Courtesy translation: in case of any discrepancy, the Italian version prevails. Italian version
1. Data Controller
The Data Controller is Luigi Zotti, VAT number 08776391214 (hereinafter, the "Controller"). Privacy contact: youcan@connectyourlife.it — general contact: youcan@connectyourlife.it.
2. Categories of data processed
2.1 Data provided by the user
- Account data: first name, last name, username, email address, password (stored exclusively as a non-reversible cryptographic hash — argon2).
- Sports registration data: date of birth and gender — used exclusively for the automatic validation of age categories (e.g. Under/Over tournaments) and team composition constraints ("gender quota") required by tournament regulations.
- Sports profile: preferred role, height, city/playing area, teams, profile picture (optional).
- Generated content: tournaments created, registrations, match results and scores, invitations sent, messages to support.
- Declared origin (optional): the answer to the question about how you heard about VolleyFriends (for example: a friend, social media, a Google search, a tournament). This is a question that can be skipped and the answer is not visible to other users.
- Subscription and billing data (facility managers only): subscription status, chosen plan, activation/renewal/cancellation dates and customer identifiers generated by the payment provider (Stripe). Full payment card details are never stored nor do they transit through the Controller's systems: they are processed exclusively by Stripe on its own secure pages (PCI-DSS certified).
- Management software data (facility managers only): payment details entered by the manager (IBAN and account holder, PayPal link) and, if configured, their Stripe account key, stored exclusively in encrypted form (AES-256-GCM) and removable at any time; API keys for external systems (stored only as a hash fingerprint, never in plain text).
- Managers' customer data: bookings recorded in the management software may contain the name, phone number, email and amounts of the manager's customers. For this data, the manager is the data controller and the Service Controller acts as a processor under Article 28 GDPR: storing and protecting it on behalf of the manager, not using it for their own purposes, and deleting it according to their instructions (or upon closure of their account). Data subjects can exercise their rights by contacting the manager with whom they booked.
2.2 Automatically collected data
- Location (optional, subject to consent): used to show nearby tournaments, players and courts. In any public display, the location is shown only in an approximate form (~1 km); precise coordinates are never visible to other users.
- Technical identifiers: device tokens for push notifications (Firebase Cloud Messaging), IP address and technical logs necessary for security, abuse prevention and the defence of the Controller's rights.
- Consent log: type, version, date/time and IP address at the time consent was given.
- Origin and campaign data: campaign parameters present in the landing address (
utm_source,utm_medium,utm_campaign,utm_content,utm_term), advertising click identifiers (gclid,fbclid), referring site, landing page path, registration platform (iOS, Android, web) and, on Android devices only, the installation string provided by Google Play. Parameters that require storage on the device to be kept between pages are collected only subject to consent to the "statistics" category of the cookie banner: without that consent, only the origin of the single page from which the registration or request was sent remains. The query string of the landing page is not stored: only the path.
3. Purposes and legal bases
| Purpose | Legal basis (Article 6 GDPR) |
|---|---|
| Account creation and management; provision of features (tournaments, teams, live scoring, standings) | Performance of a contract (point b) |
| Automatic validation of age categories and gender quotas via date of birth and gender | Performance of a contract (point b) |
| Push notifications related to your activity (invitations, results to confirm, confirmations) | Performance of a contract (point b); can be deactivated at any time from the settings |
| Transactional emails (welcome, invitations, credentials) | Performance of a contract (point b) |
| Geolocation for finding nearby tournaments/courts | Consent (point a), revocable at any time from the device settings |
| Security, fraud and abuse prevention (rate limiting, audit log, anti-cheat on personal data) | Legitimate interest (point f) |
| "Court manager" subscription management: payment, automatic renewal, receipts, cancellation | Performance of a contract (point b); retention of accounting documents for legal obligation (point c) |
| Provision of management software to managers (booking calendar, price list, reports, payment details, API keys) | Performance of a contract (point b); for managers' customer data, the Controller acts as a processor under Article 28 on the instruction of the manager |
| Compliance with legal obligations | Legal obligation (point c) |
| Measuring the effectiveness of communication channels through the user's declared origin (optional data) | Legitimate interest (point f) |
| Campaign attribution (UTM parameters, referring site, installation string) | Consent (point a) for the part requiring storage on the device, revocable from cookie preferences; legitimate interest (point f) for parameters already present in the request |
| Promotional communications (only if activated) | Consent (point a), revocable at any time |
Providing the data marked as mandatory during registration is necessary for the provision of the Service; failure to provide it prevents account creation. Providing optional data (photo, location, height, etc.) is voluntary and its absence does not affect the basic features.
4. Recipients and data processors
Data is not sold or transferred to third parties for commercial purposes. Only the information necessary for the sporting operation of the Service is visible to other users (e.g. name and sports profile in a team roster, in the results and standings of a public tournament). Data may be processed, on behalf of the Controller and as processors under Article 28 GDPR, by:
- Hosting provider of the application server and database (datacentre in the European Union);
- Brevo (Sendinblue SAS, France) — sending transactional emails;
- Google Ireland Ltd. / Google LLC (Firebase Cloud Messaging) — delivery of push notifications;
- Google Ireland Ltd. / Google LLC (Google Tag Manager) — management of website measurement tools; data collected by any activated tools is processed only subject to consent, as described in the Cookie policy;
- Apple Inc. (APNs) — delivery of push notifications on iOS;
- Stripe Payments Europe Ltd. (Ireland) — payment processing and subscription management for facility managers (cards, Apple Pay, Google Pay), as an independent controller for payment data and a processor for billing data processed on behalf of the Controller.
The updated list of processors is available upon request by writing to youcan@connectyourlife.it.
5. Transfers outside the EU
The Service is hosted in the European Union. Some providers (Google/Firebase, Apple, Stripe) may involve data transfers to third countries, in particular the United States: such transfers take place on the basis of the Standard Contractual Clauses approved by the European Commission and/or the EU-US Data Privacy Framework, with the applicable supplementary safeguards.
6. Retention period
- Account and profile data: for the entire duration of the account.
- Upon account deletion: personal data is deleted or anonymised within 30 days; tournament sports results remain in anonymised form to preserve the integrity of standings and historical records.
- Technical and security logs: maximum 12 months, unless required for the investigation of offences.
- Origin and campaign data: 24 months from registration. After this period, specific data (click identifiers, referring site, landing path, installation string) is automatically deleted and only channel and campaign information remains, which does not allow identification of an individual. The origin declared by the user is retained for the duration of the account.
- Consent and audit log: for the time necessary to demonstrate compliance with legal obligations.
- Subscription billing data: 10 years from the accounting entry, pursuant to Article 2220 of the Italian Civil Code and tax regulations.
- Management software data and bookings of managers' customers: for the entire duration of the manager's account, or until deleted by them; payment details and keys removed immediately upon request from the settings.
7. Rights of the data subject
Pursuant to Articles 15-22 GDPR, you have the right to obtain: access to your data, rectification, erasure ("right to be forgotten"), restriction of processing, portability in a structured and readable format, objection to processing based on legitimate interest, and withdrawal of consent given (without affecting the lawfulness of previous processing).
You can exercise your rights independently directly from the app: Profile → Privacy → "Download my data" (complete export in JSON format) and "Delete account" (deletion with anonymisation). The deletion procedure is described step-by-step on the dedicated page Account deletion. Alternatively, write to youcan@connectyourlife.it: we will reply within 30 days.
Hai inoltre diritto di proporre reclamo al Garante per la protezione dei dati personali (www.garanteprivacy.it) o all'autorità di controllo dello Stato membro di residenza.
8. Minors
The Service is reserved for those who are at least 16 years old. For users aged between 14 and 16, registration is subject to the consent of the person exercising parental responsibility, with limited features (in particular: no location sharing and no contact from unknown users). If you believe that a minor has provided personal data without the necessary authorisations, please contact us and we will remove it.
9. Security measures
- Encryption of traffic (HTTPS/TLS) on all communications;
- passwords stored exclusively as argon2 hashes; two-factor authentication for administrative access;
- database not publicly exposed, access restricted and logged (immutable audit log);
- rate limiting of requests and anti-abuse controls;
- blurred public location (~1 km) and precise coordinates never exposed to other users.
10. Cookies and tracking tools
The website uses exclusively technical cookies and storage; the app does not use cookies but only technical local storage necessary for its operation. For full details and preference management, please consult the Cookie policy.
11. Changes to the privacy policy
Any material changes will be communicated via the app or by email before they take effect, indicating the new version and date. Previous versions are available upon request.