PRIVACY POLICY
How we handle your data.
Last updated: June 1, 2026
This policy applies to 38Matches PMA and the platforms operated at 38matches.club and app.38matches.club. Legal review by Freedom Group is pending — the current version reflects our operating practice.
- 01
Data we collect
Only the minimum operational data: membership email, account identifiers, membership tier (Striker / Match / Founding 38), content you post inside the platform, access/security logs to prevent abuse, moderation reports. We do NOT collect advertising trackers, third-party behavior profiles, or usage metadata for sale.
- 02
Legal bases (GDPR · LFPDPPP)
Private membership association contract (PMA): processing is necessary to deliver the service. Annual donations: contractual necessity + legal (tax) obligation. Security communications: legitimate interest in protecting members.
- 03
Who accesses your data
Internal personnel under least-privilege principle (staff role in Supabase RLS). Subprocessors: Supabase (storage + auth), Stripe (payments), Cloudflare (CDN + WAF), Resend or equivalent (email). All bound by standard DPAs conforming to GDPR Art. 28.
- 04
Your rights
You can request: (a) export of your data (GDPR Art. 20 · right to portability), (b) deletion of your account and data (Art. 17 · right to erasure), (c) correction of inaccurate information, (d) restriction of processing. Send requests to [email protected]. We respond within 30 days.
- 05
Retention
Active membership data: while you are a member. Rejected applications: 12 months, then deleted. Voluntarily deleted accounts: immediate soft-delete, hard-delete after 30 days. Tax-obligation data (donations): 5 years. Security logs: 90 days.
- 06
International transfers
Your data may be stored in the United States (Supabase US-East). This transfer is governed by EU Standard Contractual Clauses and by data-protection guarantees equivalent to Mexico under LFPDPPP.
- 07
Cookies and trackers
We use cookies strictly necessary for authentication (Supabase session). We do not use marketing cookies, third-party analytics, or advertising trackers. We do not use Google Analytics, Facebook Pixel, or similar services.
- 08
Security
TLS in transit (including post-quantum hybrid encryption via Cloudflare since 2024). Encryption at rest in Supabase. Row-Level Security for per-member data isolation. Magic-link authentication (no reusable passwords). Audit logs for administrative actions.
- 09
Changes to this policy
We will notify material changes inside the platform with at least 30 days notice. Minor changes (grammatical corrections, clarifications) will be posted without notice.
- 10
Contact
Privacy: [email protected] · Security: [email protected] · Legal: [email protected] · Address: 38Matches PMA, Wyoming USA.