Privacy Policy
Last updated: [DATE]
Effective date: [EFFECTIVE DATE]
This Privacy Policy explains how FootPulse ("we," "us," "our"), operated by [LEGAL ENTITY NAME] based in [OPERATOR COUNTRY/STATE], collects, uses, and protects your personal information when you use https://footpulse.news and related services (the "Service"). By using the Service, you agree to this Policy.
1. Who we are (data controller)
For the EU/UK GDPR, the data controller is [LEGAL ENTITY NAME], contactable at privacy@footpulse.news.
2. Information we collect
- Account information — your email address and authentication data used to sign you in (via our processor, Supabase).
- Engagement data — likes, saves, comments, follows (teams, players, competitions), and the content of comments you post.
- Newsletter & email data — email address, language preference, and subscription status. We use double opt-in and only send after you confirm.
- Notification preferences — your choices for in-app and email notifications and match alerts.
- Analytics & usage data — aggregate usage via a privacy-focused provider; where required by law, only after you consent.
- Technical & log data — IP address, browser type, and request logs, for security and performance.
- Cookies — see our Cookie Policy.
We do not intentionally collect special-category data. Please do not include such data in comments.
3. How we use your information and legal bases
| Purpose | GDPR legal basis |
|---|---|
| Provide the Service (sign-in, dashboard, follows) | Performance of a contract |
| Engagement features (comments, likes, follows) | Performance of a contract |
| Newsletters | Consent (withdrawable anytime) |
| Notifications & match alerts | Consent / legitimate interests |
| Analytics | Consent (where required) / legitimate interests |
| Security & abuse prevention | Legitimate interests / legal obligation |
4. How we share information (processors)
We do not sell your personal information. We share it only with service providers under appropriate agreements: Supabase (database, authentication, storage), Vercel (hosting), Resend (email delivery), [Analytics provider] (privacy-focused analytics), and API-Football (football data source; we do not share your personal data with them). We may also disclose information where required by law or to protect users and the public.
5. International data transfers
The Service and our providers may process data in the United States and other countries. For EU/UK/EEA residents, international transfers rely on appropriate safeguards such as Standard Contractual Clauses.
6. Data retention
We keep account and engagement data while your account is active (deleted or anonymized on deletion); newsletter subscriptions until you unsubscribe; and logs for a limited period for security and operations.
7. Your rights
EU/UK/EEA (GDPR): access, rectification, erasure, restriction, objection, portability, and withdrawal of consent at any time; and the right to lodge a complaint with your supervisory authority.
California (CCPA/CPRA): the right to know, access, delete, and correct your information, and to opt out of "sale"/"sharing" — though we do not sell or share your personal information for cross-context behavioral advertising. We will not discriminate against you for exercising your rights.
To exercise any right, email privacy@footpulse.news. You can manage preferences in your account and unsubscribe from any email via its footer link.
8. Security
We use measures including encryption in transit, access controls, and Row-Level Security on user data. No method is 100% secure, and we cannot guarantee absolute security.
9. Children's privacy
The Service is not directed to children under [16 / age of digital consent], and we do not knowingly collect their data. Contact privacy@footpulse.news if you believe a child provided us data.
10. Changes to this Policy
We may update this Policy and will post the new version with an updated date. Continued use means you accept the changes.
11. Contact
privacy@footpulse.news — [LEGAL ENTITY NAME], [OPERATOR ADDRESS].