- Status
- DRAFT
- Version
- 2026-08-draft-1
- Language
- English
- Last updated
- 2026-08-18
- Effective date
- Not effective — draft
1. Operator and contact
MyTeamTravel is operated by Janis Zarins, Gründerstrasse 14, 4600 Olten, Switzerland. Email: janis@myteamtravel.app. Telephone: +41 76 226 77 47.
2. Scope
This draft covers the public website, account registration and the MyTeamTravel sports-team travel-coordination application. It does not replace a Customer's own notices where that Customer decides why and how member data is used.
3. Roles under data-protection law
A Club or independent Workspace Customer normally decides which members and TravelPlans are administered and may therefore act as controller for that operational data. MyTeamTravel may process that data on the Customer's instructions while separately determining processing needed for accounts, security, abuse prevention and its own legal obligations. The final allocation under the Swiss Federal Act on Data Protection and, where applicable, the GDPR requires lawyer review.
4. Account and identity data
We process names, email addresses, optional telephone numbers and images, preferred language, password hashes, verification status, account status and role information to authenticate Users and operate accounts. Plain-text passwords are not stored.
5. Club, team and relationship data
We process Club and team names, sports, seasons, roles, membership status, jersey numbers and Parent/Family/Player or other authorised relationships to provide scoped access and team administration.
6. Travel and transport data
TravelPlans can contain dates, timing, destinations, departure places, stops, transport choices, boarding points, carpool offers, passengers, drivers, Persons in Charge, attendance and cleanliness information. Customer-authorised Users enter and manage this data.
7. Location, route and weather data
Addresses, place identifiers and coordinates may be processed to verify destinations, calculate route estimates, create directions links and retrieve destination weather. Provider keys remain server-side. Normalised results may be cached and shown to authorised Users.
8. Home addresses and carpool meeting points
A saved home address is intended to be private to its owner and used for that person's private route functionality. Other roster views normally show only whether an address exists. A User may separately enter a carpool meeting address; the final audience restriction for a meeting point that is also a home address remains under technical and lawyer review, so Users should enter only information needed for the relevant carpool.
9. Notes and sensitive information
Public Travel Notes are shown to authorised travellers. Private operational notes are intended for authorised Admins and Managers. MyTeamTravel is not designed as a medical-record system; Users and Customers should not enter unnecessary health or other sensitive personal information.
10. Updates and acknowledgements
The service records update versions, changed fields, recipients, reminder and manual-contact states, and acknowledgement timestamps. An acknowledgement records that a User confirmed seeing an update; it does not prove understanding or action.
11. Communications
We process email and notification details to verify accounts, reset credentials, communicate TravelPlan updates and operate Club deletion. Delivery records may include channel, provider status and error information. Delivery does not guarantee reading.
12. Exports and access links
Authorised Users can create calendar exports, Travel Lineup PDFs and limited driver-access outputs. Recipients must protect exported files and secret subscription or access links from unauthorised sharing.
13. Subscription and promotion data
We process plan, team-limit, access-status, promotion and redemption data. Stripe is not currently active and no payment-card data is processed by MyTeamTravel. This Policy will be updated before a payment provider is activated.
14. Technical, security and audit data
We process session information, security events, audit entries, request and delivery metadata, token hashes, quota ledgers and limited error information to protect the service, investigate incidents and demonstrate operational actions.
15. Sources
Data comes from Users, Customers and authorised Club representatives; imported schedule sources; generated route, place and weather providers; and technical operation of the service. A Club may have supplied basic roster data before a User registers.
16. Purposes
- Provide accounts, Club/team access and travel coordination.
- Create notifications, acknowledgements, directions, forecasts and exports.
- Protect accounts, enforce permissions, prevent abuse and maintain audit evidence.
- Handle support, deletion, legal requests, promotions and future subscription administration.
17. Legal bases where the GDPR applies
Depending on the context, proposed bases include performance of a contract, legitimate interests in secure service operation, compliance with legal obligations, and the Customer's independently selected basis for team administration. Consent is used only where legally required for a distinct purpose; Privacy Policy acknowledgement is not blanket consent. Final bases require lawyer review.
18. Minors and youth teams
Players aged approximately 13–15 may use their own accounts. The Customer is responsible for informing Parents or guardians and having any legally required authority. MyTeamTravel remains optional during the pilot and the Club must retain another method for essential communication. The under-16 model requires lawyer review.
19. Service providers and recipients
Current technical providers can include Vercel for hosting/runtime, a Supabase/PostgreSQL database, Resend for configured transactional email, and Google Maps Platform services for Routes, Geocoding, Places, Weather and directions links. Provider roles and contracts require verification. Google is not automatically classified as a subprocessor.
20. International processing
The primary Supabase/PostgreSQL project is configured in Zurich. Provider support, subprocessors and related processing may take place elsewhere. Applicable safeguards, contracts and transfer mechanisms must be verified before publication; we do not claim that all processing remains in Switzerland.
21. Retention
Operational data is currently retained while needed for the active Workspace and related functions. Club deletion uses a 30-day recovery period followed by soft deletion; immediate physical erasure is not implemented. Log, token-hash, support, cache, ledger and backup targets remain under implementation and lawyer review. Legal/accounting retention may apply where relevant.
22. Security
Measures include password hashing, verified-email checks, scoped memberships, role checks, server-side provider keys, hashed or signed security tokens in many flows, expiry/revocation checks and audit records. No system is risk-free, and raw driver/invitation link storage remains a technical improvement item.
23. Data breaches
Suspected incidents are assessed, contained and documented. Relevant Customers, providers, the Swiss Federal Data Protection and Information Commissioner and, where applicable, GDPR authorities or affected people will be considered according to the facts and legal requirements.
24. Cookies and similar technologies
Current source uses necessary authentication/security cookies and functional browser storage for interface and selected-team state. No optional analytics or advertising tracking was found in source. Development-only profile and weather preview state is not a normal production technology. See the Cookie and Storage Policy.
25. Automated decisions
MyTeamTravel does not currently make legal or similarly significant decisions about people solely by automated means. Route and weather risk outputs are informational and do not decide driver eligibility or safety.
26. Rights
Depending on applicable law and the processing role, people may request access, correction, deletion, restriction, portability or objection, and may withdraw a separate consent where consent was used. Rights can be limited by legal obligations and the rights of others.
27. Requests where a Club is controller
Where the Club controls operational member data, requests may need to be directed to or coordinated with that Club. MyTeamTravel will verify identity and role, route the request and assist the Customer as required by the final DPA and applicable law.
28. Complaints
People may contact the Swiss Federal Data Protection and Information Commissioner or another competent supervisory authority where applicable. The correct authority and process depend on the facts and location.
29. Changes
Material published changes may require renewed acceptance or acknowledgement as indicated in the legal registry. Draft changes do not become effective merely because they appear on this site.
30. Contact
MyTeamTravel is operated by Janis Zarins, Gründerstrasse 14, 4600 Olten, Switzerland. Email: janis@myteamtravel.app. Telephone: +41 76 226 77 47.
Legal contact
janis@myteamtravel.appThe English and German versions are parallel drafts. Language precedence in case of conflict remains open for lawyer review.

