Privacy

What we collect, and what we don't

Cyprus Now is a free events site, made in Limassol. This page explains what we collect, why, and what happens to it. We have written it in plain English on purpose. A privacy policy you cannot read is not really a privacy policy.

Last updated 16 July 2026.

The short version

  • We count visitors. We don't track you. Our analytics stores nothing on your device and cannot follow you to other sites.
  • We never sell your data. Not to anyone, for any price.
  • We run no third-party ad trackers. Our ads are sold by us, directly. They are pictures and links, not surveillance.
  • We only email you what you asked for.
  • If you want your data gone, ask. Email hello@cyprusnow.app and we will delete it.

When you are just reading the site

You do not need an account to use Cyprus Now, and if you are just browsing, we do not know who you are.

We do measure traffic, using a tool called PostHog, on its European servers. We run it in a cookieless mode: it sets no cookie and stores no identifier in your browser. Your visitor id lives in memory for as long as the tab is open, and then it is gone. Come back tomorrow and you are a new anonymous face to us.

What it records:

  • Which pages get viewed.
  • Actions that tell us the site works: opening an event, tapping through to tickets or directions, saving, sharing, filtering, and whether an ad was seen or clicked.
  • Clicks on buttons and links, captured automatically rather than one by one.
  • Errors, so we can find out what crashed.

What it does not record:

  • Session replay is switched off. We cannot watch a recording of your screen.
  • No name, email address, or message content is attached to any of it.

One thing worth being straight about: this analytics is served through an address on our own domain, which then forwards to PostHog. That is so ad blockers do not silently break our visitor count, not to hide who we use. The data reaches PostHog either way, and now you know it does.

Why we are allowed to: legitimate interest. We think counting anonymous visitors, while storing nothing on your device, is a fair thing to do without interrupting everyone with a cookie banner. If you disagree, tell us at hello@cyprusnow.app and we will stop counting you.

If you make an account

You can sign in with Google, with an email magic link, or with an email and password. We store what that sign-in gives us: your email address, your name and profile picture if the provider supplies them, and which method you used. Passwords are stored as a hash, never as text we could read.

We give you a random handle, like a nickname, and you can change it. It is deliberately not derived from your email address, so your email is not exposed by the profile you post under.

Your account also carries your own privacy settings, controlling what other people can see, and your notification preferences, controlling what we are allowed to email you. Both are yours to change in your account settings at any time.

When you give us something

Submitting an event. We keep what you submit, which is event information rather than personal information, linked to your account so we know who sent it. Approved events are published, which is the point of sending one.

Subscribing to the newsletter. We keep your email, your city, the categories you picked, how often you want it, and a phone number only if you chose to add one. That is consent: you asked for it, so you can take it back. To stop, email hello@cyprusnow.app and we will remove you.

Asking about advertising. The enquiry form sends us your name, your business, your contact details, and your message, as an email. There is no separate database of enquiries. It arrives in our inbox and lives there like any other email from someone who wants to work with us.

Searching. We record what people search for, so we can see what Cyprus is looking for and cover more of it. We store the words typed, not who typed them: search records are not linked to your account.

If you buy an ad

Payments are handled by Stripe. We never see or store your card details. Stripe does, and it is theirs to hold, not ours.

One disclosure we would rather make than bury: when a campaign is paid for, approved, or goes live, we send that event to our analytics with the buyer's email address attached, so we can connect a sale to the visit that produced it. This is the single place where an email address reaches our analytics, and it only ever applies to advertisers, never to readers.

Cookies, and what is stored on your device

We use no tracking cookies and no advertising cookies. We are not cookie-free, though, and it would be easy to pretend otherwise, so here is the actual list.

  • Sign-in cookies. Set only if you sign in. They keep you signed in and protect the forms you submit. Without them, signing in cannot work.
  • A preferences cookie. Remembers the location and language you last filtered by, so you are not made to pick them every single visit. It holds a place name and a language code. Nothing else, and nobody else reads it.
  • Things your browser keeps to itself. Your light or dark theme, whether you dismissed the install prompt, and similar small preferences. These sit in your browser and are never sent to us.

Clearing your browser storage clears all of it. Nothing in the list above is used to build a profile of you or to follow you anywhere.

Who else touches your data

We are a small operation and we use other companies to run the site. They process data on our behalf, under their own agreements, and they are not allowed to use it for their own purposes.

  • PostHog for analytics, on its European servers.
  • Resend to deliver our email.
  • Stripe for advertiser payments.
  • Neon for the database, and Vercel for hosting the site itself.

That is the whole list. If we ever add to it, this page changes first.

What we do not do

  • We do not sell your data, and we do not share it for anyone else's marketing.
  • We do not run third-party ad trackers, ad networks, or tracking pixels. Our advertising is sold by us to local businesses, and the ads are images and links, which cannot watch you.
  • We do not record your screen.
  • We do not track you across other websites, and we could not if we wanted to.
  • We do not email you things you did not ask for.

How long we keep it

Here we will be straight with you rather than quote a number we made up. We keep your account and what you have given us for as long as your account exists. We have not yet set fixed expiry windows for every kind of record, and rather than print a comfortable-sounding period we do not actually enforce, we would rather say so plainly and point you at the part that does work: if you want your data gone, ask us and it goes.

Your rights

Cyprus Now is run from Cyprus, so the GDPR applies and you have the full set of rights under it. You can ask us to:

  • show you what we hold about you,
  • correct it if it is wrong,
  • delete it,
  • hand it over in a portable form,
  • restrict what we do with it, or object to it, including our analytics,
  • stop emailing you, or withdraw a consent you gave us earlier.

How to do it: email hello@cyprusnow.app. A person reads it and acts on it. We do not make you fill in a form or find a hidden switch, and we will not charge you or ask why.

Some of it you can just do yourself: your email, handle, and picture are editable in your account settings, and so is every notification you can receive from us.

If we get it wrong, you can complain about us to the Office of the Commissioner for Personal Data Protection in Cyprus, which supervises us. We would rather you told us first and gave us the chance to fix it, but it is your right either way.

If this page changes

If we start collecting something new, or add a company to the list above, we will update this page and change the date at the top. We are not going to quietly widen what we do and leave the old promise sitting here.

Questions about any of this

Write to us. A real person answers.

hello@cyprusnow.app

Prefer to keep reading? Back to what's on.