[ PRIVACY ]

Privacy Policy

Effective from 18 June 2026 · GDPR art. 13

This English version is a translation. In case of any conflict, the Finnish version prevails. See the Finnish version.

1. Data controller

Playtonite Oy
Business ID: 3635959-2
Address: Liekokuja 8, 01150 Söderkulla
Email: support@playtonite.app

2. Personal data processed

  • Account data: email, display name, profile picture (if provided).
  • Player profile: preferred sports, skill level, search radius, location (city).
  • Booking data: booked shifts, times, prices.
  • Payment data: the Service does not currently process payments or card data; shift payments are handled directly with the team outside the Service.
  • Team data: team name, home venue, contact person, billing details.
  • Technical data: IP address, browser type, log data required for the service to function.

3. Purposes and legal bases of processing

  • Contract: Facilitating bookings between a team and a player (GDPR art. 6(1)(b)).
  • Legitimate interest: Service development, fraud prevention, statistics (art. 6(1)(f)).
  • Legal obligation: Accounting, taxation (art. 6(1)(c)).
  • Consent: Email marketing, cookies (art. 6(1)(a)), which you can withdraw at any time.

4. Recipients and third-party services

  • Supabase (EU): database and authentication.
  • Stripe (Ireland / United States): payment processing, not currently in use. If payment processing is introduced later, Stripe will be an independent controller for payment data.
  • Google Maps: displaying maps and address search.
  • Cloudflare: SSR and content delivery.

Any transfers outside the EU are based on EU-approved standard contractual clauses (SCCs).

5. Retention period

  • Active account data is retained until the user deletes their account.
  • Booking and payment data is retained for 6 years under the Finnish Accounting Act (1336/1997).
  • Log data is retained for a maximum of 12 months.

6. Your rights

You have the right to:

  • Access your data (right of access).
  • Request correction of inaccurate data.
  • Request erasure of your data (right to be forgotten).
  • Request data portability to another system.
  • Object to or restrict processing.
  • Withdraw your consent.
  • Lodge a complaint with the Office of the Data Protection Ombudsman.

You can send requests to the controller by email. We respond within 30 days.

7. Cookies

We use essential cookies (login, session) and cookies set by Google Maps. We do not use advertising tracking.

8. Data security

Data is transmitted encrypted (HTTPS/TLS). The database is protected by access control (Row Level Security). Card data is not stored in our own systems.

This policy is updated as needed. Users will be notified in the app of any material changes. More in the contact details.