Privacy Policy
1. Controller
STATLYZER SH STUDIO S.R.L.
Registered office: Strada 1 Decembrie, Nr. 132, Sat Lechința, Comuna Lechința, Jud. Bistrița-Năsăud, 427105, Romania
Email: contact@statlyzer-studio.com
Phone: +40 751 590 601
2. What we process and why
Only the categories below are in active production. We do not collect date of birth, national ID, home address, or precise location as account fields.
- Account identifiers (Google user id, email, display name if Google returns it) — to create and secure your account. Legal basis: contract (Art. 6(1)(b)). Required to sign in. Without this data you cannot use personalised features.
- Authentication metadata (session tokens stored by the app as essential storage) — to keep you signed in. Basis: contract / essential security.
- Subscription status and billing identifiers (PRO flag, provider such as Google Play or Whop, external customer/subscription ids, expiry) — to deliver paid access and prevent duplicate billing. Basis: contract. Card PAN/CVV are processed by Google or Whop, not stored by STATLYZER.
- Notification preferences and device/push tokens (Android FCM token when board alerts are used) — to send the alerts you enable. Basis: contract for service messages; you can disable alerts in Account. Tokens are deleted with the account; opted-out tokens are not used for new alerts.
- Email digest opt-in — daily board email via Resend only if you tick the optional Account box. Basis: consent (Art. 6(1)(a)). Not implied by accepting Terms. You can untick it at any time.
- Support messages you send to our email or phone — to answer you. Basis: contract / legitimate interest in handling requests. LEGAL REVIEW REQUIRED if legitimate interest is relied on for unstructured mail.
- Security / anti-abuse signals (IP and user-agent as processed at the Cloudflare edge) — to deliver and protect the service. FingerprintJS is not used. LEGAL REVIEW REQUIRED — LIA if any residual edge logs are later treated as legitimate-interest processing.
- Cookies / localStorage — see the Cookie Policy. Essential storage: legal basis Art. 6(1)(b)/(f) and ePrivacy necessary storage. Optional functional (Google Translate), product analytics, and marketing / advertising measurement: consent.
- Consent-based advertising measurement (Google tag, Google Ads destination
AW-18327818485) — page and permitted funnel events such as Start Free, checkout start, and a confirmed PRO subscription. The STATLYZER event layer removes email, phone number, login tokens, payment tokens, and card data before an event is sent. Legal basis: consent (Art. 6(1)(a)); off by default and controllable in Cookie Settings. - Crash/error logs — Cloudflare/Workers/browser console as generated by the platform. Not a separate consumer profiling product.
Not present / not active: Meta Pixel, a Google Analytics property tag, precise-geolocation APIs, and marketing / advertising measurement without the separate visitor consent. Google Ads measurement is active only as described above after that consent.
Automated decision-making (Art. 22): Football model outputs are statistical analyses shown to you. They do not by themselves produce legal or similarly significant effects about you. We do not use profiling to decide credit, employment, or equivalent.
3. Recipients / processors actually used
- Supabase — authentication and application database.
- Cloudflare — hosting (Workers / Pages), CDN, edge security.
- Google — Google sign-in (OAuth); Google Play Billing and FCM on Android; optional Google Translate if you enable Functional cookies; and Google Ads measurement only if you enable Marketing / advertising measurement. Fonts are self-hosted; we do not load Google Fonts.
- Whop — Merchant of Record for web subscriptions.
- Resend — transactional/digest email when you opt in.
We do not sell personal data.
4. International transfers
Several processors are US-headquartered or operate globally (Google, Cloudflare, Whop, Resend; Supabase depending on project region). FingerprintJS is not used. LEGAL REVIEW REQUIRED — INTERNATIONAL TRANSFER BASIS. We do not invent SCCs, DPF certification, or an adequacy decision in this notice. Transfers occur because those providers host the production stack.
5. Retention
- Account profile: until you delete the account or we close it for a lawful reason.
- In-app deletion: profile fields we control are removed immediately from the application database when the in-app delete action succeeds.
- Email deletion requests: processed after we verify the requesting address belongs to the account.
- Billing / accounting records: payment records are held by Google Play or Whop as seller of record, and may also be retained as required by Romanian accounting and tax rules (commonly up to 10 years). STATLYZER does not issue all consumer invoices. ACCOUNTANT REVIEW REQUIRED.
- Push tokens: while alerts are enabled; removed on account deletion (device_tokens rows) and ignored when you opt out of board alerts.
- Cookie preferences: in localStorage until you clear site data or change them.
- Security logs: according to Cloudflare/Supabase platform defaults. We do not currently operate a documented custom purge schedule for edge logs. Technical remediation if a shorter internal retention is required.
- Consent-based advertising measurement: Google tag data is handled under Google's configured retention and processing terms once you enable the Marketing category. STATLYZER does not create a separate internal marketing profile from these client events.
6. Your rights
You may request access, rectification, erasure, restriction, objection, and portability, and you may withdraw consent for processing that relies on consent, without affecting prior lawful processing. Email contact@statlyzer-studio.com. We do not currently offer a full self-service export portal beyond Account deletion and preference toggles that actually exist in the app.
You may complain to Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) — https://www.dataprotection.ro — or to another supervisory authority in your EU member state of residence or work.
7. Children
The service is offered under a contractual 18+ access rule. We do not knowingly create accounts for children. If you believe a child created an account, contact us and we will delete it.
8. Security
We use HTTPS, Cloudflare edge protection, Google OAuth (we do not store your Google password), and access-controlled hosting. We do not claim that the service is unhackable, bank-grade, or military-grade.
If a personal-data breach occurs, we will notify the supervisory authority and affected users when legally required. We do not promise that every incident will be emailed to every user.
9. Changes
Material changes will be dated on this page. Where required, we will also notify signed-in users through the product or email.