Privacy

Your data. No funny business.

This notice explains what techRebels processes, why, for how long and what you can do about it.

Draft for legal review · updated 8 October 2026

Before launch: replace the bracketed controller and contact details and confirm the final hosting, email and retention setup.

1. Who controls your data

The controller is [full legal name / business name], [registered address], ID [company or registration number, if applicable]. Privacy contact: [hello@your-domain].

2. What we process

  • Account: login email, optional verified personal/company contact emails, notification choices, account identifiers and authentication/security logs.
  • Application and membership: name, city, your answers, application status, internal review note and dates.
  • Community profile: optional title, role, company, age range, interests, activities, ambitions and dream project.
  • Participation: your Rebel Bug, Radar votes and suggestions, matching preferences, approved matches, event or crew submissions and merch interest.
  • Technical data: IP address, browser/device information and security logs processed by infrastructure providers.

We never store or see your plain-text password. Authentication is handled by Supabase Auth, which stores a salted password hash.

3. Why we use it and our legal basis

Create and secure your account; review and manage membershipSteps requested before membership and performance of the community membership arrangement.
Operate Inside, the Swarm, Radar and member matchingPerformance of the membership arrangement. Matching only runs when you opt in.
Keep the service secure and prevent abuseOur legitimate interest in protecting members, the service and our systems.
Send optional event, matching, merch or general updatesYour consent per notification category. Each category is optional and can be withdrawn in Inside at any time.
Handle legal requests and disputesCompliance with legal obligations and establishment, exercise or defence of legal claims.

We do not sell personal data and do not use it for third-party advertising.

4. Who processes data for us

Access is limited to authorised techRebels crew members who need it. Our current or planned processors are:

  • Supabase: authentication, database and security infrastructure.
  • Cloudflare (planned): domain, DNS, website delivery and technical/security logs.
  • Resend: confirmation, password reset and transactional community emails.
  • [analytics provider, if enabled]: privacy-friendly aggregate website measurement.

Some providers may process data outside the EEA. Before launch we will document the actual processing locations and safeguards, such as an adequacy decision or EU Standard Contractual Clauses, in this notice.

5. How long we keep it

  • Pending, rejected and waitlisted applications: [choose and document a period, recommended 6–12 months] after the last decision or activity.
  • Member account and profile: while membership is active, then deleted or anonymised within [choose a period] after account deletion, except where law requires longer retention.
  • Security and infrastructure logs: according to the documented provider settings, no longer than necessary for security and incident response.
  • Contact-email verification codes: up to 15 minutes; only a salted cryptographic hash is stored while verification is pending.
  • Marketing data: until consent is withdrawn or the contact becomes inactive under the documented deletion schedule.

You can delete your account directly in Inside. The deletion flow removes your profile, bug and account; limited records may only be retained where required by law or for legal claims.

6. Your rights

Depending on the circumstances, you may request access, correction, deletion, restriction, portability or object to processing. You can withdraw consent at any time without affecting earlier lawful processing. We respond without undue delay and normally within one month.

Write to [hello@your-domain]. You may also complain to the competent supervisory authority; in Czechia this is the Office for Personal Data Protection (ÚOOÚ).

Membership decisions are reviewed by a human. We do not use solely automated decision-making that produces legal or similarly significant effects.

7. How we protect it

We use role-based access, database Row Level Security, separate applicant/member/admin permissions, email verification, hashed passwords, short-lived reset links and restricted admin functions. No internet service is risk-free, so we review access and security settings as the project changes.

8. Changes

We will update this notice when the service, providers or purposes change. Material changes affecting members will be communicated through the service or by email where appropriate.