Privacy policy

Last updated: 30 August 2026

1. Data controller

1.1. The controller of the personal data collected through the Application is the private individual who maintains Padel Cubelles, who will identify themselves to any data subject who asks at the address given below.

1.2. Contact address for data protection purposes: info@padelcubelles.com.

1.3. Given the nature and scale of the processing, the appointment of a data protection officer is not required.

2. Categories of personal data processed

2.1. Identity and profile data: name, email address, playing level, preferred side, language and, where provided, profile photograph and days of weekly availability.

2.2. Authentication data: password, stored as a hash and not readable by the controller; a Google identifier, only where the user chooses to sign in with that provider, in which case no password is stored at all; and the elements needed for two-factor authentication, if the user enables it.

2.3. Activity data: the games the user takes part in, messages published in those games' chats, court status changes recorded, and notices generated inside the Application.

2.4. Connection data: IP address and browser user agent, associated with the session.

2.5. No special categories of data within the meaning of article 9 of the General Data Protection Regulation are processed.

3. Purposes and legal bases

3.1. Managing the account and providing the service, including displaying the profile to other users and organising games. Legal basis: performance of the contract for the service, article 6.1.b of the General Data Protection Regulation.

3.2. Sending communications necessary for the service to function, in particular a player joining or leaving a game and its cancellation, since these affect whether the game happens at all. Legal basis: performance of the contract, article 6.1.b.

3.3. Sending notices that the user can configure, concerning invitations, court status changes, chat messages and reminders. Legal basis: the data subject's consent, article 6.1.a, which may be withdrawn at any time from the settings section without affecting the lawfulness of processing carried out beforehand.

3.4. Account security, by limiting the number of sign-in attempts from a given IP address. Legal basis: the legitimate interest of the controller and of the users themselves in preventing unauthorised access, article 6.1.f.

3.5. Content moderation and handling of complaints. Legal basis: the legitimate interest in maintaining a usable environment, article 6.1.f.

3.6. Recording the technical errors that occur in the Application, in order to detect and correct them. What is recorded is the user's internal identifier, the address of the page on which the error occurred, technical data about the browser, and the approximate location — at town level — that the provider derives from the connection before discarding the IP address; the name, the email address and the contents of messages are not recorded. Legal basis: the legitimate interest of the controller and of the users themselves in the Application working correctly, Article 6.1.f.

3.7. No automated decision-making or profiling producing legal or similarly significant effects takes place, no information is disclosed for advertising purposes, and no personal data is sold.

4. Retention periods

4.1. Account data is retained for as long as the relationship with the user continues.

4.2. Notices generated inside the Application are deleted automatically after 120 days.

4.3. Messages published in a game's chat are deleted automatically 15 days after the date of the game, whether it was played or cancelled.

4.4. Invitations sent by email expire after 7 days.

4.5. Backups of the database are kept, of which the 7 most recent are retained on the server.

4.6. Once the account is closed, the user's name, email address, photograph and other identifying data are deleted immediately. The record of games already played is retained without that data, because it belongs to the other participants as well, and messages already published are deleted when the period in paragraph 4.3 expires.

4.7. Data whose retention is required in order to address possible liabilities will be retained, blocked, for the applicable limitation period.

5. Recipients and processors

5.1. The user's name and playing level are visible to other registered users. The user's first name also appears on a game's public link, which is accessible without an account.

5.2. The content of chats is accessible only to the players in the game concerned.

5.3. There is a single administration account, with access to account data for moderation and support purposes.

5.4. The following provide services as processors, with access to the data solely in order to provide those services: the hosting provider, which hosts the application and the database and provides the email sending service; Cloudflare, Inc., as a content delivery and attack protection network, with access to connecting IP addresses; and Functional Software, Inc. (Sentry), as a technical error-logging service, whose data is held in its European Union region.

5.5. Where the user chooses to sign in with Google, Google Ireland Limited processes that authentication data as an independent controller, under its own privacy policy.

5.6. Data is not disclosed to third parties except where required by law.

6. International transfers

6.1. The services identified in paragraph 5.4 may involve processing by entities established in the United States of America.

6.2. Those transfers rely on the European Commission adequacy decision of 10 July 2023 concerning the EU-US Data Privacy Framework, in respect of providers certified under it, and in the alternative on the Standard Contractual Clauses approved by the European Commission.

7. Third-party data supplied by users

7.1. The Application allows a user to invite other people by supplying their email address, and to add guest players by supplying their name. Such cases involve processing the data of people who have no account.

7.2. The email address supplied is used solely to send the invitation concerned, which expires after 7 days.

7.3. The legal basis for this processing is the legitimate interest in allowing games to be organised between people who know one another; it falls to the user supplying the data to have informed the person concerned and to have their consent.

7.4. Anyone whose data has been supplied in this way may request its deletion at info@padelcubelles.com.

8. Cookies and connection data

8.1. The Application uses only technical cookies necessary for it to work: the session cookie, the cookie that keeps the user signed in, and the cookie that protects against request forgery.

8.2. No analytics, advertising or third-party cookies are used. As only strictly necessary technical cookies are involved, prior consent is not required under article 22.2 of Spanish Law 34/2002 on information society services.

8.3. The IP address and user agent are retained with the session for as long as it remains active.

9. Rights of data subjects

9.1. The data subject may exercise the rights of access, rectification, erasure, restriction of processing, portability and objection, and may withdraw any consent given, by writing to info@padelcubelles.com.

9.2. The rights of access, rectification and erasure may in addition be exercised directly and immediately from the settings section of the Application, without having to give reasons.

9.3. Requests will be answered within one month of receipt, extendable on the terms set out in article 12.3 of the General Data Protection Regulation.

9.4. The data subject has the right to lodge a complaint with the Spanish Data Protection Agency (aepd.es), without having to contact the controller first.

10. Minors

10.1. The Application is intended solely for persons aged 18 or over and data is not knowingly collected from minors.

10.2. Where it becomes known that an account belongs to a minor, the account will be closed and the associated data deleted.

11. Security measures

11.1. The controller applies technical and organisational measures appropriate to the risk of the processing, including encryption of communications, storage of passwords as hashes, rate limiting of sign-in attempts, the availability of two-factor authentication, and the taking of backups.

11.2. No security measure offers absolute protection. In the event of a personal data breach entailing a risk to the rights and freedoms of data subjects, the controller will proceed in accordance with articles 33 and 34 of the General Data Protection Regulation.

12. Changes to this privacy policy

12.1. This policy may be amended. The version published in the Application applies, together with its stated date of last update.

12.2. Substantial changes will be notified to registered users by email.