Privacy Policy
1. Who we are
SPORTR is a Swiss association (association au sens des art. 60 ss CC) with its registered seat at:
SPORTR
Route des Jeunes 35
1227 Carouge
Switzerland
For all questions about this policy or about how we handle your personal data, you can reach us at privacy@sportr.ch.
SPORTR is the data controller for the personal data described in this policy.
2. What this policy covers
This policy explains what personal data SPORTR collects when you use our mobile app and website (together, “the Service”), why we collect it, how long we keep it, who we share it with, and what rights you have over your data.
It applies to everyone who uses SPORTR, regardless of where they live.
We have written this policy to be readable. Where the law uses specific terms (like “data controller” or “legitimate interest”), we use them too ; but we explain what they mean. If anything is unclear, write to us.
3. The law that applies to us
We process personal data in accordance with:
- The Swiss Federal Act on Data Protection (FADP/LPD), as revised in September 2023
- The EU General Data Protection Regulation (GDPR), where applicable to users in the European Union and European Economic Area
Where the two laws differ, we apply whichever offers stronger protection to you.
4. The data we collect
4.1 Data you give us when you create an account
When you sign up for SPORTR, we collect:
- Your first name and last name
- Your email address
- A password (stored in encrypted form ; we never see it in plain text)
- Your date of birth (used to confirm you meet the minimum age requirement of 16)
- The sports you practise and your self-declared level for each
- A profile photo, if you choose to upload one
If you sign up using Google, Apple, or Facebook, we receive only the information that provider shares with us when you authorise the connection. This is typically your name, email address, and a unique identifier ; and, in some cases, a profile picture. We request the minimum information necessary to create your account. We never receive your password from these providers.
4.2 Data you create by using SPORTR
As you use the Service, the following information is generated:
- Events you create, join, or are invited to, including the sport, time, location, level, and other participants
- Communities you join and your role within them
- Messages you send in event chats and community chats
- Ratings you give and receive after events
- Your reliability score and badges, calculated from your activity and ratings
- Match history : the games you have played, with whom, and where
4.3 Data we collect automatically
When you use the Service, we automatically collect:
- Device information : type of device, operating system, app version
- Technical information : IP address, language settings, time zone
- Usage data : when you open the app, which features you use, how long you spend in each section
- Crash and error logs, to help us fix bugs
We do not collect your precise location at the launch of SPORTR. In the future, we may add features that use your device’s location to suggest nearby games and facilities. Before we do, we will update this policy and ask for your explicit consent. You will always be able to refuse without losing access to the Service.
4.4 Cookies and similar technologies
Our website uses cookies and similar technologies. Please see our separate Cookie Policy for full details.
5. Why we use your data, and on what legal basis
Under GDPR, we must have a legal basis for every kind of processing. Under the Swiss FADP, we must process data in good faith and proportionately. Here is what we do, and why we are allowed to do it:
| What we do | Why we do it | Legal basis |
|---|---|---|
| Create and maintain your account | To give you access to the Service | Performance of the contract between us |
| Show your profile and activity to other users you interact with | This is the core function of the Service : connecting players | Performance of the contract |
| Send you operational notifications (event confirmations, rating prompts, system messages) | To deliver the Service you signed up for | Performance of the contract |
| Calculate your reliability score and award badges | To build trust between players, which is central to the Service | Performance of the contract |
| Send you marketing emails and promotional push notifications | To tell you about new features, events, and SPORTR news | Your explicit consent : which you give separately at signup, and which you can withdraw at any time |
| Use analytics to understand how the Service is used and improve it | To make SPORTR better | Our legitimate interest in improving the Service, balanced against your privacy rights |
| Detect and prevent fraud, abuse, and violations of our Terms | To keep SPORTR safe for everyone | Our legitimate interest in protecting users and the Service |
| Comply with legal obligations (e.g. responding to court orders) | We have to | Compliance with a legal obligation |
If you withdraw consent for marketing communications, we stop sending them. We continue to send you operational messages necessary for the Service.
6. Who can see your data
6.1 Other SPORTR users
SPORTR is a social platform. By design, certain information about you is visible to other users:
- Your first name and profile photo are visible to anyone you interact with
- Your sports, levels, match history, reliability score, and badges are visible to players whose events you join, and to members of communities you belong to
- Your messages are visible to other participants in the chat (event or community chat)
- Your ratings are aggregated into your reliability score, but individual ratings are anonymous to the rated player ; you cannot see who rated you
You control what is visible by choosing which events to join, which communities to belong to, and what information to put in your profile.
6.2 Service providers (subprocessors)
We use third-party service providers to run SPORTR. They process data on our behalf, under contracts that require them to protect it:
- Hosting: Amazon Web Services and/or Google Cloud, in EU regions (Frankfurt, Belgium, Ireland)
- Authentication: Google, Apple, and Meta, when you use sign-in with Google, Apple, or Facebook
- Email delivery: [TO BE CONFIRMED : typically a service such as Resend, Postmark, or SendGrid]
- Analytics: [TO BE CONFIRMED : privacy-respecting analytics will be selected before launch]
- Crash reporting and error monitoring: [TO BE CONFIRMED]
We will publish a complete and up-to-date subprocessor list at sportr.ch/legal/subprocessors before launch. We will notify users of material changes.
6.3 Legal requirements
We will share data with authorities if we are legally required to (for example, in response to a Swiss court order or a valid legal request from EU authorities). We will only share what is strictly necessary, and we will tell you about it unless we are legally prohibited from doing so.
6.4 We do not sell your data
We do not sell, rent, or trade your personal data. We do not allow advertisers to target you based on your SPORTR activity. We do not share your data with third parties for their own marketing purposes.
7. Where we store your data
Your data is stored on servers located in the European Union (Frankfurt, Belgium, or Ireland), operated by Amazon Web Services or Google Cloud.
Some of our subprocessors (for example, the providers of Apple, Google, and Facebook sign-in) may process limited data outside the EU and Switzerland. Where this happens, we rely on the safeguards required by GDPR Chapter V : typically Standard Contractual Clauses (SCCs) approved by the European Commission, and certifications under the EU-US Data Privacy Framework and the Swiss-US Data Privacy Framework.
8. How long we keep your data
We keep your data only as long as we need to:
- Account data: for as long as your account is active. If you delete your account, we delete or anonymise your data within 30 days, except where we are required to keep certain information for legal reasons (such as records of payments, where applicable).
- Event and match data: retained for as long as your account is active. After deletion, your name is removed and any data we are required to keep is anonymised.
- Messages: retained for as long as the relevant chat exists, or until you delete your account.
- Analytics and technical logs: retained for up to 12 months in identifiable form, then anonymised or deleted.
- Marketing consent records: retained for as long as we send you marketing, plus 3 years after withdrawal, to demonstrate compliance.
- Backups: our backups are retained for up to 30 days. Deleted data may persist in backups during that window before being permanently removed.
9. Your rights
You have the following rights over your personal data:
- Right of access : you can ask us what data we hold about you, and receive a copy.
- Right of rectification : you can correct inaccurate or incomplete data. Most fields are editable directly in the app.
- Right of erasure (“right to be forgotten”) : you can ask us to delete your data. You can also delete your account at any time from the app’s settings.
- Right to restrict processing : in certain cases, you can ask us to limit how we use your data.
- Right to data portability : you can ask for a copy of your data in a structured, machine-readable format.
- Right to object : you can object to processing based on our legitimate interest, including profiling.
- Right to withdraw consent : where we rely on your consent (for example, for marketing), you can withdraw it at any time. Withdrawal does not affect processing carried out before the withdrawal.
- Right not to be subject to automated decisions : we do not currently make decisions about you based solely on automated processing that produce legal or similarly significant effects on you.
To exercise any of these rights, write to us at privacy@sportr.ch. We will respond within 30 days. If we cannot fulfil your request (for example, because of a legal obligation to retain certain data), we will explain why.
You also have the right to lodge a complaint with a supervisory authority:
- In Switzerland: the Federal Data Protection and Information Commissioner (FDPIC / PFPDT) : edoeb.admin.ch
- In the EU: the data protection authority of your country of residence
10. Children
SPORTR is not for children under the age of 16. We do not knowingly collect data from anyone under 16. If you become aware that a child under 16 has created an account, please contact us at privacy@sportr.ch and we will remove the account and the associated data.
11. Security
We protect your data with technical and organisational measures appropriate to the risk:
- Encryption of data in transit (TLS) and at rest
- Restricted access : only employees and contractors who need access to do their job have it
- Regular security reviews and updates
- Hosting with providers that meet recognised security standards (ISO 27001, SOC 2)
No system is perfectly secure. If a data breach affects you, we will notify you and the relevant authority as required by law (within 72 hours where GDPR applies).
12. EU representative
In accordance with GDPR Article 27, an EU representative will be appointed prior to processing the personal data of EU users at scale. Details of the EU representative will be added to this policy at that time. In the meantime, EU users can contact us directly at privacy@sportr.ch.
13. Changes to this policy
We may update this policy from time to time. When we make material changes, we will:
- Update the “Last updated” date at the top of this policy
- Notify you in the app and/or by email at least 30 days before the changes take effect
If you continue to use the Service after the changes take effect, you accept the updated policy. If you do not agree, you can stop using the Service and delete your account.
14. Contact
For any question about this policy, your data, or your rights:
Email: privacy@sportr.ch
Postal address:
SPORTR
Route des Jeunes 35
1227 Carouge
Switzerland
This policy is available in English. A French version is also available. In case of inconsistency between language versions, the French version will prevail for users resident in Switzerland.