Last updated: July 7, 2026
This Privacy Policy describes how Core Street Football Community, LDA ("Company", "we", "us", or "our"), a company registered in Portugal (NIF 519248600, Alameda Fonte Velha 50A, 2710-144 Sintra, Portugal), collects, uses, and protects your information when you use CSFC.app (the "Service").
If you have any questions about this Policy, contact us at team@csfc.app.
Core Street Football Community, LDA acts as the data controller for the personal data described in this Policy.
We have not appointed a Data Protection Officer (DPO), as this is not required under Article 37 GDPR given the nature and scale of our processing activities. If this changes, we will update this Policy with DPO contact details. For all data protection matters, contact team@csfc.app.
Personal Information:
Usage Data:
Location Data:
Analytics & Cookies: We use cookies and similar technologies to operate and improve the Service. Non-essential cookies (analytics, marketing) are only set with your consent, collected via our cookie banner. See our Cookie Policy for full details on cookie types, purposes, and how to manage your preferences.
| Purpose | Data Used | Legal Basis (Art. 6 GDPR) |
|---|---|---|
| Provide and maintain the Service, manage accounts | Personal Information, Usage Data | Contract performance |
| Process transactions and subscriptions | Personal Information, payment metadata | Contract performance |
| Improve user experience, product analytics | Usage Data, Analytics cookies | Legitimate interests / Consent (for cookies) |
| Communicate with users (service messages) | Email, Phone | Contract performance |
| Marketing communications | Consent | |
| Ensure security and prevent fraud | Usage Data, IP address | Legitimate interests |
| Comply with legal obligations (tax, accounting, law enforcement requests) | Personal Information | Legal obligation |
You may withdraw consent-based processing (e.g., marketing, non-essential cookies) at any time without affecting the lawfulness of prior processing.
We share data with the following trusted processors, each bound by a Data Processing Agreement:
| Provider | Purpose | Data Location |
|---|---|---|
| Stripe | Payment processing | EU/US (Stripe Standard Contractual Clauses apply) |
| Supabase | Database and backend hosting | EU (Frankfurt, Germany) |
| Google Analytics | Analytics and usage tracking | US (Google's EU-US Data Privacy Framework / SCCs apply) |
These providers process data under their own privacy policies and only as instructed by us for the purposes listed above. We do not permit them to use your data for their own independent purposes.
All payments are processed securely via Stripe. We do not store full payment card details on our servers; Stripe handles this in compliance with PCI-DSS standards.
We retain personal data only as long as necessary for the purposes described in this Policy:
We may share your data:
We do not sell your personal data.
Under GDPR, you have the right to:
To exercise your rights, contact team@csfc.app. We will respond within one (1) month, as required by Article 12(3) GDPR (extendable by two further months for complex requests, with notice).
Right to lodge a complaint: If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local supervisory authority, or with Portugal's data protection authority: Comissão Nacional de Proteção de Dados (CNPD), www.cnpd.pt.
We implement appropriate technical and organizational measures to protect your data against unauthorized access, loss or misuse, and alteration or disclosure, including encryption in transit, access controls, and regular security review of third-party processors.
No system is 100% secure; in the event of a data breach likely to result in a risk to your rights, we will notify affected users and the relevant supervisory authority as required by Articles 33–34 GDPR.
Our primary database infrastructure (Supabase) is hosted in Frankfurt, Germany, within the European Economic Area (EEA), and does not involve an international transfer.
Some data may still be processed outside the EEA, including in the United States (via Stripe for payment processing and Google Analytics for analytics). Where this occurs, we rely on appropriate safeguards, including the EU Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework.
Our Service is not intended for individuals under 16 years of age. We do not knowingly collect personal data from children under 16. If you become aware that a child has provided us with personal data, please contact us at team@csfc.app so we can take appropriate action.
CSFC.app is operated from Portugal and is not specifically marketed or directed to users in the United States. However, if you access the Service as a California resident, you may have additional rights under the CCPA/CPRA, including the right to know what personal information is collected, the right to deletion, and the right to opt out of the sale/sharing of personal information. We do not sell or share personal information as defined under the CCPA. To exercise these rights, contact team@csfc.app.
We may update this Privacy Policy from time to time. Material changes will be communicated via the Service or by email, and the "Last updated" date will be revised accordingly. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
If you have any questions, requests, or complaints regarding this Policy: