Legal
Privacy Policy
Last updated · 1 August 2026
This Privacy Policy describes how Joino (operated by AICO Tech L.L.C-FZ, Meydan Free Zone, Dubai, UAE, license 2646735.01, hereafter "we", "us", "our") collects, uses, stores, and protects your personal data when you use the Joino web app at joinosport.com (the "Service"). The Service currently includes the web app. This Policy also applies to an official JOINO mobile Beta from the moment JOINO distributes it to an authorised tester. The iPad court display, watchOS companion and local-network scoreboard remain outside the Service until an active release expressly includes them.
1. Data we collect
When you create an account or use the Service we collect:
- Account data: email address, password hash (managed by Supabase Auth), name, optional avatar URL.
- Eligibility and policy records: the timestamp, source and policy version of your 18+ self-attestation, plus the timestamp and version bundle for the Terms of Use, Privacy Policy and Community Guidelines you accepted or acknowledged.
- Profile data: padel level, area in the UAE, availability windows, phone number (optional).
- Activity data: matches you create or join, scores you record, events you register for, reviews you leave, points, streaks, and padel performance signals. Apple may classify sport activity signals as fitness data.
- Photos and videos: the avatar you choose to upload and, when you explicitly use JOINO Vision early access, the padel clip you submit for analysis, its processing state and the measurements approved for your private Film Room. Before a Vision upload, you confirm that every visible participant agreed, every visible participant is 18 or older, and you have the right to submit the clip. You can also submit a photo of a padel venue. Venue photos enter a moderation queue before they can appear publicly.
- Community content: connection requests, private messages between accepted connections, blocks, reports, moderation status and the content snapshot attached to a report.
- Device data: device type, OS version, app version, IP address (for security and rate-limiting), and first-party crash diagnostics. Diagnostics can include the error message, technical stack, screen context, platform, app version, and your internal player ID.
- Optional push notification data: after the official iPhone app registers with Apple and Expo, JOINO can receive an opaque installation identifier, the current APNs and Expo delivery tokens, authorization state, app version and build number. Tokens remain private, are never displayed to other players and are disabled on sign-out, opt-out, provider rejection or account deletion. Invalidated device records are removed after 90 days. Delivery records are retained for up to 180 days.
- Product interaction data: selected screens and actions, session identifiers, and a pseudonymous browser identifier. Signed-in activity can include your internal player ID. Event properties use a restricted technical schema and are retained for up to 180 days.
- Booking attribution data: when tracking is active for your Beta cohort, an external booking open records the venue, channel, campaign fields, allowlisted destination host and a pseudonymous browser fingerprint. A booking is marked confirmed only after a separate venue callback or provider integration.
- Creator pilot data: if the controlled creator pilot is opened for your account, we record your versioned consent, public content URL, platform content key, linked campaign, review state and evidence-bound aggregate metrics such as views, likes, comments and shares. Metric receipts exclude viewer identities and audience contact data. The current foundation cannot issue money, redeemable rewards or in-kind settlement.
- Support data: questions sent to the reviewed knowledge assistant are stored as one-way fingerprints with the returned article references. Human support cases store the subject, description, category, priority and case history you submit.
- Game Plan Beta context: when you deliberately select Generate, we assemble a data-minimised summary of your level and uncertainty, reliability, configured availability count, onboarding Padel DNA values, and recent verified organic result summaries. The provider context excludes your name, email, phone number, exact location, venue names, partner names, exact match dates, and direct account identifiers. A one-way pseudonymous safety identifier accompanies the request.
- Lead and partner enquiry data: the contact and business details you submit through the waitlist, partner, or Padel Courts forms. These records can be forwarded to our configured Google Workspace lead register for operational follow-up.
The current Service excludes precise location coordinates, address-book contacts, calendar data, HealthKit records and health sensor data.
2. How we use your data
- To run the Service (match the right players, show events).
- To send transactional emails (match joined, event registered, password recovery) through our configured transactional email provider.
- To send the Community, match, event and booking push updates you explicitly enable on a supported device. The control can be withdrawn in JOINO Settings and in iPhone Settings.
- To compute your Padel DNA, leaderboard rank, and badges.
- To review venue photos for relevance and safety, then display approved photos in the public venue directory.
- To prevent abuse (rate-limiting, anti-spam, anti-no-show restrictions).
- To deliver private messages between accepted connections and support human review of blocks, reports and safety incidents.
- To measure activation funnels and improve the Service.
- To generate the Game Plan Beta you request and operate its security, quota, reliability, and abuse controls.
Personal data is never sold or used for third-party advertising. Optional features such as Discover visibility, Game Plan, Vision Creator Rewards and launch updates process the relevant data after you select or enable them. Their controls remain available in the Service.
The current Vision pilot does not analyse audio, identify faces or perform biometric processing. An authorised reviewer approves the source before processing and approves the result before any measurement appears in the private Film Room.
3. Who sees your data
- Other players: your name, avatar, level, area, public match totals, reliability score, nickname, city or country when provided, Padel DNA archetype and confidence, and badges can be visible in community surfaces. Availability, contact details, play intentions, travel radius, budget signals, restriction status, and last-active time remain private.
- Accepted connections: each participant in an active connection can see the private messages exchanged in that conversation. Reported content is also available to authorised human safety reviewers.
- Venue visitors: approved venue photos and their optional captions can be viewed by anyone using the venue directory. Pending and rejected uploads remain private.
- Authorized JOINO operations admins: your profile name, opaque account reference, role, confirmation state, onboarding readiness, court access state, registration date and last sign-in time can be viewed in a protected, read-only support directory. Email address, phone number, internal Auth ID, availability, private DNA payloads, onboarding answers, level, match activity and credentials remain outside that directory.
- Processors: Supabase (database, auth, storage), Vercel (hosting and AI Gateway routing when enabled), our configured transactional email provider, Google (account sign-in when selected and Google Workspace lead intake when configured), Apple (Sign In with Apple and APNs), Expo (push token routing and delivery receipts when push is enabled), Microsoft Azure (Gateway-routed Game Plan inference when enabled), and OpenAI (direct Game Plan inference when configured and model technology for the Gateway route). All are governed by their applicable data processing terms.
- Authorities: only if compelled by valid legal process in the UAE or EU.
4. Where data is stored
Database and authentication are hosted on Supabase, EU-West-1 (Ireland). Web hosting via Vercel, global edge. Backups are encrypted at rest.
Game Plan Beta sends its limited context either directly to the OpenAI API or through Vercel AI Gateway to an OpenAI model hosted by Microsoft Azure, according to the server configuration selected for the release. Processing can occur outside the UAE and the EEA, subject to the applicable Vercel, Microsoft and OpenAI processing terms and transfer safeguards. Every request sets store: false. The Gateway route also sets zeroDataRetention: true, disallowPromptTraining: true, and restricts inference routing to Microsoft Azure. Production access requires a canary confirming that the selected route accepts these controls and returns the required structured response.
5. Your rights
You can at any time:
- Receive information about the personal data, purposes, recipients, retention controls and international transfers that apply to you.
- Access and obtain a copy of your data by writing to us.
- Correct your profile directly from the Service or by writing to us.
- Delete your account from Profile, Edit profile, Delete account, or directly from the onboarding page if setup is incomplete. Account closure starts immediately, private cleanup failures enter a prompt automatic retry queue, and the Auth record is permanently purged after seven days.
- Withdraw consent for waitlist and launch updates at any time by using the unsubscribe option or writing to us.
- Request restriction, erasure or cessation of eligible processing, and object to direct marketing or unlawful processing.
- Request transfer of eligible personal data where technically feasible and request human review of an automated decision that has a legal or similarly serious effect.
- Receive notice of a personal-data breach where the applicable rules require notification.
- File a complaint with the UAE Data Office or another competent data protection authority.
6. Data retention
We keep your data for as long as your account is active. Account deletion starts live profile anonymization immediately and purges the authentication record after seven days. Temporary cleanup failures are retried automatically. Match, score, event, and safety records can remain in anonymized form to preserve competition integrity and legal audit trails. Client crash diagnostics are retained for up to 30 days. Pending venue photos are removed after 30 days, and rejected venue photos are removed 30 days after the moderation decision. Approved venue photos remain until removal, account deletion, or a valid deletion request.
Authenticated activity days and external booking intents are retained for up to 180 days. Knowledge assistant query receipts are retained for up to 90 days and exclude the raw question text. Human support cases follow the safety and dispute retention needed to resolve the request and preserve the operational audit trail.
Private Vision source videos are removed no later than seven days after a completed upload. Cancelled, rejected and expired uploads enter the cleanup queue earlier. Approved measurements, processing receipts and review records can remain with the private Film Room while the account is active. Account deletion removes the source objects and the linked Vision records.
Creator pilot metric receipts are retained for up to 365 days to support attribution, integrity review and dispute handling. Public content references, consent receipts and review decisions can remain while the pilot record is active or where an audit or legal obligation requires them. Account deletion removes the member-linked creator enrollment and submissions through the same controlled account lifecycle.
Active private conversations are deleted from the live chat when either participant deletes their account. A restricted snapshot of reported content can remain with the related safety case for the time needed to resolve the report, prevent repeated abuse and meet legal obligations. It is unavailable to other players.
Waitlist and partner enquiry records are retained for up to 12 months after the latest submission. Unsuccessful Padel Courts enquiries follow the same 12-month period. Active court partner records remain for the duration of the relationship, and churned partner records are retained for up to 24 months. Lead intake copies in Google Workspace are removed after 12 months through the configured retention job. Longer retention applies where a legal, accounting, or dispute obligation requires it.
JOINO keeps a privacy-safe Game Plan operational ledger containing the user ID, selected focus, model and prompt versions, request status, provider request ID, token counts, latency, timestamps, and a small aggregate context summary. JOINO does not store the raw provider prompt, full player context, or generated plan in this ledger. The direct OpenAI route can retain API content in abuse-monitoring logs for up to 30 days under its default controls. The Vercel AI Gateway route requests zero data retention and blocks prompt training for each Game Plan request. JOINO activates that route only after the production canary confirms policy enforcement.
7. Children
Player accounts in the UAE Closed Beta are restricted to adults aged 18 or older. JOINO stores the timestamp and policy version of the user's self-attestation. JOINO does not collect a date of birth for this purpose. If we learn that an ineligible person has created an account, we restrict access and process the account for deletion.
8. Changes to this policy
We may update this policy. Material changes will be announced on this page and, where appropriate, by email at least 14 days before they take effect.
9. Contact
For privacy-related requests write to hello@joinosport.com. Postal: AICO Tech L.L.C-FZ, Meydan Free Zone, Dubai, UAE.