Last updated: February 19, 2026
SupClub ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you use our mobile application, web dashboard, and related services (collectively, the "Service"). We operate in accordance with the General Data Protection Regulation (GDPR) and other applicable European data protection laws.
The data controller responsible for your personal data is:
Wayrone Enterprises5 SRL
Operating the SupClub platform
CUI: 51300363 | Reg. No: J2025011224003
CAEN: 6210, 6310, 6391
Str. Pandurilor 185, Sat Closani, Gorj 217329, Romania
Email: hello@supclub.vip
Website: supclub.vip
When you create an account, we collect:
You may voluntarily provide:
When you check in to a venue using an access code or QR scan:
If you subscribe to a paid plan (venue owners), payment processing is handled entirely by our payment provider, Lemon Squeezy. We store:
We do not store credit card numbers or full payment details. These are held securely by Lemon Squeezy.
Processing your account, profile, venue access, messaging, and subscription data is necessary to provide the Service.
Security measures (rate limiting, content moderation, fraud prevention), analytics for service improvement, and ensuring platform safety.
Push notifications and optional profile information are collected based on your consent, which you can withdraw at any time.
Processing required to comply with applicable laws, such as tax and accounting obligations for subscription billing.
We share your personal data with the following third-party service providers who process data on our behalf:
Purpose: Authentication, database hosting, and user management
Data shared: Account data, profile data, all application data
Purpose: Backend API server hosting
Data shared: All data that passes through our API servers (encrypted in transit)
Purpose: Web dashboard and marketing website hosting
Data shared: IP address, HTTP request metadata, authentication cookies
Purpose: Redis caching and rate limiting
Data shared: Rate-limiting counters keyed by IP address or user ID (no personal content stored)
Purpose: Real-time messaging infrastructure
Data shared: User ID, username, display name, avatar URL, online/offline status, chat messages, message read receipts, reactions, group memberships and roles, device information for push notifications via Stream
Purpose: Subscription billing, payment processing, VAT collection and remittance. Lemon Squeezy acts as the Merchant of Record, meaning they are the legal seller for subscription transactions.
Data shared: Email, name, subscription plan, payment and billing details. As Merchant of Record, Lemon Squeezy is an independent data controller for payment data.
Purpose: Push notification delivery
Data shared: User ID (pseudonymous identifier), device push tokens, platform and OS information, notification preferences
All third-party processors are contractually required to handle your data in accordance with GDPR requirements and their respective terms of service include data processing provisions. Note that Lemon Squeezy, as Merchant of Record, acts as an independent data controller for payment and billing data — their processing of such data is governed by their own privacy policy.
Our primary infrastructure is hosted within the European Economic Area (EEA): Supabase in EU West (Ireland), Google Cloud Run in Belgium (europe-west1), and Upstash in Belgium (europe-west1). However, the following third-party processors transfer data outside the EEA:
Transfer to: United States
Safeguard: Standard Contractual Clauses (SCCs)
Data: Chat messages, user profiles, group memberships
Transfer to: United States
Safeguard: Standard Contractual Clauses (SCCs)
Data: Email, subscription and billing data
Transfer to: United States
Safeguard: Standard Contractual Clauses (SCCs)
Data: User ID, device push tokens, notification preferences
Transfer to: United States (Edge Network)
Safeguard: Standard Contractual Clauses (SCCs)
Data: IP address, HTTP request metadata, authentication cookies
All transfers are protected by Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring your data receives an equivalent level of protection as within the EEA.
As a data subject in the European Union, you have the following rights:
Request a copy of the personal data we hold about you.
Request correction of inaccurate or incomplete data.
Request deletion of your personal data. You can delete your account directly in the app or web dashboard.
Request that we limit how we process your data.
Request your data in a structured, commonly used, machine-readable format.
Object to processing based on legitimate interests.
Withdraw consent at any time where processing is based on consent (e.g., push notifications).
To exercise any of these rights, contact us at hello@supclub.vip. We will respond within one month of receipt. This period may be extended by two further months where necessary, taking into account the complexity and number of requests. We will inform you of any such extension within one month of receipt, together with the reasons for the delay.
We implement appropriate technical and organisational measures to protect your personal data, including:
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the competent supervisory authority (ANSPDCP) within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay (GDPR Article 34).
We use a combination of automated and manual tools for content moderation. Profile text, group names, and uploaded images are subject to automated moderation (image moderation is provided by our messaging infrastructure provider, GetStream). Chat messages are not automatically scanned; instead, users may report inappropriate messages through an in-app reporting system, and our team reviews reports manually.
Under GDPR Article 22, you have the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you. Where automated moderation results in content removal, you may request human review by contacting us at hello@supclub.vip.
Our Service is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have collected data from a minor, please contact us at hello@supclub.vip and we will promptly delete it.
In accordance with Articles 11 and 12 of the EU Digital Services Act (Regulation 2022/2065), we designate the following single point of contact for communications with authorities and users regarding content moderation and legal matters:
Our Service does not use tracking or advertising cookies and does not track users across third-party websites. We respect browser Do Not Track (DNT) signals; however, because we do not engage in cross-site tracking, no change in behaviour occurs when a DNT signal is detected.
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or through the Service. Your continued use of the Service after such changes constitutes acceptance of the updated policy.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. Our supervisory authority is:
ANSPDCP
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336, București, Romania
Website: www.dataprotection.ro
You may also lodge a complaint with the supervisory authority in the EU member state of your habitual residence or place of work.
For any questions or requests regarding this Privacy Policy or your personal data:
Wayrone Enterprises5 SRL
CUI: 51300363 | Reg. No: J2025011224003
Str. Pandurilor 185, Sat Closani, Gorj 217329, Romania
Email: hello@supclub.vip
Website: supclub.vip