Spolumo brings people together to play sports. For that to work, others need to know something about you: your name, city, sports, and which activities you join. We try to keep it to what is necessary and to leave the decisions to you. Privacy is a feature of Spolumo, not an afterthought: routes are private by default, we do not read your messages, we have no advertising cookies, and we do not sell your data.
1. Who the controller is and how to contact us
[GDPR-1.1] The controller of your personal data is [[JMÉNO_PROVOZOVATELE]], company ID (IČO) [[IČO]], [[ADRESA_SÍDLA]] ("we"). Privacy contact: [[EMAIL_SOUKROMÍ]], or by post to the registered address.
[GDPR-1.2] We have not appointed a data protection officer because the law does not require it (Art. 37 GDPR). All requests are handled directly by the operator.
[GDPR-1.3] If the operation of Spolumo is transferred to a company (for example an s.r.o., a Czech limited liability company), that company becomes the controller. We will inform you in advance.
2. What data we process, why, and on what legal basis
| # | Data | Purpose | Legal basis (Art. 6 GDPR) | Who can see it |
|---|---|---|---|---|
| 2.1 | Account: email, Google or Apple account identifier, registration date, 18+ declaration | sign-in, account communication | performance of a contract (b) | only us |
| 2.2 | Profile: name or nickname, photo, city, sports, level, pace, when you play, short bio, language | finding buddies and activities | performance of a contract (b) | publicly, other users |
| 2.3 | Activities and participation: activities, events and groups you create, sign-ups, waiting list, "Going now", follows, invitations, badges, challenges | running the community | performance of a contract (b) | participants and organizers; the list of participants according to the event settings |
| 2.4 | Messages: private messages, messages in groups and discussions | making arrangements | performance of a contract (b) | private messages and messages about listings and bookings are visible only to the participants of the conversation; the admin has no access to them unless one of the participants reports the conversation (2.11). Messages in public channels and activity discussions are public. |
| 2.5 | Reviews: stars and text after an activity or booking | trust in the community | performance of a contract (b) | publicly |
| 2.6 | Location: city from your profile; precise device location only when you turn it on yourself (map "near me", "Going now", check-in, route recording) | showing what is nearby and recording a route | performance of a contract (b); you grant location access in your device | we do not store precise location, except for a route you record and save yourself (2.7). In the mobile app, route recording continues with the screen off, but only from the moment you start it until the moment you stop it; outside a recording we do not track your location in the background. |
| 2.7 | Journal and routes: sport, date, distance, time, route from GPX, TCX, a recording or drawn by hand | your sports journal | performance of a contract (b) | by default only you; a shared route is saved by the server without all points within 200 m of the start and of the finish (privacy zone), so they are also missing from the GPX export and from the map shown to others |
| 2.8 | Weight (optional) | estimating calories burned and hydration | explicit consent (Art. 9(2)(a) GDPR), see 2.8a | only you; never in your profile, never in an AI request |
| 2.9 | Marketplace: listings, photos, price offers, bookings, handover and return status; for traders their name or company, company ID, address, phone, email; for coaches proof of qualifications | buying, renting, lessons; information about the trader | performance of a contract (b); for traders a legal obligation (c) under Section 11b of the Czech Consumer Protection Act | listings publicly; bookings only the parties; the trader's contact details next to their offer |
| 2.10 | Paid services: plan, period, billing details, payment status, Stripe identifiers | providing the service, accounting and taxes | performance of a contract (b); legal obligation (c) | only us and Stripe; we do not see your card number |
| 2.11 | Reports and moderation: who reported what, a copy of the reported content, the decision, the statement of reasons, appeals | safety, obligations under the DSA | legal obligation (c); legitimate interest in the safety of the community (f) | only us; we do not disclose the reporter to the reported person. If a participant reports a private conversation, booking or offer, the admin may open it for no more than 72 hours; every opening is written to the intervention log (section 6) together with a reference to the report. Otherwise the admin has no access to private messages. |
| 2.12 | Enquiries from organizations (leads), venue claims: name, email, phone, organization | replying to the enquiry | steps prior to entering into a contract (b); legitimate interest (f) | only us |
| 2.13 | Technical data: IP address, device and browser type, error reports, sign-in times | security, abuse prevention, bug fixing | legitimate interest (f) | only us and our processors (section 4) |
| 2.13a | Acceptance of the terms: time, version of the terms and of this policy, language and browser type at registration | proving that the contract was concluded | performance of a contract (b); legitimate interest (f) | only us |
| 2.14 | Notifications: push notification token, notification settings | reminders about events and messages | performance of a contract (b); permission in your device | only us |
| 2.15 | AI requests: the text you enter into an AI feature and the context of the event | a text suggestion or an answer | performance of a contract (b) at your request | us and Anthropic as a processor |
| 2.16 | Usage statistics without cookies, aggregated | improving Spolumo | legitimate interest (f) | only us |
| 2.17 | Email newsletter | news about Spolumo and events in your city | consent (a); for customers legitimate interest under Section 7(3) of Czech Act No. 480/2004 Coll. | only us |
[GDPR-2.8a]Weight. Your weight is optional. We use it only for calculations in your device and in your private account settings. You give consent by ticking the box when entering it and you can withdraw it at any time by deleting the value. Without signing in, the value stays only in your browser.
[GDPR-2.18]Legitimate interest. Where we rely on legitimate interest, we have assessed that your rights do not override it: the purpose is the security of the service and improvements without profiling for advertising. You can object to such processing (section 7).
[GDPR-2.19]What we do not process. We do not build advertising profiles, we do not sell data, we do not collect health data (except the optional weight under 2.8) and we do not scan your contacts. We track the device location only during a route recording that you start and stop yourself (2.6); outside of it we neither track nor store precise location in the background.
[GDPR-2.20]Automated decision-making. We do not make automated decisions about you with legal effects (Art. 22 GDPR). Activity recommendations and the ranking of offers are automatic according to the rules in the Terms of Service (section 12). Anti-spam filters may temporarily limit how many messages new accounts can send; a human always decides on blocking an account.
[GDPR-2.21]Age. Spolumo is intended for people over 18. If we find out that an account belongs to a younger person, we will close the account and delete the data.
3. Where we get the data
Most of the data is entered by you. From your Google or Apple account we receive only your email, name and identifier (with Apple you can hide your email). Other users may also add something about you: a review, a mention in a message, a photo from an event or a report. From Stripe we receive information about the payment status.
4. Who we share data with
[GDPR-4.1]Other users see your profile, public activities, reviews and shared journal entries according to your settings.
[GDPR-4.2]Processors who work for us under a data processing agreement (Art. 28 GDPR):
| Processor | What they do | Where the data is | Transfer outside the EU and safeguard |
|---|---|---|---|
| Supabase (Supabase Pte. Ltd., Singapore) | database, sign-in, photo storage, realtime, server functions | EU, Frankfurt | remote support access from outside the EU: standard contractual clauses (SCC) in the Supabase DPA |
| Cloudflare (Cloudflare, Inc., USA) | web hosting, DNS, protection against attacks, map tiles (R2) | global network, R2 region EU | EU–US Data Privacy Framework (DPF) and SCC |
| Resend [OVĚŘIT entitu] | sending emails (confirmations, reminders) | [OVĚŘIT region] | DPF or SCC |
| Sentry (Functional Software, Inc., USA) | error reporting without IP addresses or personal data | EU region | DPF and SCC |
| Anthropic [OVĚŘIT entitu pro API] | the Claude AI model for AI features (2.15), only at your request | USA | SCC under the Anthropic DPA; API data is not used for training |
| Google (Firebase Cloud Messaging) | delivering push notifications to Android | globally | DPF and SCC |
| Apple (Apple Push Notification service) | delivering push notifications to iOS | globally | DPF and SCC |
[GDPR-4.2a]Fonts and libraries are loaded from our own domain spolumo.cz, not from Google Fonts or public CDNs, so your IP address is not sent to any third party when the app loads, other than the processors above.
[GDPR-4.3]Independent controllers who process data under their own policies:
- Stripe (Stripe Payments Europe, Ltd., Ireland): card payments, identity verification of providers (KYC), fraud prevention. Stripe privacy policy.
- Google and Apple: sign-in with a Google or Apple account, the Google Play and App Store stores (payments, downloads).
- Organizers, rental shops and coaches: the data you give them when signing up or booking is processed by them as independent controllers for their own purposes (for example customer records).
[GDPR-4.4]Authorities. Where required by law, we disclose data to courts, the police and other public authorities, and only to the extent necessary.
5. How long we keep the data
| Data | Period |
|---|---|
| Account, profile, journal, routes, photos | until you delete the account or the item; an account nobody signs in to for 24 months is deleted, and we warn you 30 days in advance by email to the account address |
| Public messages in channels and discussions | after 90 days we move them from the app to an archive (they are no longer visible) and delete them from the archive after another 12 months; when the account is deleted they lose your name |
| Private messages, messages about listings and bookings | until the account is deleted; the other party keeps the conversation labelled "Deleted user" until they delete it or delete their own account |
| Reviews you wrote | after the account is deleted they remain anonymized ("Deleted user") |
| Past activities, events and sign-ups | 24 months after the date; then we delete the sign-ups and remove the organizer, description and payment details from the activity (only an anonymous record for statistics remains) |
| Reports, moderation and the admin intervention log | 12 months from the report or intervention; in case of an appeal or dispute until it is resolved |
| Invoices and accounting and tax records | for the period set by tax and accounting law (up to 10 years) |
| Enquiries from organizations (leads) | 24 months from the last contact |
| Error reports (Sentry), if we enable it | no more than 90 days |
| Technical logs (sign-ins, requests, security) | no more than 30 days (7 days at the database provider) |
| Database backups | no more than 30 days; deleted data survives in them for this period |
| Record of acceptance of the terms | for the lifetime of the account; after deletion without any link to you |
| Newsletter consent | until withdrawn |
6. How we protect the data
Encrypted connection (HTTPS), data access only according to row-level rules in the database (RLS), password-less sign-in (one-time code, Google, Apple), minimal admin access (to private messages and bookings only after a report, temporarily and with a log), an admin intervention log (audit log), route privacy zones enforced on the server, removal of metadata (EXIF including GPS) from photos, regular backups and restore tests. In the event of a security breach that puts you at risk, we will inform you (Art. 34 GDPR) and the Czech Office for Personal Data Protection within 72 hours (Art. 33 GDPR).
7. Your rights
You have the right:
- of access to your data and to a copy of it (Art. 15 GDPR),
- to rectification (Art. 16); you can edit most data yourself in your profile,
- to erasure (Art. 17): More › Account › Delete account,
- to restriction of processing (Art. 18),
- to data portability (Art. 20): More › Account › Download my data (a JSON file, journal also as GPX),
- to object to processing based on legitimate interest (Art. 21) and at any time to direct marketing,
- to withdraw consent (weight, newsletter) without affecting processing carried out before the withdrawal,
- to lodge a complaint with the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, uoou.gov.cz, or with the supervisory authority of your EU country.
We handle requests within 1 month (Art. 12(3) GDPR). If we cannot verify that the request comes from you, we will ask for confirmation from the account email.
8. Account deletion
[GDPR-8.1] After you tap Delete account and confirm:
- we immediately hide your profile and sign you out on all devices,
- within 30 days we delete your profile, journal, routes, photos, listings, sign-ups, follows, settings and push tokens,
- we anonymize your messages to other parties, your reviews and past activities you organized ("Deleted user"); we do not delete other people's content (their messages to you, reviews, photos),
- we keep only what the law requires us to keep (invoices, data about an ongoing dispute or moderation),
- deleted data survives in backups according to section 5.
[GDPR-8.2] If you have an active subscription through the App Store or Google Play, cancel it there. Deleting the account does not stop the store payment.
9. Changes to this policy
We update this policy when the processing changes (a new feature, a new processor). We will inform you of any substantial change by email or in the app in advance. Previous versions are available at spolumo.cz/soukromi/archiv.