Privacy

What we store, and how to get it removed

Leaving Board exists to collect farewell messages on one card. That needs a little information about the people who sign it — and nothing else. Here is the whole of it, in plain language.

What we collect

  • Your name, as you type it. It is a display name: it does not have to be your legal name, and two people may use the same one.
  • Your email address, which we check with a one-time link so that one person cannot sign a card twice.
  • Your message, up to 1000 characters.
  • Your GIF choice, if you pick one — we store the GIPHY link and its description, not the animation itself.

That is the complete list. There is no account, no password, no profile, and no tracking or analytics of any kind.

Why we collect it

Solely to run the card: to let you add your message once, to show it to everyone the card is shared with, and to let the organiser hand the finished card to the person leaving. Nothing is used for anything else.

What everyone can see

The card itself is public to anyone who has the link. On it, a message shows your display name, your message text and your GIF — and nothing else.

Email addresses are never shown publicly. Not to other contributors, not to the person the card is for, and not to anyone who opens the shared link. No public page and no public data file contains an address.

Who sees what

The organiser
Can see the email addresses of everyone who signed, in their own organiser dashboard — and in the copy of the card they download, if they export it. They collected those addresses by inviting you to the card, and this is the same access they would have to a paper card passed round the office.
The person the card is for
Sees the finished card, and only ever the card: display names, messages and GIFs. They are never shown an email address.
Anyone else with the link
Sees exactly the same public card, and no email addresses.
The people running this server
Can read the database, as with any self-hosted tool. It is not shared with a third party, and there are no analytics or advertising scripts.
GIPHY
If you pick a GIF, your browser loads it straight from GIPHY's own servers, as their terms require — so GIPHY sees that request, as it would on any site showing their GIFs. We send them nothing else, and no address is ever passed to them.

How long we keep it

Until the organiser deletes the card. There is no automatic expiry and no scheduled wipe: a card stays in the database exactly as long as its organiser leaves it there.

We suggest tidying up older cards — deleting a card once it is more than a year old, or once the leaving do is a distant memory, is plenty. That is a manual step today: the organiser does it themselves from their dashboard.

How to get your data removed

Ask the organiser of the card. Deleting a card removes the card, every message on it, the email addresses of everyone who signed, any pending email for it, and the one-time sign-in links that point at it. It cannot be undone.

You can also simply ask to have your own message removed, without deleting the whole card — the organiser can remove any message from their dashboard. If you are the organiser, the delete control is at the bottom of your dashboard and asks you to type the card's link code to confirm.

If you do not know who the organiser is, they are the person who sent you the card's link.

Email

We send email for one reason only: the one-time link that confirms you can sign the card. That is transactional mail, not marketing — there is no newsletter, no drip campaign and nothing to unsubscribe from, because we have nothing else to send you. Once the card is revealed, the only other message is the single notification to the person it is for.

Back to the home page