ROXMATCH ‹ Back to app

Privacy Policy

Last updated: 12 July 2026

This policy explains what personal data ROXMATCH ("we") collects, why, and your rights. We process data in line with the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP).

1. Who is responsible

The controller for your data is Emiliano Cantarutti, Wiesenstrasse 14a, 8952 Schlieren, Zürich, Switzerland. Contact: legal@roxmatchapp.com. See our Impressum.

2. Data we collect

AccountEmail address, and (if you use it) your Google account identifier for sign-in.
ProfileName, home city, bio, photos, gender, division(s), category, goal time, languages, and the races you target. This is shown to other athletes to make matches.
VerificationIf you request the verified badge, a selfie you upload so we can confirm you're a real person. It is stored privately, reviewed by us, deleted promptly after review, and never shown to other athletes.
Connections (optional)An Instagram handle, shown as a link on your profile. If you connect Strava, we receive your Strava athlete ID and a recent training summary (recent run distance and count) to display on your profile; you can disconnect at any time.
ActivitySwipes, matches, chat messages, blocks and reports you create.
PaymentIf you subscribe, Stripe processes your payment. We store a Stripe customer/subscription reference and your premium status — never your card number.
TechnicalDevice/usage data for analytics and error diagnostics (e.g. pages viewed, actions taken, error reports, approximate region, browser type).

3. Why we use it (legal bases)

4. Who we share it with (processors)

We use trusted providers who process data on our behalf:

SupabaseDatabase, authentication, file storage (your account and app data).
StripeSubscription payments.
ResendTransactional email (confirmations, password resets, match & report notifications).
PostHog (EU)Product analytics.
Sentry (EU)Error tracking.
Vercel / CloudflareHosting, content delivery and DNS.
GoogleOnly if you choose "Sign in with Google".
StravaOnly if you choose to connect your Strava account, to import your recent training summary.

We do not sell your personal data.

5. International transfers

We aim to keep data in the EU/Switzerland where possible (e.g. EU-hosted analytics and error tracking). Some providers may process data outside the EU/CH under appropriate safeguards such as EU Standard Contractual Clauses.

6. How long we keep it

We keep your data while your account is active. Verification selfies are deleted promptly after review. When you delete your account, your profile, photos, swipes, matches and messages are deleted. Some records may be retained where legally required (e.g. payment records) or in backups for a limited period.

7. Your rights

You have the right to access, correct, delete, restrict, or object to processing of your data, and to data portability. You can delete your account and data at any time from your profile ("Delete my account"). To exercise other rights, contact legal@roxmatchapp.com. You may also lodge a complaint with a supervisory authority (in Switzerland, the FDPIC; in the EU, your local authority).

8. Cookies & local storage

We use local storage for sign-in sessions and analytics. We do not use advertising or cross-site tracking cookies.

9. Age

ROXMATCH is only for users aged 18 or over. We do not knowingly collect data from anyone under 18.

10. Changes

We may update this policy; material changes will be reflected by the "last updated" date and, where appropriate, notified in-app or by email.