Privacy Policy
Last updated: May 20, 2026
1. Data Controller
Matchery is responsible for the processing of your personal information. For any privacy-related question, contact our Data Protection Officer:
Email: privacy@matchery.app
2. Personal Data Collected
- Phone number — OTP authentication (required)
- Username — Platform identification
- Email address — Communications (optional)
- Profile photo — Public display (optional)
- City, sport, level — Personalization (optional)
- Match participation — Activity history
- Match address and coordinates — Sports organization
- Push notification token — Alerts (with consent)
- IP address and User-Agent — Session security
3. Purposes and Legal Bases
| Purpose | Legal Basis |
|---|---|
| OTP Authentication | Contract performance |
| Match management | Contract performance |
| Push notifications | Consent |
| Usage analytics | Legitimate interest (anonymized) |
| Session security | Legal obligation / legitimate interest |
| Service improvement | Consent |
4. Data Retention
- Profile data: duration of account + 30 days after deletion
- Session tokens: 90 days or until logout
- OTP tokens: 10 minutes
- Security logs: 1 year
- Match data: 2 years after match date
5. Your Rights (Loi 25 + PIPEDA)
Under Loi 25 (Quebec) and PIPEDA (Canada), you have the following rights:
- Access — Get a copy of your personal data
- Rectification — Correct inaccurate data
- Deletion — Request anonymization of your account
- Portability — Receive your data in structured format (JSON)
- Withdrawal — Withdraw consent at any time without penalty
Exercise your rights via the My Data page or by email to privacy@matchery.app. Response time: 30 days.
6. Cookies
We use essential cookies for service operation and, with your consent, analytics cookies. See our Cookie Policy.
7. Data Sharing
Your data is never sold. It may be shared with:
- Expo (push notifications — US servers) with your consent
- Infrastructure providers (secure hosting)
- Competent authorities, when required by law
8. Security
- Encryption in transit (TLS 1.3)
- Session tokens hashed (SHA-256) — never stored in plaintext
- Automatic session token rotation
- Access limited to authorized personnel
9. Privacy Incidents
In case of an incident, we will notify the Commission d'accès à l'information (CAI) within 72 hours if Loi 25 criteria are met, and affected users as soon as possible.
10. Contact and Complaints
Data Protection Officer:
Email: privacy@matchery.app
You may also file a complaint with the Office of the Privacy Commissioner of Canada (OPC): priv.gc.ca