Privacy Policy
Last updated: 5 October 2026
This policy explains how The PaddleMate LTD. (“PaddleMate”, “we”, “us”) processes personal data when you use thepaddlemate.com, the PaddleMate shop, mobile app, analytics portal, or compatible devices.
Controller: The PaddleMate LTD.
Company registration no. 12-09-011065 · Tax no. 27989045-2-12
2600 Vác, Szent-Györgyi Albert u. 1., Hungary
Email: contact@thepaddlemate.com
Processing is based on the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679).
1. What we process and why
| Data | Examples | Purpose | Legal basis (GDPR) |
|---|---|---|---|
| Account | Email, name or nickname, password hash, optional phone | Sign-in, security, service messages | Art. 6(1)(b) contract; Art. 6(1)(f) account security |
| Profile (optional) | Sport, photo, gender, birthdate, height, weight | Calories and coaching features you enable | Art. 6(1)(a) consent — delete anytime in the account |
| Activity / health-related training data | Force, GPS, heart rate, sessions you upload | Analysis in the app/portal | Art. 6(1)(a) and, where applicable, Art. 9(2)(a) explicit consent. Default sharing is private. |
| Device / sync | IP, sync time, diagnostics, battery level, network type | Support and reliability | Art. 6(1)(f) product support |
| Live tracking invite | Email or phone you provide for a Live link | Send the tracking invitation | Art. 6(1)(f) / your request |
| Shop / orders | Name, shipping and billing address, email, phone, products, VAT number | Fulfil orders, invoices, tax | Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation |
| Payments | Stripe customer / payment identifiers (not full card PAN) | Take payment | Art. 6(1)(b); Stripe as processor / independent controller for card data |
| Support messages | Email, form or WhatsApp content | Answer you and keep a record of claims | Art. 6(1)(b) and (f) |
| Technical / analytics | IP, browser, pages, approximate location | Security, traffic statistics | Art. 6(1)(f); cookies that are not strictly necessary: Art. 6(1)(a) |
| Marketing | Email if you opt in or after a purchase where allowed | News and offers | Art. 6(1)(a) consent and/or Art. 6(1)(f) with an unsubscribe link |
We do not seek special-category data other than training/heart-rate data you choose to upload.
2. How we collect data
- Directly from you (account, shop, contact form, VAT check).
- From the Device and app when you sync or upload.
- Automatically from the website (logs, cookies — see section 7).
- From processors: Stripe (payments), hosting (Vercel), database (Turso), email delivery, and analytics/ads only if you consent.
3. Recipients
We share data only as needed with:
- IT hosts, email and error-logging providers
- Stripe and, where required, tax/accounting advisers
- Couriers for delivery
- Public authorities when legally required
- Other PaddleMate users only if you change activity privacy from Private
- People you invite to a Live tracking link (anyone with the link can see location — share carefully)
We do not sell personal data.
4. International transfers
Some providers are in the United States or other countries outside the EEA. Where required we rely on an adequacy decision (including the EU–US Data Privacy Framework where the provider is certified) and/or Standard Contractual Clauses (GDPR Art. 46). The former EU–US Privacy Shield is no longer used.
5. Retention
- Orders and invoices: at least 8 years (Hungarian accounting / tax rules).
- Account and training data: while the account is active, then deleted or anonymised after a reasonable close-out period unless we must keep them.
- Support tickets: as long as needed for the enquiry and possible claims.
- Marketing: until you unsubscribe.
- Anonymised statistics may be kept without a time limit.
6. Your rights (GDPR)
You may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interests. You may withdraw consent at any time without affecting prior lawful processing.
Write to contact@thepaddlemate.com. We normally reply within one month (GDPR Art. 12). We may ask for proof of identity. We may refuse or charge a reasonable fee for manifestly unfounded or excessive requests.
You may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), 1055 Budapest, Falk Miksa utca 9-11., www.naih.hu, ugyfelszolgalat@naih.hu — or with your local EU supervisory authority.
7. Cookies
We use cookies and similar technologies:
- Necessary — cart, security, language, checkout. Legal basis: legitimate interest / strictly necessary (ePrivacy).
- Analytics / advertising — only with your consent where required.
You can block cookies in the browser; the shop may not work if all cookies are blocked. Third parties (e.g. Google, Meta) have their own policies. Interest-based ads: youronlinechoices.eu (EEA).
8. Security
The site is served over HTTPS. Access to systems is restricted. No method of transmission is 100% secure.
9. Children
The shop and accounts are not directed at children under 16. If you believe we hold such data, contact us and we will delete it.
10. Changes
We may update this policy. The date at the top is the latest version. Material changes will be indicated on this page or by email where appropriate.