Back to home

Privacy Policy

GDPR-compliant · EU AI Act-compliant

Last updated: 30 September 2026

1. Data controller

Richi AI, Owner: Yves-Marcel Richel. Homburger Landstraße 851, 60437 Frankfurt am Main, Germany. Email: info@richi.solutions. Website: https://padelleague.ai

2. Data protection contact

For data protection inquiries: info@richi.solutions

3. AI usage (EU AI Act)

PadelLeague uses AI systems in accordance with Regulation (EU) 2024/1689 (EU AI Act) and the GDPR.

Areas of AI use: (1) AI-generated decorative imagery for static marketing pages (format guide, getting-started guide, FAQ) via Google Gemini through fal.ai — only admin-defined text prompts are sent, no user data. (2) Classification of padel clubs in the club-discovery feature via the Google Gemini API — only public business/venue signals are sent (club name, type, web signals); no personal data of platform users. No account profile data is sent to any of these AI services.

Risk category: Low risk.

Compliance notes: No fully automated decision-making with legal or significant effects takes place (Art. 22 GDPR, Art. 86 EU AI Act). AI-generated content is labeled as such (Art. 50 EU AI Act). User data is not used to train external AI models.

Your AI-related rights: Right to human review of automated decisions, right to explanation of the logic behind AI recommendations, right to object to AI-based processing (Art. 21 GDPR).

4. Data categories

We process the following data categories: contact data (name, email, display name), technical data (IP address, browser, device, operating system, pages visited), tournament data (tournament participations, results, rankings, player profiles), communication data (content of direct messages between users, sender, recipient, timestamp), payment data (Stripe customer ID, subscription status – no credit card data). Optional profile fields (provided voluntarily): skill level, gender, year of birth, and — only if you opt in — birth month and day. Year of birth is used only to show an approximate age on your public player profile; birth month and day are used only to unlock optional birthday-themed achievement banners. All of these fields are optional and can be cleared at any time.

5. Legal basis

Your data is processed on the following legal bases: performance of contract (Art. 6(1)(b) GDPR) for the provision of our services, legitimate interests (Art. 6(1)(f) GDPR) for the technical maintenance and improvement of our services, consent (Art. 6(1)(a) GDPR) for optional features such as newsletters.

6. Hosting

PadelLeague is hosted by Vercel Inc. (USA). The database and authentication are operated via Supabase Inc. (EU region). For data transfers to the USA, Standard Contractual Clauses (SCC) and/or adequacy decisions (EU-US Data Privacy Framework) are in place.

7. Data processors (Art. 28 GDPR)

Supabase Inc. – database, authentication, serverless functions, storage (EU region). Vercel Inc. – frontend hosting and web analytics (USA, EU-US DPF). Vercel Analytics is cookie-free and uses no personal identifiers; only anonymised aggregate statistics are processed (page views per path, coarse device type, approximate region). Stripe Payments Europe Ltd. (incl. Stripe Connect) – payment processing for subscriptions and league/tournament entry fees, and payouts to partner organisers (Ireland, with US sub-processing via EU-US DPF and SCCs). Stripe processes name, email, payment data (card/IBAN), billing address and transaction history; for partner organisers additionally identity-verification (KYC) data collected by Stripe directly. We store only Stripe customer/account IDs and status — no card data. Resend Inc. – delivery of transactional emails (registration confirmations, season reminders, refund notices); recipient address and email content are transmitted for delivery (USA, EU-US DPF). Mapbox Inc. – location autocomplete and geocoding for tournament/league venue input (USA, EU-US DPF). Search queries (text typed by hosts when picking a venue) and IP address are processed by Mapbox solely to return location suggestions; no profile data is shared. Google LLC (Places API) – padel-club discovery; approximate coordinates and the client IP are processed to return nearby clubs (USA, EU-US DPF, Google Cloud DPA). Google LLC (Gemini API) – background classification of clubs in the discovery feature; only public business/venue signals are sent, no platform-user personal data (USA, EU-US DPF). Sentry (Functional Software, Inc.) – frontend error and performance monitoring; sendDefaultPii is disabled and session replay is not used (EU or US depending on project region, EU-US DPF and SCCs). fal.ai Inc. – AI image generation for static marketing pages (USA, EU-US DPF); only admin-defined text prompts are sent — no user data. Google LLC – underlying GPAI model (Gemini), invoked through fal.ai (USA, EU-US DPF). Legal basis: Art. 6(1)(b) GDPR (performance of contract — Stripe and Resend for payment- and service-related processing) and Art. 6(1)(f) GDPR (legitimate interest in audience measurement and product functionality — Vercel, Mapbox, Google, Sentry). All processors are contractually bound to GDPR compliance under Art. 28 data processing agreements. In addition, official/federation tournament listings are ingested from RankedIn ApS as an inbound third-party data source only — no platform-user personal data is sent to RankedIn.

8. Cookies and local storage

PadelLeague uses only technically necessary cookies and local storage: session management, language preferences, authentication status, theme preference (light/dark). No tracking or analytics cookies are used. Legal basis: Art. 6(1)(f) GDPR, § 25 para. 2 TDDDG.

9. Authentication

PadelLeague uses Supabase Auth for authentication. Data processed during authentication: email address, display name, avatar URL. Authentication data is stored securely using Supabase Row-Level Security (RLS). Legal basis: performance of contract (Art. 6(1)(b) GDPR).

10. Payment processing

Should paid features be introduced, payment processing will be handled by Stripe Payments Europe Ltd. (PCI DSS certified). Credit card data is processed exclusively by Stripe and never stored on our servers.

11. Data storage and security

We implement the following technical and organizational measures: encryption of all data transfers (TLS/HTTPS), encryption of stored data at rest (AES-256, via Supabase Postgres), Row-Level Security (RLS) in the database, regular security updates, access control based on the principle of least privilege. Direct messages between users are not end-to-end encrypted; they are stored on our servers in the EU (Ireland) and are accessible only to the respective conversation participants via Row-Level Security.

12. International data transfers

Data transfers to third countries (USA) are based on Standard Contractual Clauses (SCC) and/or adequacy decisions (EU-US Data Privacy Framework) pursuant to Art. 46 GDPR.

13. Data subject rights (GDPR)

You have the following rights: right of access (Art. 15), right to rectification (Art. 16), right to erasure / 'right to be forgotten' (Art. 17), right to restriction of processing (Art. 18), right to object (Art. 21), right to data portability (Art. 20), right to human review of automated decisions (Art. 22 GDPR, Art. 86 EU AI Act), right to lodge a complaint with the competent supervisory authority.

You can exercise the right of access (Art. 15) and erasure (Art. 17) at any time directly in the app under "Profile → My account → Export data" or "Delete account". For all other rights, contact us at info@richi.solutions.

Competent supervisory authority: The Hessian Commissioner for Data Protection and Freedom of Information, Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany.

14. Retention periods

Account data: deletion within 30 days after account deletion. Tax-relevant data: 10 years (§ 147 AO, § 257 HGB). Server logs: max. 90 days. Tournament data: deletion with the associated tournament or upon request. Direct messages: until deletion of the conversation by a participant or until account closure. When a conversation is deleted, all associated messages are permanently removed.

15. Updates

This privacy policy is updated when our services, data processors, or legal requirements change. Significant changes will be communicated to users.

16. Partner Network (affiliate program)

For active Richi Padel Partner Network participants, we additionally process the following data to operate the program: your generated referral code, the attribution of your referrals (referrer ↔ referred user), the calculated commission and bonus amounts, and the payout status. The legal basis is contract performance (Art. 6(1)(b) GDPR) for the Partner subscription and legal obligation (Art. 6(1)(c) GDPR) for commercial and tax retention. Program participants see only aggregated data in their dashboard plus a pseudonymous handle (username or hash) of their referrals — never email addresses or real names of referred users. Payout recipients are processed via Stripe Connect (Stripe Payments Europe, Ltd., Ireland); see the data processor list. Retention: 10 years (tax-relevant) for payout records, 24 months for inactive referral relationships (dormancy).

18. Affiliate links (advertising links)

On editorial pages such as the racket guide we use advertising links to online shops and label them as advertising. If you buy there after a click, we receive a commission; the price does not change for you. No processing for this happens on our site: we set no advertising cookies, embed no network tracking scripts, and transmit nothing to third parties before your click. Product images and prices come from the shops' product data, are copied to our own server once a day and served from there, so opening the page loads nothing from a shop's server. Only when you click such a link are you forwarded to the shop through the affiliate network's service (Awin Ltd., 10 Bloomsbury Way, London WC1A 2SL, United Kingdom). According to its own information, Awin then processes click and device data in order to attribute a later purchase to our recommendation, and sets its own cookies on the destination domain. Awin is the independent controller for that; Awin's privacy notice applies. The legal basis for placing the links on our site is Art. 6(1)(f) GDPR (legitimate interest in funding editorial content). You can avoid the redirect at any time by visiting the shop directly instead of using the link. The same rules apply where advertising appears alongside analyses, insights or recommendations about your game: it is labelled, sets no advertising cookies on our side, and does not influence the results shown.