PedalaPlay Privacy Policy
Review-ready privacy scaffold covering identity, membership, payment state, attendance, communication preferences, and provider integrations.
Document status
This policy scaffold is not final legal advice. It must be reviewed and approved before public paid acquisition or production-scale use.
It reflects the current architecture: Supabase Auth for identity and PedalaPlay API for business data.
Data categories
PedalaPlay may process these categories to operate the service:
- Account and identity data such as email, authentication status, profile name, and preferred language.
- Arena, group, membership, subscription, billing-cycle, attendance, and RSVP data.
- Payment and provider status needed to confirm access, without storing card details in PedalaPlay.
- Communication preferences, phone number for WhatsApp reminders when opted in, and delivery/fallback logs.
- Operational logs, security/audit data, and support notes needed to keep the service reliable.
How data is used
Data is used to authenticate users, separate organizer/player roles, operate groups, process payment state, confirm attendance, and provide support.
Marketing consent must be separate from transactional communication and should not be assumed from account creation.
Providers and integrations
Supabase Auth handles identity. Stripe and Pagar.me may process payments. Discord may support community access. WhatsApp may send transactional reminders only after opt-in and readiness checks.
Provider secrets and low-level identifiers must stay server-side or in explicit operator-only diagnostics, not normal user-facing pages.
Access, correction, deletion, and export
A production policy must define how users can request access, correction, deletion, or export of their personal data under applicable law.
For private beta, this can start as a manual support process if the process is documented and tracked.
Retention and deletion
Retention rules must distinguish active account data, payment/access audit records, communication logs, provider payloads, and future venue intelligence records.
Before public launch
PedalaPlay must replace review placeholders with approved legal copy, keep payment/provider wording aligned with the current runtime, and update these pages whenever launch scope changes.