Box Events

Privacy policy

Last updated: [FECHA]

At Box Events we respect your privacy. This policy explains what personal data we process, for what purpose, and what rights you have, in accordance with Regulation (EU) 2016/679 (GDPR) and applicable law.

1. Data controller

Controller: [LEGAL NAME] — Tax ID [TAX ID] — Address: [ADDRESS] — Contact email: [CONTACT EMAIL]. [If applicable: Data Protection Officer (DPO): [DPO CONTACT]].

2. Data we process

Depending on how you use the Service, we may process:

  • Identity and account data: first name, last name, gender, email and password.
  • Registration data: competition and category, team, participant name, shirt size, waiver signature and data related to your participation.
  • Payment data: when you pay for a registration, payment is handled by Stripe; we process payment status information, not your full card details.
  • Optional content: photos or results uploaded by you or the organizer.
  • Technical data: access logs and data required for security.

3. Purposes and legal basis

  • Managing your account and registrations — basis: performance of the contract/Service terms.
  • Processing registration payments — basis: performance of the contract.
  • Sending operational communications (confirmations, verifications, event notices) — basis: performance of the contract and legitimate interest.
  • Processing you accept when registering (consent checkbox) — basis: consent, which you may withdraw at any time.
  • Compliance with legal obligations — basis: legal obligation.

4. Recipients and processors

We share data with providers that supply services under a data processing agreement, only for the purposes above:

  • Supabase — database hosting and authentication.
  • Stripe — payment processing.
  • Resend — transactional email delivery.
  • Cloudflare — web hosting and file storage.
  • The gym/organizer of the event you register for, to manage your participation.

Some providers may process data outside the European Economic Area; in that case the appropriate safeguards under the GDPR apply (e.g. standard contractual clauses). [Review and detail according to providers.]

5. Retention

We retain your data while you have an active account and for the periods necessary to comply with legal obligations and address potential liabilities. After that, data is deleted or anonymized. [Specify concrete retention periods.]

6. Your rights

You may exercise your rights of access, rectification, erasure, objection, restriction and portability, and withdraw your consent, by writing to [CONTACT EMAIL]. If you believe we have not handled your request properly, you may lodge a complaint with the competent supervisory authority (in Spain, the Spanish Data Protection Agency, www.aepd.es).

7. Security

We apply reasonable technical and organizational measures to protect your data. No system is completely infallible, but we work to minimize risks.

8. Cookies

The Service uses cookies or strictly necessary technical storage for its operation (e.g. to maintain your session). [If analytics or third-party cookies are used, detail them here and include the consent mechanism.]

9. Changes to this policy

We may update this policy. We will publish the current version on this page with its update date.

10. Contact

For any privacy inquiry: [CONTACT EMAIL].