Privacy Policy

Last updated: May 20, 2026

1. Data Controller

Matchery is responsible for the processing of your personal information. For any privacy-related question, contact our Data Protection Officer:

Email: privacy@matchery.app

2. Personal Data Collected

  • Phone number — OTP authentication (required)
  • Username — Platform identification
  • Email address — Communications (optional)
  • Profile photo — Public display (optional)
  • City, sport, level — Personalization (optional)
  • Match participation — Activity history
  • Match address and coordinates — Sports organization
  • Push notification token — Alerts (with consent)
  • IP address and User-Agent — Session security

3. Purposes and Legal Bases

PurposeLegal Basis
OTP AuthenticationContract performance
Match managementContract performance
Push notificationsConsent
Usage analyticsLegitimate interest (anonymized)
Session securityLegal obligation / legitimate interest
Service improvementConsent

4. Data Retention

  • Profile data: duration of account + 30 days after deletion
  • Session tokens: 90 days or until logout
  • OTP tokens: 10 minutes
  • Security logs: 1 year
  • Match data: 2 years after match date

5. Your Rights (Loi 25 + PIPEDA)

Under Loi 25 (Quebec) and PIPEDA (Canada), you have the following rights:

  • Access — Get a copy of your personal data
  • Rectification — Correct inaccurate data
  • Deletion — Request anonymization of your account
  • Portability — Receive your data in structured format (JSON)
  • Withdrawal — Withdraw consent at any time without penalty

Exercise your rights via the My Data page or by email to privacy@matchery.app. Response time: 30 days.

6. Cookies

We use essential cookies for service operation and, with your consent, analytics cookies. See our Cookie Policy.

7. Data Sharing

Your data is never sold. It may be shared with:

  • Expo (push notifications — US servers) with your consent
  • Infrastructure providers (secure hosting)
  • Competent authorities, when required by law

8. Security

  • Encryption in transit (TLS 1.3)
  • Session tokens hashed (SHA-256) — never stored in plaintext
  • Automatic session token rotation
  • Access limited to authorized personnel

9. Privacy Incidents

In case of an incident, we will notify the Commission d'accès à l'information (CAI) within 72 hours if Loi 25 criteria are met, and affected users as soon as possible.

10. Contact and Complaints

Data Protection Officer:
Email: privacy@matchery.app

You may also file a complaint with the Office of the Privacy Commissioner of Canada (OPC): priv.gc.ca