Legal

PRIVACY POLICY

Effective: February 16, 2026

Last Updated: February 16, 2026

Version 1.0

1.Identity & Contact of the Data Controller

Data Controller: Olvexis Group

Trading as: MatchSport

Email: support@matchsport.org

Website: www.matchsport.org

Data Protection Officer (DPO): support@matchsport.org

In compliance with Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD), MatchSport informs users about its policy regarding the processing and protection of personal data.

2.Introduction and Scope

MatchSport is a mobile dating application that connects users through shared sports interests. This Policy explains how we collect, use, store, share, and protect your personal information when you use our app (iOS and Android) and related services. It applies to all users registered on MatchSport, visitors to our website, and users globally — with primary operations in Spain (Madrid + 50 km radius).

3.Legal Basis for Processing

Legal BasisProcessing Activities
Consent (Art. 6.1.a)Profile, photos, sports, location, optional verification, premium features.
Contract (Art. 6.1.b)Registration, account, matching, chat, subscriptions.
Legal Obligation (Art. 6.1.c)Tax, legal requests, ToS enforcement.
Legitimate Interest (Art. 6.1.f)Security, fraud prevention, analytics, support.

4.Categories of Personal Data Collected

4.1 Registration & Profile

Full name, email, date of birth, encrypted password, gender, biography (up to 150 chars), profile photos, 3–5 favorite sports from 18+ activities, location (city, region, GPS for proximity within 50 km).

4.2 Authentication & Security

Firebase Authentication credentials, Google/Apple Sign-In data, device info (type, OS, identifiers for push), security logs (IPs, timestamps, failed logins), optional Veriff photo-ID data, OTP via email/SMS.

4.3 Usage & Interaction

Swipe activity (likes, passes, super likes), match history and timestamps, real-time chat messages (Firestore), screen views, feature usage, session duration.

4.4 Payment & Subscription

Premium status ($9.99/mo), Stripe-processed payments (we do NOT store card numbers), transaction history.

4.5 Safety & Reporting

User reports, blocked users, investigation evidence (screenshots, logs).

4.6 Technical & Analytics

Firebase Analytics metrics, Google Maps usage, FCM push tokens.

5.Purpose of Data Processing

5.1 Core Service Delivery

Account creation and authentication, profile display under matching criteria (gender, ±5 years, 50 km, shared sport), matching algorithm, real-time chat, push notifications.

5.2 Premium Features

Stripe payment processing, premium benefits (unlimited likes, super likes, who liked you, filters, ad-free, priority), subscription management.

5.3 Safety & Security

Age verification, investigation of reports, enforcement of guidelines, fraud and bot prevention, automatic blocking.

5.4 Service Improvement

Behavior analytics, performance monitoring, A/B testing, anonymized aggregate statistics.

5.5 Legal Compliance

Responding to legal requests, tax records, dispute resolution, ToS enforcement.

6.Data Retention Period

Data CategoryRetentionJustification
Account dataAccount life + 30 daysRecovery grace period
Profile photosAccount life + 30 daysDeleted from Firebase Storage
Chat messagesAccount life + 30 daysService functionality
Match historyAccount life + 30 daysService functionality
Payment records10 yearsSpanish tax law
Safety reports3 yearsInvestigation & defense
Analytics26 monthsGDPR Art. 5.1.e
Security logs12 monthsFraud prevention

When you delete your account, all personal data is permanently removed within 30 days, except payment records (legal compliance) and anonymized analytics.

7.Data Recipients & Third-Party Processors

All processors are bound by Data Processing Agreements compliant with GDPR Article 28.

ProviderPurposeData Shared
Firebase (Google)Auth, DB, storage, pushEmail, name, photos, messages, tokens
StripePaymentsEmail, subscription, transactions (no card data)
Google Maps APILocation servicesCity, coordinates
Veriff (optional)Photo ID verificationSelfie, government ID
Twilio / Firebase AuthSMS OTPPhone number

Firebase data is stored in the europe-west1 region (Belgium, EU). Stripe transfers to US servers occur under EU Standard Contractual Clauses. MatchSport does NOT sell, rent, or trade your personal data.

8.Your Rights Under GDPR & LOPDGDD

8.1 Right of Access (Art. 15)

Request a copy of your data, processing purposes, recipients, retention, and source. Email: support@matchsport.org — subject "Data Access Request".

8.2 Right to Rectification (Art. 16)

Update inaccurate data via Settings → Edit Profile or by email.

8.3 Right to Erasure (Art. 17)

Delete your data when no longer needed, on consent withdrawal, on objection, or for unlawful processing. Settings → Delete Account, or email subject "Account Deletion Request". Exceptions: payment records (10 years) and anonymized analytics.

8.4 Right to Restriction (Art. 18)

Request temporary suspension while accuracy is contested or claims are pending.

8.5 Right to Data Portability (Art. 20)

Receive your data in JSON or CSV format. Includes profile, sports, match history, messages. Response within 30 days.

8.6 Right to Object (Art. 21)

Disable marketing in Settings → Notifications, or object via email.

8.7 Right Re: Automated Decision-Making (Art. 22)

You can request human review of matching decisions. The algorithm uses gender preference, ±5 years, 50 km, and shared sport — no credit scoring or discriminatory profiling.

8.8 Right to Withdraw Consent (Art. 7)

Disable location and notifications anytime in Settings or device permissions.

8.9 Right to Lodge a Complaint

Spanish Data Protection Authority (AEPD) — Calle Jorge Juan, 6, 28001 Madrid · +34 901 100 099 · www.aepd.es · consultas@aepd.es

9.Data Security Measures

9.1 Technical

TLS 1.3 encryption, bcrypt password hashing, Firebase Storage access control, Stripe PCI-DSS Level 1, encrypted FCM tokens, AI photo verification, mandatory OTP, AI spam detection.

9.2 Organizational

Strict access control, GDPR-compliant DPAs, quarterly audits, 72-hour breach notification (Art. 33), regular GDPR training, privacy by design.

9.3 User Responsibilities

Use strong unique passwords, enable 2FA when available, report suspicious behavior, never share credentials, log out on shared devices.

10.Cookies and Tracking

The mobile app does NOT use cookies. We use Firebase Auth tokens (1h sessions), anonymized Firebase Analytics, and FCM for push delivery. No third-party advertising networks or tracking pixels. Premium users are ad-free.

11.Data Protection Impact Assessment (DPIA)

High-risk activities identified: real-time GPS within 50 km, automated profiling for matching, private messaging.

Mitigations: explicit consent for location, city-only display (exact coords hidden), no sensitive categories in matching, encrypted chat, automated moderation with human review, photo verification AI (95% fake-profile reduction), anti-spam Cloud Functions, automatic deletion of rejected profiles after 30 days.

12.Age Verification & Child Protection

MatchSport is exclusively for users 18+. Date of birth is required and automatically verified during registration. Optional photo-ID verification is available. Suspected underage accounts are immediately suspended and permanently deleted if confirmed. Report at support@matchsport.org.

13.International Data Transfers

Primary storage: Firebase europe-west1 (Belgium, EU). Stripe payment data may be transferred to the US under EU Standard Contractual Clauses (SCCs) and PCI-DSS Level 1. Apple/Google Sign-In tokens may be processed in the US under their GDPR commitments.

14.Changes to this Privacy Policy

Material changes are notified in-app and via email with 30 days' notice; you may delete your account if you disagree. Non-material updates appear in-app without separate notification.

15.Contact & Data Protection Officer

General inquiries and DPO: support@matchsport.org — subject [Data Subject Request] or [Privacy Question]. Response within 30 days (extendable to 60 for complex requests, GDPR Art. 12).

16.Specific Provisions for Spanish Users (LOPDGDD)

Right to digital disconnection, right to privacy in digital devices, right to rectification online. Biometric data is processed only for optional verification with explicit consent and deleted immediately after — never used for matching or profiling. Sports preferences are NOT considered sensitive data.

17.Legal Compliance Summary

  • Regulation (EU) 2016/679 (GDPR)
  • Organic Law 3/2018 (LOPDGDD - Spain)
  • Directive 2002/58/EC (ePrivacy)
  • Royal Decree 1720/2007
  • Spanish Code of Commerce — Art. 30 (payment retention)

Supervisory Authority: Agencia Española de Protección de Datos (AEPD) — www.aepd.es

18.Consent and Acknowledgment

By creating a MatchSport account, you acknowledge you have read and understood this Policy, consent to the processing described, are at least 18, understand your GDPR/LOPDGDD rights, and may withdraw consent or delete your account anytime.

End of Privacy Policy — Version 1.0