Privacy Policy
This Privacy Policy explains how Ricardo Boysen Ruiz ("we", "us"), operator of Match Royale, processes personal data under the EU General Data Protection Regulation (GDPR).
1. Controller
2. Data we process
For venue owners: name, email, phone, venue address, billing details and signed reservation agreement.
For guests: a randomly generated session token, display name, predictions and trivia answers. No account, email or phone number is required to play.
Technical data: IP address, browser type and minimal request logs needed to operate the service.
Payment data (name, billing address, payment method details, transaction amount) is collected and processed by Paddle as our payment provider — see Section 4.
3. Purposes & legal basis
- Performance of contract (Art. 6(1)(b) GDPR) — operating the platform, processing reservations, running competitions, fulfilling purchases.
- Legitimate interest (Art. 6(1)(f) GDPR) — security, fraud prevention, service analytics.
- Legal obligation (Art. 6(1)(c) GDPR) — tax & accounting records.
4. Data sharing & processors (Subprocessors)
We share personal data with the following categories of recipients. All processors are bound by Art. 28 GDPR data processing agreements where applicable.
- Paddle.com Market Ltd (Ireland / United Kingdom) — our Merchant of Record and payment provider. Paddle acts as a separate data controller for payment, billing, fraud prevention, tax compliance and invoicing. See paddle.com/legal/privacy.
- Supabase Inc. (United States, EU region used where available) — managed Postgres database, authentication, storage and edge functions, operated for us via Lovable Cloud.
- Lovable (Sweden / EU) — hosting, deployment and SSR runtime (Cloudflare Workers, EU/global edge).
- Cloudflare, Inc. (United States / global edge) — CDN, DDoS protection and edge compute (subprocessor).
- Sportmonks B.V. (Netherlands) and/or API-Football (France) — public football fixture & result data. No personal data is shared with these providers.
- Lovable AI Gateway — optional AI features. No personal data is sent unless required for a specific feature.
- Email delivery provider (Resend / EU & US regions) — sending transactional emails (reservation confirmations, receipts, account emails).
- Professional advisers (legal, accounting) and competent authorities where required by law.
5. Retention
- Reservation records, invoices, signed PDFs: retained for as long as required by tax and commercial law (typically 10 years in Germany, § 147 AO / § 257 HGB).
- Guest predictions, trivia answers, nicknames: kept for the duration of the tournament plus 90 days, then deleted or anonymised.
- Authentication accounts: kept until the user deletes the account or requests deletion.
- Content reports (DSA Notice & Action): retained for 6 months after resolution.
- Server access logs: typically 14–30 days for security & abuse investigation.
6. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict and port your personal data, to object to processing, to withdraw consent, and to lodge a complaint with a supervisory authority. We respond to requests within one month.
7. Security measures
We apply appropriate technical and organisational measures to protect personal data, including: TLS/HTTPS encryption in transit, encryption at rest on managed database and storage services, role-based access control, row-level security policies in the database, principle of least privilege for staff and service accounts, regular dependency and vulnerability scanning, audit logging of administrative actions, and secure handling of secrets via managed vaults. Payment card data is never stored on our servers — it is handled directly by Paddle in a PCI-DSS compliant environment.
8. Cookies & local storage
We use strictly necessary cookies and browser storage to keep guests signed into a venue session, remember venue owner authentication, and store your language and cookie-notice preference. We do not use advertising or third-party tracking cookies. When you start a checkout, the Paddle.com payment script is loaded — this is strictly necessary to fulfil the order you requested (§ 25 (2) Nr. 2 TTDSG) and may set cookies set by Paddle as a separate controller.
9. International transfers
Where data is processed outside the EU/EEA (e.g. by Supabase / Cloudflare in the United States), we rely on the EU Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework as transfer safeguards.
10. Right to withdrawal (consumers)
If you are a consumer, you have a 14-day right of withdrawal for purchases of digital products. The full statutory information and the model withdrawal form are available at Widerrufsbelehrung.
Last updated: 10 June 2026