Skip to content

Privacy Policy

Last updated: June 2, 2026

Notice under Art. 13 of EU Reg. 2016/679 (GDPR) and Italian D.Lgs. 196/2003 (Privacy Code), as amended by D.Lgs. 101/2018.

1. Data Controller

The Data Controller for the data of users registered on the SimplySport platform is the company operating the service (hereinafter also "SimplySport"). Contact: privacy@simplysport.app

Note for ASD/SSD customers: with respect to the data of members entered into the platform, the individual customer gym is the Data Controller; SimplySport acts as Data Processor under Art. 28 GDPR.

2. Data Collected

SimplySport collects the following categories of data:

  • Personal and contact data (first/last name, email, phone, date of birth, fiscal code, address): provided during registration or gym sign-up.
  • Access data (email, encrypted password, login date and time): required for authentication.
  • Sports data (subscriptions, lesson attendance, payments, expenses): generated through ordinary use of the platform.
  • Special category data (Art. 9 GDPR) — health data: expiry date and type of sports medical certificate (competitive / non-competitive). This data is collected only if entered by the gym operator and is processed with additional security measures. It is never exposed via the API without authentication.
  • Browsing data (IP address, browser, pages visited): collected automatically for security purposes and error monitoring (Sentry).

3. Purposes and Legal Bases of Processing

PurposeLegal basis
Providing the SaaS serviceContract performance (Art. 6.1.b GDPR)
Billing and tax obligationsLegal obligation (Art. 6.1.c GDPR)
Expiry reminders (subscriptions, medical certificates)Legitimate interest / contract performance
Processing of health data (medical certificate)Explicit consent (Art. 9.2.a GDPR)
Error monitoring and securityLegitimate interest (Art. 6.1.f GDPR)
Marketing communicationsConsent (Art. 6.1.a GDPR)

4. Data Retention

  • Account data: for the duration of the contractual relationship + 30 days after cancellation
  • Member data (entered by the customer gym): until cancellation is requested by the Customer; max 5 years from termination of membership (Member Register obligation)
  • Health data: same duration as member data, with periodic review
  • System logs and browsing data: max 12 months
  • Tax and accounting data: 10 years, as required by law

5. Data Recipients

Data may be shared with:

  • PayPal — payment processing (EU location available)
  • Resend — transactional email delivery (reminders, receipts)
  • Sentry — application error monitoring
  • Vercel / Supabase — hosting and database (cloud infrastructure)

All providers were selected with adequate safeguards under Articles 44-49 GDPR (standard contractual clauses or adequacy decisions).

6. Data Subject Rights

Under Articles 15-22 GDPR, every data subject has the right to:

  • Access: obtain confirmation of processing and a copy of the data
  • Rectification: correct inaccurate or incomplete data
  • Erasure ("right to be forgotten")
  • Restriction of processing
  • Portability: receive data in a structured format (CSV)
  • Objection to processing based on legitimate interest
  • Withdrawal of consent at any time, without affecting the lawfulness of prior processing

Requests should be sent to privacy@simplysport.app. We will respond within 30 days. You may also file a complaint with the Italian Data Protection Authority (Garante).

7. Minors

SimplySport does not directly collect data from minors under 14. Data of minor members (entered by the customer gym) must be accompanied by parental or guardian consent, under Art. 8 GDPR and D.Lgs. 101/2018. The customer gym is responsible for obtaining such consent.

9. Changes to this Privacy Policy

SimplySport reserves the right to update this notice. Material changes will be communicated via email with 30 days' notice. The updated version will always be available on this page with the last-updated date.