← Back

PRIVACY POLICY

How we handle your data.

Last updated: June 1, 2026

This policy applies to 38Matches PMA and the platforms operated at 38matches.club and app.38matches.club. Legal review by Freedom Group is pending — the current version reflects our operating practice.

  1. 01

    Data we collect

    Only the minimum operational data: membership email, account identifiers, membership tier (Striker / Match / Founding 38), content you post inside the platform, access/security logs to prevent abuse, moderation reports. We do NOT collect advertising trackers, third-party behavior profiles, or usage metadata for sale.

  2. 02

    Legal bases (GDPR · LFPDPPP)

    Private membership association contract (PMA): processing is necessary to deliver the service. Annual donations: contractual necessity + legal (tax) obligation. Security communications: legitimate interest in protecting members.

  3. 03

    Who accesses your data

    Internal personnel under least-privilege principle (staff role in Supabase RLS). Subprocessors: Supabase (storage + auth), Stripe (payments), Cloudflare (CDN + WAF), Resend or equivalent (email). All bound by standard DPAs conforming to GDPR Art. 28.

  4. 04

    Your rights

    You can request: (a) export of your data (GDPR Art. 20 · right to portability), (b) deletion of your account and data (Art. 17 · right to erasure), (c) correction of inaccurate information, (d) restriction of processing. Send requests to [email protected]. We respond within 30 days.

  5. 05

    Retention

    Active membership data: while you are a member. Rejected applications: 12 months, then deleted. Voluntarily deleted accounts: immediate soft-delete, hard-delete after 30 days. Tax-obligation data (donations): 5 years. Security logs: 90 days.

  6. 06

    International transfers

    Your data may be stored in the United States (Supabase US-East). This transfer is governed by EU Standard Contractual Clauses and by data-protection guarantees equivalent to Mexico under LFPDPPP.

  7. 07

    Cookies and trackers

    We use cookies strictly necessary for authentication (Supabase session). We do not use marketing cookies, third-party analytics, or advertising trackers. We do not use Google Analytics, Facebook Pixel, or similar services.

  8. 08

    Security

    TLS in transit (including post-quantum hybrid encryption via Cloudflare since 2024). Encryption at rest in Supabase. Row-Level Security for per-member data isolation. Magic-link authentication (no reusable passwords). Audit logs for administrative actions.

  9. 09

    Changes to this policy

    We will notify material changes inside the platform with at least 30 days notice. Minor changes (grammatical corrections, clarifications) will be posted without notice.

  10. 10

    Contact

    Privacy: [email protected] · Security: [email protected] · Legal: [email protected] · Address: 38Matches PMA, Wyoming USA.