Privacy Policy and Personal Data Protection
- Provozovatel
- Daniel Javorský, IČO 02696339
- Sídlo
- Přípotoční 17, 101 00 Praha 10, Česká republika
- Kontakt
- dan@singleoff.cz
- Účinné od
- 29. 8. 2026
- Verze
- 1.2
Processing is governed by Regulation (EU) 2016/679 (GDPR) and Act No. 110/2019 Coll., on the processing of personal data. The supervisory authority is the Office for Personal Data Protection (uoou.gov.cz).
In plain English. We only collect what we need for you to use SingleOFF safely and effectively. We don't sell your data. You're in control, and you can unsubscribe or request deletion anytime. Below is the full, fair, and accurate policy.
1. Who is the controller
The controller is Daniel Javorský, Company ID 02696339, with registered office at Přípotoční 17, 101 00 Prague 10, email dan@singleoff.cz. We do not appoint a data protection officer (there is no legal obligation); for privacy matters, please write to the email provided.
2. What it applies to
These policies apply to the singleoff.cz website, the SingleOFF App, and events organized through it.
3. What data we process
The scope corresponds to how far you are in using the Service — from just an email during registration to a full profile and event participation.
A. Registration (basic):
- email; when logging in via Google, the identifier and email of your Google account;
- gender, age (year of birth);
- selected location(s);
- information about granted consent (content, time).
B. Full user account (before signing up for an event):
- first name (shown to other participants);
- phone (optional, for urgent SMS);
- languages, hobbies / interests;
- link to social networks (identity verification and help with matching);
- gender you are interested in and preferred age range;
- text "What you are looking for" (only visible to the administrator, used for pairing);
- choice of participation in events for new couples;
- message to other participants and message to creators;
- app language.
C. Participation, payments, and behavior:
- purchase history and Tickets, credits, payment records (we do not store card numbers — they are processed by the payment gateway);
- event participation, on-site confirmation, waitlist status;
- behavioral log — at what stage you left, feedback (satisfied/dissatisfied), reasons for "I won't come", reporting. You only see your own history; internal notes for pairing and moderation are only visible to the administrator;
- reports you submit or that concern you.
D. Location (only during event):
- in SingleOFF Live mode, we process precise location to guide you to the venue. We process it only for the duration of the event and only with consent granted on the device.
E. Technical data:
- IP address, device and browser type, technically necessary cookies (see Cookie Settings), technical and security logs.
3.1 Special categories of data
SingleOFF is a dating service, so data about sexual orientation can be inferred from participation, which GDPR classifies as special categories (Art. 9). We process this data exclusively based on your explicit consent (Art. 9(2)(a) GDPR) and minimize it. You can withdraw your consent at any time.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Inform about launch and send related information | Consent (Art. 6/1/a) |
| Account management and Service provision (registration, profile, events) | Performance of contract (Art. 6/1/b) |
| Inferable orientation data | Explicit consent (Art. 9/2/a) |
| Location in event mode | Consent (Art. 6/1/a) + performance of contract |
| Payments, accounting, taxes | Performance of contract and legal obligation (Art. 6/1/b, c) |
| Security, handling reports, abuse prevention, Service development | Legitimate interest (Art. 6/1/f) |
| Security features (SOS) and protection of health and life | Vital interest (Art. 6/1/d) |
5. Automated processing and matching
We divide people into event groups based on age and preferences. This is organizational automated processing without legal or similarly significant effect within the meaning of Art. 22 GDPR — we do not make automated decisions that would grant or deny you anything fundamental. We will explain the logic clearly upon request.
6. To whom we disclose data (processors)
We only disclose data to verified processors based on processing agreements. We do not sell them and do not transfer them for third-party marketing.
- Service development, operation, and hosting: Lovable; database and backend Supabase, possibly Vercel.
- Emails: Resend (via Lovable).
- Analytics: Microsoft Clarity (via Lovable) — session measurement and recording; it starts only after your consent in the cookie banner, and sensitive fields are masked.
- Login: Google (OAuth), if you choose it.
- Payments: Stripe (via Lovable) — payment processor; card numbers are not stored by us.
- Maps: Google Maps or Mapbox (final choice may be specified).
- Operational and assistance tools: in operation, we may use AI tools Google Gemini, Anthropic Claude, and Perplexity in paid versions. Their providers for paid versions declare that they do not use submitted data to train their models; they provide this guarantee. We only enter necessary data into these tools and avoid entering sensitive data.
7. Transfer outside EU/EEA
Some processors may process data outside the EU/EEA (e.g., providers based in the USA). In such cases, the transfer is based on an adequacy decision (e.g., EU-US Data Privacy Framework) or standard contractual clauses (SCC) with additional safeguards.
8. How long we retain data
- Email in contact list: until consent is withdrawn / unsubscribe.
- Account data: for the duration of the account; upon its cancellation, we delete or anonymize it without undue delay, unless a legal retention period prevents it.
- Location from event mode: deleted after the event ends.
- Accounting and tax documents: for the statutory period (usually up to 10 years according to tax regulations).
- Technical and security logs: 24 months.
9. Security
We implement appropriate technical and organizational measures: access control, Row Level Security in the database, transmission encryption, data minimization, and restriction of access to necessary personnel. If a security breach occurs with a risk to your rights, we will inform you and the supervisory authority in accordance with the law.
10. Your rights
You have the right to access, rectify, erase ("right to be forgotten"), restrict processing, data portability, object to processing based on legitimate interest, and withdraw consent at any time (without affecting processing prior to withdrawal). We will process your request without undue delay. To exercise these rights: dan@singleoff.cz.
You also have the right to lodge a complaint with the Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7 (uoou.gov.cz).
11. Unsubscribing from emails
You can unsubscribe via the link in every email or by writing to dan@singleoff.cz.
12. Children
The Service is intended exclusively for individuals 18+. We do not knowingly process data of individuals under 18; if we discover such data, we will delete it.
13. Cookies
We use technically necessary cookies and — with your consent — analytics (Microsoft Clarity). For details and settings, see Cookie Settings.
14. Users outside the EU
We also respect local data protection regulations wherever you use the Service. If you are from the UK (UK GDPR) or California (CCPA/CPRA) and wish to exercise your local rights — including the fact that we do not sell data — please write to us at dan@singleoff.cz.
15. Changes
We may update these policies; the current version on this page with the effective date always applies. We will inform you of significant changes.