Back to home

Privacy Policy

Last updated: 26 September 2026

This policy describes how ICLICS SRL processes the personal data of users of the TeeConnect and PopConnect applications, of the teeconnect.io and PopConnect websites, and of people who respond to an invitation without creating an account (hereinafter "the Service"). Both applications share the same infrastructure and the same rules.

It has been drawn up in accordance with Regulation (EU) 2016/679 ("GDPR") and the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data.

1. Data controller

The data controller is:

  • ICLICS SRL, a private limited liability company under Belgian law
  • Registered office: Chemin du Beau Vallon 42, 5100 Wépion (Namur), Belgium
  • Company number (CBE) / VAT: BE 0548.813.132
  • Contact for your data: contact@teeconnect.io

ICLICS SRL has not appointed a data protection officer, as such an appointment is not mandatory for its activities. Requests are handled directly by its manager.

Two specific situations: the contacts you record in your logbook and the notes a coach takes about their students are data that you decide to record; you are responsible for them and we process them on your behalf (see the terms of use, article "Third-party data"). Likewise, the organiser of a community is responsible for the use they make, outside the Service, of their members' information.

2. Data collected and purposes

We only collect what is needed for the Service to work. Data marked "optional" is only collected if you provide it.

2.1. Account and profile

DataPurpose
Email address, password (stored in irreversibly encrypted form) or Google or Apple identifierCreating the account, signing in, account-related messages
First name, last name, nickname, photoIdentification between members (you can choose to display only your nickname)
Sports played, level, handicap, club, licence, years of practice, availability, playing preferencesSuggesting suitable partners and games
Country, region, languagesFinding nearby partners, clubs and communities; language of the app and emails
Occupation, company, company size, sector, networking goals, LinkedIn profile, introduction text (optional)Professional networking between members
Date of birth, gender, phone number (optional)Completing the profile; they are not shown to other members
Acceptance of the terms of use (date and version)Proof of your consent

The profile information you provide is visible to other members, according to your visibility settings. Your email address, date of birth, phone number and location are never displayed.

2.2. Location

If you allow access to your phone's location, the app records your location each time it is opened, rounded to about one kilometre. It is used to calculate distances: members, clubs, communities and partner offers near you. It is never shown to other members. Each new location replaces the previous one, and it is deleted along with your account. You can withdraw permission at any time in your phone's settings.

2.3. Activity in the Service

DataPurpose
Private messages, community messages, polls, reactions, shared documentsEnabling exchanges between members
Games, matches, tournaments, scores, invitations, requests to joinOrganising games and keeping their history
Communities: membership, role, events, responses, lists, proposalsRunning communities and their events
Coaching: bookings, assessments, the coach's notes on the studentRunning lesson bookings
Logbook: contacts, games, reminders you recordLetting you keep track of the people you meet; this data is visible only to you
Favourites, blocks, reportsPersonalising your experience and keeping members safe
Feedback and problem reports (text, optional screenshot, phone model, system and app version, language)Handling your request and fixing defects

2.4. Matchmaking and automatic summaries

To suggest partners who share your interests, part of your profile (level, club, country, region, sector, occupation, company, availability, preferences and introduction text, without your name or email address) is turned into a numerical representation by an artificial intelligence model, through our provider OpenRouter. Each week, we may present your first name, occupation and region to other members with a similar profile, and vice versa.

In a community, when a member has many unread messages, and for the community's weekly newsletter, the messages concerned and their authors' first names are sent to the same provider to write a short summary, shown only to members of the community.

None of these operations produces a decision that has legal effects on you: they are suggestions.

2.5. Notifications and emails

DataPurpose
Your device's notification identifier, languageSending you the notifications you have accepted
Email address, email delivery events (delivered, rejected, unsubscribed)Sending emails relating to your account, communities and weekly introductions, and no longer writing to an address that refuses them
Email addressInforming you of news about the Service; each email contains an unsubscribe link

2.6. Responding to an invitation without an account

If you respond to an event from a link, without creating an account, we record your first name, email address, response, the number of people accompanying you and your language. The address is used only to confirm your response and to let you change or withdraw it. An unconfirmed response is deleted after 72 hours; a confirmed response is deleted six months after the date of the event, or as soon as you withdraw it. If you later create an account with the same address, the response is linked to it.

2.7. Event payments

When an organiser enables online payment for an event, the payment is processed by Stripe. We send Stripe your email address and the name of the event; your card or bank account details never reach us. We keep the amount, date and status of the payment.

To receive payments, an organiser opens an account with Stripe, which asks them directly for the information required by anti-fraud and anti-money-laundering regulations: identity, date of birth, address, national identification number (in Belgium, the national register number), bank details and, where applicable, an identity document. Stripe processes this data as a separate data controller, under its own privacy policy. We neither receive nor keep this information: only the status of the account and the list of items still required by Stripe.

2.8. Audience measurement and advertising

The app uses Google Firebase Analytics to measure its use (screens opened, steps completed such as signing up or creating a game, device model, version, country), linked to a technical identifier of your account, without your name or email address.

It also uses the Meta App Events kit to measure the effectiveness of our advertising campaigns on Facebook and Instagram: installation, opening of the app, sign-up and a few key steps are sent to Meta. The app does not access your phone's advertising identifier.

You can object to these measurements by writing to us. A future version of the app will offer you a setting to refuse them directly.

2.9. Websites, maps and weather

The websites use neither advertising cookies nor audience measurement tools. They store in your browser the language you chose and, for the organiser and administration areas, your session. The websites' host keeps technical logs (IP address, page requested, date).

The club map displays OpenStreetMap base maps: your device requests them directly from the OpenStreetMap Foundation, which receives your IP address and the area displayed. A club's weather is requested by your device from the OpenWeather service, with the club's coordinates (not yours) and your IP address.

2.10. Support and partnership requests

When you write to us, or fill in the partnership form on the website (name, email address, company, country, message), we use this information to reply to you.

3. Legal bases

  • Performance of the contract (Art. 6(1)(b)): account, profile, messaging, games, communities, coaching, logbook, matchmaking, notifications and emails relating to the Service, responses to invitations, payments.
  • Consent (Art. 6(1)(a)): location, device notifications, the "Partner events" option, optional profile data. You can withdraw it at any time.
  • Legitimate interest (Art. 6(1)(f)): security and abuse prevention, weekly summaries and introductions, informational emails to members, audience measurement and measurement of our campaigns, handling of support and partnership requests. You can object to it.
  • Legal obligation (Art. 6(1)(c)): retention of accounting records relating to payments, responses to the authorities.

4. Who receives your data

We never sell your data. It is visible to other members to the extent described in section 2, and to the organiser of a community as regards its members and events. We use the following providers, each bound by contractual commitments in accordance with Article 28 of the GDPR:

ProviderRoleLocation
Supabase, Inc.Database, authentication, photo storage, server functionsEuropean Union (Frankfurt); US company
Netlify, Inc.Website hostingUnited States, global network
Resend, Inc.Sending emailsUnited States
Google (Firebase)Notifications on Android and iPhone, audience measurementUnited States and European Union
Google and AppleSign-in with a Google or Apple account (if you choose it), notifications on iPhoneUnited States
Meta Platforms Ireland LtdMeasurement of advertising campaignsIreland and United States
OpenRouter, Inc. and the model provider (OpenAI)Numerical representation of the profile, discussion summariesUnited States
Stripe Payments Europe, LtdEvent payments (when enabled)Ireland and United States
OpenStreetMap FoundationBase mapsUnited Kingdom
OpenWeather LtdClub weatherUnited Kingdom

We may also disclose data to an authority that legally requires it.

5. Transfers outside the European Union

Our database is hosted in the European Union. Some of the providers listed above are established in the United States or process data there. These transfers are governed by the standard contractual clauses adopted by the European Commission and, where the provider is certified under it, by the EU-US Data Privacy Framework. The United Kingdom benefits from an adequacy decision of the European Commission.

6. Retention periods

  • Account, profile, activity and messages sent: for as long as your account exists. When you delete your account, this data is erased immediately; the host's backup copies then disappear through rotation, within 30 days at most.
  • Location: replaced at each update, erased with the account.
  • Responses to an invitation without an account: 72 hours if they are not confirmed; six months after the date of the event if they are.
  • Payments: for the period required by Belgian accounting and tax legislation.
  • Technical logs, sign-in log and audit log: 12 months at most.
  • Audience measurement: 14 months at most at Google Firebase; at Meta, according to its own retention rules.
  • Exchanges with support and partnership requests: the time needed to handle the request, then 3 years at most.

7. Your rights

You have the following rights:

  • Access and portability (Art. 15 and 20): on simple request to contact@teeconnect.io, from your account's address, we provide you with all your data in a structured, reusable file (JSON).
  • Rectification (Art. 16): directly from your profile, or by writing to us.
  • Erasure (Art. 17): from the app (Profile, then "Delete my account"), from the page teeconnect.io/en/delete-account, or by writing to us.
  • Objection (Art. 21): to processing based on our legitimate interest, including audience measurement and informational emails (unsubscribe link in each email).
  • Restriction (Art. 18): in the cases provided for by the GDPR.
  • Withdrawal of consent: at any time, in your phone's settings (location, notifications) or in your profile, without affecting what was done before.

We reply within one month. If your data appears in a member's logbook or in a community, you can contact that member or the organiser, or us directly: we will help them handle your request.

You can lodge a complaint with the Data Protection Authority, Rue de la Presse 35, 1000 Brussels (www.dataprotectionauthority.be), or with the authority of your country of residence.

8. Our team's access to your data

Our team only accesses your data to run the Service, handle a request you send us, moderate reported content or ensure security. Sensitive operations (change of rights, assignment of a moderator or administrator role, data export, account deletion, changes to the legal texts) are recorded in an audit log, without your name or address. Tests are carried out on test accounts, never on yours.

9. Security

  • Encryption of exchanges (TLS) and of stored data
  • Passwords stored in irreversibly encrypted form
  • Access rules in the database: each member only accesses what concerns them
  • Limited and logged administrative access
  • Hosting with Supabase on SOC 2 certified infrastructure

In the event of a data breach posing a risk to you, we notify the Data Protection Authority within 72 hours and, if the risk is high, the people concerned. Any breach discovered is recorded in our incident register, even if it has no consequences.

10. Minimum age

The Service is reserved for people aged 16 or over. If we learn that an account belongs to a younger person, we delete it.

11. Changes

We may change this policy to reflect changes to the Service or to regulations. The date of the last update appears at the top of the page. Any significant change will be announced to you in the app or by email.

12. Contact

  • Email: contact@teeconnect.io
  • Post: ICLICS SRL, Chemin du Beau Vallon 42, 5100 Wépion, Belgium
  • Subject: "Data protection — [your request]"