Skip to content
JOINO Sport
  • How it works
  • Venues
  • Padel DNA
  • JOINO AI
  • Community
Get the app

Legal

Privacy Policy

Last updated · 9 September 2026

This Privacy Policy describes how Joino (operated by AICO Tech L.L.C-FZ, Meydan Free Zone, Dubai, UAE, license 2646735.01, hereafter "we", "us", "our") collects, uses, stores, and protects your personal data when you use the Joino web app at joinosport.com (the "Service"). The Service includes the web app and the official JOINO mobile app. The iPad court display, watchOS companion and local-network scoreboard remain outside the Service until an active release expressly includes them.

1. Data we collect

When you create an account or use the Service we collect:

  • Account data: email address, password hash (managed by Supabase Auth), name, optional avatar URL.
  • Eligibility and policy records: the timestamp, source and policy version of your 18+ self-attestation, plus the timestamp and version bundle for the Terms of Use, Privacy Policy and Community Guidelines you accepted or acknowledged.
  • Profile data: padel level, area in the UAE, availability windows, optional sport interests, an optional self-declared broad Discover time preference, phone number (optional).
  • Activity data: matches you create or join, scores you record, events you register for, reviews you leave, points, streaks, and padel performance signals. Apple may classify sport activity signals as fitness data.
  • Purchase and reward records: the subscription product, store transaction references, status and validity of access, plus earned reward eligibility and redemption receipts. Event tickets record the event, player, price, currency, merchant, accepted policy, checkout/payment/refund references and status. JOINO does not receive or store your full card number or security code. Apple and Stripe collect payment information through their respective purchase flows; RevenueCat helps verify membership access.
  • Photos and videos: the avatar you choose to upload and, when you explicitly use JOINO Vision early access, the padel clip you submit for analysis, its processing state and the measurements approved for your private Film Room. Before a Vision upload, you confirm that every visible participant agreed, every visible participant is 18 or older, and you have the right to submit the clip. When community venue photos are available in your account, we also process the images you select, optional captions, venue reference, sharing acknowledgements, upload and moderation records. Participation is optional. Before each upload, you confirm your sharing rights, the consent of identifiable adults and the absence of children or private information. See the venue photo sharing rules. Originals remain in private quarantine before review. Match Memories also process the photo you choose to submit for a completed match, its ownership, match access, publication and moderation state. Uploaded avatars can become visible on your profile after file and account checks, and remain reportable.
  • Community content: connection requests, private messages between accepted connections, match group messages accessible to the confirmed roster, blocks, reports, moderation status and the content snapshot attached to a report.
  • Device data: device type, OS version, app version, IP address (for security and rate-limiting), and first-party crash diagnostics. Diagnostics can include the error message, technical stack, screen context, platform, app version, and your internal player ID.
  • Optional push notification data: after the official iPhone app registers with Apple and Expo, JOINO can receive an opaque installation identifier, the current APNs and Expo delivery tokens, authorization state, app version and build number. Tokens remain private, are never displayed to other players and are disabled on sign-out, opt-out, provider rejection or account deletion. Invalidated device records are removed after 90 days. Delivery records are retained for up to 180 days.
  • Product interaction data: selected screens and actions, session identifiers, and a pseudonymous browser identifier. Signed-in activity can include your internal player ID. Event properties use a restricted technical schema and are retained for up to 180 days.
  • Booking attribution data: when tracking is active for your account, an external booking open records the venue, channel, campaign fields, allowlisted destination host and a pseudonymous browser fingerprint. A booking is marked confirmed only after a separate venue callback or provider integration.
  • Creator pilot data: if the controlled creator pilot is opened for your account, we record your versioned consent, public content URL, platform content key, linked campaign, review state and evidence-bound aggregate metrics such as views, likes, comments and shares. Metric receipts exclude viewer identities and audience contact data. The current foundation cannot issue money, redeemable rewards or in-kind settlement.
  • Support data: questions sent to the reviewed knowledge assistant are stored as one-way fingerprints with the returned article references. Human support cases store the subject, description, category, priority and case history you submit.
  • Game Plan context: when you deliberately select Generate, we assemble a data-minimised summary of your level and uncertainty, reliability, configured availability count, onboarding Padel DNA values, and recent verified organic result summaries. The provider context excludes your name, email, phone number, exact location, venue names, partner names, exact match dates, and direct account identifiers. A one-way pseudonymous safety identifier accompanies the request.
  • Lead and partner enquiry data: the contact and business details you submit through the waitlist, partner, or Padel Courts forms. These records can be forwarded to our configured Google Workspace lead register for operational follow-up.

The current Service excludes precise location coordinates, address-book contacts, calendar data, HealthKit records and health sensor data.

2. How we use your data

  • To run the Service (match the right players, show events).
  • To send transactional emails (match joined, event registered, password recovery) through our configured transactional email provider.
  • To send the Community, match, event and booking push updates you explicitly enable on a supported device. The control can be withdrawn in JOINO Settings and in iPhone Settings.
  • To compute your Padel DNA, leaderboard rank, and badges.
  • To operate curated venue media and the optional community venue gallery, verify upload acknowledgements, review contributions, remove embedded metadata from approved images and handle photo reports or withdrawal requests.
  • To prevent abuse (rate-limiting, anti-spam, anti-no-show restrictions).
  • To deliver private messages between accepted connections and support human review of blocks, reports and safety incidents.
  • To measure activation funnels and improve the Service.
  • To generate the Game Plan you request and operate its security, quota, reliability, and abuse controls.

Personal data is never sold or used for third-party advertising. Optional features such as Discover visibility, Game Plan, Vision Creator Rewards and launch updates process the relevant data after you select or enable them. Their controls remain available in the Service.

The current Vision pilot does not analyse audio, identify faces or perform biometric processing. An authorised reviewer approves the source before processing and approves the result before any measurement appears in the private Film Room.

3. Who sees your data

  • Other players: your name, avatar, level, area, public match totals, reliability score, nickname, city or country when provided, Padel DNA archetype and confidence, and badges can be visible in community surfaces. Your raw availability, contact details, play intentions, travel radius, budget signals, restriction status, and last-active time remain private. A broad self-declared preference of morning, afternoon or evening is visible in Discover only when you turn on its separate visibility control.
  • Accepted connections: each participant in an active connection can see the private messages exchanged in that conversation. Reported content is also available to authorised human safety reviewers.
  • Confirmed match participants: authorised roster members can see match group messages and approved Match Memories. Pending join requests do not grant access. Leaving the roster or a safety restriction can remove access. A private post-match note is available to authorised moderation staff, not the rated player or public profile. Optional ratings remain subject to verification.
  • Venue visitors and community members: curated venue images in the public directory can be viewed by anyone. Community venue photos remain private to the uploader and authorised moderators until approved by a human reviewer. Approved community photos are available to signed-in members eligible to access that content. A report hides a photo from new gallery requests during review. Private preview links expire shortly; previously downloaded or externally saved copies may persist. Community photos do not replace curated venue covers.
  • Authorized JOINO operations admins: your profile name, opaque account reference, role, confirmation state, onboarding readiness, court access state, registration date and last sign-in time can be viewed in a protected, read-only support directory. Operators holding a separate sensitive-user permission can also view the account email for support and account recovery. Phone number, internal Auth ID, availability, private DNA payloads, onboarding answers, level, match activity and credentials remain outside that directory.
  • Processors: Supabase (database, auth, storage), Vercel (hosting and AI Gateway routing when enabled), our configured transactional email provider, Google (account sign-in when selected and Google Workspace lead intake when configured), Apple (Sign In with Apple, App Store purchases and APNs), Stripe (physical-event payment and refund processing), RevenueCat (subscription verification and lifecycle management), Expo (push token routing and delivery receipts when push is enabled), Microsoft Azure (Gateway-routed Game Plan inference when enabled), and OpenAI (direct Game Plan inference when configured and model technology for the Gateway route). All are governed by their applicable data processing terms.
  • Authorities: only if compelled by valid legal process in the UAE or EU.

4. Where data is stored

Database and authentication are hosted on Supabase, EU-West-1 (Ireland). Web hosting via Vercel, global edge. Backups are encrypted at rest.

Game Plan sends its limited context either directly to the OpenAI API or through Vercel AI Gateway to an OpenAI model hosted by Microsoft Azure, according to the server configuration selected for the release. Processing can occur outside the UAE and the EEA, subject to the applicable Vercel, Microsoft and OpenAI processing terms and transfer safeguards. Every request sets store: false. The Gateway route also sets zeroDataRetention: true, disallowPromptTraining: true, and restricts inference routing to Microsoft Azure. Production access requires a canary confirming that the selected route accepts these controls and returns the required structured response.

5. Your rights

You can at any time:

  • Receive information about the personal data, purposes, recipients, retention controls and international transfers that apply to you.
  • Access and obtain a copy of your data by writing to us.
  • Correct your profile directly from the Service or by writing to us.
  • Delete your account from Profile, Edit profile, Delete account, or directly from the onboarding page if setup is incomplete. Account closure starts immediately, private cleanup failures enter a prompt automatic retry queue, and the Auth record is permanently purged after seven days.
  • Withdraw consent for waitlist and launch updates at any time by using the unsubscribe option or writing to us.
  • Request restriction, erasure or cessation of eligible processing, and object to direct marketing or unlawful processing.
  • Request transfer of eligible personal data where technically feasible and request human review of an automated decision that has a legal or similarly serious effect.
  • Receive notice of a personal-data breach where the applicable rules require notification.
  • File a complaint with the UAE Data Office or another competent data protection authority.

6. Data retention

We keep your data for as long as your account is active. Account deletion starts live profile anonymization immediately and purges the authentication record after seven days. Temporary cleanup failures are retried automatically. Match, score, event, and safety records can remain in anonymized form to preserve competition integrity and legal audit trails. Client crash diagnostics are retained for up to 30 days. Abandoned community venue photo upload reservations expire after 15 minutes and enter automated cleanup. Original uploads are queued for deletion after a moderation decision. Approved, sanitised copies remain until the uploader removes them, their account is deleted or moderation removes them. Reported copies remain private for re-review. Failed cleanup is retried. Restricted photo reports and audit records may be retained to resolve disputes and meet applicable obligations. Existing legacy venue-photo records remain private while retained for moderation, account cleanup and valid deletion requests.

Authenticated activity days and external booking intents are retained for up to 180 days. Knowledge assistant query receipts are retained for up to 90 days and exclude the raw question text. Human support cases follow the safety and dispute retention needed to resolve the request and preserve the operational audit trail.

Payment, refund and accounting records may remain for the applicable statutory retention period and for unresolved payment disputes after account deletion. Access is restricted to authorised operations and the relevant providers. Public profile deletion does not publish these records or cancel an Apple subscription. Contact us for the retention and access information applicable to your transaction.

Venue referral share facts are retained for up to 180 days. They record only the venue, timestamp and share channel. JOINO does not collect the person you choose in the device share sheet, their email address, phone number or message content.

Private Vision source videos are removed no later than seven days after a completed upload. Cancelled, rejected and expired uploads enter the cleanup queue earlier. Approved measurements, processing receipts and review records can remain with the private Film Room while the account is active. Account deletion removes the source objects and the linked Vision records.

Creator pilot metric receipts are retained for up to 365 days to support attribution, integrity review and dispute handling. Public content references, consent receipts and review decisions can remain while the pilot record is active or where an audit or legal obligation requires them. Account deletion removes the member-linked creator enrollment and submissions through the same controlled account lifecycle.

Active private conversations are deleted from the live chat when either participant deletes their account. A restricted snapshot of reported content can remain with the related safety case for the time needed to resolve the report, prevent repeated abuse and meet legal obligations. It is unavailable to other players.

Waitlist and partner enquiry records are retained for up to 12 months after the latest submission. Unsuccessful Padel Courts enquiries follow the same 12-month period. Active court partner records remain for the duration of the relationship, and churned partner records are retained for up to 24 months. Lead intake copies in Google Workspace are removed after 12 months through the configured retention job. Longer retention applies where a legal, accounting, or dispute obligation requires it.

JOINO keeps a privacy-safe Game Plan operational ledger containing the user ID, selected focus, model and prompt versions, request status, provider request ID, token counts, latency, timestamps, and a small aggregate context summary. JOINO does not store the raw provider prompt, full player context, or generated plan in this ledger. The direct OpenAI route can retain API content in abuse-monitoring logs for up to 30 days under its default controls. The Vercel AI Gateway route requests zero data retention and blocks prompt training for each Game Plan request. JOINO activates that route only after the production canary confirms policy enforcement.

7. Children

JOINO player accounts are restricted to adults aged 18 or older. JOINO stores the timestamp and policy version of the user's self-attestation. JOINO does not collect a date of birth for this purpose. If we learn that an ineligible person has created an account, we restrict access and process the account for deletion.

8. Changes to this policy

We may update this policy. Material changes will be announced on this page and, where appropriate, by email at least 14 days before they take effect.

9. Contact

For privacy-related requests write to hello@joinosport.com. Postal: AICO Tech L.L.C-FZ, Meydan Free Zone, Dubai, UAE.

Joino · operated by AICO Tech L.L.C-FZ
JOINO Sport

Find your level. Find your people.

Your next game starts with your people. Get in touch: hello@joinosport.com.

Open CommunityDownload on the App Store

Play

  • How it works
  • Venues
  • Community
  • Padel DNA
  • JOINO AI

Members

  • Create profile
  • Log in
  • Support

Partners

  • For Venues
  • For Brands
  • Contact

Legal

  • Privacy
  • Delete account
  • Terms
  • Community Guidelines

© 2026 JOINO Sport · Padel. Together. · All rights reserved