Version 2.0 — in force from 2026-09-01
Courtesy translation; the Polish version prevails in case of discrepancy.
This document is information, not consent. Confirming it in the App only means you have read it. Marketing consents are separate, optional and withdrawable at any time.
§1. Controller
The controller of your personal data is:
AMATOR SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ ul. Stefana Okrzei 1A lok. 5E, 03-715 Warszawa, Polska KRS: 0001253869, NIP: 1133207315, REGON: 545251651
— the „Controller" or „Operator".
Data-protection contact: [email protected].
No Data Protection Officer has been appointed; please write to the address above.
§2. Change of controller — notice of transfer
- Until 2026-09-01 the controller of App users' data was a natural person trading under the GameHunter brand. From that date the controller is AMATOR SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, which took over the operation of the App (now branded Amator).
- The purposes and scope of processing were not broadened by the change of controller itself. Legal bases, retention periods and your rights remain the same or are clarified in this Policy.
- If you do not accept the change, you may delete your Account at any time — see §9.
§3. Data we process
| Category | Data | Nature |
|---|---|---|
| Registration | phone number, e-mail address, Apple ID / Google ID identifier, internal Account identifier | necessary |
| Age | date of birth | necessary — without it we cannot confirm you are at least 16 |
| Profile | first name or nickname, profile picture, country and city/district chosen from a list, App language | partly optional |
| Sports data | skill level, preferred position, dominant foot, height, weight, participation statistics and post-game ratings | optional |
| Activity | Events created and joined, Team membership, ratings given, reports submitted | necessary |
| User Content | descriptions, avatars, Team logos, Event banners | optional |
| Device | model, operating system, App version, installation identifier, push notification token, language settings | necessary |
| Diagnostics | error logs, crash events, IP address in technical logs | necessary |
| Consents | the wording, version, language and date of each consent or acceptance, and of its withdrawal | required by law |
| Coins Programme | Coin balance, accrual history, Partner rewards collected | necessary for the programme |
| Billing | data needed to issue an accounting document — only for Paid Services | required by law |
Location data. The App does not read your device's GPS location. „Location" in the App means only the country, city and district you pick manually from a list, plus the Venue location entered by an Organiser.
Special categories. We do not collect health data. Height, weight and skill level are ordinary data provided voluntarily and do not constitute health data within the meaning of Article 9 GDPR. Please do not post information about injuries, illnesses or other sensitive data in the App.
§4. Purposes and legal bases
| Purpose | Legal basis | Retention |
|---|---|---|
| Running the Account and providing the App's services (Profile, Events, Teams, Coins) | Art. 6(1)(b) GDPR — performance of a contract | until the Account is deleted |
| Phone-number verification by SMS code | Art. 6(1)(b) GDPR | up to 12 months from verification |
| Notifications about Events you take part in (service messages) | Art. 6(1)(b) GDPR | until Account deletion or notifications are turned off |
| Marketing messages (e-mail, SMS, push about news) | Art. 6(1)(a) GDPR — consent, in conjunction with Art. 398 of the Polish Electronic Communications Law | until consent is withdrawn |
| Personalisation of Event and offer recommendations | Art. 6(1)(a) GDPR — consent | until consent is withdrawn |
| Age assurance, community safety, abuse and spam prevention | Art. 6(1)(f) GDPR — legitimate interest | up to 12 months from the event |
| Content moderation and handling of notices (DSA) | Art. 6(1)(c) and (f) GDPR | 6 years from the decision |
| Error diagnostics and App maintenance | Art. 6(1)(f) GDPR | up to 12 months |
| Aggregate statistics and product development (no individual profiling) | Art. 6(1)(f) GDPR | indefinitely, in aggregate form |
| Demonstrating consents and acceptances (accountability) | Art. 6(1)(c) in conjunction with Art. 7(1) GDPR | 6 years from withdrawal or Account deletion |
| Complaints and defence against claims | Art. 6(1)(b), (c) and (f) GDPR | 6 years |
| Accounting and tax obligations for Paid Services | Art. 6(1)(c) GDPR | 5 years from the end of the tax year |
Automated decision-making. We do not take decisions about you based solely on automated processing that produce legal or similarly significant effects. Sorting Events and offers by your chosen city, sport and preferences produces no such effects; moderation decisions are taken by a human.
§5. Recipients and processors
We entrust data only to providers under data-processing agreements (Article 28 GDPR):
| Provider | Scope | Location |
|---|---|---|
| Supabase (PostgreSQL) | database hosting and authentication | EU / outside the EEA |
| DigitalOcean | application servers | EU |
| Cloudflare | CDN, abuse protection | EU / global |
| Twilio | sending SMS verification codes | outside the EEA (USA) |
| Google (Firebase Cloud Messaging) | Android and web push notifications | outside the EEA (USA) |
| Apple (APNs) | iOS push notifications | outside the EEA (USA) |
| Apple, Google | „Sign in with Apple" / „Sign in with Google" (separate controllers) | outside the EEA (USA) |
| Resend | sending e-mail | outside the EEA (USA) |
| Sentry | technical error collection | outside the EEA (USA) |
| Capgo | delivering updates to the App's web layer | EU / outside the EEA |
| Telegram | Event participant group chats — a separate controller, joining is optional | outside the EEA |
- Data may be disclosed to public authorities where the law so requires.
- We do not sell personal data and do not disclose it to third parties for advertising purposes. Partners presenting offers receive only what is needed to fulfil a reward you have collected (e.g. a reward code, first name or nickname), as described in the Coins & Rewards Programme Terms.
§6. Transfers outside the EEA
- Some providers listed in §5 process data in third countries, in particular the United States.
- Transfers rely on: a European Commission adequacy decision (EU–US Data Privacy Framework, where the provider is certified) or standard contractual clauses (SCC) together with supplementary technical measures (encryption in transit, data minimisation).
- A copy of the safeguards is available on request at [email protected].
§7. Visibility of your data in the App
- You decide which Profile data is visible: publicly, only to participants of an Event, only to Team members, or only to you. Change this in the Profile privacy section.
- Defaults: your e-mail address is visible only to your contacts and your phone number only to the organiser and administrators of the context (game, team). Other Profile fields are visible to other Users by default; you can narrow each of them yourself in the Profile privacy section.
- Data you make public yourself (e.g. in an Event description) may be seen and copied by other Users — this is outside the Controller's control.
- The App provides no private messaging between Users. Telegram groups are an external space.
§8. Children and minors
- The App is intended solely for persons aged 16 and over and is not directed at children.
- We do not knowingly collect data of persons below 16. If we learn that an Account belongs to such a person, we suspend it and delete the data under §5 of the Terms.
- A parent or legal guardian may report such an Account to [email protected]; we handle these reports as a priority.
§9. Your rights
You have the right to: access your data and obtain a copy, rectification, erasure („right to be forgotten"), restriction of processing, data portability, objection to processing based on legitimate interest, and withdrawal of consent at any time — without affecting the lawfulness of processing before withdrawal.
Marketing consents can be withdrawn by you directly in the App settings (consents section) — immediately and without giving reasons.
Account deletion. You can delete your Account in the App settings, and also from the profile setup screen and the required-consents screen. We carry this out without undue delay and no later than 30 days.
Deletion means detaching the Account from your login and overwriting the identifying data: we remove your first and last name, e-mail address, phone number, social links and the authentication account itself. Your profile picture is deleted as a file from our file servers, not merely unlinked.
What remains is an anonymised record of participation in past Events (that a game happened, its results and ratings) which cannot be linked back to you — this is necessary so that the Event history of the other participants is not distorted (Article 17(3)(e) GDPR in conjunction with Article 6(1)(f)).
Alongside it we keep your date of birth, height, weight and gender. Without a name, contact details or photo these identify no one, and without them the anonymised Event history loses its statistical value (the age and build distribution of participants). The basis is Article 6(1)(f) GDPR in conjunction with Article 89 GDPR (statistical purposes). You can object to this retention by writing to [email protected], and we will erase those fields too.
We also keep the data the law requires us to keep (consent accountability, accounting obligations, defence against claims), restricted to the necessary minimum.
If you have already paid for an upcoming Event, deletion is deferred until that Event is over — see §14 of the Terms. The deferral concerns only when it is carried out, and you can withdraw the request at any time.
You may lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland).
Requests are handled free of charge within one month; in complex cases the period may be extended by two further months, of which we will inform you.
§10. Security
- We apply, among others: transport encryption (TLS), role-based access control, network-level restriction of database access, environment separation, backups and logging of administrative events.
- Only authorised persons bound by confidentiality have access to the data.
- In the event of a personal-data breach likely to result in a high risk to your rights, we will inform you without undue delay and notify the supervisory authority within 72 hours.
- No technical measure guarantees absolute security; please protect your device and login credentials.
§11. Changes to this Policy
- This Policy may change following changes in law, in the scope of the services or in providers.
- Material changes are announced in the App at least 14 days in advance, and previous versions are archived with their effective dates.
§12. Contact
Personal-data matters: [email protected] AMATOR SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, ul. Stefana Okrzei 1A lok. 5E, 03-715 Warszawa, Poland