Privacy Policy
Last updated: October 1, 2026
1. Data controller
The data controller is Valentin HARRANG, sole proprietor, reachable at .
2. Data collected
When using Buddiz, we collect the following data:
- Identification data : first name, last name, email address, avatar
- Sign-in with Google, Apple or Facebook : if you choose one of these services to sign in, we only receive your name, your email address, your profile picture (depending on the service) and an account identifier specific to Buddiz. Buddiz never posts anything on your behalf and does not access your friends list or your posts.
- Profile data : city, sport level, preferred side, phone number (optional), gender (optional) and contact preferences (everyone, women only, men only)
- Usage data : sessions created/joined, messages sent in chat, chat mentions, attendance confirmed via QR-code check-in, reliability score
- Geolocation data : approximate position (latitude / longitude) when you enable location services, and any manual location you enter yourself. Used for the map, distance calculations and radius-based filtering. Your position is never stored in our database: it is processed on the fly and replaced by a city (reverse-geocoding) when needed.
- Spots (partner shops) : When you use a perk at a partner shop ("Spot"), we record the use (shop, date/time and your proximity verified by geolocation at unlock time) to prevent fraud and give the merchant aggregate statistics. If you sign up via a counter QR stand, the Spot that referred you is linked to your account. This data is never public and the merchant only receives aggregate numbers, never your identity. Legal basis: legitimate interest (measurement and fraud prevention).
- Identity verification data (optional) : when you start profile certification, your camera captures a live video stream and a face-detection model runs entirely inside your browser or your application. No image, video, or biometric template is transmitted to our servers or retained: only the result (success / failure) is saved on your profile.
- Intentions and matching : when you declare a practice intention, we keep the sport, the date/time window, the geographic zone, the radius, the desired number of people and any members of your party. This data feeds the automatic matching system that puts you in touch with compatible members.
- Social data : favorites, list of blocked users, club memberships and anonymous votes cast in club polls.
- Post-session rating data : ratings (thumbs up / thumbs down), detailed evaluation (attitude, matching level) and free-form comment left after a session. Ratings are shown anonymously to the rated person (average only) and revealed when reciprocity is reached or after 7 days.
- Technical data : push notification subscription (one or more devices per user), browser type (via User-Agent), application update error reports (bundle version, error message)
- Notification data : push subscription, notification preferences, in-app notifications (joins, messages, mentions, intention matching, polls, etc.)
- Product analytics data (subject to consent) : user identifier, usage events (registration, session creation and participation, withdrawal, chat messages, centre view, club registration, etc.) and profile properties (level, role, city, reliability score, onboarded sports). This data is measured from your browser as well as server-side (app and web), using a pseudonymous identifier, on the basis of our legitimate interest in improving the service.
- Session recording (replay) : to understand friction and improve the experience, some browsing sessions (web) may be recorded as a "replay": your on-screen interactions and navigation. All input fields are masked (your name, phone, email or date of birth are never visible) and the identity-verification step (camera) is never recorded. These recordings are pseudonymous, hosted in the European Union (PostHog), kept for 30 days at most, and made on the basis of our legitimate interest in improving the service.
- Aggregate audience measurement : pages viewed, traffic source, visit duration. Anonymized data, without persistent identifier, exempt from consent in accordance with CNIL recommendations.
- Moderation data : in case of a report, we retain the reporting user's identifier, the reported user's identifier, the reason for the report, optional details provided, and the related message identifier if applicable. For women-only sessions, an optional safety feedback form may also be recorded.
- Anonymous players (party) : when you indicate that you are coming with companions, seats are reserved for partners who are not registered on Buddiz. Only a counter is stored; no personal data about third parties is collected unless those people create their own account.
- Session photos : the photos you add to a session are stored and visible to other members. When the session is public, they may appear on the "Latest community moments" wall and be featured by Buddiz for promotion and communication purposes, including on its social networks. Legal basis: legitimate interest (community engagement and promotion). You, or anyone appearing in a photo, may request its removal at any time.
3. Purposes of processing
Your data is used to:
- Manage your account and user profile
- Enable the creation and participation in sports sessions
- Send notifications related to sessions, messages, mentions and matching proposals
- Calculate the reliability score and confirm attendance through check-in
- Manage notification and privacy preferences, including contact preferences: who can message you, and the gender filter that applies to new conversations and member suggestions
- Display the map, calculate distances and suggest nearby sessions or members
- Power the intentions and automatic matching system
- Optionally verify the authenticity of your profile (face certification)
- Support club life (polls, registrations, team sessions)
- Improve the service, fix technical issues and diagnose application update errors
- Process reports and ensure platform moderation
- Analyze usage patterns (funnels, retention) to improve the product, subject to your consent
- Engage and promote the community, in particular by featuring photos from public sessions, including on our social networks
4. Legal basis for processing
- Contract performance : processing necessary for service delivery (account creation, session participation, matching)
- Consent : for push notifications, geolocation access, face certification and product analytics (PostHog)
- Legitimate interest : for service improvement, audience measurement and product analytics, abuse prevention and community safety
5. Data recipients
Your data may be shared with:
- Other users : first name, last name, avatar, level, city (visible on your public profile and in sessions). Ratings you submit are always shown anonymously.
- Supabase : database hosting and avatar storage (servers in Singapore)
- Vercel : frontend hosting
- Firebase : mobile and web push notifications (Firebase Cloud Messaging)
- Amazon SES : sending emails (notifications, service messages and Buddiz news). Receives your email address, your first name and the message content.
- Stripe : online payment (paid sessions, shop, professional offers) and identity verification for professional accounts that request it. Buddiz never sees or stores your card numbers.
- Mapbox : map rendering and reverse-geocoding (lat/long → city) for address entry and location. Mapbox may process these requests from infrastructure located in the United States.
- PostHog (EU Cloud) : product analytics, servers located in Frankfurt (Germany). Receives events collected from your browser as well as product events measured server-side (app and web), associated with a pseudonymous identifier.
- Umami : aggregate audience measurement (page views, traffic sources), hosted in Europe. Anonymized data.
We never sell your personal data to third parties.
6. Data transfers outside the EU
Some data is hosted by Supabase in Singapore. These transfers are governed by the European Commission's standard contractual clauses. Vercel and Mapbox also operate from the United States under the Data Privacy Framework (DPF). Product analytics data collected by PostHog remains within the European Union (Frankfurt, Germany): no transfer outside the EU is made for this data. Amazon Web Services (Amazon SES) and Stripe may also process data in the United States, under the Data Privacy Framework (DPF).
7. Data retention
- Account data : retained as long as the account is active, then deleted 30 days after account deletion
- Session data : retained 12 months after the session date
- Rating data : retained 12 months after the date of the corresponding session, then anonymized
- Practice intentions : retained as long as the intention is open, then automatically deleted 30 days after expiration or cancellation
- Geolocation data : not stored persistently. Your position is used on the fly to calculate distances or run reverse-geocoding; only the resulting city (as text) is kept if you save it on your profile.
- Identity verification data : no biometric template, image or video is retained. Only the certification result (success/failure and date) is stored on your profile, and deleted together with your account.
- Block lists : retained as long as the account is active or until you explicitly unblock the user
- Notification data : retained as long as the account is active. In-app notifications are kept for 90 days, then purged.
- Moderation data (reports and safety feedback) : retained 2 years from the report date, for abuse prevention and traceability purposes
- Application update error reports : retained 90 days, with no direct personal data (only the bundle version and error message)
- Product analytics data : retained for a maximum of 13 months, in accordance with CNIL recommendations on audience measurement and product analytics
8. Cookies, trackers and local storage
Buddiz uses the following trackers and local storage:
- Essential cookies (exempt from consent) : Supabase authentication (user session) and cookie
buddiz_ccwhich stores your consent choice for 182 days. - Local preferences (localStorage, exempt from consent) : we store your usage preferences on your device: active sport (buddiz-sport), light/dark theme (buddiz:theme), search radius (buddiz_radius_km), manually entered location (buddiz_manual_location), current activity tab, drafts of unsent forms, and the referral code if you arrived via an invitation link. This data stays on your device and is never sent to our servers.
- Umami audience measurement (exempt from consent) : aggregate page view counters, without persistent identifier or cross-site matching, compliant with CNIL exemption criteria.
- PostHog product analytics : local storage (localStorage, prefix
ph_) of a pseudonymous identifier used to attach your usage events to your profile, on the basis of our legitimate interest in improving the service. The same measurement is performed server-side (app and web). Maximum retention: 13 months.
You can object to product analytics or request deletion of the associated identifiers at any time by contacting us; you can also clear the site data in your browser.
9. Geolocation
The Buddiz app uses your position to display the map, calculate distances to sessions and centres, suggest nearby sessions (notifications) and run the intentions and matching system.
- On the web : your browser explicitly asks for permission to access your position (navigator.geolocation API). You can refuse or revoke it at any time from your browser settings.
- On mobile (iOS / Android) : the app uses the Capacitor geolocation plugin. iOS and Android ask for permission on first use; you can revoke it at any time from your device's system settings.
- Processing : your position is processed on the fly to calculate distances, render the map, or obtain a city via reverse-geocoding (Mapbox). It is not stored persistently in our database. Only the entered or derived city is saved if you attach it to your profile or to a session.
- Optional : you can use Buddiz without enabling geolocation by entering your city manually. In that case, distance-based features will use that city as the reference point.
10. Identity verification (face certification)
Buddiz offers an optional certification that confirms a real person is behind the profile, to strengthen community trust and protect sensitive sessions (especially women-only sessions).
- Local processing : face detection uses the face-api.js library and runs entirely inside your browser or your application. No image, video, or biometric template is transmitted to our servers.
- Storage : only the certification result (success / failure) and its date are saved on your profile. The video stream is stopped immediately after the attempt and no image is retained.
- Legal basis : your explicit consent. Certification is optional; you can use Buddiz without it, subject to access restrictions on certain sensitive sessions.
- Revocation : you can request deletion of the certification status at any time by contacting us. Deleting your account also removes the result.
11. Intentions and matching
The intentions system lets you signal that you want to move within a time window and a zone, without creating a full session. When compatible intentions meet, Buddiz suggests confirming a session together.
- Data processed : sport, date / time window, geographic zone (point + radius), desired number of people, identifiers of members of your party.
- Matching : matching is fully automatic on the server side. You are only put in touch with members whose intention is compatible (sport, slot, zone, contact preferences). No data about other users is revealed to you until a compatibility has been confirmed on both sides.
- Visibility : your intention remains private until a compatibility is confirmed. At that point, a draft session is created and only the members involved can see it, until confirmation.
- Cancellation : you can edit or cancel an intention at any time from the "My intentions" screen. Cancellation also removes pending compatibilities, without affecting sessions already confirmed.
12. Health data (Apple Health and Health Connect)
If you wish, Buddiz can fill in your sports profile from your watch or phone, through Apple Health on iPhone or Health Connect on Android. This feature is optional: you can use Buddiz without it.
- What is read : only your activities from the last 12 weeks (activity type, start and end time, duration and distance), read-only. Buddiz never reads your GPS route, your heart rate or any other biometric data, and never writes to Apple Health or Health Connect.
- Processing on your phone : activities are analysed on your device to work out your pace, your usual distances and your usual times (day of the week and time of day). The activities themselves never leave your phone.
- What is kept : on our servers, only your usual times per sport (for example "Tuesday evening"), how regular they are, the number of activities analysed, and the values you choose to save to your profile yourself (pace, distances, times). Usual times that are not refreshed for 30 days are deleted automatically. The measurements used to tell you that your pace has changed stay on your phone and are deleted from it when you sign out.
- Numbers of a finished session : if you organize a session, you can pre-fill its distance and duration from your watch. Buddiz finds the matching activity on your phone, and nothing is sent until you save. Once saved, these numbers belong to the session and are visible to its participants, like a manual entry.
- Sharing with other members : your usual times are never shown to other members. If you agree (box unticked by default), they may help suggest compatible partners, only between verified profiles and in line with your contact preferences and blocks. You can withdraw this agreement at any time.
- Legal basis : your explicit consent, collected in the app before anything is read, in addition to the permission requested by your phone. This information is data concerning health within the meaning of Article 9 of the GDPR.
- What we never do : no advertising or marketing use, no sale and no transfer to third parties. Our audience measurement and error tracking tools only receive usage facts (for example "watch connected"), never a pace, a distance or a usual time. No ranking, badge or reward depends on this data.
- Age : this feature is reserved for people aged 18 and over.
- Withdrawal and deletion : at any time you can choose "Disconnect my watch" in Me > Privacy > My watch: your consent and your usual times are then deleted from our servers. The values you chose stay in your profile as if you had typed them, and you can change them whenever you like. You can also remove access in your phone's settings. Deleting your account deletes all of this data.
13. Your rights
Under the GDPR, you have the following rights:
- Right of access : obtain a copy of your personal data
- Right to rectification : correct inaccurate or incomplete data
- Right to erasure : request deletion of your data (or via the "Delete my account" option in the application)
- Facebook, Google or Apple account : deleting your Buddiz account also erases the information received from these services. You can also remove Buddiz's access at any time: on Facebook, Settings & privacy > Settings > Apps and websites; on Google, Security > Your connections to third-party apps & services; on iPhone, Settings > [your name] > Sign-In & Security > Sign in with Apple.
- Right to data portability : receive your data in a structured, readable format
- Right to object : object to the processing of your data
- Right to restriction : request restriction of processing
To exercise these rights, contact us at: . We will respond within 30 days. You may also file a complaint with the CNIL ( www.cnil.fr).
14. Data security
We implement appropriate technical and organizational measures to protect your personal data: encrypted communications (HTTPS/TLS), secure authentication, data access control via Supabase RLS policies, encryption of sensitive tokens, regular security updates.
15. Changes to this policy
This policy may be updated. In case of substantial changes, users will be notified via the application and asked to accept the new terms.
16. Contact
For any questions regarding the protection of your data:

