Dograjmy Privacy Policy
Version: 1.1
Effective date: 19 August 2026
1. Data controller and contact
The data controller is Tomasz Guzik, a sole trader operating under the business name Tomasz Guzik, ul. Długa 66a, 32-300 Olkusz, Poland, tax ID (NIP) 6372203978.
For privacy questions and rights requests, e-mail tomasz.guzik94@gmail.com.
2. Data we process
We process:
- account data: e-mail address, sign-in identifiers, sign-in provider and session data;
- player data: first name, optional last name and photo, language, status and 18+ confirmation;
- sport profiles: city, sport, skill level, formats and preferred venues;
- availability: times, durations, venues, formats and optional notes;
- proposals and games: participants, time, format, venue, roster and status;
- notifications and, when enabled, a push subscription;
- venue suggestions, corrections and operator decision history;
- the accepted Terms version, the Privacy Policy version presented and the time of both events;
- correspondence, limited security logs and technical data.
Dograjmy does not require special-category data. Do not put health information or other sensitive data about yourself or another person in notes.
Sign-in data is required to create an account. An 18+ confirmation, first name, city, sport, skill level, format and at least one preferred venue are required to complete the first profile. Without them, you cannot complete the profile or use matching. Last name, photo, notes, further sport profiles and push notifications are optional. Proposal, game and venue-suggestion data is required only when you choose that feature; without it, we cannot perform that specific operation.
Dograjmy does not ask the browser for precise or approximate device location. It processes the selected city, venue data and the text entered when searching for a venue through LocationIQ.
3. Where the data comes from
We receive data from you and from your activity in Dograjmy. Another player's activity creates information that they sent you or answered a proposal or joined a game with you; we do not let them create an account or profile in your name. If you choose Google sign-in, we receive the basic account data shared during sign-in. The Dograjmy server, not your browser, sends venue-search queries to LocationIQ.
4. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Account, profiles, matching, games and notifications | account, profile, availability, proposals, games and push subscription | contract performance — Article 6(1)(b) GDPR |
| Security, abuse prevention and service maintenance | sessions, technical data and logs | legitimate interests — Article 6(1)(f) GDPR |
| Consumer complaints | correspondence and account history | legal obligation — Article 6(1)(c) GDPR |
| GDPR rights requests | correspondence, account data and legal-document history | legal obligation — Article 6(1)(c) GDPR |
| Service support | correspondence and data needed to solve the issue | contract performance — Article 6(1)(b) GDPR |
| Establishing, pursuing and defending legal claims | correspondence, account and event history | legitimate interests — Article 6(1)(f) GDPR |
You may object to processing based on legitimate interests; we will then assess whether overriding grounds require its continuation.
5. Who sees data in Dograjmy
Signed-in players with an active profile for the same city and sport see the player's first name, optional last name, skill level, availability time, formats and names of venues attached to the published availability. The photo is shown in the same view, but a signed-in player with a completed profile may also access it through a previously received photo address. Proposal and game participants see first names, optional last names, time, format, venue, roster and status needed to manage them. We do not show another player your e-mail address or sign-in data.
A public link to an open game shows the time, format, venue name, occupied places and capacity without authentication. It does not show participant names, photos or e-mail addresses. An operator sees the venue submitter's first name and optional last name, venue-suggestion data and decision history needed to review it. Legal-document history and sign-in data are not public.
6. Providers and recipients
We use services including:
- Vercel for application hosting and server functions;
- Supabase for authentication, database, Storage and infrastructure;
- Google for optional OAuth sign-in;
- Cloudflare Turnstile for protection against automated sign-in abuse;
- LocationIQ for venue searches based on text sent by the Dograjmy server;
- the e-mail provider used by Supabase Auth;
- browser-vendor push services when notifications are enabled.
Authorized advisers and public authorities may also receive data where required by law. We do not sell personal data or use it for behavioural advertising.
7. Data outside the European Economic Area
If data is transferred outside the EEA, the transfer may take place only under a mechanism required by the GDPR, such as an adequacy decision or standard contractual clauses. You may contact the controller for information about the safeguard used.
8. How long we keep data
We use the following retention criteria:
| Data | Retention criterion |
|---|---|
| Account and profile | for the contract term; afterwards only as needed for legal obligations or claims |
| Legal-document history | as long as needed to prove which version was presented and accepted |
| Availability, proposals and games | as needed to operate the service, provide participant history, handle complaints or deal with claims |
| Notifications | until account deletion or earlier removal when no longer needed to handle the event |
| Push subscriptions | until disabled in the profile or confirmed to have an invalid subscription address |
| Venue suggestions | while reviewing the suggestion and afterwards where the decision history is needed for the catalog or claims |
| Security and technical logs | as needed for security, error analysis or abuse prevention |
| Correspondence | as long as needed to handle the matter and meet legal obligations |
When a purpose ends, we delete or anonymize the data unless the law requires continued storage or it is needed to establish, pursue or defend a legal claim.
9. Your rights
In the cases set out in the GDPR, you may request access to and a copy of your data, correction, deletion, restriction, portability and handling of an objection.
Send a request by e-mail. We may verify your identity before acting. We will respond without undue delay, generally within one month after receiving the request. Where the GDPR allows, this may be extended by two further months; we will explain the extension within one month after receiving the request. You may lodge a complaint with the President of the Polish Personal Data Protection Office or your local supervisory authority.
10. Matching and automated decisions
Dograjmy limits results to the selected city and sport, lets you filter availability by format and venue, and orders results by start time. Skill level may be used to explain why a suggestion may fit. We do not make solely automated decisions that produce legal or similarly significant effects for you.
11. Cookies, browser storage and push notifications
We do not use marketing cookies or product-analytics tools. We use only:
| Browser storage item | Purpose | Period |
|---|---|---|
| Supabase Auth session cookies | sign-in, session refresh and security | until session expiry or sign-out |
| `badmeet:pwa-install-prompt:v1` | remember dismissal of the install prompt | until site data is cleared in the browser |
| Cache Storage `badmeet-shell-p09-v2` | offline page and application icons | until a cache update or site-data deletion |
Push notifications are optional. Disabling them in the profile removes the active subscription from Dograjmy. Revoking permission only in browser settings blocks messages; the Dograjmy record is removed after disabling in the profile or when the push service reports an invalid subscription address.
12. Security
We use access controls, encrypted connections, least privilege, private photo storage and technical logs. No system can guarantee complete security. If you suspect account takeover or a data leak, contact us without delay.
13. Policy changes
For a material change to a purpose or method of processing, we will publish a new version and notify players in the service. Where required, we will present the new Privacy Policy. We will ask for renewed acceptance when the Terms change. The history of these events remains linked to the account.
14. People under 18
Dograjmy is intended only for adults and does not intend to collect data about people under 18. If we identify such an account, we will contact the user and take the measures required by law. A suspected underage account may be reported to the controller.