Privacy Policy
Legal
Last updated: 6 September 2026
Pre-launch draft. The controller's final legal name and correspondence address must be inserted before public launch.
At a glance
Sportelier processes the information needed to create accounts, publish and join sports events, manage attendance and series, deliver notifications, provide support, and keep the service secure. We record product events on our own server and store a 30-day attribution cookie only with your consent. We do not use advertising technology or third-party analytics.
Controller and contact
The data controller is the person or entity operating Sportelier. Its final legal name and correspondence address will be added before public launch. Privacy requests can be sent to sportelier.app@gmail.com.
Data we process
- Account data: username, email address, password hash, email-verification status, authentication sessions, and account-security records.
- Profile data: name, avatar, city, biography, preferred sports, favorite cities, and notification preferences that you choose to provide.
- Event and participation data: events and series you organize, locations, schedules, roster membership, waitlist/reserve placement, team assignments, attendance reviews, correction requests, correction audit records, and related actions.
- Communications: support reports, in-app notifications, email-delivery records, and push-subscription details when enabled.
- Technical and security data: IP address, user agent, timestamps, application logs, session identifiers, and browser storage described in the Cookie Policy.
- Product events: We record registration, event creation, joining, waitlist promotion, leaving, reconfirmation and event outcomes on our server. Anonymous tagged-link visits contain no visitor identifier. Without analytics consent, the link source is held in sourceTagReported in session storage and connected to your registration only in the same browser session. With consent, the first-party HttpOnly cookie sb_attr retains the sanitized UTM source for 30 days and can attribute a later registration. You can withdraw consent in the cookie settings in the footer; this removes the cookie. We use no third-party analytics or page-view tracking. Product event records are retained for 12 months.
Sign in with Google
When you choose "Sign in with Google", the sign-in is handled by Google Identity Services. Sportelier receives your Google account identifier, email address, email-verification status, and display name. We use this information to authenticate you and, on a first-time sign-in, to create your account. Sportelier never receives your Google password, and does not request or access your Google contacts, calendar, or Drive.
Log in with Facebook
When you choose "Log in with Facebook", the sign-in is handled by Facebook Login, a Meta service. Sportelier receives the identifier Facebook gives your account for our app, your profile name (only to suggest a username), and your email address if you allow it. We use this information to authenticate you and, on a first-time sign-in, to create your account; we confirm the email address with our own code before the account exists. Sportelier never receives your Facebook password, and does not request or access your Facebook friends, posts, or photos. You can remove the Facebook connection in your profile's security settings, or by removing the Sportelier app in your Facebook settings and asking for your data to be deleted: we then delete the identifier and the email address we received from Facebook.
Sign in with Apple
When you choose "Sign in with Apple", the sign-in is handled by Apple. Sportelier receives the identifier Apple gives your account for our app, your email address, and, on your first sign-in only, the name you choose to share (only to suggest a username). If you choose to hide your email address, Apple gives us a unique relay address, and our emails reach your inbox through Apple's private email relay. We use this information to authenticate you and, on a first-time sign-in, to create your account. When you sign in, Apple also gives us a token for your authorization. We keep it encrypted, and only for as long as your Apple connection (or a sign-up in progress) needs it, so that we can ask Apple to revoke it when the connection ends, as Apple requires of apps; we then revoke and delete it, usually within minutes. We never use it to read anything from your Apple Account. Sportelier never receives your Apple Account password. You can remove the Apple connection in your profile's security settings, or by no longer using Sign in with Apple for Sportelier in your Apple Account settings: Apple then tells us, and we remove the connection and the identifier we received from Apple. Your Sportelier account stays, also if you delete your Apple Account.
Purposes and legal bases
- Providing accounts, events, participation, series, notifications, and support: performance of the service agreement or steps requested before entering it.
- Preventing abuse, securing accounts, diagnosing failures, and maintaining reliable event rosters: legitimate interests in operating and protecting the service and its users.
- Keeping records required by law and responding to lawful requests: compliance with legal obligations.
- Optional technologies or communications that legally require consent: consent, which may be withdrawn without affecting earlier lawful processing.
Visibility and recipients
Public event, organizer, and profile information can be seen by other users and visitors. Roster information is visible on event pages as described by the event's visibility model; anyone holding a private-event link may be able to see its roster. Organizers can see information needed to manage their events.
Your public games-played total may include games from private events, but your public profile does not reveal which private events contributed to it. Attendance correction messages, audit actors, and reasons are visible only to the people authorized to resolve or support the correction.
Data may also be processed by vetted providers supporting hosting, databases, email, push notifications, maps/geocoding, weather data, storage, security, and support. We disclose information to authorities where legally required.
International transfers
Some service providers may process data outside the European Economic Area. Where required, Sportelier will use an adequacy decision, Standard Contractual Clauses, or another lawful safeguard. The final production provider list and transfer details must be completed before launch.
Retention
Account and profile data are generally retained while the account is active. Event and participation history may be retained to preserve rosters, attendance records, series history, safety, and dispute context. Authentication sessions expire or are revoked; operational, support, email-delivery, and security records are kept only as long as needed for their purpose, legal obligations, or the establishment and defense of claims. Data is deleted or anonymized when it is no longer necessary.
Free-text evidence in a decided attendance correction request is blanked 180 days after the request is resolved or dismissed. If a request is never decided, its free text is blanked 180 days after the seven-day correction window closes. The structured outcome and correction audit may remain with the event so attendance totals and dispute history stay internally consistent.
You can permanently delete your account at any time from your profile security settings. Your profile, email address, and sessions are removed immediately, and upcoming events you organize are canceled with participants notified. Entries in historical event rosters are anonymized rather than removed, so other participants keep an accurate record of who attended their events; the anonymized entry cannot be linked back to you.
Your rights
Depending on the circumstances, you may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time. We may need to verify your identity and normally respond within one month.
You may lodge a complaint with your competent supervisory authority. In Poland this is the President of the Personal Data Protection Office (UODO): complaint information.
Automated decisions and children
Sportelier does not currently make decisions producing legal or similarly significant effects based solely on automated processing. The service is not designed for children who cannot validly agree to use it under applicable law; where required, a parent or guardian must authorize use.
Security and changes
We use password hashing, sessions in HTTP-only cookies that the server checks on every request and can end at any time, access controls and audit logs. No service can guarantee absolute security. We update this policy when processing or legal obligations change and ask for a new choice before introducing additional optional purposes, advertising or third-party analytics.