Courtesy translation: in case of any discrepancy, the Italian version prevails. Italian version
1. Data controller
The Data Controller is Luigi Zotti, VAT number 08776391214 (hereinafter, the "Controller"). Privacy contact: youcan@connectyourlife.it — general contact: youcan@connectyourlife.it.
2. Categories of data processed
2.1 Data provided by the user
- Account data: first name, last name, username, email address, password (stored exclusively as a non-reversible cryptographic hash — argon2).
- Sports registration data: date of birth and gender — used exclusively for the automatic validation of age categories (e.g. Under/Over tournaments) and team composition constraints ("female quota") required by tournament regulations.
- Sports profile: preferred role, height, city/playing area, teams, profile picture (optional).
- User-generated content: tournaments created, registrations, match results and scores, invitations sent, messages to support.
- Subscription and billing data (facility managers only): subscription status, chosen plan, activation/renewal/cancellation dates and customer identifiers generated by the payment provider (Stripe). Full payment card details are never stored nor do they transit through the Controller's systems: they are processed exclusively by Stripe on its own secure pages (PCI-DSS certified).
- Management software data (facility managers only): payment details entered by the manager (IBAN and account holder, PayPal link) and, if configured, their Stripe account key, stored exclusively in encrypted form (AES-256-GCM) and removable at any time; API keys for external systems (stored only as a hash fingerprint, never in plain text).
- Managers' customer data: bookings registered in the management software may contain the name, phone number, email and payment amounts of the manager's customers. For this data, the manager is the data controller and the Service Controller acts as a processor under art. 28 GDPR: they store and protect it on behalf of the manager, do not use it for their own purposes and delete it according to the manager's instructions (or upon closure of their account). Data subjects can exercise their rights by contacting the manager with whom they booked.
2.2 Automatically collected data
- Location (optional, subject to consent): used to show nearby tournaments, players and courts. In any public display, the location is shown only in an approximate form (~1 km); precise coordinates are never visible to other users.
- Technical identifiers: device tokens for push notifications (Firebase Cloud Messaging), IP address and technical logs necessary for security, abuse prevention and the defense of the Controller's rights.
- Consent log: type, version, date/time and IP address at the time consent was given.
3. Purposes and legal bases
| Purpose | Legal basis (art. 6 GDPR) |
|---|---|
| Account creation and management; provision of features (tournaments, teams, live scoring, standings) | Performance of a contract (point b) |
| Automatic validation of age categories and female quota via date of birth and gender | Performance of a contract (point b) |
| Push notifications related to user activity (invitations, results to confirm, confirmations) | Performance of a contract (point b); can be deactivated at any time in the settings |
| Transactional emails (welcome, invitations, credentials) | Performance of a contract (point b) |
| Geolocation to search for nearby tournaments/courts | Consent (point a), revocable at any time from the device settings |
| Security, fraud and abuse prevention (rate limiting, audit logs, anti-cheat on registration data) | Legitimate interest (point f) |
| "Court manager" subscription management: payment, automatic renewal, receipts, cancellation | Performance of a contract (point b); retention of accounting documents for legal obligation (point c) |
| Provision of management software to managers (booking calendar, price list, reports, payment details, API keys) | Performance of a contract (point b); for managers' customer data, the Controller acts as a processor under art. 28 on the manager's instructions |
| Compliance with legal obligations | Legal obligation (point c) |
| Promotional communications (only if opted in) | Consent (point a), revocable at any time |
The provision of data marked as mandatory during registration is necessary for the provision of the Service; failure to provide it prevents account creation. The provision of optional data (photo, location, height, etc.) is voluntary and its absence does not affect basic functionality.
4. Recipients and processors of data
Data is not sold or transferred to third parties for commercial purposes. Only information necessary for the sporting operation of the Service is visible to other users (e.g. name and sports profile in a team roster, in the results and standings of a public tournament). Data may be processed, on behalf of the Controller and as processors under art. 28 GDPR, by:
- Hosting provider of the application server and database (datacentre in the European Union);
- Brevo (Sendinblue SAS, France) — sending transactional emails;
- Google Ireland Ltd. / Google LLC (Firebase Cloud Messaging) — delivery of push notifications;
- Apple Inc. (APNs) — delivery of push notifications on iOS;
- Stripe Payments Europe Ltd. (Ireland) — payment processing and subscription management for facility managers (cards, Apple Pay, Google Pay), as an independent controller for payment data and a processor for billing data processed on behalf of the Controller.
The updated list of processors is available upon request by writing to youcan@connectyourlife.it.
5. Transfers outside the EU
The Service is hosted in the European Union. Some providers (Google/Firebase, Apple, Stripe) may involve data transfers to third countries, in particular the United States: such transfers take place on the basis of Standard Contractual Clauses approved by the European Commission and/or the EU-US Data Privacy Framework, with applicable supplementary safeguards.
6. Retention period
- Account and profile data: for the entire duration of the account.
- Upon account deletion: personal data is deleted or anonymised within 30 days; tournament sports results remain in anonymised form to preserve the integrity of standings and historical records.
- Technical and security logs: maximum 12 months, unless required for investigating offences.
- Consent and audit log: for the time necessary to demonstrate compliance with legal obligations.
- Subscription billing data: 10 years from the accounting entry, in accordance with art. 2220 of the Italian Civil Code and tax regulations.
- Management software data and bookings of managers' customers: for the entire duration of the manager's account, or until deleted by them; payment details and keys removed immediately upon request from the settings.
7. Rights of the data subject
Under Articles 15-22 of the GDPR, you have the right to obtain: access to your data, rectification, erasure ("right to be forgotten"), restriction of processing, portability in a structured and readable format, objection to processing based on legitimate interest, and withdrawal of consent given (without affecting the lawfulness of previous processing).
You can exercise your rights independently directly from the app: Profile → Privacy → "Download my data" (complete export in JSON format) and "Delete account" (deletion with anonymisation). The deletion procedure is described step-by-step on the dedicated page Account deletion. Alternatively, write to youcan@connectyourlife.it: we will respond within 30 days.
You also have the right to lodge a complaint with the Garante per la protezione dei dati personali (www.garanteprivacy.it) or the supervisory authority of your Member State of residence.
8. Minors
The Service is restricted to individuals who are at least 16 years old. For users aged between 14 and 16, registration is subject to the consent of the person exercising parental responsibility, with limited features (specifically: no location sharing and no contact from unknown users). If you believe a minor has provided personal data without the necessary authorization, please contact us and we will remove it.
9. Security measures
- Encryption of traffic (HTTPS/TLS) on all communications;
- passwords stored exclusively as argon2 hashes; two-factor authentication for administrative access;
- database not publicly exposed, access restricted and logged (immutable audit log);
- rate limiting of requests and anti-abuse checks;
- blurred public location (~1 km) and precise coordinates never exposed to other users.
10. Cookies and tracking tools
The website uses exclusively technical cookies and storage; the app does not use cookies but only technical local storage necessary for its operation. For full details and preference management, please consult the Cookie policy.
11. Changes to the policy
Any material changes will be communicated via the app or by email before they take effect, indicating the new version and date. Previous versions are available upon request.