Introduction
This policy explains how ChessDate (referred to below as "we", "the service" or "the app") collects, uses and protects your personal data when you use our iOS app or visit our website.
ChessDate is published by Eliott Vanlerberghe, a sole trader operating under the business name "ChessDate", registered with the Paris Trade and Companies Register under number 878 073 543, with its registered office at 173 rue de Courcelles, 75017 Paris, France. For any question about your data, you can reach us at [email protected].
We process your data in accordance with the General Data Protection Regulation (GDPR), the French Data Protection Act, and the guidance issued by the CNIL for mobile applications. These rules apply to you wherever you are located, because we are established in France.
1. The data we collect
Here is a clear summary of what we collect, why, on what legal basis, and how long we keep it.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Apple ID and email address | Creating and securing your account | Performance of the contract | Lifetime of the account |
| First name, date of birth, gender | Displaying your profile, verifying you are 18+ | Performance of the contract | Lifetime of the account |
| Preferred partners | Filtering the profiles shown to you | Explicit consent (special category data) | Lifetime of the account |
| Profile photos | Public display of your profile | Consent | Lifetime of the account |
| Precise location | Calculating the distance between you and other players | Consent (iOS permission) | Lifetime of the account |
| Verification selfie | Checking that you are the person in your profile photos, "Verified profile" badge, prevention of fake profiles | Consent | Deleted as soon as your request has been reviewed, whether accepted or refused (see section 5) |
| Online chess username and rating | Verifying your chess level | Performance of the contract | Lifetime of the account |
| Profile content and answers | Profile content and gameplay experience | Performance of the contract | Lifetime of the account |
| Messages, matches, interactions, games | Operating the matchmaking service | Performance of the contract | Lifetime of the account |
| Usage statistics (analytics) | Improving and securing the service | Legitimate interest | 26 months maximum |
| In-app purchase history | Managing your Premium subscription | Performance of the contract / Legal obligation | Deleted from our servers when you delete your account; accounting records are kept for 10 years by Apple and our billing provider |
| Reports and blocks | Moderation and community safety | Legitimate interest / Legal obligation | 3 years after the account is closed — reports you have submitted are retained and then anonymised (see section 7) |
| IP address, approximate country, user agent (waitlist form) | Securing the form, preventing abuse, technical logging | Legitimate interest | 24 months maximum |
Special category data
Because of the nature of our service, we process data that may qualify as special category data under Article 9 GDPR: your preferences regarding the gender of the partners you are looking for may reveal your sexual orientation. This processing relies on your explicit and revocable consent, given when you enter this information in the app.
The verification selfie, by contrast, is not subject to any biometric processing. It is compared with your profile photos visually, by a member of our team. We use no facial recognition system, no biometric template is computed, and no decision is automated. A photograph falls under Article 9 GDPR only where it undergoes specific technical processing allowing the unique identification of a person, which is not the case here.
2. Legal bases for processing
In accordance with Article 6(1) GDPR, we only process your personal data where we have a legal basis for doing so. Here is how each of our processing activities maps onto those bases.
Performance of the contract (Article 6(1)(b))
Creating and managing your account, authentication, displaying your profile, matching you with other users, handling match interactions, organising some chess games through a partner platform, managing your Premium subscription, processing payments, and responding to your support requests relating to the use of the Service.
Consent (Article 6(1)(a))
Enabling location, adding photos to your profile, profile verification by selfie, processing your partner preferences (special category data — Article 9(2)(a) GDPR), and signing up to the waitlist form. You can withdraw your consent at any time in the app settings or by contacting us. Withdrawal does not affect the lawfulness of processing carried out beforehand.
Legitimate interest (Article 6(1)(f))
Security and integrity of the Service, prevention of fraud and abuse, moderation of reports, access logging, protection against automated behaviour, aggregate measurement of product performance, and defence of our rights in the event of a dispute. We balance these interests against your rights and freedoms before relying on this basis, and you have a right to object (see section 6).
Legal obligation (Article 6(1)(c))
Retention of accounting and tax records relating to Premium subscriptions, responses to requests from competent authorities, retention of reports and associated data for the purpose of cooperating with the authorities, and compliance with applicable French and European legislation (GDPR, French Consumer Code, French Act on Confidence in the Digital Economy).
3. iOS permissions requested
The app requests three permissions from iOS:
- Camera — to take the profile verification selfie, when you enable that feature on your profile.
- Location (while the app is open only) — to calculate the distance between you and other players.
- Notifications — to send you game reminders and alerts about your matches. The permission is requested when the app launches.
You can decline these permissions, or withdraw them at any time, in iOS Settings > ChessDate. Some features will then be unavailable.
4. Processors and partners
ChessDate relies on technical service providers to operate. We have selected partners offering strong data protection guarantees. No data is sold or shared for third-party advertising purposes.
| Provider | Role | Location |
|---|---|---|
| Apple Inc. | Authentication (Sign in with Apple), App Store, in-app purchases, notifications | United States (DPF) |
| Google (Firebase) | Hosting, database, photo storage, authentication, analytics, crash reporting | United States and European Union (DPF) |
| RevenueCat, Inc. | Technical management of Premium subscriptions | United States (DPF) |
| Chess platform partner | Authentication of your chess account and organisation of games | European Union |
| Cloudflare, Inc. | Website hosting and storage of waitlist sign-ups | United States (DPF) — storage location preference set to Western Europe |
Transfers outside the European Union
Some of our providers (Apple, Google/Firebase, RevenueCat, Cloudflare) are established in the United States or operate across several jurisdictions. In accordance with Chapter V GDPR, any transfer of your data to a country outside the European Economic Area is covered by one of the following mechanisms:
- The EU–US Data Privacy Framework, adopted by the European Commission adequacy decision of 10 July 2023, where the provider is certified.
- The Standard Contractual Clauses approved by the European Commission on 4 June 2021, incorporated into our contracts with processors.
- Where applicable, supplementary technical and organisational measures (encryption, pseudonymisation, access control) where the transfer assessment requires them.
You can obtain a copy of the safeguards applicable to a specific transfer by writing to [email protected].
5. Security of your data
We implement appropriate technical and organisational measures to protect your data:
- Communication between the app and our servers is encrypted with HTTPS/TLS.
- The access token for your online chess account is stored in the iOS Keychain, separately from the rest of your data.
- The public GPS coordinates shown to other users are deliberately rounded to roughly one kilometre, so your exact position is never exposed.
- Access to the database is governed by strict server-side rules that prevent unauthorised accounts from reading or modifying data.
- The verification selfie is stored in a location isolated from the rest of your data, accessible only for the review of your request. It is deleted as soon as that request has been reviewed, whether accepted or refused: only the badge and the status are kept, not the photo. If a submission is interrupted before completing, a file may remain temporarily; it is overwritten by your next attempt and deleted along with your account. You can request its early deletion at any time at [email protected].
6. Your rights
Under Articles 15 to 22 GDPR, you have the following rights over your data:
- Right of access (Article 15) — obtain confirmation that your data is being processed and receive a copy of it.
- Right to rectification (Article 16) — correct any inaccurate or incomplete data. Most of it can be edited directly in the app.
- Right to erasure (Article 17) — delete your account and your data from the Profile screen in the app. The procedure starts immediately and cannot be cancelled. Section 7 sets out exactly what is erased straight away, and the few items that remain, either because they also concern other users or for the safety of the community.
- Right to restriction (Article 18) — ask us to temporarily suspend the processing of your data in certain circumstances.
- Right to data portability (Article 20) — receive your data in a structured, commonly used, machine-readable format. For this request, write to [email protected].
- Right to object (Article 21) — object to processing based on legitimate interest, or to processing for direct marketing purposes.
- Right to withdraw consent (Article 7(3)) — at any time, without affecting the lawfulness of processing carried out beforehand.
- Automated decisions (Article 22) — we do not take decisions producing legal or similarly significant effects concerning you based solely on automated processing.
We respond to your request within one month, which may be extended by two further months where the request is complex or where we receive a high number of requests (Article 12(3) GDPR). We may ask you to prove your identity before acting on it.
If you believe your rights are not being respected, you can lodge a complaint at any time with the CNIL, the French data protection authority, at www.cnil.fr/en/plaintes. You may also lodge a complaint with the supervisory authority of your country of residence.
7. Account deletion
You can delete your account at any time from Profile > Delete my account. For your security, the app asks you to confirm your identity with Apple before the procedure starts. Once started, deletion cannot be cancelled.
Deleting your account does not cancel your Premium subscription. Subscriptions are managed by Apple, not by us. You need to cancel it separately in iOS Settings > your name > Subscriptions, otherwise it will keep renewing and being charged.
What is deleted
- Your profile photos and your verification selfie.
- Your private and public profile: first name, date of birth, gender, preferences, location, profile content and statistics.
- Your matchmaking decisions, the likes you have received and the ones you have sent.
- The blocks you have placed, and the reveals you had unlocked about other players.
- Your profile verification requests and the data relating to your games.
- Your waitlist entry, your referral as a referred user, your technical subscription history, your usage statistics and your error logs.
- Your authentication account, along with the "Sign in with Apple" authorisation granted to ChessDate, which we revoke with Apple.
What remains, and why
We would rather be accurate than reassuring: we cannot promise immediate and total erasure. Some data does not belong to you alone, and some of it protects other users. Here is the complete list of what remains after deletion.
- The messages you have exchanged. A conversation belongs to two people. The matches you took part in are marked "account deleted" and become inaccessible, but the messages you sent may remain visible to your former match until they delete their own account, or until the conversation is purged by our maintenance operations.
- The receipts of the games you played, attached to those same conversations.
- The game invitations you sent or received. Each one links two accounts: it remains visible to the other person, who has not asked for theirs to be deleted.
- The reports you have submitted. We keep them for moderation purposes: deleting them would erase safety records concerning other accounts, irreversibly. The identifier linking you to those reports is anonymised during a later maintenance operation, after which it is no longer possible to trace them back to you.
- Decisions made by other users about you: their own matchmaking choices, and the blocks they placed against your former account. That data belongs to them, and erasing a block you were subject to would remove a protection from the person who put it in place.
- Reveals about you that other players unlocked. When an opponent put you in check, they unlocked one of your personal answers. Those answers stay visible on their side: they are part of their game, and only they can erase them.
- Your referral code. It stays attached to the people you referred, whose history it must not break.
- Technical security logs — in particular sign-in attempts on your account. We keep them to detect fraudulent access and automated behaviour. They contain no profile data.
- A technical record of the deletion itself. It contains only your account identifier, an operation number and timestamps — no profile data. It guarantees that the procedure cannot be bypassed, and that your account cannot be recreated, if it is interrupted. It will be erased once the server-side purge is finalised.
These residual items are subject to a server-side purge and anonymisation, currently being rolled out. You can ask at any time for details of what remains for your account, or for its early erasure where that is legally possible, by writing to [email protected].
If deletion is interrupted
A network outage or closing the app can interrupt the procedure. If that happens, the app automatically resumes it where it stopped the next time you open it, and does not let you return to normal use of the service until it has finished. During that interval, no data can be recreated on your account.
8. Minors
ChessDate is strictly reserved for adults (18 and over). Your date of birth is required at sign-up, and the picker prevents entering a date corresponding to an age under 18. If we discover that an account has been created by a minor, or if a report brings it to our attention, we delete it immediately.
If you believe a user is a minor, report them directly from the app using the "Underage user" reason, or write to us at [email protected].
9. Notifications
The app can send you local notifications (generated on your device, without passing through our servers) for game reminders. A remote (push) notification feature may be added in a future version; if so, this policy will be updated before it is enabled.
10. Website and waitlist form
The chessdate.app website offers a waitlist sign-up form ahead of the public release of the app. When you sign up, we collect:
- Your first name — to personalise our communications.
- Your email address — to notify you on launch day.
- Your city (optional) — to estimate the geographic coverage of the future community.
- Your browser language — to write to you in the right language.
When the form is submitted, we also record limited technical data: your IP address, the country inferred by Cloudflare from that address, and your browser's user agent. This information is used solely to secure the form, prevent abuse (spam, automated submissions) and ensure technical traceability of sign-ups. It is processed on the basis of our legitimate interest and kept for 24 months at most.
This data is processed on the basis of your consent (submitting the form) and stored using the Cloudflare D1 database service (Cloudflare, Inc.), configured with a location preference in Western Europe. As Cloudflare is established in the United States, any transfer outside the European Economic Area is covered by the EU–US Data Privacy Framework and by the European Commission's Standard Contractual Clauses. It is kept until the public launch of the app, and for no more than 24 months after your sign-up. You can request its deletion at any time by writing to [email protected].
Waitlist data can be viewed by ChessDate through a secure internal administration tool, hosted on the same Cloudflare infrastructure and protected by strong authentication. It is used solely to manage sign-ups, answer support requests and prepare the launch of the service. Access is strictly limited to authorised persons.
The iOS app does not use cookies. The website does not currently set any analytics, advertising or social network cookies. Should that change, a consent banner meeting CNIL requirements would be put in place before anything is set.
11. Changes
We may update this policy to reflect technical, legal or feature changes. The date of the last update appears at the top of the page. For substantial changes, we will inform you through a message in the app.
12. Contact
For any question, request to exercise your rights, or complaint relating to your personal data:
Eliott Vanlerberghe
Sole trader — Business name: ChessDate
Paris Trade and Companies Register 878 073 543
173 rue de Courcelles, 75017 Paris, France
[email protected]