1. Controller and contact
Matcho is a service of Mumba, established in the Netherlands.
Mumba is responsible for the processing of personal data within the app and related services.
Questions about privacy, data deletion, or other requests can be sent to: info@mumba.nl.
2. Which data we process
Depending on how Matcho is used, we may process the following categories of data:
- account and profile data, such as first name, last name, display name, email address, preferred language, date of birth, favorite club, and profile image
- authentication and account data, such as a Firebase user ID, last login time, and the moment terms were accepted
- pool and gameplay data, such as memberships, invites, predictions, rankings, badges, subscriptions, and other data connected to participation in pools
- technical and session data, such as session ID, IP address, user agent, device type, and last used timestamp
- push notification data, such as FCM tokens and locale settings used for notifications
- files uploaded by users, such as profile images and pool images
3. Why we process this data
We process data to create and manage accounts, run pools and predictions, show rankings and results, send invites and notifications, secure the app, and handle questions or support requests.
Most processing is necessary for the performance of the agreement with the user, for example for account management, participation in pools, predictions, and showing results.
For certain features, such as notifications or similar communications, processing may be based on consent. In addition, we may process data on the basis of legitimate interest or a legal obligation, depending on the type of data and the purpose involved.
4. Storage and technical infrastructure
Data is stored in the technical infrastructure Matcho uses to provide the service. This includes a relational database, session and cache storage, cloud storage for uploaded files, and infrastructure used for push notifications.
Based on the current configuration, Matcho's core data storage is primarily set up in European regions. The application infrastructure uses Laravel Cloud in a European region, and certain Firebase services are configured within the project to use a European region.
For some supporting third-party services, such as authentication or push notifications, processing may also take place outside the European Economic Area. In that case, such processing takes place under the relevant provider's terms and applicable safeguards.
5. Sharing with third parties and processors
We only share personal data to the extent needed for the technical operation or management of Matcho.
We do not sell personal data to third parties.
- hosting and database providers, including Laravel Cloud
- cloud storage providers for images and other files
- services used for authentication and push notifications, including Firebase or Google services
- parties needed for support, management, or security
- public authorities or other third parties if we are legally required to do so
6. Retention periods
We do not keep personal data longer than necessary for the purpose for which it was collected or processed.
Account data and related pool data may be retained while an account remains active or as long as needed for pool functionality, administration, security, or dispute handling.
When an account is deleted or anonymized, directly identifying data is removed or nulled where possible. Certain functional or administrative data may be retained on a limited basis for ranking integrity, security, or legal obligations.
7. Security
We take reasonable technical and organizational measures to protect personal data and other relevant data against loss, misuse, and unauthorized access.
Even with these measures, absolute security can never be guaranteed.
8. User rights
To the extent applicable under the General Data Protection Regulation (GDPR) and other privacy laws, users may request access, correction, deletion, restriction, or portability of their personal data.
Users may also request that their account be anonymized or deleted. Requests are assessed with due regard for legal obligations, technical limitations, and legitimate interests.
9. External services and links
Matcho may use third-party services or link to external websites and platforms. Data processing by those third parties is governed by their own privacy policies and responsibilities.
10. Changes
We may update this privacy statement from time to time. The most recent version will be published on this page.
This privacy statement is intended as a general public explanation. For business customers, additional arrangements such as a data processing agreement or security information may be made available separately.