What Hubbaly collects
The product stores the data it needs to run communities events trust and support workflows
That data is not one single bucket. Different parts of the codebase store different classes of records for identity, event operations, moderation, payments, and delivery.
Account and profile data
Email, username, display name, bio, avatar, location, website, timezone, profile visibility settings, memberships, and linked public-profile state.
Authentication and security data
Password hashes, session records, refresh-token hashes, hashed session IPs, user-agent summaries, password reset and email-link tokens, Google SSO identities, passkeys, MFA factors, and backup codes.
Communities events and tickets
Community roles, share links, invites, membership requests, events, ticket orders, ticket transfers, guest attendee names/emails, purchases, refund workflows, and calendar subscriptions.
Reusable hub-scoped details
Where a hub uses Details to collect, Hubbaly can store answers such as full name, phone number, organisation or group, and other operational details required for interest, joining, invite acceptance, or ticket checkout. These answers stay with that hub, are not shared with other hubs, are encrypted at rest, and are visible only to authorised Hub Admin roles chosen by that hub.
Records a hub keeps about you
When a hub organiser imports an existing member list, they can keep some columns as hub records, such as answers you gave on an older application form. A hub record belongs to the organiser, not to you: only that hub's owners and admins can see it, it is encrypted at rest, and you cannot change or remove it in Hubbaly. It is kept until an owner or admin deletes it, so it can outlast a declined invitation or an import you never joined. Your applications to join a hub are kept alongside these records in the same way. You can ask the hub organiser for a copy of what they hold about you or ask them to correct or delete it, and they can export or delete it from your person page.
Content moderation and support
Chat messages, reactions, mentions, photo uploads, tags, reports, takedown requests, incident records, trust-safety restriction records, moderation history, and admin audit records.
Forms and verification
Document signatures can store signer name, rendered content snapshot, form-field answers, IP address, and user agent. Optional member verification can store legal name and a private verification photo.
Payments notifications and analytics
Order and payout records, Stripe reference IDs, email delivery and suppression state, push subscription/device identifiers, notification preferences, and first-party product analytics events.