Български

Effective Date: September 9, 2025

Last Updated: July 20, 2026




Data Controller


Data controller and service provider:


DPO: No DPO appointed. For privacy-related questions: privacy@supairnic.com


1. Introduction


Welcome to Supairnic ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application (the "App"). We are committed to protecting your personal information and your right to privacy.


We use your personal data only for the purposes and on the legal bases described in this Privacy Policy. For certain optional features — such as certain notifications, analytics settings, or location access — we may ask for separate consent, which you can withdraw at any time through the app or device settings.


2. Information We Collect


2.1 Personal Information You Provide


Account Information:


Social Authentication (Optional):


Profile Data:


Trust and Reputation Data:


How the Trust Score works:

The Trust Score uses factors such as completed events (as a participant and as an organizer) and penalties. A no-show penalty is applied when a majority of an event's other participants report that you did not attend, or when the venue reports non-attendance for a booked event. Three no-show penalties within 30 days result in an automatic 7-day suspension from joining and creating events. These decisions are applied automatically based on the rules above, and you always have the right to obtain human review: contact support@supairnic.com and we will review whether the penalty was applied correctly. Reports you submit and reports about you are stored privately — other users never see who reported whom or how many reports exist — and are deleted once the event's attendance is finalized (24 hours after the event ends). A smaller penalty is applied for late disruptions: leaving an event, cancelling an event you organize, or removing a participant from an event you organize less than 2 hours before its start. These penalties decrease only your Trust Score and never lead to a suspension on their own — suspensions arise solely from repeated no-shows as described above. An organizer's late cancellation is not penalized when a participant has already left the event within the same 2-hour window. The Trust Score is not used for automatic account termination without human review.


Event and Activity Data:


Safety and Moderation Data:


Social Connections:


2.2 Automatically Collected Information


Device and Usage Information:


Device Identifiers:

Firebase Analytics automatically collects an App Instance ID to analyze usage patterns and app performance. This identifier is unique to your app installation and resets when you uninstall the app. We also collect device information (model, OS version, screen resolution, language settings) for compatibility and localization purposes. We do NOT collect advertising IDs (IDFA/AAID) or permanent device hardware identifiers. You can disable analytics via Settings → Privacy Controls → Analytics & Error Reporting.


Push Notification Data:


Location Information:


No Location for Attendance:

We do not use background location tracking. Event attendance does not use your location at all: attendance is recorded automatically unless other participants report a no-show (see "How the Trust Score works" above).


Technical Data:


2.3 Information from Third Parties


Social Validation:


2.4 Venue Representative Data


If you register or claim a sports venue profile (venue account), we process:


Purpose: verifying the claim request, creating and managing the venue account, partnership communication. Legal basis: contract (Art. 6(1)(b) GDPR) and our legitimate interest in verifying that venues are managed by authorized persons (Art. 6(1)(f) GDPR). Retention: while the venue account is active. Venue claim data may be retained for up to 12 months after rejection, termination, or suspected abuse, to the extent necessary to prevent fraudulent venue claims, protect legal interests, or comply with a legal obligation.


2.5 Publicly Available Venue Data


The App displays information about sports venues without a partner profile (name, address, coordinates, supported sports) sourced from publicly available sources. Where a venue is operated by an individual (e.g. a sole trader or independent coach), this information may constitute personal data.


3. How We Use Your Information


3.1 Primary Purposes


Service Delivery:


Event Management:


Community Features:


3.2 Secondary Purposes


Service Improvement:


Safety and Security:


Legal Compliance:


4. Information Sharing and Disclosure


4.1 Within the App Community


Public Information:


Limited Sharing:


4.2 Third-Party Service Providers


We use technical service providers (Google Firebase / Google Cloud, Google Maps, Expo Notifications) and authentication providers (Google Sign-In, Apple Sign-In). The full list of recipients and their roles is set out in Section 10.2.


Partner Sports Venues:


4.3 Legal and Safety Requirements


We may disclose your information when required by law or when we believe disclosure is necessary to:


5. Data Storage and Security


5.1 Security Measures


Technical Safeguards:


Operational Safeguards:


5.2 Data Retention


Account Information:


Activity Data:


De-identification:

Some historical event and validation records are retained after account deletion in de-identified form (the name is replaced with "Anonymous" and personal profile data is erased). Where de-identification cannot reasonably exclude re-identification, these records are treated as personal data and stored only with appropriate safeguards and restricted access.


Backups and Technical Records:

Data removed from active systems may temporarily remain in backups, system logs, or security records for a limited period necessary for recovery, security, abuse prevention, and demonstrating compliance. This data is not used for active app functionality and is deleted or overwritten in accordance with internal retention schedules. As indicative maximum periods: backups — up to 90 days; security and system logs — up to 12 months, unless a longer period is required for a specific legal claim or legal obligation.


Chat Messages:


Validation Data:


Social Connections:


Technical Data:


5.3 International Data Transfers


Some data may be processed outside your country of residence. The detailed framework for transfers outside the EEA and applicable safeguards is set out in Section 10.3.


6. Your Rights and Choices


6.1 Access and Control


Account Management:


Data Rights:


How to Exercise Your Rights:

To request access to, correction of, or a portable copy of your personal data, contact us at privacy@supairnic.com. We respond without undue delay, usually within 1 month. For account deletion, use the in-app deletion feature in Settings — this is processed immediately with no waiting period.


6.2 Account Deletion Process


Immediate Deletion:


What Gets Deleted:


What Gets Preserved (De-identified):


Process:

1. Go to Settings > Privacy Controls > Delete My Account

2. Confirm deletion through security prompts

3. Immediate processing begins automatically

4. You will be logged out and cannot recover the account


6.3 Location Services


Location Control:


Withdrawal of Consent:


6.4 Communication Preferences


Notifications:


Marketing Communications:

We send marketing communications only where we have a valid legal basis, including your consent where required. You can opt out of marketing communications at any time through the app settings or via the instructions in each message. Operational messages related to your account, security, or events may be sent regardless of marketing preferences.


7. Children's Privacy


Our App is restricted to users who are 18 years of age or older. We do not knowingly collect personal information from users under 18. Age verification is required during account registration, and users under 18 are automatically blocked from creating accounts.


If you are a parent or guardian and believe your child under 18 has somehow accessed our service, please contact us immediately and we will promptly delete any associated data.


8. Third-Party Links and Services


Our App may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read the privacy policies of any third-party services you access through our App.


8.1 Google Services


We use Google services, including Google Maps / Places API and Firebase (Google Cloud), for location features, authentication, database, cloud functions, storage, and related infrastructure. Additional details about these providers as recipients and about international transfers are described in Section 10 below.


9. Users Outside the European Economic Area


The App is primarily directed at users in Bulgaria and the EEA. If you use the App from another jurisdiction, you may have additional rights under your local privacy laws. We do not sell personal information, and we apply the standards described in this policy to all users. To exercise any privacy right, contact privacy@supairnic.com.


10. European Privacy Rights (GDPR)


If you are located in the European Economic Area (EEA), your data is processed in accordance with Regulation (EU) 2016/679 (GDPR).


10.1 Purposes, Legal Bases, and Retention



10.2 Recipients and Categories of Recipients



10.3 Transfers Outside the EEA


Some data may be processed outside the EEA by our service providers — primarily Google and Expo, which process data in the United States. These transfers are covered by appropriate safeguards: Standard Contractual Clauses (SCCs) and/or the adequacy decision under the EU-U.S. Data Privacy Framework, in accordance with the respective provider's data processing terms (Google Firebase Data Processing Terms, Google Cloud DPA, Expo DPA). A current list of providers is available upon request at privacy@supairnic.com.


10.4 Your Rights



To exercise your rights, contact privacy@supairnic.com. We respond without undue delay, usually within 1 month.


10.5 Complaint to Supervisory Authority


You have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP):


11. Device Technologies (SDKs, Identifiers, and Tokens)


The App uses the following device technologies:


Firebase Analytics (Google)


Firebase Crashlytics (Google)


Push token (Expo)


Google Maps


Disabling certain technologies may limit parts of the App's functionality.


12. Changes to This Privacy Policy


We may update this Privacy Policy from time to time. Non-material editorial or technical changes may take effect upon posting. Material changes that affect your rights, the categories of data processed, the purposes or legal bases of processing, or recipients will be communicated in advance via the App and/or by email, and where the law or the nature of the change requires it, we will ask for your explicit acceptance. The "Last Updated" date at the top of this policy always reflects the current version.


If you do not agree with the changes, you can stop using the App and delete your account before they take effect.


13. Contact Information


If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:


The controller's full details are set out in the "Data Controller" section at the top of this policy.


Email: privacy@supairnic.com

Support: support@supairnic.com


We respond to data subject requests and privacy questions without undue delay, usually within 1 month.


14. Jurisdiction and Governing Law


This Privacy Policy is governed by and construed in accordance with the laws of the Republic of Bulgaria. Any disputes arising from this Privacy Policy will be resolved through applicable legal channels in accordance with Bulgarian law.




This Privacy Policy is effective as of the date listed above and applies to all users of the Supairnic mobile application.

Last Updated: July 20, 2026