Privacy Policy
Last updated: June 2, 2026
Notice under Art. 13 of EU Reg. 2016/679 (GDPR) and Italian D.Lgs. 196/2003 (Privacy Code), as amended by D.Lgs. 101/2018.
1. Data Controller
The Data Controller for the data of users registered on the SimplySport platform is the company operating the service (hereinafter also "SimplySport"). Contact: privacy@simplysport.app
Note for ASD/SSD customers: with respect to the data of members entered into the platform, the individual customer gym is the Data Controller; SimplySport acts as Data Processor under Art. 28 GDPR.
2. Data Collected
SimplySport collects the following categories of data:
- Personal and contact data (first/last name, email, phone, date of birth, fiscal code, address): provided during registration or gym sign-up.
- Access data (email, encrypted password, login date and time): required for authentication.
- Sports data (subscriptions, lesson attendance, payments, expenses): generated through ordinary use of the platform.
- Special category data (Art. 9 GDPR) — health data: expiry date and type of sports medical certificate (competitive / non-competitive). This data is collected only if entered by the gym operator and is processed with additional security measures. It is never exposed via the API without authentication.
- Browsing data (IP address, browser, pages visited): collected automatically for security purposes and error monitoring (Sentry).
3. Purposes and Legal Bases of Processing
| Purpose | Legal basis |
|---|---|
| Providing the SaaS service | Contract performance (Art. 6.1.b GDPR) |
| Billing and tax obligations | Legal obligation (Art. 6.1.c GDPR) |
| Expiry reminders (subscriptions, medical certificates) | Legitimate interest / contract performance |
| Processing of health data (medical certificate) | Explicit consent (Art. 9.2.a GDPR) |
| Error monitoring and security | Legitimate interest (Art. 6.1.f GDPR) |
| Marketing communications | Consent (Art. 6.1.a GDPR) |
4. Data Retention
- Account data: for the duration of the contractual relationship + 30 days after cancellation
- Member data (entered by the customer gym): until cancellation is requested by the Customer; max 5 years from termination of membership (Member Register obligation)
- Health data: same duration as member data, with periodic review
- System logs and browsing data: max 12 months
- Tax and accounting data: 10 years, as required by law
5. Data Recipients
Data may be shared with:
- PayPal — payment processing (EU location available)
- Resend — transactional email delivery (reminders, receipts)
- Sentry — application error monitoring
- Vercel / Supabase — hosting and database (cloud infrastructure)
All providers were selected with adequate safeguards under Articles 44-49 GDPR (standard contractual clauses or adequacy decisions).
6. Data Subject Rights
Under Articles 15-22 GDPR, every data subject has the right to:
- Access: obtain confirmation of processing and a copy of the data
- Rectification: correct inaccurate or incomplete data
- Erasure ("right to be forgotten")
- Restriction of processing
- Portability: receive data in a structured format (CSV)
- Objection to processing based on legitimate interest
- Withdrawal of consent at any time, without affecting the lawfulness of prior processing
Requests should be sent to privacy@simplysport.app. We will respond within 30 days. You may also file a complaint with the Italian Data Protection Authority (Garante).
7. Minors
SimplySport does not directly collect data from minors under 14. Data of minor members (entered by the customer gym) must be accompanied by parental or guardian consent, under Art. 8 GDPR and D.Lgs. 101/2018. The customer gym is responsible for obtaining such consent.
9. Changes to this Privacy Policy
SimplySport reserves the right to update this notice. Material changes will be communicated via email with 30 days' notice. The updated version will always be available on this page with the last-updated date.