1. Controller
The controller under the GDPR is Christopher Adelmann, trading as Adelmann Labs, c/o Online-Impressum 7259, Europaring 90, 53757 Sankt Augustin, Germany. Contact privacy@adelmannlabs.de for privacy requests.
2. Account and authentication
We process your user ID, email address, sign-in state, and technical authentication data to create and protect your account. You may use email and password, Sign in with Apple, or Google Sign-In. The legal basis is Article 6(1)(b) GDPR, with security measures additionally based on Article 6(1)(f).
3. Profile and discoverability
Your profile may contain a name or pseudonym, username, image, bio, sports, and skill levels. Signed-in members can discover this information to connect with you. Sportive does not verify identity. Please do not publish unnecessary health information, political opinions, or other highly sensitive information.
- Optional profile details are your choice.
- Pseudonyms are allowed; deception and impersonation are prohibited.
- Processing is necessary to provide the service under Article 6(1)(b) GDPR.
4. Social features and clubs
We store friendships, requests, blocks, chats, club invitations, memberships, club-feed posts, workouts, and rankings to provide these features. Messages and feed content remain until you delete them. When you delete your account, personal content is deleted or redacted unless a compelling reason requires limited retention.
5. Location and matchmaking
With device permission, Sportive may use your location to show nearby sports places, support suggestions, and assist workouts. Matchmaking shows other members only an approximate area or derived distance—never your exact coordinates. You can withdraw location permission in iOS.
- Optional permission and consent: Article 6(1)(a) GDPR.
- Nearby discovery may be limited without location permission.
6. Places, reports, and images
When you contribute a sports place, we process location details, your user ID, and submitted information. Issue reports can contain a description, images, and technical metadata. Resolved venue reports and evidence are normally retained for 12 months, then deleted or anonymised.
7. Device features
- Apple Health: with explicit permission, Sportive can write workouts to Apple Health. Health data is not used for advertising.
- Calendar: invitations are written only after device permission.
- Camera and photos: accessed only when you capture or select a profile, club, or report image.
- Push notifications: optional social and transactional notices include messages, invitations, friend activity, and club activity. You can disable categories and iOS permission.
8. Subscriptions
Apple processes purchases, renewals, cancellations, and payment information under its own terms. Sportive receives transaction and entitlement data to unlock Pro, prevent abuse, and comply with legal duties. Required records are retained for applicable statutory periods.
9. Safety, moderation, and reports
We process reports, reported content, necessary context, involved profiles, relevant prior actions, and audit records to protect members and enforce our rules. Trained reviewers see only the reported item and context needed for a fair decision. Safety cases are normally retained for 12 months after closure and routine security logs for 90 days.
- Legal basis: Article 6(1)(f) GDPR and Article 6(1)(c) where a legal duty applies.
- Data may be disclosed in response to valid legal process or to address an imminent threat. We notify the affected member unless prohibited or unsafe.
10. Website and Cloudflare Analytics
Cloudflare delivers this website. Cloudflare Web Analytics measures aggregate usage without cookies, local browser storage, or advertising profiles. Technical connection data may be processed to deliver and protect the site based on our legitimate interest under Article 6(1)(f) GDPR.
11. Recipients and international transfers
Depending on the feature, we use Google/Firebase, Google Workspace, Google Sign-In, Apple, and Cloudflare. Transfers outside the EEA rely on an adequacy decision, Standard Contractual Clauses, or another lawful safeguard. Firebase Cloud Functions run in Frankfurt (europe-west3); other production storage regions will be verified before publication.
12. Retention and deletion
- Account and profile data: while the account exists.
- Messages and feed content: until user deletion; personal content is deleted or redacted on account deletion.
- Safety cases and venue reports: 12 months after closure.
- Routine security logs: 90 days.
- Encrypted backup copies of deleted data: up to 90 days before rotation.
- Transactions: only for entitlement, fraud prevention, and statutory retention.
- Longer retention only for an active dispute, incident, or legal hold.
13. Your rights
You may request access, correction, deletion, restriction, portability, or object to processing, and withdraw consent for the future. We may verify identity for security and normally respond within one month. You may also complain to a data-protection authority.
- Privacy requests: privacy@adelmannlabs.de
- Account deletion: in the app or through our account-deletion page.
14. Changes
We display a version and effective date. We will provide an in-app or suitable electronic notice of material changes. The German version controls.
Changelog
Version 1.0 · 29 August 2026 · Initial publication.