Legal information

Privacy notice

Last updated: July 15, 2026

1. Who is responsible

The controller responsible for processing personal data in Padel Turni is:

Asad Ullah Khalid
Mertensstr. 13c
13587 Berlin
Germany
Email: asadkhalid305@gmail.com

Padel Turni is a privately operated, free recreational project. It does not offer subscriptions, display advertising, or sell personal data.

2. Data processed by Padel Turni

The service processes only the data needed to operate its features:

  • Google account ID, name, and email address when you sign in;
  • club memberships, roles, invitations, and the active club you select;
  • player names, ratings, account links, availability, and active status entered by club organizers;
  • event details, venues, draws, timers, match scores, standings, and event history;
  • contact messages and an optional reply email address; and
  • coarse product events such as opening the landing page, creating an event, accepting an invitation, or submitting feedback. These events may contain an internal user or club ID and limited non-sensitive metadata, but not invite tokens, player names, or match scores.
  • short-lived pseudonymous request keys used to limit repeated landing views and feedback attempts. These keys are derived from the request address with a server-only secret; the raw address is not stored in analytics or rate-limit rows.

Hosting and security providers may also process technical request data such as IP address, browser information, timestamps, and server logs when you access the service.

3. Purposes and legal bases

Personal data is processed for the following purposes:

  • providing accounts, private clubs, invitations, tournaments, standings, and requested emails under Article 6(1)(b) GDPR;
  • protecting the service, diagnosing errors, and understanding whether its core features work under Article 6(1)(f) GDPR. The legitimate interest is operating and improving a reliable free service; and
  • replying to contact, privacy, or deletion requests under Article 6(1)(b), 6(1)(c), or 6(1)(f) GDPR, depending on the request.

There is no advertising profiling and no automated decision-making with legal or similarly significant effects.

4. Google sign-in

Padel Turni uses Google OAuth through Supabase Auth. When you choose Google sign-in, Google authenticates you and provides the account ID, name, and email address needed to create or access your Padel Turni account. Google processes the sign-in interaction under its own privacy policy. Padel Turni does not receive your Google password, contacts, or friends list.

5. Service providers and transfers

The following providers process data only where needed to deliver the service:

  • Supabase for authentication and database storage;
  • Vercel for application hosting and operational logs;
  • Google for optional Google sign-in; and
  • Resend for contact messages and final-standings emails.

These providers may process data outside the European Economic Area. Where required, transfers are covered by an adequacy decision, Standard Contractual Clauses, or another legally recognized safeguard. Their own privacy notices describe their processing in more detail.

6. Cookies and local preferences

Padel Turni uses only cookies needed for Google authentication, keeping a session active, and remembering the active club. These are necessary to provide the requested service. Padel Turni does not use advertising cookies or third-party marketing trackers, so no marketing cookie banner is shown.

7. Who can see club data

Club members can see the roster, events, scores, standings, and history belonging to clubs they have joined. Club owners and admins can manage membership, invitations, players, and account links. Do not enter information about another person unless it is appropriate to share it with the members of that club.

8. Retention and deletion

Account, club, player, and event data is retained while it is needed to provide the service and preserve the event history requested by the club. Contact messages and delivery records are retained while they are needed to answer the request, diagnose a problem, or confirm email delivery. Coarse product events are retained for 90 days.

Data is deleted or anonymized when it is no longer needed, when the project is discontinued, or following a valid deletion request, unless a legal obligation or overriding legitimate reason requires limited further retention. Expired rate-limit keys are removed by a daily cleanup. Provider backups and security logs may remain for their normal restricted retention periods.

9. Your rights

Subject to the conditions in the GDPR, you may request access, correction, deletion, restriction, or portability of your personal data. You may object to processing based on legitimate interests and withdraw consent where processing relies on consent. Withdrawal does not affect processing that was lawful before it.

Send a request through the contact form or email asadkhalid305@gmail.com. You also have the right to complain to a data protection authority. The authority responsible for Berlin is the Berlin Commissioner for Data Protection and Freedom of Information.

10. Changes to this notice

This notice will be updated when the service starts processing data differently, adds another provider, or changes in a way that affects the information above. The current revision date appears at the top of this page.

See also the Terms of Service.