Privacy policy
Last updated: 27 July 2026
1. Controller
The controller is the publisher of AthletsID: [Nom et prénom à compléter] (Entrepreneur individuel (en cours de création)).
Contact: contact@athletsid.com. Address: [Adresse postale à compléter].
No Data Protection Officer (DPO) is appointed at this stage; requests go to the contact above.
2. Data collected
Parent account: name, email, password (hashed), consent / values acknowledgement dates, optional interest in a future Premium offer.
Athlete profile (entered by the parent): sports identity (first/last name, birth date, sport, club, position, category, declared measurements, free text, photo, social links, sport metadata).
Session technical data: session token, optionally IP address and user-agent (security / auth).
Premium is not sold yet; Premium features do not collect data until enabled.
3. Purposes and legal bases
Providing a shareable sports profile service (contract performance / pre-contractual steps).
Parental / legal guardian consent for processing a minor’s data in the service.
Legitimate interest: account security, abuse prevention, measuring interest in a future Premium offer (timestamp only).
Legal obligation (minimal billing retention) only if a paid offer goes live.
4. Recipients and processors
Application hosting: OVH SAS (VPS, European Union). Database and photo storage: Supabase (Postgres, photo bucket).
Public profiles are reachable by anyone with the link.
No data resale, no third-party targeted ads.
5. Transfers outside the EU
Depending on hosting and Supabase configuration, data may be processed outside the EU. Appropriate safeguards (e.g. SCCs) are sought from providers.
6. Retention
Account and profiles: while the account is active.
After account or profile deletion: associated data is erased within a reasonable time (subject to short-lived technical backups).
Sessions: until expiry / sign-out.
Premium interest: until Premium launch or account deletion.
7. Your rights
You have rights of access, rectification, erasure, restriction, objection, and portability where applicable (GDPR).
In the logged-in area: edit / hide / delete an athlete profile, and delete the parent account.
For other requests: contact@athletsid.com. You may also lodge a complaint with your supervisory authority (in France: CNIL, www.cnil.fr).
8. Minors
The service is for parents / legal guardians. Creating a minor’s profile requires explicit guardian consent.
Published content remains the parent account’s responsibility (image rights, accuracy, sharing the public link).
For social links, the parent/legal guardian confirms publication authorization, or the athlete is aged 15+ and manages their own accounts.
9. Cookies
Strictly necessary cookies / storage: auth session, locale preference (next-intl).
No advertising cookies or third-party analytics at this stage. No consent banner is required for these technical cookies alone.
10. Security
Reasonable measures: hashed passwords, restricted server access, secrets kept out of source, database RLS limiting anon access.
No system is perfect; report suspicious incidents to the contact email.
11. Changes
This policy may evolve (e.g. Premium payments, analytics). The update date is shown at the top of the page.