This Privacy Policy describes how Tourneon ("we", "us") collects, uses and shares personal information when you use our website and services. We are committed to complying with the EU General Data Protection Regulation (GDPR), the South African Protection of Personal Information Act (POPIA), and applicable U.S. state privacy laws including the California Consumer Privacy Act (CCPA/CPRA).
1. Who we are
Tourneon is operated as the data controller for the personal information described below. For privacy questions, data-access requests, or to lodge a complaint, contact us at privacy@tourneon.com.
2. Information we collect
2.1 Information you give us
- Account: first name, last name, nickname, email, password (hashed), date of birth, self-assessed play level.
- Profile (optional): avatar image, public-profile preference.
- Bookings: courts you book, matches you join, scores you submit.
- Wallet: top-up amounts, payout requests, bank details for payouts (clubs only).
- Club operators: club name, location, contact details, banner/logo images, court details, pricing.
2.2 Information collected automatically
- Authentication cookies issued by our auth provider (Supabase) to keep you signed in.
- Basic technical logs (IP address, browser, request times) for security and abuse prevention.
- If you consent: Google Maps usage data (for address autocomplete) and aggregated analytics.
3. How we use your information
- To provide the booking, matchmaking, rating and payment features you request (contractual necessity).
- To verify identity, prevent fraud, and resolve disputes (legitimate interest).
- To send transactional emails (booking confirmations, refund notices, password resets).
- With your consent only: to load Google Maps and to gather product analytics.
4. Legal basis (GDPR / POPIA)
We process personal data on the basis of (a) contract when delivering the service you signed up for, (b) consent for non-essential cookies and marketing, (c) legitimate interest for fraud prevention and platform security, and (d) legal obligation for tax and accounting records.
5. Sharing
We do not sell your personal information. We share it only with:
- Supabase (database, authentication, file storage) — our infrastructure provider.
- Payment processor — to charge cards and pay out clubs (limited to data necessary for the transaction).
- Google Maps Platform — only if you've enabled functional cookies; addresses you type are sent to Google.
- Other match participants and the club operator — your nickname, avatar and rating, so they can play with you.
- Authorities — when required by law.
6. International transfers
Our infrastructure is hosted in the European Union and the United States. Where personal data is transferred out of the EEA/UK or South Africa, we rely on Standard Contractual Clauses (SCCs) or equivalent safeguards.
7. Retention
- Account & profile: kept while your account is active. Deleted within 30 days of account closure (financial records may be retained longer for legal reasons — typically 5–7 years for tax purposes).
- Booking & match history: retained while your account exists, then anonymised.
- Server logs: 90 days.
8. Your rights
Subject to local law you have the right to:
- Access — download a copy of your data from Settings.
- Rectification — correct inaccurate data via your profile or by contacting us.
- Erasure — delete your account from Settings.
- Restriction and objection — to certain processing.
- Portability — receive your data in a machine-readable JSON format.
- Withdraw consent at any time via the cookie banner ("Manage cookies").
- Lodge a complaint with a supervisory authority (e.g., your local DPA, the Information Regulator in South Africa, or applicable U.S. state Attorney General).
California residents (CCPA/CPRA)
We do not "sell" or "share" personal information for cross-context behavioural advertising as defined by the CCPA. You may exercise your rights to know, delete, correct, and limit by emailing privacy@tourneon.com or using the in-app tools above.
9. Children
Tourneon is not directed at children under 13 (or under 16 in the EU/UK). If you believe a child has provided us with personal information, contact us and we will delete it.
10. Changes to this policy
Material changes will be notified by email or in-app banner at least 30 days before they take effect.