1. Scope
This Privacy Policy describes how Rondo FC processes personal data for adult members and participants in Abu Dhabi, UAE, in accordance with UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (PDPL).
2. Data we collect
- Account and contact data: name, email, phone, date of birth, emergency contact, and profile details.
- Booking and session data: bookings, attendance, waitlist interest, membership status, and session credits.
- Payment data: order references, payment status, and limited billing metadata via payment providers such as Ziina. We do not store full card numbers.
- Health or safety data you choose to disclose for safe participation or emergency response.
- Operational communications and, where opted in, marketing communications.
3. How we use data
- Provide coaching, booking, membership, payment, and support services.
- Send operational communications such as session reminders, venue updates, safety notices, and payment confirmations.
- Process payments, prevent fraud, and maintain service security.
- Use health or safety information only for safety, emergency response, and legal compliance.
4. Sharing and processors
- We use service providers such as Supabase, Vercel, Ziina, Resend (transactional communications), and messaging providers to operate the platform.
- Google and Apple identity data may be processed when you sign in with Google or Apple authentication providers. We receive only the identity attributes you consent to share.
- Supabase stores and processes platform data including account, booking, membership, and communications metadata.
- Resend is used for transactional emails such as session reminders, payment confirmations, and account notices. We do not send marketing emails through Resend.
- We do not sell personal data.
- We may share data with emergency services or venue operators where reasonably necessary in a medical emergency.
5. Retention and security
We retain data for as long as needed to provide services, meet legal obligations, and resolve disputes. We apply technical and organisational measures to protect personal data.
6. Your rights and contact
You may request access, correction, or deletion subject to applicable law and operational requirements. Marketing communications can be opted out of without affecting required operational messages.
Questions: team@rondo.ae.