Privacy policy
Last updated: 5 September 2026
1. Controller
Monile AB ("Membly"), company reg. no. 559273-6051, Nackagatan 3, 116 49 Stockholm, Sweden, EU VAT SE559273605101, is the controller for the processing of personal data described in this policy. For questions about the processing of personal data, or to exercise your rights, contact us at privacy@membly.app. For members' personal data processed within a specific association, the association is itself the controller. Membly is then the processor — see our data processing agreement (DPA).
2. What data we collect
We process the following categories of personal data: • Identity and contact details: name, email address, telephone number (if provided), profile picture. • Association data: membership status, roles, participation in events, custom fields configured by an administrator. • Communication content: messages in chat, posts in the feed, comments, documents you upload. • Attendance and activity data: recorded attendance at events, RSVP status, participation in team activities. • Payment metadata: amount, date, status, payment method, transaction ID. Actual card details are handled by Stripe and are never stored with us. • Technical data: IP address, device and browser type, login timestamps, push notification tokens. • Children's personal data: when a guardian adds their child as a member, we process the child's name, date of birth (where relevant to the membership category) and, where applicable, national identity number for LOK subsidy reporting (sports associations).
3. Legal basis for processing
We process your personal data on the following legal bases under Article 6 of the GDPR: • Contract (Art. 6(1)(b)): to provide your account, manage subscription and payments, and deliver the service. • Legitimate interests (Art. 6(1)(f)): for security, fraud prevention, platform operations and product improvement. You have the right to object to this processing. • Legal obligation (Art. 6(1)(c)): for accounting under Chapter 7, Section 2 of the Swedish Accounting Act (1999:1078), which requires transaction records to be retained for seven years after the end of the financial year. • Consent (Art. 6(1)(a)): for non-essential cookies, marketing communications and any processing of special categories of personal data. You may withdraw your consent at any time.
4. Purposes of the processing
We use your personal data in order to: • Provide and improve Membly's services. • Enable communication between members and administrators. • Handle payments, invoices and payouts. • Send transactional messages (account activation, payment confirmations, security notices). • Ensure the security of the platform and prevent abuse. • Meet statutory requirements (accounting, regulatory compliance). We do not use your personal data for automated decisions that produce legal or similarly significant effects on you (Art. 22 GDPR), and we do not profile you.
5. Retention periods
We retain your personal data for as long as it is needed for each purpose: • Account data: for as long as your membership is active. When you delete your account, or request erasure (Art. 17), your personal data is anonymised — the link between you and your membership and payment history is removed, while the data that must be retained for legal reasons (e.g. accounting records) is kept for the statutory period. • Removed members: when an administrator removes a member, special categories of personal data (e.g. national identity number, date of birth) processed for LOK subsidy reporting are automatically erased no later than two (2) years after the removal. • Chat and feed content: for the lifetime of the association; erased when the association is closed. • Payment records and transaction logs: seven (7) years after the end of the financial year, under Chapter 7, Section 2 of the Swedish Accounting Act. • Data exports (GDPR): downloadable export files you request are automatically deleted within a week of being created. • Email dispatch logs: processed rows (sent/failed) containing email content are automatically deleted within 30 days. • Audit logs (security-related events): up to twelve (12) months. • Backups: rotated on a 30-day schedule and overwritten thereafter. • Push notification tokens: removed on logout or when the device is deregistered. • We may also delete accounts that have been inactive for a long period, after giving you prior notice.
6. Recipients and sub-processors
We engage the following sub-processors in order to provide the service. All are bound by data processing agreements and adequate security measures: • Supabase Inc. — database and authentication. Data is stored within the EU (AWS eu-west, Ireland). • Stripe Payments Europe Ltd. — payment processing. Established in Ireland. Stripe is also an independent controller for fraud prevention, identity verification and regulatory compliance under anti-money-laundering legislation. • Vercel Inc. — hosting and frontend delivery. Established in the USA, covered by the EU-US Data Privacy Framework and the EU Standard Contractual Clauses (SCC). • Resend (Drip Email Inc.) — transactional email. Established in the USA, covered by the EU-US Data Privacy Framework. • Anthropic PBC — AI features (Claude API). Established in the USA, covered by the EU Standard Contractual Clauses (SCC). Anthropic does not use your data for model training. • Voyage AI (MongoDB, Inc.) — AI embeddings (vectorisation of association content) for AI search and the knowledge base (RAG). Established in the USA, covered by the EU Standard Contractual Clauses (SCC). Under the provider's terms, the content is not used to train the provider's models. • Sentry (Functional Software, Inc.) — error reporting and monitoring. Established in the USA, covered by the EU-US Data Privacy Framework and the SCC. Personal data is scrubbed before logging as far as is technically possible. • Upstash, Inc. — rate limiting and technical deduplication of webhooks (Redis). Only short-lived technical keys. Established in the USA, covered by the EU Standard Contractual Clauses (SCC). • Google Ireland Limited (with Google LLC, USA) — address lookup and geocoding (Google Places/Maps) when you fill in addresses in the service. Covered by the EU-US Data Privacy Framework and the EU Standard Contractual Clauses (SCC). An up-to-date list of sub-processors is always available in our data processing agreement (DPA). We notify association administrators at least 30 days in advance of any replacement or addition of a sub-processor.
7. Transfers to third countries
Some of our sub-processors are established outside the EU/EEA (mainly in the USA). For these transfers we rely on: • The EU-US Data Privacy Framework — for providers certified under the framework (Vercel, Resend, Sentry). • The EU Standard Contractual Clauses (Commission Decision 2021/914) — for other transfers, including Anthropic. Module 3 (processor-to-processor) applies. • Supplementary technical and organisational measures (encryption in transit and at rest, access controls) where appropriate in line with the EDPB's recommendations. You may request a copy of the applicable safeguards by contacting privacy@membly.app.
8. Children's personal data
Under Chapter 2, Section 4 of the Swedish Data Protection Act (2018:218), Sweden has set the age of digital consent at 13 (Article 8 GDPR allows member states to lower it from 16). • Members aged 13 or older can themselves consent to processing that is based on consent. • For members under 13, processing takes place via a guardian. Membly provides a dedicated guardian flow in which the parent creates an account for the child and retains control. • For minors in sports associations we minimise data collection. We do not process special categories of personal data (Art. 9 GDPR) other than with the explicit consent of a guardian. • We do not profile minors and do not send marketing material to children. • National identity numbers are processed only where required for LOK subsidy reporting and are handled under a dedicated encryption routine.
9. Your rights under the GDPR
You have the following rights under Articles 15–22 of the GDPR: • Right of access (Art. 15): you can request a copy of the personal data we process about you. • Right to rectification (Art. 16): you can correct inaccurate or incomplete data directly in your account or by contacting us. • Right to erasure (Art. 17, the "right to be forgotten"): you can request erasure of your data. Some data we must retain because of legal obligations (e.g. accounting data). • Right to restriction of processing (Art. 18). • Right to data portability (Art. 20): you can export your data in a structured, commonly used format. Use Account → Export my data (corresponding to the API call POST /api/v1/profiles/me/export). • Right to object to processing (Art. 21), in particular to processing based on legitimate interests. • Right not to be subject to automated decision-making (Art. 22). To exercise your rights, contact privacy@membly.app. We respond within one month in accordance with Art. 12(3) GDPR.
10. Right to lodge a complaint with a supervisory authority
If you consider that our processing of your personal data infringes data protection legislation, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY): Integritetsskyddsmyndigheten Box 8114 104 20 Stockholm, Sweden imy@imy.se www.imy.se We would appreciate it if you contacted us first at privacy@membly.app so that we have the opportunity to put any problems right.
11. Cookies and similar technologies
We use only strictly necessary cookies for the service to work (login sessions, security) together with functional local storage for your preferences (language, dark mode). We use no advertising cookies and no third-party analytics tools such as Google Analytics or Meta Pixel. Full information is available in our cookie policy.
12. The role and responsibilities of association administrators
When you as an administrator create an association in Membly, the association is the controller of the members' data. Membly is the processor and processes the data on the association's instructions in accordance with Article 28 of the GDPR. On registering an association, the administrator accepts Membly's data processing agreement (DPA) on the association's behalf. The association administrator is responsible for informing its members how their data is processed, for obtaining any necessary consents, and for handling the members' rights (access, rectification, erasure). Membly assists the association with technical tools for managing these obligations (member list, export, erasure on request).
13. Changes and contact
We may update this privacy policy. Material changes are notified by email to association administrators and by a notice in the app at least 30 days before the changes take effect. Minor linguistic or clarifying changes are published immediately with an updated "last updated" date. Contact: Monile AB ("Membly") Company reg. no. 559273-6051 Nackagatan 3, 116 49 Stockholm, Sweden Email: privacy@membly.app
14. Waiting list and expressions of interest
On our public pages you can leave your email address to hear when we open for a new type of association, and when an association is created you can register interest in a country where Membly is not yet available. We then process the following data: • Email address: the address you enter yourself. • Country: only for expressions of interest concerning a country we do not yet operate in, and only the country you select yourself. • Answers to optional questions: if you apply for a pilot place you may choose to tell us what you are missing today, how many apartments the association has, and what you would consider a reasonable monthly price. All three are optional — you can leave your address without answering any of them, and we never ask for information about individual members. The purpose is partly to be able to contact you when the service opens, and partly to see which countries and types of association there is demand in — that is how we decide what to open next. We use the answers to the optional questions to understand what associations actually need and what the service ought to cost; they inform what we build and how we price it, never a judgement about you. The legal basis is your consent (Art. 6(1)(a)): you provide the information through an active choice, and for a stated purpose. We send a confirmation the first time an address is registered. Beyond that we do not use the address for newsletters or other marketing, and we do not pass it on to anyone other than the providers listed in section 6. We keep the data — both the address and any answers — until we have been in touch about your registration, or until you ask us to remove it; email privacy@membly.app. The answers live on the same row as the address and are deleted along with it. If you delete your Membly account, your registrations are removed at the same time, and they are included in the data export you can request under Art. 15.
Language versions
This document was drafted in Swedish. The English translation is provided for convenience only. In the event of any discrepancy between the versions, the Swedish version governs.
