← Back to home

Privacy Policy

Last updated: 15 July 2026

This policy explains how Coremembers collects, uses, stores and protects your personal data when you use our mobile app and website corememberz.com, a marketplace for booking sports sessions.

1. Data controller

The controller of personal data is:

In the absence of a designated Data Protection Officer (DPO), any request regarding your data is handled directly by the controller at privacy@coremembers.com.

2. Data collected and purposes

Depending on how you use the Service, we may process:

  • Identity: first name, last name, profile photo
  • Contact: email address
  • Location: city (and, if you allow it, approximate position to show nearby sessions)
  • Account: user ID, preferences, organizer status
  • Sports activity: registrations, waitlist, reviews, favourites, participation history
  • Payment: amounts, transaction status, Stripe identifiers (we do not store full bank details)
  • Communications: messages to support or an organizer
  • Technical: device type, OS, push notification tokens, technical logs

This data is used notably to:

  • create and manage your account;
  • enable discovery, booking and management of sports sessions;
  • process payments via Stripe;
  • send confirmations, reminders and Service-related notifications;
  • ensure security, fraud prevention and user support;
  • comply with our legal and accounting obligations.

3. Legal basis for each processing activity

Under the GDPR, each processing activity relies on a legal basis:

TraitementBase légale
Account creation, authentication, profilePerformance of contract (Art. 6.1.b GDPR)
Session booking and managementPerformance of contract
Payment for paid sessionsPerformance of contract and legal obligation (accounting)
Booking notifications and remindersPerformance of contract and legitimate interest (Art. 6.1.f)
Showing sessions near youPerformance of contract and, where applicable, consent for geolocation
Security, technical logs, fraud preventionLegitimate interest
Marketing emails (excluding service messages)Consent (Art. 6.1.a), where applicable
Retention of accounting evidence related to paymentsLegal obligation (Art. 6.1.c)

4. Retention period

  • Account data (profile, email, photo, city): for the duration of use of the Service, then deleted within 30 days after an account deletion request, unless a legal obligation requires otherwise.
  • Session and registration history: for the duration of the account, then anonymised or deleted with the account.
  • Payment data: identifiers and statuses kept as long as necessary for the Service and accounting obligations (generally 10 years). Bank details are processed by Stripe under its own policy.
  • Support / contact messages: up to 3 years after the last exchange, unless a dispute is ongoing.
  • Technical and security logs: up to 12 months.

5. Processors and transfers outside the EU

We use providers acting on our behalf. Your data may be shared only for the needs of the Service:

  • Google Firebase (Google LLC, USA): authentication, Firestore, storage, cloud functions, push notifications (FCM), App Check.
  • Stripe, Inc. (USA): secure payment processing and Connect accounts for organizers.
  • SendGrid / Twilio (USA): transactional emails (signup, verification, confirmations).
  • Google Sign-In (where applicable): sign-in via Google account.
  • Vercel Inc. (USA): hosting of the corememberz.com website.

Some providers are located in the United States. Transfers are governed by GDPR-recognised safeguards, including the European Commission's Standard Contractual Clauses (SCC) and, where applicable, the EU-US Data Privacy Framework when the provider participates.

Your data is never sold to third parties for advertising purposes.

6. Your rights (GDPR)

Under the General Data Protection Regulation, you have the following rights:

  • Right of access: obtain a copy of your data
  • Right to rectification: correct inaccurate data
  • Right to erasure ('right to be forgotten')
  • Right to restriction of processing
  • Right to object to processing based on legitimate interest
  • Right to data portability in a structured format
  • Right to withdraw consent at any time when processing is based on consent
  • Right to define directives regarding your data after death (France)

7. How to exercise your rights

To exercise any of these rights, contact us with your request and, if possible, the email address linked to your account. We may ask for proof of identity if there is reasonable doubt. privacy@coremembers.com

You can also delete your account from the app (Account settings → Delete my account).

If, after contacting us, you believe your rights are not being respected, you may lodge a complaint with the CNIL. www.cnil.fr.

8. Cookies and trackers

Mobile app: Coremembers does not use advertising cookies. Technical identifiers (session tokens, notifications) are required for the Service to work.

Website corememberz.com: we do not use third-party advertising or analytics cookies. Only strictly necessary cookies or local storage may be used (e.g. language preference). If non-essential trackers were added, your prior consent would be collected.

9. Data security

We implement appropriate technical and organisational measures: encrypted communications (HTTPS/TLS), secure authentication, Firestore access rules, limited access to sensitive data (e.g. Stripe accounts), server-side error logging.

No system is infallible; please protect your credentials and report any suspected unauthorised access.

10. Changes to this policy

We may update this policy to reflect changes to the Service or regulations. The 'Last updated' date at the top will be amended accordingly. In case of a material change, we will inform you by an appropriate means (in-app notification or email).

Official URL of this policy:

https://corememberz.com/fr/confidentialite