Privacy Policy
Last updated: 2026-07-31
1. Who we are
Paddy is operated by Thomas Di Benedetto (the "controller"). The service runs at getpaddy.app and in the Paddy mobile app for Android and iOS. For any privacy question, contact hello@getpaddy.app.
2. What we collect
Phone number (used to identify your account, send sign-in codes, and send game invites and updates). Name (shown in your groups and games). Email — only if you provide it — used for game notifications and, if you opt in, product news. Your availability, club preferences and court side, to organise games. Technical metadata (IP address, user agent, timestamps) tied to consent and authentication events. A push notification token for each device where you turn notifications on. Usage and diagnostic data about how the service is used — see "Analytics and session recording" below.
3. Why we use it
To run the service you signed up for: invites, notifications, organising games. To prove consent and prevent abuse. To understand how the service is used and to diagnose faults. To send product news only if you ticked the opt-in box.
4. Legal basis (GDPR)
Phone, name, availability and game-related notifications: performance of contract (Art. 6(1)(b)). Product-news email marketing: your consent (Art. 6(1)(a)). Consent and security logs: legal obligation and our legitimate interest in preventing abuse (Art. 6(1)(c) and (f)). Usage analytics, error reports and session recordings: our legitimate interest in operating and improving the service (Art. 6(1)(f)).
5. Sharing
We use Twilio (SMS sign-in codes and game updates), Resend (email notifications), PostHog (usage analytics and error reporting, on its EU instance), Expo (delivery of push notifications, which pass through Apple and Google push services), Cloudflare R2 (encrypted backups), and a European VPS provider for hosting. These act as our processors. We do not sell your data and do not share it with advertisers.
6. International transfers
Your data is hosted in the EU where possible, including PostHog's EU instance. Twilio and Resend are US-based and operate under EU Standard Contractual Clauses. Push notifications are delivered through Expo, Apple and Google, which are US-based.
7. Retention
Account data is kept while your account is active. Deleting your account removes it immediately — there is no recovery window. Consent records are kept for 5 years after withdrawal, as recommended by CNIL guidance, unless you delete your account, in which case they are removed with it. Sign-in codes are deleted within 24 hours.
8. Your rights
You have the right to access, correct, delete, restrict, port, or object to the processing of your data, and to withdraw consent at any time. You can delete your account yourself at any time from Settings → Account → Delete account; see /legal/delete-account for what that removes. For anything else, email hello@getpaddy.app — we respond within 30 days. You may also lodge a complaint with the CNIL (France), CNPD (Portugal) or AEPD (Spain).
9. Analytics and session recording
On the website we use PostHog to record page views, errors and session replays — a reconstruction of your visit showing the pages you open and where you click. Text you type into form fields is masked before the recording leaves your browser. An analytics profile is only created once you sign in; before that, activity is not linked to an account. In the mobile app PostHog is limited to diagnostic events about push notification registration: it stores no identifier on your device and does not record sessions.
10. Cookies
We use two first-party cookies. `pp-session`: a strictly necessary session token set at sign-in and deleted on sign-out. `pp-locale`: a preference cookie that stores your chosen language, set at sign-in and updated when you change language in Settings. PostHog sets its own cookies on the website to recognise your browser across page views. No advertising cookies. The mobile app uses no cookies — your session token and appearance preference are held in the device secure storage.
11. Security
Data is encrypted in transit (TLS) and backups are encrypted at rest. Server access is restricted. We do not store secrets in plain text.
12. Changes
We may update this policy. The effective date at the top of this page shows the current version. Material changes will be notified by email or in-app.