PRIVACY POLICY
Version 2.0 of July 27, 2026, replaces the version of March 12, 2026. English translation provided for convenience; only the French version is authoritative.
1. Who we are
The Smatchy mobile application and the website smatchy.app (together, "Smatchy") are published by LBDC Organisation, a French simplified joint-stock company (SAS) registered with the Annecy Trade and Companies Register under number 839 338 514, with its registered office at 5 rue de l'Industrie, 74000 Annecy, France.
LBDC Organisation is the data controller for the processing described in this policy. For any question or request regarding your data: donneespersonnelles@smatchy.app.
2. Who this policy applies to
It applies to anyone who uses the Smatchy application (activity participants and organizers), visits smatchy.app, contacts us through our forms or social networks, subscribes to our communications, or applies for a position with us.
3. The data we collect
Account and sports profile data. When you create your account: name or username, e-mail address, password, declaration of legal age (checkbox certifying you are 18 or older), profile picture where applicable, and your sports profile: sports practiced, level per sport, preferences and availability. Your profile and activities are visible to other users, that is the point of the service.
Geolocation. With your permission (requested by your phone), the application uses your device's position to suggest activities and partners near you, within the search radius you choose. You can withdraw this permission at any time in your device settings; the application remains usable by manually entering a city. We keep a history of your positions to operate the service and improve the relevance of recommendations, for as long as your account exists. The locations of activities you join are stored with the activity.
Recommendations. Smatchy recommends activities and partners using an algorithm based on your sports, level, availability and location. These recommendations only personalize the content shown to you; they produce no decision with legal effect on you.
Messaging and groups. The content of the messages you exchange (private messaging and groups) is stored to provide the service. These exchanges are not systematically monitored; they may be reviewed by our teams following a report of content or behaviour contrary to our terms of use, or upon request from an authority.
Activities. The activities you create or join: sport, date, location, level, participants, history.
Payments and organizer documents. Payments for paid activities are processed by our payment service provider Stripe; Smatchy never stores your card numbers. For professional organizers, we collect the documents required by our Terms of Sale (diploma or professional card, Kbis extract or RNA receipt, federal licence, professional liability insurance certificate, SIRET number), and Stripe collects the identification and account information needed for payouts.
Notifications. To send you notifications (new participation request, message received, activity reminder…), we process your device's technical identifier and your notification preferences, which you can change at any time in the application or your phone settings.
Technical and audience measurement data. Technical logs required for the security and proper operation of the service. On the website, audience measurement cookies (Google Analytics) are used only with your consent, see our Cookie Policy.
Forms. The information you submit through our forms (contact, pre-registration): name, e-mail, subject and message content.
4. Why we use your data, and on what legal basis
- Providing the Smatchy service (account, profile, matching, recommendations, messaging, activities, service notifications): performance of the contract (Terms of Use).
- Processing payments and payouts (payment for an activity, organizer wallet, verification of professional documents): performance of the contract; legal obligations (anti-fraud, accounting).
- Geolocating your searches (nearby activities and partners): consent (device permission), withdrawable at any time.
- Securing the service (fraud prevention, handling of reports, moderation upon report): legitimate interest (safety of users and of the service).
- Communicating with you (responses to your requests, information about the service and its changes): performance of the contract; legitimate interest.
- Sending you marketing communications (newsletter, offers, unsubscribe available in every message): consent.
- Measuring website audience (visit statistics, Google Analytics): consent (cookie banner).
- Complying with our legal obligations (accounting, tax, including reporting of organizers' income, legal requests): legal obligation.
- Handling job applications (review of applications, interviews): pre-contractual measures.
5. Who has access to your data
- Other users: your profile (username, picture, sports, level) and the activities you create or join are visible to other users. The organizer of an activity sees the list of registered participants.
- Stripe (payment service provider) for transactions and payouts to organizers.
- Our hosting and technical providers: MongoDB Atlas (application database, hosted in the European Union, in Frankfurt), Amazon Web Services (hosting of the smatchy.app website, on servers located in Paris, and image storage), acting as processors.
- Google (website audience measurement, if you have consented).
- Brevo (e-mail delivery provider) for messages relating to the smatchy.app website, our service e-mails and, if you have consented, our marketing communications and information lists.
- SendGrid (e-mail delivery provider) for the messages and notifications sent by the Smatchy app.
- Notion (tool we use to track our exchanges) when you send us a request relating to our fundraising round: your name, your e-mail address, your LinkedIn profile where applicable and the information you send us are recorded there so that we can review your request and follow it up.
- Our advisers and contractual partners (accountants, lawyers, insurers) where necessary, and the authorities where required by law (notably the tax administration under platform reporting obligations, and judicial authorities upon request).
We do not sell your data to anyone and do not pass it to any third party for their own marketing purposes.
6. Transfers outside the European Union
Your data is hosted in the European Union. Some of our providers are, however, US companies (Google, Amazon Web Services, MongoDB Inc., Stripe, Notion Labs, Twilio SendGrid): where a transfer outside the EU occurs, it is governed by the safeguards provided by the GDPR, the European Commission's standard contractual clauses and, for certified providers, the EU–US Data Privacy Framework. You can obtain a copy of these safeguards by writing to donneespersonnelles@smatchy.app.
7. How long we keep your data
- Account and profile: until you delete your account, and at the latest 10 years after your last activity.
- Messages (messaging and groups): until account deletion, and at the latest 10 years after the last activity.
- Geolocation history: until account deletion, and at the latest 10 years after the last activity.
- Payment data: 13 months (banking data, held by Stripe); 10 years for accounting documents (invoices).
- Organizer documents (diplomas, Kbis, insurance…): duration of the contractual relationship + 5 years.
- Technical logs: 6 to 12 months.
- Contact forms: 1 year after the request is closed.
- Prospects (newsletter, pre-registration): 3 years after last contact.
- Job applications: 2 years after last contact.
- Reports and sanctioned accounts: time needed for processing, then archiving for the applicable limitation period.
Inactive accounts are in any event deleted, together with all associated data (profile, messages, geolocation history), at the latest 10 years after the last activity.
8. Your rights
You have the rights of access, rectification, erasure, restriction, objection and portability, the right to set instructions regarding your data after your death, and the right to withdraw consent at any time. To exercise them: donneespersonnelles@smatchy.app (or directly in the application for most profile information). We respond within one month, extendable by two months for complex requests. If you believe your rights are not being respected, you may lodge a complaint with the French supervisory authority, the CNIL (3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 – www.cnil.fr).
9. Minors
Smatchy is restricted to adults. Each user declares that they are 18 or older when creating their account; this declaration is their own responsibility, as Smatchy does not carry out systematic identity verification. We do not knowingly collect data about minors: if we discover, or are informed, that an account belongs to a minor, the account and associated data are deleted. Reports can be sent to support@smatchy.app.
10. Security
We implement appropriate technical and organizational measures: encrypted communications (HTTPS), access control to the database, hosting in the European Union, payment handling segregated with our authorized provider. As no system is infallible, we recommend using a strong, unique password and never sharing your credentials.
11. Changes to this policy
Each version of this policy has a number and a date. In the event of a substantial change (new purpose, new recipient, change of retention period), we will inform you by e-mail or in-app notification before it takes effect. The version history is available on request.
Version 2.0 of July 27, 2026 · Complete overhaul: description of the application's actual processing (geolocation, recommendations, messaging, notifications, payments), updated recipients and transfers, minors section, introduction of versioning. Replaces the version of March 12, 2026.