Privacy Policy
Last updated: 14 August 2026
This policy explains what personal data Padelmgr processes, why, and how you can exercise your rights. It is written to be readable: if anything is unclear, get in touch and we will explain it.
1. Data controller
Andrea Colpani — NIF Y6990226B — Canary Islands, Spain.
For anything concerning personal data: contact@padelmgr.com.
No Data Protection Officer has been appointed: the conditions of Article 37 GDPR do not apply.
2. Scope
This policy covers padelmgr.com, the application reserved for organisers, and the public tournament view reachable through a QR code.
3. What we process and why
Contact requests — when you fill in the form we collect the club name, contact name, email address and message. Alongside these we store the browser type, the referring domain, and a code derived from your IP address by hashing, which rotates daily and cannot be reversed to the original address. Purpose: replying to you and protecting the form from automated submissions. Legal bases: Article 6(1)(b) GDPR (pre-contractual steps taken at your request) and Article 6(1)(f) (legitimate interest in service security).
Organiser accounts — to use the application we process email address, name, role and the organisation you belong to. Access is by invitation only; there is no open sign-up. Legal basis: Article 6(1)(b) GDPR (performance of a contract).
Player data entered by clubs — the application lets clubs record player names, pairs and match results. For that data the club is the controller and Padelmgr acts as processor under Article 28 GDPR: we process it solely to provide the service, on the club's instructions, and never for our own purposes. If you are a player wishing to exercise your rights, your counterpart is the club running the tournament; if you write to us, we will forward the request.
Visit statistics — we record which pages are opened, whether from a mobile or desktop device, the referring domain, and a pseudonymous code identifying a visitor for the current day only. The code is regenerated daily, so individuals cannot be followed over time and no profiles are built. It exists so organisers can see how many spectators a tournament drew. Legal basis: Article 6(1)(f) GDPR (legitimate interest in measuring service usage in aggregate).
Anonymous counting of marketing-page visits — on the public pages of this site only (the home page in all three languages and this policy) we use GoatCounter, a counter that sets no cookies, does not store your IP address, and keeps aggregate data only, making it impossible to identify you or follow you across sites. The same counter also gathers visits to other sites run by the controller into a single view. It is not present in the organisers' application or in the public tournament view. Legal basis: Article 6(1)(f) GDPR (legitimate interest in knowing how traffic develops).
4. What we do not do
- We do not use profiling cookies or advertising trackers.
- We place no measurement tool inside the organisers' application or the public tournament view.
- We do not run behavioural advertising, and we neither sell nor share data with third parties for commercial purposes.
- We do not process special categories of data within the meaning of Article 9 GDPR.
- We do not make automated decisions producing legal effects on individuals.
5. Browser local storage
We set no cookies. We do use the browser's local storage for three items: the session token that keeps you signed in, the language you selected, and a random visitor identifier used to avoid counting the same person twice on the same day. You can clear them at any time from your browser settings; the only consequence is that you will need to sign in again.
6. How long we keep data
- Contact requests: up to 24 months from submission, or sooner if you ask for deletion.
- Organiser accounts: for the duration of the relationship and up to 12 months afterwards.
- Tournament and player data: for as long as the club keeps it; deleting a tournament also removes its matches, pairs and news.
- Visit statistics: automatically deleted after 180 days.
- Encrypted backups: up to 730 days, on a daily, monthly and yearly rotation.
7. Who processes data on our behalf
We rely on the following providers, acting as processors and handling data solely to deliver the service:
- Supabase — database and authentication. Data is hosted on infrastructure located in the European Union (Ireland).
- Netlify — website hosting.
- Resend — delivery of system email (invitations, password resets, notifications).
- ImprovMX — forwarding of inbound mail addressed to the domain.
- Google Drive — storage of backup copies, which are encrypted before leaving our infrastructure.
- GoatCounter — anonymous counting of visits to the public marketing pages only, without cookies and without retaining IP addresses.
8. Transfers outside the European Union
Some of the providers listed above are established in the United States. Where data is accessible outside the European Economic Area, the transfer is governed by the Standard Contractual Clauses approved by the European Commission, or by another appropriate safeguard under Chapter V GDPR.
9. Security
Traffic travels over an encrypted channel. Access to data is enforced at database level by policies that isolate each organisation from the others. Backup copies are encrypted and the private key is held offline. No system is impenetrable: in the event of a breach posing a risk to your rights, we will carry out the notifications required by Articles 33 and 34 GDPR.
10. Your rights
You may exercise the rights set out in Articles 15-22 GDPR at any time by writing to contact@padelmgr.com. We reply within one month.
- Access your data and obtain a copy of it.
- Have inaccurate data corrected.
- Request erasure of your data.
- Request restriction of processing, or object to it.
- Receive your data in a structured, commonly used format (portability).
- Withdraw consent, where processing rests on it, without affecting the lawfulness of prior processing.
11. Complaints
If you believe the processing of your data breaches the law, you may lodge a complaint with the Agencia Española de Protección de Datos (aepd.es), or with the supervisory authority of the country where you live.
12. Minors
The service is aimed at clubs and organisers, not at minors. Where a club enters under-age players into a tournament, collecting that data and obtaining any parental authorisation remains the responsibility of the club, which is the controller of it.
13. Changes
Any update to this policy will be published on this page with a new revision date. If the changes are substantial, we will inform organisers by email.