Privacy Policy
Last updated : July 4, 2026 — Version 1.4
1. Data controller
The controller of personal data collected on BasketBoard is:
- Name : Enzo MORIN, sole trader (EI)
- Address : 8 rue Didienne, 44000 Nantes, France
- SIREN : 945 083 335
- Email : privacy@basketboard.fr
BasketBoard is the data controller for users' account data (club managers). However, the licensed members' data (players and officials, including minors) is entered by clubs: the club is then the data controller and BasketBoard acts as a processor (Article 28 GDPR). Data on minor licensed members is processed under the club's responsibility; it is up to the club to establish the legal basis and inform legal guardians.
2. Personal data collected
2.1 Account data
- Email address
- Full name
- Password (stored hashed, never in plain text)
- Profile picture (URL, optional)
2.2 Licensed members' data
As part of managing your club, you may enter data about licensed players:
- Last and first name
- License number
- National number (AES-256-GCM encrypted)
- Date of birth
- Email and phone (optional)
- Gender
2.3 Technical data
- IP address (security logs)
- Browser user agent
- Action timestamps (audit logs)
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Creating and managing your account | Performance of a contract (Art. 6(1)(b)) |
| Managing clubs, teams and matches | Performance of a contract (Art. 6(1)(b)) |
| Security and abuse prevention | Legitimate interest (Art. 6(1)(f)) |
| Audit logs | Legitimate interest (Art. 6(1)(f)) |
| Audience measurement | Consent (Art. 6(1)(a)) |
BasketBoard does not carry out any processing for marketing, profiling or advertising purposes.
4. Cookies
BasketBoard only uses strictly necessary cookies to operate the service:
| Cookie | Purpose | Duration |
|---|---|---|
| basketboard.session_token | Authentication and session maintenance | 7 days |
| csrf-token | Protection against CSRF attacks | Session |
Analytics cookies (optional)
If you accept analytics cookies, BasketBoard uses PostHog to measure site audience. These cookies are only set after your explicit consent (opt-in).
| Cookie | Purpose | Duration |
|---|---|---|
| ph_* | Audience measurement (PostHog) | 1 year |
You can withdraw your consent at any time from your account settings (Preferences > Analytics cookies) or by deleting the cookies in your browser.
5. Data recipients
| Provider | Role | Location |
|---|---|---|
| OVH | Server, frontend and database hosting | France |
| Cloudflare | Storage of encrypted database backups | European Union (US company, SCCs + DPF) |
| PostHog | Audience measurement (optional, with consent) | EU (Frankfurt, Germany) |
| Stripe | Payment processing and subscription billing (club name and manager e-mail) | Ireland / United States (Stripe Payments Europe; SCCs + DPF) |
| Brevo (Sendinblue) | Sending transactional e-mails and SMS (call-ups, notifications): recipients' name, e-mail and phone number | European Union (France) |
Your data is never sold or shared with third parties for commercial purposes.
6. Hosting and data transfers
The application server, the frontend interface and the database are hosted in France at OVH.
Database backups are encrypted before export, then stored in the European Union at Cloudflare (Object Storage R2, EU jurisdiction). As Cloudflare is a US company, this transfer is covered by Standard Contractual Clauses and the Data Privacy Framework; the backups remain accessible only in encrypted form.
Audience measurement (PostHog, optional and subject to your consent) is hosted in the European Union (Frankfurt). Residual processing in the United States remains possible to provide the service, framed by the standard contractual clauses (SCCs) and the EU–US Data Privacy Framework.
7. Retention periods
| Data | Duration |
|---|---|
| User account | As long as the account is active |
| Data after account deletion | 30 days (grace period), then permanent deletion |
| Deleted licensed members | 30 days, then permanent deletion |
| Audit logs | 90 days |
| Encrypted database backups | 14 days to 6 months (daily / weekly / monthly rotation) |
| Session cookie | 7 days |
8. Your rights
Under the GDPR, you have the following rights:
- Right of access (Art. 15): obtain a copy of your data
- Right to rectification (Art. 16): correct your data
- Right to erasure (Art. 17): delete your account and data
- Right to data portability (Art. 20): export your data in JSON format
- Right to object (Art. 21): object to certain processing
To exercise these rights, you can use the features built into your account (settings, export, deletion) or contact us at contact@basketboard.fr.
Response time: 30 days maximum.
9. Security
BasketBoard implements the following technical measures:
- HTTPS encryption on all communications
- Password hashing (scrypt)
- AES-256-GCM encryption of sensitive data (2FA secrets, national numbers)
- Optional two-factor authentication (2FA/TOTP)
- CSRF protection
- Request rate limiting
- User input validation
10. Complaint
If you believe that the processing of your data violates the GDPR, you have the right to lodge a complaint with the CNIL (the French data protection authority):
- Commission Nationale de l'Informatique et des Libertés
- 3 Place de Fontenoy, 75007 Paris
- www.cnil.fr
11. Changes
This policy may be updated. In the event of a substantial change, you will be informed by email or by a notification in the application. The update date at the top of this page is authoritative.