Privacy Policy
Last updated: 15 July 2026
This policy explains how Coremembers collects, uses, stores and protects your personal data when you use our mobile app and website corememberz.com, a marketplace for booking sports sessions.
1. Data controller
The controller of personal data is:
- Paulo, founder of Coremembers
- Coremembers, sole proprietorship · Registered office: Paris, France · RCS Paris · Email: contact@corememberz.com
- Privacy contact: contact@corememberz.com
- General contact: contact@corememberz.com
In the absence of a designated Data Protection Officer (DPO), any request regarding your data is handled directly by the controller at contact@corememberz.com.
2. Data collected and purposes
Depending on how you use the Service, we may process:
- Identity: first name, last name, profile photo
- Contact: email address
- Location: city (and, if you allow it, approximate position to show nearby sessions)
- Account: user ID, preferences, organizer status
- Sports activity: registrations, waitlist, reviews, favourites, participation history
- Communications: messages to support or an organizer
- Technical: device type, OS, push notification tokens, technical logs
This data is used notably to:
- create and manage your account;
- enable discovery, booking and management of sports sessions;
- send confirmations, reminders and Service-related notifications;
- ensure security, fraud prevention and user support;
- comply with our legal obligations.
3. Legal basis for each processing activity
Under the GDPR, each processing activity relies on a legal basis:
| Traitement | Base légale |
|---|---|
| Account creation, authentication, profile | Performance of contract (Art. 6.1.b GDPR) |
| Session booking and management | Performance of contract |
| Booking notifications and reminders | Performance of contract and legitimate interest (Art. 6.1.f) |
| Showing sessions near you | Performance of contract and, where applicable, consent for geolocation |
| Security, technical logs, fraud prevention | Legitimate interest |
| Marketing emails (excluding service messages) | Consent (Art. 6.1.a), where applicable |
4. Retention period
- Account data (profile, email, photo, city): for the duration of use of the Service, then deleted within 30 days after an account deletion request, unless a legal obligation requires otherwise.
- Session and registration history: for the duration of the account, then anonymised or deleted with the account.
- Support / contact messages: up to 3 years after the last exchange, unless a dispute is ongoing.
- Technical and security logs: up to 12 months.
5. Processors and transfers outside the EU
We use providers acting on our behalf. Your data may be shared only for the needs of the Service:
- Google Firebase (Google LLC, USA): authentication, Firestore, storage, cloud functions, push notifications (FCM), App Check.
- SendGrid / Twilio (USA): transactional emails (signup, verification, confirmations).
- Google Sign-In (where applicable): sign-in via Google account.
- Vercel Inc. (USA): hosting of the corememberz.com website.
Some providers are located in the United States. Transfers are governed by GDPR-recognised safeguards, including the European Commission's Standard Contractual Clauses (SCC) and, where applicable, the EU-US Data Privacy Framework when the provider participates.
Your data is never sold to third parties for advertising purposes.
6. Your rights (GDPR)
Under the General Data Protection Regulation, you have the following rights:
- Right of access: obtain a copy of your data
- Right to rectification: correct inaccurate data
- Right to erasure ('right to be forgotten')
- Right to restriction of processing
- Right to object to processing based on legitimate interest
- Right to data portability in a structured format
- Right to withdraw consent at any time when processing is based on consent
- Right to define directives regarding your data after death (France)
7. How to exercise your rights
To exercise any of these rights, contact us with your request and, if possible, the email address linked to your account. We may ask for proof of identity if there is reasonable doubt. contact@corememberz.com
You can also delete your account from the app (Account settings → Delete my account).
If, after contacting us, you believe your rights are not being respected, you may lodge a complaint with the CNIL. www.cnil.fr.
8. Cookies and trackers
Mobile app: Coremembers does not use advertising cookies. Technical identifiers (session tokens, notifications) are required for the Service to work.
Website corememberz.com: we do not use third-party advertising or analytics cookies. Only strictly necessary cookies or local storage may be used (e.g. language preference). If non-essential trackers were added, your prior consent would be collected.
9. Data security
We implement appropriate technical and organisational measures: encrypted communications (HTTPS/TLS), secure authentication, Firestore access rules, limited access to personal data, server-side error logging.
No system is infallible; please protect your credentials and report any suspected unauthorised access.
10. Changes to this policy
We may update this policy to reflect changes to the Service or regulations. The 'Last updated' date at the top will be amended accordingly. In case of a material change, we will inform you by an appropriate means (in-app notification or email).
Official URL of this policy:
https://corememberz.com/fr/confidentialite