Privacy Policy
Last updated: 15 July 2026
This policy explains how Coremembers collects, uses, stores and protects your personal data when you use our mobile app and website corememberz.com, a marketplace for booking sports sessions.
1. Data controller
The controller of personal data is:
- Paulo, founder of Coremembers
- Coremembers, sole proprietorship · Registered office: Paris, France · RCS Paris · Email: contact@corememberz.com
- Privacy contact: privacy@coremembers.com
- General contact: contact@corememberz.com
In the absence of a designated Data Protection Officer (DPO), any request regarding your data is handled directly by the controller at privacy@coremembers.com.
2. Data collected and purposes
Depending on how you use the Service, we may process:
- Identity: first name, last name, profile photo
- Contact: email address
- Location: city (and, if you allow it, approximate position to show nearby sessions)
- Account: user ID, preferences, organizer status
- Sports activity: registrations, waitlist, reviews, favourites, participation history
- Payment: amounts, transaction status, Stripe identifiers (we do not store full bank details)
- Communications: messages to support or an organizer
- Technical: device type, OS, push notification tokens, technical logs
This data is used notably to:
- create and manage your account;
- enable discovery, booking and management of sports sessions;
- process payments via Stripe;
- send confirmations, reminders and Service-related notifications;
- ensure security, fraud prevention and user support;
- comply with our legal and accounting obligations.
3. Legal basis for each processing activity
Under the GDPR, each processing activity relies on a legal basis:
| Traitement | Base légale |
|---|---|
| Account creation, authentication, profile | Performance of contract (Art. 6.1.b GDPR) |
| Session booking and management | Performance of contract |
| Payment for paid sessions | Performance of contract and legal obligation (accounting) |
| Booking notifications and reminders | Performance of contract and legitimate interest (Art. 6.1.f) |
| Showing sessions near you | Performance of contract and, where applicable, consent for geolocation |
| Security, technical logs, fraud prevention | Legitimate interest |
| Marketing emails (excluding service messages) | Consent (Art. 6.1.a), where applicable |
| Retention of accounting evidence related to payments | Legal obligation (Art. 6.1.c) |
4. Retention period
- Account data (profile, email, photo, city): for the duration of use of the Service, then deleted within 30 days after an account deletion request, unless a legal obligation requires otherwise.
- Session and registration history: for the duration of the account, then anonymised or deleted with the account.
- Payment data: identifiers and statuses kept as long as necessary for the Service and accounting obligations (generally 10 years). Bank details are processed by Stripe under its own policy.
- Support / contact messages: up to 3 years after the last exchange, unless a dispute is ongoing.
- Technical and security logs: up to 12 months.
5. Processors and transfers outside the EU
We use providers acting on our behalf. Your data may be shared only for the needs of the Service:
- Google Firebase (Google LLC, USA): authentication, Firestore, storage, cloud functions, push notifications (FCM), App Check.
- Stripe, Inc. (USA): secure payment processing and Connect accounts for organizers.
- SendGrid / Twilio (USA): transactional emails (signup, verification, confirmations).
- Google Sign-In (where applicable): sign-in via Google account.
- Vercel Inc. (USA): hosting of the corememberz.com website.
Some providers are located in the United States. Transfers are governed by GDPR-recognised safeguards, including the European Commission's Standard Contractual Clauses (SCC) and, where applicable, the EU-US Data Privacy Framework when the provider participates.
Your data is never sold to third parties for advertising purposes.
6. Your rights (GDPR)
Under the General Data Protection Regulation, you have the following rights:
- Right of access: obtain a copy of your data
- Right to rectification: correct inaccurate data
- Right to erasure ('right to be forgotten')
- Right to restriction of processing
- Right to object to processing based on legitimate interest
- Right to data portability in a structured format
- Right to withdraw consent at any time when processing is based on consent
- Right to define directives regarding your data after death (France)
7. How to exercise your rights
To exercise any of these rights, contact us with your request and, if possible, the email address linked to your account. We may ask for proof of identity if there is reasonable doubt. privacy@coremembers.com
You can also delete your account from the app (Account settings → Delete my account).
If, after contacting us, you believe your rights are not being respected, you may lodge a complaint with the CNIL. www.cnil.fr.
8. Cookies and trackers
Mobile app: Coremembers does not use advertising cookies. Technical identifiers (session tokens, notifications) are required for the Service to work.
Website corememberz.com: we do not use third-party advertising or analytics cookies. Only strictly necessary cookies or local storage may be used (e.g. language preference). If non-essential trackers were added, your prior consent would be collected.
9. Data security
We implement appropriate technical and organisational measures: encrypted communications (HTTPS/TLS), secure authentication, Firestore access rules, limited access to sensitive data (e.g. Stripe accounts), server-side error logging.
No system is infallible; please protect your credentials and report any suspected unauthorised access.
10. Changes to this policy
We may update this policy to reflect changes to the Service or regulations. The 'Last updated' date at the top will be amended accordingly. In case of a material change, we will inform you by an appropriate means (in-app notification or email).
Official URL of this policy:
https://corememberz.com/fr/confidentialite