Rabbits Foot Limited Privacy Policy
Last updated: 28 August 2026
This Privacy Policy describes how Rabbits Foot Limited ("we," "us," or "our") collects, uses, and shares your personal information when you visit or use our website https://meetup.art (the "Site"), use our mobile applications, or engage with our art community platform and services (collectively, the "Services").
By using our Services, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our Services.
Information We Collect
Information You Provide to Us
We collect information you directly provide to us, including:
- Account Information: Name, email address, password, profile picture, biography, role (for example artist, model, organiser or tutor), and other information you provide when creating an account. If you sign in with Google or Apple, we receive the name and email address those providers share with us for that purpose.
- Profile Information: Artistic interests, skills, portfolio information, location, and preferences you choose to share, including your notification frequencies and whether to show images that contain nudity.
- Event, Group and Job Information: Details about events, groups, courses, jobs and announcements you create, join, apply for or follow, including descriptions, dates, locations, attendee lists, and job-application messages.
- Bookings and invitations: When a model creates a booking, or an organiser sends a structured invitation, we store the proposed or agreed time, location, rate and related messages so both parties can manage the booking.
- Communication Data: Messages, comments, reviews, announcements and other content you post on our platform.
- Artwork and shop listings: Titles, descriptions, prices, images and sale records when you list or buy artwork or reference packs.
- Payment and payout Information: Billing details, billing country, and connected payout-account status when you make purchases, take a paid subscription, or receive earnings. Card numbers are handled by our payment providers; we do not store full card details.
- Support Requests: Information you provide when contacting customer support.
- Newsletter: Your email address if you subscribe to our mailing list.
- Calendar connections: If you connect Google Calendar, Microsoft 365, Apple iCloud, or an ICS feed, we store busy/free time intervals and calendar names so organisers can see whether a slot is free. We never collect event titles, descriptions, locations, or guest lists from your own calendars. Meetup Art bookings we write back to your calendar are labelled as Meetup Art sessions only. If you opt in to booking matching, we also read titles and times from the Meetup Art Bookings calendar we created (not from your primary diary) so we can suggest sessions to confirm. An optional AI checkbox sends parsed title fields — never calendar notes — to rank ambiguous matches.
Information We Collect Automatically
When you use our Services, we may automatically collect:
- Device Information: IP address, browser type, operating system, device identifiers, and mobile device information. On registration and sign-in we also record a first-party device identifier (see Safety and Security below).
- Usage Data: Pages visited, features used, time spent on the platform, search queries, and interaction patterns.
- Location Information: General location based on IP address. If you type an address for an event or group, Google Maps Places processes that query so we can store the location you chose.
- Push tokens: If you enable notifications in a browser or our iOS app, we store a device or subscription token so we can send those alerts.
- Cookies and Tracking: Information collected through cookies, web beacons, and similar technologies. See our Cookie Policy.
How We Use Your Information
We use the information we collect to:
- Provide and Maintain Services: Operate, maintain, and improve our platform and services. Legal basis: contract (UK GDPR Article 6(1)(b)) where you have an account or purchase, and legitimate interests (Article 6(1)(f)) for running a secure public website.
- Create and Manage Accounts: Process registrations, manage accounts, and provide customer support.
- Facilitate Events, Groups and Jobs: Help users organise, discover and take part in art-related events, groups, courses, modelling jobs and bookings.
- Personalization: Customise content, recommendations, and experiences based on your interests and activity.
- Communication: Send transactional messages (for example booking, ticket and payment emails, including calendar attachments), optional newsletters, and replies to your inquiries. You can set per-type email frequency in account settings. Legal basis for marketing email: consent.
- Payment Processing: Process transactions, subscriptions, refunds and payouts for paid services.
- Image classification and moderation: Automatically classify uploaded images so that pictures with visible nudity can be hidden unless you choose to see them, and screen course and event promotional images against our public-listing rules. Classification looks at the image only, not at titles or filenames.
- Safety and Security: Detect fraud, prevent abuse, and ensure platform security. This includes recording IP addresses and a first-party device identifier on registration and sign-in so we can investigate serious abuse and prevent a suspended person from simply opening a new account. Legal basis: legitimate interests (UK GDPR Article 6(1)(f)). We do not use browser fingerprinting.
- Analytics and Research: Analyse usage patterns and improve our services (including feature flags).
- Legal Compliance: Comply with legal obligations and protect our rights.
Images Containing Nudity
Meetup Art is a life-drawing platform. Artistic nudity is permitted on model and artist profiles, portfolios and reference material. Images that contain visible nudity (nipples, genitals or bare buttocks) are hidden by default for every viewer. You can turn on "Show images with nudity" in Site options in the navigation. Concealed nudes — an unclothed figure whose private anatomy is hidden by pose, props, drapery or cropping — are not hidden by this setting. Owners always see their own uploads.
Guests: the choice is stored in a first-party cookie (ma_show_nsfw). Members: the same choice is stored on the account and overrides the cookie after login. A choice made as a guest is copied onto a new account at registration.
Course and event promotional images are a separate rule: they must be suitable for public search results, the homepage and link previews, and may be refused if they contain full-frontal nudity or sexualised imagery. See our Terms of Service.
Information Sharing and Disclosure
We may share your information in the following circumstances:
With Your Consent
We share information when you explicitly consent, such as when you choose to make your profile public or participate in community features.
Service Providers
We share information with third-party service providers who help us operate our platform, including:
- Stripe, Mollie and PayPal (payments and payouts) — process charges, refunds and connected-account payouts for tickets, artwork, subscriptions and similar purchases. Which provider is used depends on the seller's chosen payout arrangement and billing country. See How payments work.
- Apple — Sign in with Apple; App Store In-App Purchase for iOS subscriptions; Apple Push Notification service for the iOS app; and iCloud CalDAV if you connect an Apple calendar.
- Vercel hosts the website. Hostinger hosts our API and database.
- Cloudinary stores and delivers images you upload.
- Resend sends transactional email. Mailchimp sends the newsletter if you subscribe.
- PostHog (product analytics and feature flags, EU cloud) — helps us understand how the Services are used. Logged-in analytics are tied to an opaque account hash, not your email.
- Sentry (error monitoring) — helps us detect and fix technical issues.
- Pusher delivers realtime messages and in-app notifications.
- Google Maps (Places) — used when you search for or save an event or group address.
- OpenAI and, when configured, Anthropic — receive a normalised copy of an uploaded image (not titles or other profile fields) so we can classify visible nudity and screen course/event promotional images. They are not used for advertising.
- Google, Microsoft and Apple (calendar platforms you choose to connect) — we request only busy/free time from Google (calendar.freebusy plus a Meetup Art-owned bookings calendar). If you opt in to booking matching, we also list events on that app-created calendar only. Microsoft Graph has no free/busy-only scope: we request calendar access, keep busy/free times only, and never persist event titles. An Apple app-specific password is unscoped: it grants CalDAV access to your iCloud calendars. You can disconnect in Calendar settings and revoke access at Google Account permissions, Microsoft account permissions, or appleid.apple.com. Sign in with Google is separate: it only receives the name and email Google provides for sign-in.
Google Calendar Limited Use
Meetup Art's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Calendar data is used only to show busy/free availability, to write Meetup Art bookings onto a calendar we create, and — if you opt in — to match titled events on that same Meetup Art Bookings calendar to sessions on Meetup Art. Matching does not read your primary Google Calendar. It is not used for advertising, not sold, not transferred except as needed to provide that feature, and not read by humans except as required for security or to comply with law.
Event Organizers, Group Administrators and Counterparties
Information may be shared with event organisers and group administrators as necessary for event management and community coordination. Job applications are visible to the person who posted the job. Booking invitations are visible to the organiser and model who exchanged them. Public profile, event, group, job, announcement and shop content is visible according to how you published it.
Legal Requirements
We may disclose information if required by law, legal process, or government request, or to protect our rights, safety, or the rights and safety of others.
Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction.
Data Retention
We retain your personal information for as long as necessary to provide our Services and fulfill the purposes outlined in this policy. We may retain information longer if required by law or for legitimate business purposes, such as:
- Account data is retained while your account is active and for a reasonable period after deactivation.
- Content you create (posts, comments, events) may be retained to maintain platform continuity.
- Financial records are retained as required by tax and accounting laws.
- Security logs (IP address associated with registration and sign-in, hashed device identifier) are kept for 12 months, or for as long as an account remains suspended. Hashed identifiers used only to stop a banned person re-registering may be retained after an account is deleted. Held or rejected registration attempts (no password) are kept for 180 days. A strictly necessary first-party cookie (
ma_did) stores an opaque device id for this purpose and does not require consent. - Calendar busy/free intervals are deleted 60 days after they end. Opt-in booking-match diary entries from Meetup Art Bookings are deleted on the same 60-day schedule. Invitation audit rows are deleted after 2 years. Booking invitations themselves are kept as a contractual record. Calendar credentials are revoked and removed when you disconnect.
- Image-classification results are kept with the image. Push tokens are kept until you disable notifications, uninstall the app, or delete your account.
- Legal holds may extend retention periods when required.
Your Rights and Choices
Under UK GDPR you have rights regarding your personal information, including:
- Access: Request information about what personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete information.
- Deletion: Request deletion of your personal information (subject to legal limitations).
- Restriction and objection: Ask us to restrict processing, or object to processing based on legitimate interests.
- Portability: Request a copy of your data in a structured format.
- Opt-out: Unsubscribe from marketing communications, change notification frequencies, and adjust privacy settings including the nudity visibility toggle.
- Calendar disconnect: Remove a connected calendar in Calendar settings. That deletes busy/free data we stored. Meetup Art bookings stay. Revoke Google access in your Google Account, Microsoft access in your Microsoft account, or revoke an Apple app-specific password at appleid.apple.com.
- Complaint: You may complain to the Information Commissioner's Office (ICO) at ico.org.uk.
To exercise these rights, contact us at hello@meetup.art or through your account settings.
Cookies and Tracking Technologies
We use cookies, web beacons, and similar technologies to:
- Keep you signed in and protect forms (session and CSRF cookies)
- Remember your preferences, including
ma_show_nsfwfor guests - Help prevent ban evasion (
ma_did, strictly necessary) - Measure how the Services are used (PostHog)
You can control cookies through your browser settings, but some features may not function properly if cookies are disabled. Full detail is in our Cookie Policy.
Data Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit and at rest
- Secure hosting infrastructure
- Access controls and authentication requirements
- Regular security assessments and updates
- Employee training on data protection practices
However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
International Data Transfers
Your information may be transferred to and processed in countries other than your own, including by providers in the United States (for example Google, Apple, Microsoft, Stripe, PayPal, Cloudinary, OpenAI, Anthropic, Sentry, Mailchimp, Pusher and Vercel). PostHog analytics for this product are hosted in the EU. We ensure appropriate safeguards are in place to protect your data during international transfers, including standard contractual clauses and adequacy decisions where applicable.
Third-Party Services
Our Services may contain links to third-party websites, applications, or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal information.
Children's Privacy
Our Services are not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
A Meetup Art account requires you to be at least 13. Attendance at a particular event is set by the organiser — many sessions working from an undraped model are restricted to over-18s. That age limit is stated on the listing.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. We may also notify you through email or platform notifications for significant changes.
Your continued use of our Services after any changes indicates your acceptance of the updated Privacy Policy.
Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: hello@meetup.art
Mail: Rabbits Foot Limited
1 Spice Court
Ivory Square, Plantation Wharf
London, SW11 3UE
United Kingdom
Data Protection Officer: privacy@meetup.art
We will respond to your inquiries within 30 days.
This privacy policy is effective as of 20 August 2026 and will remain in effect except with respect to any changes in its provisions in the future.