Privacy Policy
Last updated: 1 August 2026 · EULA · Terms of Service · Imprint · Open the app
PLATZ is a self-hosted service running on European (Swiss, Infomaniak) infrastructure. The data controller is the operator named in our Imprint. We collect only what we need to run pickup-football games. We do not sell your data, we show no advertising, and we do not use advertising trackers or cross-app tracking — nothing you do here is used to profile you anywhere else, and the app asks for no tracking permission because it does not track you. We do use a small number of named service providers to run features you can see (push notifications, subscriptions, payments) — they are listed below. We use only strictly necessary cookies/tokens (your sign-in session), so no consent banner is required for those.
What we collect
- Account: email, display name, password (stored only as a salted Argon2 hash).
- Profile: position, preferred foot, birth year (optional, for age groups), and your chosen home area (approximate coordinates) and travel radius.
- Location: during sign-up you can type your city, or let the app ask your device for your position. If you allow it, the position is rounded to about one kilometre on your device before it is sent, and we store only the resulting city label and country code. We never request background location and never store a precise fix. Granting it is optional and you can decline without losing anything.
- Activity: games you host/join, chat messages, teammate ratings, and your derived PLATZ Level.
- Notifications: if you allow them, a push token for this device and whether a notification was opened. Used to tell you a game filled up or was called off — never to build an advertising profile.
- PLATZ Plus: if you subscribe, your subscription status and expiry. The purchase itself is handled by Apple; we never see your payment details.
- Pitch-owner accounts: if you register an organisation (a club, school or municipality) to publish pitches, we store the organisation's name and type, the contact and billing email addresses, an optional phone number, the login email and a hashed password, and — where the organisation is paid through the platform — a Stripe account identifier. Payout and identity checks are carried out by Stripe; we never see bank credentials or identity documents.
- Technical: minimal request logs (method, path, IP) for security and debugging. Query strings are stripped.
- Security events: to detect and investigate attacks we record failed sign-in attempts, account lockouts, denied authorisations and rejected payment-webhook calls, together with the IP address, browser/app user agent, the route called and a timestamp. Where a sign-in attempt used an email address, that address is stored so we can see an attack on an account that does not exist. These records are kept for 90 days and then deleted automatically. They are used only to keep the platform secure — never for advertising or profiling.
How we use it
To run the service: authenticate you, match you into balanced games near you, show games for your age group, power chat and friends, and keep the platform safe (rate-limiting, moderation, abuse reports).
Moderation access to messages. Game chats are not end-to-end encrypted. To investigate a report, enforce our Terms, or comply with a legal obligation, an authorised operator can read the messages in a game. Every such access is written to an internal audit log recording who looked, at which game, and when. We do not read messages for advertising, profiling or product analytics, and we do not disclose them except as described under “Who we share with” or where the law requires it.
Legal basis
We process your data to perform our contract with you (your account, games, matchmaking, chat: Art. 6(1)(b) GDPR), on the basis of our legitimate interest in a safe, working platform (security logging, rate-limiting, moderation: Art. 6(1)(f)), and, for players under 18, with the consent of a parent or guardian recorded at sign-up (Art. 8 GDPR). Equivalent provisions of the Swiss FADP apply.
We send transactional email only (address confirmation, password reset) from no-reply@mehro.ch. No marketing email.
Who we share with
Other players see your public profile (name, level, position, area) unless you turn off your public card in Settings. We share data only with the processors needed to operate the service, and where legally required:
- Infomaniak Network SA (Geneva, Switzerland): hosting and transactional email. Your account, games and messages — the bulk of your data — stay in Switzerland/EU.
- OpenStreetMap Foundation / Nominatim: turns a location you type into map coordinates when you search for an area.
- Stripe: payment processing for paid games (only when you pay a share). Card details go directly to Stripe; we never see them.
- OneSignal (United States): delivers push notifications. Receives your device push token, a device identifier, IP address and whether a notification was opened. Only if you allow notifications — decline and nothing is sent.
- RevenueCat (United States): manages PLATZ Plus subscriptions. Receives your PLATZ user id and your subscription status. Only if you buy Plus.
- Apple: sells and bills PLATZ Plus as the merchant. Your payment details go to Apple, never to us.
Children
The minimum age for a PLATZ account is 12, and 13 in the United States and its territories: we do not knowingly collect personal information from children under 13 there, as required by the US Children's Online Privacy Protection Act (COPPA). Everyone under 18 needs a parent or guardian's consent, given with that adult's name and contact details at sign-up. If you are a parent or guardian and believe a child has given us information, write to no-reply@mehro.ch and we will delete the account and its data.
International transfers
Two of the providers above (OneSignal and RevenueCat) are based in the United States, so the limited data listed against them leaves Switzerland and the EU. Those transfers are covered by the providers' standard contractual clauses. Everything else — your account, your games, your messages, your level — stays on Swiss infrastructure.
Your rights
You can access and edit your data in the app, and delete your account at any time from Settings, which erases your personal data and the content tied to it. You may also request a copy of your data. To exercise these rights, contact us. You have the right to lodge a complaint with a supervisory authority (in Switzerland, the FDPIC/EDÖB; in the EU, your local data-protection authority).
Retention
We keep your data while your account exists. Security event records (see above) are deleted automatically after 90 days. Encrypted database backups are retained for up to 14 days. Deleting your account removes your data from the live system; residual copies expire from backups within that window.