Legal
Wapate Privacy Policy
Last updated: September 2026
This Privacy Policy explains what personal information Wapate collects and how that information is used when you use the Wapate website and related services (together, "Wapate").
Wapate is a creative network that helps people discover creatives, join communities, find events, message others, and collaborate. It is operated from Norway and may be used by people in other countries.
This policy describes practices that are reflected in how Wapate currently works. It does not claim that Wapate is "GDPR compliant" as a certification. Where European data-protection rules apply (including in Norway and the EEA), we describe our processing in plain language and note areas that are still being formalised.
1. Who we are
The service is provided under the name Wapate (website: www.wapate.com). Wapate is Norway-based.
For privacy questions, contact us at [email protected].
2. Information we collect
Depending on how you use Wapate, we may process:
Account and authentication
- Name (provided at sign-up and stored on your profile).
- Email address (used to create and sign in to your account, and for password-reset and confirmation emails sent through our authentication provider).
- Password (handled by our authentication provider; Wapate does not display your password).
- Account identifiers issued by the authentication system (such as your user ID).
Profile information you choose to provide
- Photo, city, country, bio, creative disciplines, skills, and “connect for” preferences.
- Public social or portfolio links you add.
- Profile fields that may hold portfolio or project content if present on your profile.
- A last-seen / presence timestamp while you use the app when signed in.
Activity on the platform
- Events you create (title, category, date, time, city, country, location, description, cover image), RSVPs, and event discussion messages if you use event discussion.
- Communities you create or join, including membership, and community chat messages if you use community chat.
- Collaboration posts you publish (title, description, discipline, optional city/country/timeline).
- Direct messages you send or receive, including text, optional images, and optional file attachments, plus related conversation membership.
- Images and files you upload (for example profile, event, or community images, and message media).
Technical and usage information
- Session cookies needed to keep you signed in (via our authentication and hosting stack).
- Limited browser session storage used for technical error recovery (not for advertising).
- Browser local storage used to remember your analytics Accept / Reject choice.
Wapate does not currently ask for phone numbers, payment details, or government ID in the product flows audited for this policy.
3. How we use information
We use personal information to:
- Create and secure your account, authenticate you, and reset passwords.
- Show your public profile in the creatives directory and on profile pages.
- Operate events, communities, collaboration posts, and messaging.
- Store and deliver images and files you upload so the service can display them.
- Show approximate online / last-seen status to other users where the product uses that signal.
- Enforce our Terms, Community Guidelines, Content Policy, Events & Communities Policy, and Safety & Reporting practices, including investigating reports and taking account or content action where appropriate.
- Comply with law where we are legally required to preserve or disclose information.
Where European data-protection law applies, these uses are generally based on performing the service you request (providing the Wapate account and features), our legitimate interests in operating a secure creative network, and legal obligations when applicable. Optional product analytics and session recording (Bigdelta) run only if you accept them in the in-product analytics banner (see section 7).
4. What is public vs private
Generally public on Wapate
- Creative profiles (name, photo, location fields, bio, disciplines, skills, connect-for preferences, links, and any portfolio/project content stored on the profile).
- Events and event attendance lists.
- Communities and community membership lists.
- Collaboration posts and author profile details shown with them.
- Images stored in Wapate’s public image storage (for example profile, event, community, and some message images), which are accessible via public URLs while those objects exist.
Profile data is readable under the platform’s public profile access rules. Presence / last-seen information is stored with the profile and used in messaging presence features.
Not shown as public profile fields
- Your email address and password (account credentials).
- Direct message content and conversation membership (limited to participants in that conversation under platform access rules).
- Community chat messages (limited to members of that community under platform access rules).
- Event discussion messages (limited to the event host and attendees under platform access rules).
- File attachments in direct messages stored in private attachment storage (accessible to conversation participants as implemented).
“Private” here means not displayed on public profile pages and restricted by access controls in the product. It does not mean invisible to Wapate operators with privileged database or service access, or invisible to our infrastructure providers that host the data.
5. Messaging and uploads
Direct messages may include text, images, and file attachments. Message images may be stored in public image storage; non-image attachments are stored in a private attachments store and retrieved for conversation members.
You may edit or soft-delete your own direct messages in the product where that feature is available. Soft-deletion updates the message record; it is not the same as full account erasure.
Community chat stores message text for members of that community. Event discussion stores message text for the host and attendees of that event.
6. Cookies and local storage
Wapate uses cookies (and related browser storage managed by our authentication library) to maintain your signed-in session.
The app also uses browser sessionStorage for a technical reload guard related to certain client errors, and localStorage to remember your analytics Accept / Reject choice so we do not re-prompt on every visit.
We did not find advertising cookies or a marketing pixel implementation in the application code audited for this policy.
7. Analytics, session recording, and advertising
Wapate may use a third-party product analytics tool (Bigdelta) for page views and session recording to help us understand how the site is used and improve it. Message composer text is masked in recordings where that masking is configured in the product.
Bigdelta is not loaded and session recording does not start until you choose Accept on the analytics banner. If you choose Reject, Bigdelta stays disabled. Your choice is stored in your browser (localStorage). You can change it later via Analytics preferences in the site footer, or here: .
An operator can still turn Bigdelta off entirely with an environment flag; when that flag is off, the banner and SDK stay inactive.
We did not find a separate advertising network, ad pixel, or paid-ads SDK installed in the application dependencies audited for this policy.
8. Who we share information with
We share or process information with service providers that help run Wapate:
- Supabase — authentication, database, realtime features, and file storage.
- Hosting / deployment infrastructure used to serve www.wapate.com (Wapate’s deployment documentation references Vercel).
- Bigdelta — optional product analytics and session recording, only if you Accept in the analytics banner.
These providers process data on our behalf to provide their services. They may also process technical data according to their own roles as independent controllers where that applies under their terms.
We may also disclose information if required by applicable law, or in connection with safety, abuse, or Terms enforcement as described in our Safety & Reporting policy.
We do not sell personal information. We do not use your content to train third-party generative AI models in any feature audited for this policy.
9. International transfers
Wapate is Norway-based and used internationally. Core application data is stored with Supabase and may be processed by hosting infrastructure listed above.
Our Supabase project is configured in the Oslo region. Authentication, database, and file storage for that project use the project region unless a separate provider setting indicates otherwise.
Our Vercel project currently runs server-side Functions in the arn1 region (Stockholm, Sweden). Build infrastructure may use other Vercel locations; edge delivery may also involve Vercel's global network.
Personal data handled by those Functions is processed in Stockholm under the current Function region configuration. Build infrastructure and edge delivery may still involve other Vercel locations. International transfers may also occur through other service providers that help run Wapate. Where required by applicable law, Wapate will use appropriate safeguards for such transfers.
10. Retention
Wapate has not defined fixed automated retention periods in the application or database scripts audited for this policy. There is no automatic deletion of inactive accounts, messages, uploads, RSVPs, memberships, collaborations, or safety reports on a schedule.
In practice, information generally remains for as long as your account and related content exist on the platform, unless removed through available product actions (for example leaving a community, cancelling an RSVP, deleting your own collaboration post or hosted event/community where permitted, soft-deleting your own messages, or deleting your account) or through operator action.
11. Account and data deletion
You can delete your own account from Edit profile. Deletion requires typing a confirmation phrase before it runs.
When account deletion succeeds (after the supporting database function has been enabled), Wapate removes your authentication user so you can no longer sign in, and related data is handled as follows:
- Your profile is removed.
- Your community memberships, conversation memberships, RSVPs, and collaboration posts you authored are removed.
- Events you host are removed (including RSVPs on those events).
- Communities you host keep the community but clear the host link.
- Your direct messages are soft-deleted (content cleared) so the other participant keeps a deleted-message placeholder.
- Your community chat and event discussion messages are anonymised.
- Files in your own image and attachment storage folders are removed when deletion runs successfully from the app.
Account deletion uses a server-side database function scoped to your signed-in user. It does not expose a service-role key to the browser. Official platform accounts cannot self-delete.
You can also update your profile, leave communities, cancel event RSVPs, remove content you are allowed to delete, and soft-delete your own direct messages where that feature exists, without deleting the whole account.
12. Your choices and rights
Depending on where you live (including under European data-protection rules for people in Norway / the EEA), you may have rights to access, correct, delete, or restrict certain personal data, or to object to certain processing.
For optional Bigdelta analytics and session recording, you can Accept or Reject in the banner, and change that choice later with Analytics preferences in the footer.
You can correct many profile fields yourself in account settings and delete your account yourself from Edit profile. Other requests can be sent to [email protected].
13. Children and minimum age
Wapate is for users who are at least 16 years old. You must confirm this at sign-up. We do not use ID verification or KYC to check age.
If you believe someone under 16 has created an account or provided personal information, contact us at [email protected] so we can review and take appropriate action.
14. Security
Wapate uses access controls (including database row-level security policies and private storage rules for message attachments) and signed-in sessions to protect accounts and private features.
No online service is perfectly secure. Please protect your password and use appropriate caution when sharing personal details in public profiles, events, communities, or messages.
15. Changes to this policy
We may update this Privacy Policy as Wapate evolves. When we do, we will change the "Last updated" date on this page. Continued use of Wapate after an update means the updated policy applies to your ongoing use.
16. Contact
Privacy questions and data requests can be sent to [email protected].
Related policies: Terms of Use, Community Guidelines, Content Policy, Events & Communities, and Safety & Reporting.