Legal
Privacy Policy
This policy explains what personal data Clubzs collects when you use our mobile app and website, why we process it, and your rights under the GDPR.
Last updated: June 1, 2026
Who we are
Clubzs is operated by [Company legal name], a company registered in Romania under registration number [Registration number], with its registered office at [Registered office address] ("Clubzs," "we," "us," or "our"). This Privacy Policy applies to the Clubzs mobile application and to https://www.clubzs.com.
We are the controller of the personal data described in this Policy, within the meaning of Article 4(7) of Regulation (EU) 2016/679 (the "GDPR").
Data Protection Officer
We have not appointed a Data Protection Officer, because our processing activities do not meet the thresholds in Article 37(1) GDPR. For privacy questions, please contact us at the address in Section 12.
Information we collect, why, and on what legal basis
Under Article 6(1) GDPR, we may only process your personal data where at least one lawful basis applies. The table below sets out, for each category of data we collect, what we use it for and which legal basis we rely on.
| Data category | Purpose | Legal basis (Art. 6(1) GDPR) |
|---|---|---|
| Account information (email, name, profile photo, handle, account type, optional profile fields) | Create and operate your account | (b) necessary for performance of the contract with you (our Terms & Conditions) |
| Authentication data (email, Apple, Google sign-in) | Verify your identity and secure your account | (b) contract |
| Club and event content (hangouts, RSVPs, attendance, photos, feedback) | Provide core club/event functionality | (b) contract |
| Location data | Discovery, event locations, map views, geo-based attendance | (a) your consent, given via device permission, which you can withdraw at any time in device settings; (b) contract |
| Payment data (via Stripe / RevenueCat) | Process subscriptions and event payments | (b) contract; (c) compliance with tax and accounting (legal) obligations |
| Photos (camera/library) | Upload avatars or event images | (a) consent, given via device permission |
| Calendar access | Add events to your device calendar | (a) consent, given via device permission |
| QR/barcode data | Attendance check-in, voucher redemption | (b) contract |
| Usage/device data, push tokens | Keep the app functioning, deliver notifications | (b) contract; (f) our legitimate interest in operating a reliable service, balanced against your privacy — see below |
| Product analytics, session replay (fields masked) | Understand and improve app usage | (f) legitimate interest, or (a) consent where required by your jurisdiction's ePrivacy/cookie rules |
| Crash and error reports | Diagnose and fix reliability issues | (f) legitimate interest in a functioning product |
| Advertising data (free-tier users) | Show in-app ads via Google AdMob | (a) consent (personalized ads) or (f) legitimate interest (basic, non-personalized ad delivery), depending on your region and choices — see Section 6 |
| Public profile / social / sponsor links | Display your public page, if you choose to make it public | (a) consent, exercised through your visibility settings |
| Fraud and abuse signals | Detect and prevent fraud, enforce community rules | (f) legitimate interest in platform integrity and safety; (c) where required by applicable law |
Where we rely on legitimate interest (Art. 6(1)(f)), our interest is operating a functioning, safe, and improvable product, and we have assessed that this interest is not overridden by your rights and freedoms. You may object to processing based on legitimate interest at any time — see Section 7.
Where we rely on consent (Art. 6(1)(a)), you may withdraw that consent at any time, as easily as you gave it (Art. 7(3) GDPR), without affecting the lawfulness of processing carried out before withdrawal.
How we share information
We share personal data with the following categories of recipients, on the legal bases already identified in Section 2:
- Other users, according to your visibility and club-membership settings (for example, public profiles, club membership or event attendance).
- Processors acting on our instructions, under data processing agreements compliant with Article 28 GDPR:
- Supabase (hosting and database)
- Stripe (payment processing)
- RevenueCat (app-store subscription management)
- PostHog (product analytics)
- Sentry (crash and error monitoring)
- Google (Sign-In, Maps, AdMob advertising)
- Apple (Sign-In)
- Push notification infrastructure
- Business partners, only where you interact with their listings or voucher offers through a Clubzs feature you actively use.
- Public authorities, where required by law, or to protect the vital interests or rights of a data subject or the public, consistent with Article 6(1)(c) or (d).
We do not disclose personal data to third parties for their own independent marketing or commercial purposes without your consent.
International transfers
Several of our processors are located outside the European Economic Area, mainly in the United States. Where we transfer personal data outside the EEA, we rely on one of the following safeguards, as required by Chapter V GDPR:
- an adequacy decision of the European Commission under Article 45 GDPR, where the recipient's country (or, for the US, a certified recipient under the EU-US Data Privacy Framework – see Commission Implementing Decision EU 2023/1795) is covered by one; or
- the Standard Contractual Clauses adopted by the European Commission under Article 46(2)(c) GDPR, incorporated into our contracts with the relevant processor.
You can request a copy of the relevant safeguard by contacting us at the address in Section 12.
Public content and the website
Club and event pages, and user profiles, are private by default. A profile, club, or event becomes visible on public web pages only if you affirmatively choose to make it public through your visibility settings, in which case it may be accessible to non-members and indexed by search engines. You can revert a public profile, club, or event to private at any time; this removes it from newly generated public pages but does not retract copies already cached by third parties (e.g., search engine caches), which are outside our control.
Analytics and error reporting
We use PostHog for product analytics and Sentry for crash and error reporting, on the legal bases described in Section 2. Session replay, where enabled, masks text inputs and images before it reaches our analytics provider. Error reports do not include email addresses or other direct identifiers by default. Where analytics or session-replay tools set cookies or similar identifiers on the website and applicable law requires consent for that we will request that consent through a cookie/consent banner before non-essential identifiers are set.
Advertising
Free-tier users may see advertisements in the mobile app, served through Google AdMob.
Personalized ads are shown only with your consent, collected through Google's User Messaging Platform, and you may withdraw that consent at any time through the in-app privacy settings or your device's ad-tracking controls.
Non-personalized, contextual ads may be shown without consent where permitted by your jurisdiction, on the basis of our legitimate interest in operating a free version of the service (Art. 6(1)(f)).
Paid subscribers do not see advertising placements tied to the free version.
Your rights
Subject to the conditions and exceptions set out in the GDPR, you have the following rights in relation to your personal data:
- Access (Art. 15) — obtain confirmation of whether we process your data, and a copy of it.
- Rectification (Art. 16) — correct inaccurate or incomplete data.
- Erasure (Art. 17) — request deletion, where one of the Art. 17(1) grounds applies (for example, the data is no longer necessary, or you withdraw consent and there is no other legal basis).
- Restriction of processing (Art. 18) — request that we limit processing while a dispute about accuracy or lawfulness is resolved.
- Data portability (Art. 20) — receive the personal data you provided to us, based on consent or contract and processed by automated means, in a structured, commonly used, machine-readable format, and transmit it to another controller. You can request an export from Account settings in the app, or by contacting us.
- Object (Art. 21) — object, on grounds relating to your particular situation, to processing based on our legitimate interest (Art. 6(1)(f)), including profiling; and object at any time, free of charge, to processing for direct marketing purposes.
- Withdraw consent (Art. 7(3)) — where processing is based on consent, withdraw it at any time, without affecting the lawfulness of processing before withdrawal.
- Lodge a complaint (Art. 77) — with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement. In Romania, this is the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, București, cod poștal 010336, anspdcp.ro. This right exists regardless of where Clubzs is established and does not require you to contact us first.
To exercise any of these rights, contact us using the details in Section 12. We will respond within one month of receipt (Art. 12(3) GDPR), extendable by a further two months for complex or numerous requests, in which case we will tell you within the first month and explain why.
We do not charge a fee for these requests unless they are manifestly unfounded or excessive, in particular because of their repetitive character (Art. 12(5)), in which case we may charge a reasonable administrative fee or decline to act, and we bear the burden of showing the request meets that standard.
Data retention
We retain personal data only for as long as necessary for the purposes described in Section 2, applying the following approximate periods:
| Data category | Retention period |
|---|---|
| Account and profile data | While your account is active; deleted when you delete your account, with no recovery period |
| Participant identity snapshot (display name and avatar for past event history) | Written when you delete your account; retained while the related club or event records exist, so attendance history remains intelligible to other members |
| Club/event content | While your account is active; on account deletion, content linked only to you is removed, and content in shared clubs or events may be retained in anonymized form (without your user account) while those clubs or events exist |
| Payment records | Up to 10 years, as required by applicable tax and accounting law; payment processors such as Stripe and RevenueCat may also retain records under their own terms |
| Analytics and session-replay data | 12 months, after which it is aggregated or deleted |
| Crash/error reports | 90 days |
| Support communications | 24 months from resolution |
When you delete your account, we delete your account and profile data promptly and do not offer a recovery period. A limited identity snapshot (display name and avatar) may remain as described above so past event attendance history stays meaningful to other members. Shared club or event records may also retain anonymized references after your account is removed. We do not retain other personal data longer than the periods above, except where we are required to keep specific records by law (for example, tax records) or need limited data to defend against or bring a legal claim (Art. 17(3)(e)). Our processors (such as Stripe, PostHog, and Sentry) may retain data for their own periods under our agreements with them.
Security
We apply technical and organizational measures appropriate to the risk of the processing, in line with Article 32 GDPR, including encrypted connections (TLS), access controls, and row-level security at the database layer. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it (Art. 33), and will notify you directly, without undue delay, if the breach is likely to result in a high risk to your rights and freedoms (Art. 34).
Children
Consistent with Article 8 GDPR, our default minimum age for using Clubzs without parental consent is 16. Where your country of residence has lawfully set a lower digital-consent age (no lower than 13, per Art. 8(1)), that lower age applies to you instead. We do not knowingly collect personal data from children below the applicable threshold without verifiable parental consent. If you believe a child has provided us data in breach of this section, contact us at the address in Section 12 and we will take appropriate action, including deletion.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the "Last updated" date. Where a change is material — for example, a new processing purpose or a new category of recipient — we will notify you in the app and, where the change relies on your consent, request that consent again before the change takes effect.
Contact
For privacy questions, to exercise the rights in Section 7 contact:
Nica Dragos PFA
Email: support@clubzs.com
You may also use the support options on our contact page.
You may also lodge a complaint directly with your local supervisory authority at any time — see Section 7.