1. Who controls your data
The controller is [full legal name / business name], [registered address], ID [company or registration number, if applicable]. Privacy contact: [hello@your-domain].
2. What we process
- Account: login email, optional verified personal/company contact emails, notification choices, account identifiers and authentication/security logs.
- Application and membership: name, city, your answers, application status, internal review note and dates.
- Community profile: optional title, role, company, age range, interests, activities, ambitions and dream project.
- Participation: your Rebel Bug, Radar votes and suggestions, matching preferences, approved matches, event or crew submissions and merch interest.
- Technical data: IP address, browser/device information and security logs processed by infrastructure providers.
We never store or see your plain-text password. Authentication is handled by Supabase Auth, which stores a salted password hash.
3. Why we use it and our legal basis
We do not sell personal data and do not use it for third-party advertising.
5. How long we keep it
- Pending, rejected and waitlisted applications: [choose and document a period, recommended 6–12 months] after the last decision or activity.
- Member account and profile: while membership is active, then deleted or anonymised within [choose a period] after account deletion, except where law requires longer retention.
- Security and infrastructure logs: according to the documented provider settings, no longer than necessary for security and incident response.
- Contact-email verification codes: up to 15 minutes; only a salted cryptographic hash is stored while verification is pending.
- Marketing data: until consent is withdrawn or the contact becomes inactive under the documented deletion schedule.
You can delete your account directly in Inside. The deletion flow removes your profile, bug and account; limited records may only be retained where required by law or for legal claims.
6. Your rights
Depending on the circumstances, you may request access, correction, deletion, restriction, portability or object to processing. You can withdraw consent at any time without affecting earlier lawful processing. We respond without undue delay and normally within one month.
Write to [hello@your-domain]. You may also complain to the competent supervisory authority; in Czechia this is the Office for Personal Data Protection (ÚOOÚ).
Membership decisions are reviewed by a human. We do not use solely automated decision-making that produces legal or similarly significant effects.
7. How we protect it
We use role-based access, database Row Level Security, separate applicant/member/admin permissions, email verification, hashed passwords, short-lived reset links and restricted admin functions. No internet service is risk-free, so we review access and security settings as the project changes.
8. Changes
We will update this notice when the service, providers or purposes change. Material changes affecting members will be communicated through the service or by email where appropriate.