removed within 1 year.
Restriction:You can request that we limit how we process your data in certain circumstances.
Portability:You can request a copy of your data in a structured, machine-readable format.
Objection:You can object to our processing of your data based on legitimate interest.
Complaint:You have the right to lodge a complaint with your local data protection authority (the supervisory authority in your EU member state) if you believe our processing of your data infringes the GDPR.

Deleting your account

You can delete your account at any time from your account settings. When you do, your email address, password, and all identifying information are immediately replaced with random data (anonymized). Your class lists, student names, and team configurations are permanently deleted. After 1 year, the anonymized record is completely removed from our database. Some data, such as payment records, may be retained longer as required by law.

How to contact us

If you have questions about this Privacy Policy or wish to exercise your data subject rights, please contact us through our contact form or send an email to our data protection contact.

Changes to this policy

We may update this Privacy Policy from time to time. The updated version will be indicated by the revised "Last updated" date. We encourage you to review this page periodically.

v0.8.1