Privacy Policy.
What personal data Perch collects, why, and the rights you have over it.
1. Who we are
Perch is a desk-booking service. For an organization's data, the organization is the data controller and Perch is the processor (see the Data Processing Agreement). This policy covers personal data we process directly.
2. What we collect
Account identity (name, email, and an optional profile photo) from your SSO provider; your organization membership and role; your bookings and check-in activity; and an append-only audit log of administrative actions. Provider photos are normalized and stored as a private Perch copy. We do not collect special-category data and do not store passwords or provider access tokens.
3. Why we process it
To operate the service: authenticate you, place you in your organization, manage desk bookings, send transactional email you ask for, and keep the product secure and observable.
4. Cookies and analytics
Essential cookies make the app work. Privacy-friendly product analytics run only with your consent (the cookie banner’s “Accept all”); “Essential only” declines them.
5. Sub-processors and data location
Your data is kept in the EU. The third parties that process it are listed on the Sub-processors page, with their purpose, the data they touch, and their region. Profile photos are kept privately in Perch’s existing EU Supabase storage and are shown only to authorized people in the same organization where your identity is already visible.
6. Retention
Account data is kept while your account is active. Hiding your provider photo or requesting account deletion removes Perch’s private photo copy immediately; account recovery does not restore it, but a later SSO sign-in can import it again when the preference is enabled. Other account data is soft-deleted immediately and purged after a 30-day grace window. Audit-log entries are retained per the retention policy with the actor anonymized.
7. Your rights
You can globally hide your provider photo, export your own data (including the stored photo when present), and request deletion of your account from Settings. Under the GDPR you also have rights of access, rectification, erasure, restriction, and objection. For reviewThe full statutory rights wording and the supervisory-authority details (Polish UODO) are finalized by the legal review.
8. Contact
Privacy questions or requests: privacy@perch.app.