Privacy Policy
Last updated: 31 August 2026
ConnEasy is a football networking platform operated from Ireland. We are committed to protecting your privacy and handling your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Irish Data Protection Act 2018, and all applicable data protection legislation.
1. Data Controller
The data controller for your personal data is:
ConnEasy
Operated by Tom O'Donovan
Ireland
Email: conneasyofficial@gmail.com
ConnEasy has not appointed a Data Protection Officer (DPO) at this time. For all data protection enquiries, rights requests, or complaints, please contact us at the email address above.
2. Data We Collect
We collect and process the following categories of personal data:
- Account information: name, email address, password (hashed and salted — we never store your password in plain text), date of birth, countries you are eligible to play for, county and sub-area location.
- Profile data: avatar photo, bio, football position, play style, preferred foot, height, weight, coaching qualifications, club history, achievements, and traits.
- Football statistics: goals, assists, games played, clean sheets, man of the match awards, years coaching, players coached, sessions per week, trophies, and other performance metrics.
- Communications: messages sent and received through the ConnEasy chat system, including message content and read receipts.
- Media: profile photos stored in our file storage. (In-app game-clip uploads are not currently available.)
- Location data: county and sub-area (town/area) for profile discoverability on the map. For clubs, an optional street address is geocoded to map coordinates.
- Connection data: endorsements, references, chat requests, and parent/guardian-player account links.
- Technical data: IP address, browser type, device information, and access logs collected automatically by our hosting provider (Vercel) and database provider (Supabase).
- Usage data: authentication sessions, notification preferences, visibility settings, and theme preferences.
Special Category Data
Height and weight data collected for player profiles may be considered health-related data under GDPR Article 9. We process this data on the basis of your explicit consent, given when you voluntarily provide it during profile creation. You are not required to enter height or weight — these fields are optional. You may remove them at any time by editing your profile.
3. Lawful Basis for Processing
We process your data on the following legal bases under GDPR Article 6:
- Consent (Article 6(1)(a)): You provide consent when you create an account and agree to these terms. You may withdraw consent at any time by deleting your account or adjusting your privacy settings.
- Contractual necessity (Article 6(1)(b)): Processing is necessary to provide the ConnEasy platform and its features — profile display, messaging, discovery, and notifications.
- Legitimate interest (Article 6(1)(f)): We process certain data for platform safety, safeguarding minors, preventing abuse, and maintaining platform integrity.
For users under 18, we rely on verifiable parental/guardian consent in accordance with GDPR Article 8 and the Irish Data Protection Act 2018 (Section 31), which sets the digital age of consent at 16 in Ireland. ConnEasy exceeds the legal minimum by requiring parental/guardian consent for all users under the age of 18.
4. Under-18 Data Handling
ConnEasy treats all users under the age of 18 as minors, exceeding the legal minimum age of digital consent (16) set by the Irish Data Protection Act 2018. We handle children's data with extra care, in compliance with GDPR Article 8 and Sections 29–33 of the Data Protection Act 2018.
We operate a parent/guardian paired account system for all users under 18:
What Data We Collect from Minors
We collect the same categories of data from minors as from adults (name, date of birth, county, position, stats, etc.), with the following differences:
- A parent/guardian email address is collected during registration. It is stored so we can send the verification invite, but it is masked from every other user at the database level.
- The minor's own contact and social handles (email, Instagram, TikTok, Facebook) are not stored at all — a database trigger strips these fields to null before an under-18 row is written, so there is nothing to expose (see "How Minors' Data Is Protected" below).
How Parental Consent Is Obtained
- During registration, under-18 players must provide a parent/guardian email address.
- A verification email containing a unique, time-limited token (7-day expiry) is sent to the parent/guardian.
- The parent/guardian must create their own ConnEasy account and the child must confirm the link. An under-18 player's profile is not visible to anyone until their confirmed parent/guardian has reviewed and approved it — before approval it is private to the child, their confirmed parent/guardian, and an administrator. Once approved, the profile is discoverable (with contact details always hidden), but the player still cannot be contacted directly: all contact is routed through the parent/guardian, who can return the profile to private at any time.
How Minors' Data Is Protected
- Contact details (email, Instagram, TikTok, Facebook) are never stored for minor accounts, and both those fields and the parent/guardian email are masked from all viewers at the database level — even the child's own account cannot display the social/contact handles. This is enforced by a database trigger, a view, and the user interface (three independent layers).
- Under-18 players cannot send or receive messages directly. All messaging is handled by their parent/guardian on their behalf.
- Messages to an unverified minor are blocked at the database level. Once a parent/guardian has verified the link, any coach-initiated conversation must still be approved by the parent/guardian. The child is never a participant in the conversation and never sees its messages — all communication is handled by the parent/guardian on the child's behalf.
- Safeguarding rules are enforced by database triggers that cannot be bypassed by the application layer.
No marketing or profiling for under-18s.
We will never use data from users under 18 for marketing, behavioural profiling, targeted advertising, recommender ranking, or any non-essential processing. Under-18 contact fields (email, Instagram, TikTok, Facebook) are masked at the database level and are never exposed to coaches, clubs, or external parties.
Parent/Guardian Rights
Parents/guardians of users under 18 have the right to:
- Access all data held about their child by contacting conneasyofficial@gmail.com.
- Request correction of their child's data.
- Request deletion of their child's account and all associated data (see Section 5, Right to Erasure).
- Manage their child's communications through the Parent/Guardian Dashboard, including approving or declining chat requests. Approved conversations are strictly between adults — the child is never a participant and never sees the conversation.
Under Section 33 of the Data Protection Act 2018, individuals have a specific right to request the erasure of personal data collected about them during childhood. ConnEasy fully supports this right — account deletion permanently removes all data.
5. Your Rights Under GDPR
Under the GDPR, you have the following rights regarding your personal data. For each right, we have listed the simplest way to exercise it.
5.1 Right of Access (Article 15)
You can request a copy of all personal data we hold about you.
How to exercise: Sign in and go to Settings > Danger Zone > Download My Data. You will receive a machine-readable JSON file containing every row we hold that belongs to you. Or email conneasyofficial@gmail.com.
5.2 Right to Rectification (Article 16)
You can correct any inaccurate or incomplete personal data.
How to exercise: Edit your profile directly from the Profile page. Your date of birth is locked after it is first set, to protect safeguarding age checks — if it is wrong, email conneasyofficial@gmail.com and an administrator will correct it (every such change is audit-logged).
5.3 Right to Erasure (Article 17)
You can permanently delete your account and all associated data.
How to exercise: Sign in and go to Settings > Danger Zone > Delete Account. Deletion is irreversible and atomic — profile data, messages, endorsements, references, your uploaded photos (profile picture and any club logo) in file storage, and authentication records are all removed. Under Section 33 of the Data Protection Act 2018, this right applies specifically to data collected during childhood.
5.4 Right to Data Portability (Article 20)
You can receive your data in a structured, commonly used, machine-readable format, and have the right to transmit that data to another controller.
How to exercise: Use Settings > Danger Zone > Download My Data. The JSON export satisfies Article 20 requirements. Limited to one export every 24 hours to prevent abuse.
5.5 Right to Restrict Processing (Article 18)
You can request that we limit how we use your data while a complaint or request is being resolved.
How to exercise: Email conneasyofficial@gmail.com. In the meantime, you can tighten your own processing footprint from Settings > Profile Visibility (hide profile, disable map, restrict who can message you).
5.6 Right to Object (Article 21)
You can object to processing of your personal data.
How to exercise: Use the visibility controls in Settings > Profile Visibility to disable discovery/map/public profile, or email conneasyofficial@gmail.com for anything not covered by the self-service controls. You can also block a specific user from any profile — a block is mutual and takes effect immediately: the two accounts become invisible to each other across discovery, profiles, and messaging until you remove the block from Settings > Blocked users.
Other rights
- Right Not to Be Subject to Automated Decision-Making (Article 22): ConnEasy does not use automated decision-making or profiling that produces legal or similarly significant effects. Age-based access controls are rule-based safeguarding measures, not profiling.
- Right to Withdraw Consent: You may withdraw your consent at any time by deleting your account or adjusting your privacy settings. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
We will respond to any rights request within 30 days as required by GDPR. If you are not satisfied with our response, you have the right to lodge a complaint with the Irish Data Protection Commission (DPC):
Data Protection Commission
21 Fitzwilliam Square South
Dublin 2, D02 RD28
Ireland
www.dataprotection.ie
6. Data Retention
We retain each category of data only for as long as it is needed for the purpose it was collected, or as required by law:
| Data category | Retention period | Basis |
|---|---|---|
| Profile & account data | Until account deletion | Contractual necessity |
| Messages & conversations | Until account deletion (then hard-deleted atomically) | Contractual necessity |
| Endorsements, references, chat requests | Until account deletion | Contractual necessity |
| Avatar images | Until account deletion | Contractual necessity |
| Parent/guardian verification tokens | 7 days (marked used after first use) | Safeguarding |
| Authentication session cookie | 7 days of inactivity | Strictly necessary |
| Cookie consent preference (localStorage) | 6 months, then re-prompted | Consent record-keeping |
| Server access & login logs (Vercel) | 90 days (processor default) | Security / legitimate interest |
| CSP violation reports | 30 days | Security / legitimate interest |
| Encrypted backups (Supabase) | 30 days, rolling | Business continuity |
| Admin audit log (DOB corrections, admin actions) | Retained post-deletion — required to demonstrate lawful rectification under GDPR Art 5(2) accountability | Legal obligation |
Deletion is immediate and irreversible once initiated from Settings > Danger Zone. We do not currently operate a soft-delete or 30-day recovery window.
7. Third-Party Processors
We use the following third-party services to operate ConnEasy. Each acts as a data processor under GDPR, covered by a Data Processing Agreement (DPA). Transfers outside the EEA rely on Standard Contractual Clauses (SCCs) or an equivalent adequacy mechanism.
- Supabase (database, authentication, file storage) — data stored in Supabase's EU-region infrastructure. DPA in place; transfers covered by SCCs. See Supabase Privacy Policy.
- Vercel (web hosting, serverless functions, and Vercel BotID bot-protection on the sign-up and account-deletion endpoints) — IP addresses and access logs processed for service delivery and abuse prevention. DPA in place; transfers covered by SCCs. See Vercel Privacy Policy.
- Resend (transactional email) — used for parent/guardian verification, deletion confirmation, and parent notification emails. Only recipient address + email content are shared. DPA in place; transfers covered by SCCs. See Resend Privacy Policy.
- Upstash (rate limiting) — a Redis service used to enforce request rate limits. Your IP address (or user id) is stored transiently as a rate-limit key. See Upstash Privacy Policy.
- OpenStreetMap Foundation (map tiles) — the club map loads its background map tiles from OpenStreetMap's public tile servers at
tile.openstreetmap.org(map data © OpenStreetMap contributors). Your IP address is sent to the tile server when you view the map. These tiles are a free public service that we use without an account, so unlike the services above there is no Data Processing Agreement with the Foundation, and tiles may be served from outside the EEA. See OpenStreetMap Foundation Privacy Policy. - Google Maps Platform (Places) (address autocomplete) — used only during club profile creation to autocomplete and geocode the club's registered address. Only the address text typed by the club administrator is sent to Google; no player, coach, or under-18 personal data is involved. See Google Privacy Policy.
- PostHog (product analytics) — used to count how the site is used: the pages you open, the buttons and links you click or tap, how far people get through the waitlist form, and which of the fixed answers they choose. It runs on PostHog's EU infrastructure and only after you accept on the cookie banner. It is never loaded if you decline or do not answer. What a recorded click contains: which page you were on, which kind of element you pressed and where it sat, and the element's label — but the label is only ever sent when it is one of a fixed list of our own wording, such as "Accept", "Player" or "Dublin". Any other text on the page, including any person's name, is replaced with
[redacted]before anything leaves your browser, and web addresses are reduced to the page name with any account number removed. We never send your name, your email address, your date of birth, or anything you type in your own words; the one exception is the club you pick from our own club list on the waitlist form, which is sent so we know which clubs people are joining from, and a club name you type yourself is never sent. We never create a profile of you as a person, and an analytics event cannot be linked to your waitlist entry. Session recording is switched off. Your IP address is seen by PostHog when an event is sent. DPA in place. See PostHog Privacy Policy.
We do not sell, rent, or share your personal data with third parties for marketing or advertising purposes.
8. Cookies
ConnEasy uses essential cookies required for authentication and session management, and — only if you accept on the cookie banner — analytics cookies set by PostHog, which records the pages you open and the buttons you click or tap. We do not use advertising cookies of any kind, and we never sell or share what we collect.
- Authentication cookie (
sb-*-auth-token): Strictly necessary for keeping you logged in. Set withSecure,SameSite=Lax, and a 7-day expiry. This cookie is exempt from consent requirements under ePR Article 5(3) as it is strictly necessary for the service. - Theme preference: Stored in
localStorage(not a cookie). - Cookie consent status: Stored in
localStorage(not a cookie), refreshed every 6 months. - Analytics cookie (
ph_*, PostHog): Not strictly necessary, so it is only ever set after you press Accept. It gives this browser a random identifier so that repeat visits are not counted as new people. It is not linked to your name, your email address or your waitlist entry, and it is never used for advertising.
If you decline, or simply do not answer, no analytics cookie is set and no analytics code is loaded at all. You may change your cookie preferences at any time via the "Cookie Preferences" link on the homepage; declining after having accepted stops any further analytics being collected.
9. International Data Transfers
Your primary data is stored in Supabase's EU infrastructure, and PostHog analytics are sent to PostHog's EU infrastructure. However, some of our processors (for example Vercel, Upstash, and Google Maps Platform) may process limited data (such as IP addresses, or a club's typed address) outside the European Economic Area (EEA). Where data is transferred outside the EEA, it is protected by Standard Contractual Clauses (SCCs) or equivalent safeguards as required by GDPR Chapter V. We only use processors that provide adequate data protection guarantees.
10. Data Security
We implement the following security measures to protect your data:
- Row Level Security (RLS) on all database tables, ensuring users can only access data they are authorised to see.
- Database triggers that enforce safeguarding rules and prevent unauthorised data modification.
- Encrypted connections (HTTPS/TLS) for all data transmission.
- Security headers including HSTS, X-Frame-Options, X-Content-Type-Options, and Content Security Policy.
- Server-side authentication middleware protecting all private routes.
- Password hashing via Supabase Auth (bcrypt).
- File upload validation (type and size restrictions) to prevent malicious uploads.
11. Data Minimisation
ConnEasy collects only the personal data necessary to provide its football networking features. Most profile fields (bio, stats, height, weight, social links) are optional — you are not required to complete them. We do not collect data beyond what is needed for the platform's stated purpose.
12. Changes to This Policy
We may update this privacy policy from time to time. Significant changes will be communicated via a notice on the platform. The "Last updated" date at the top of this page indicates when the policy was last revised. We encourage you to review this policy periodically.
13. Contact & Complaints
If you have any questions about this privacy policy, wish to exercise your data protection rights, or have concerns about how your data is handled, please contact:
ConnEasy
Tom O'Donovan
Email: conneasyofficial@gmail.com
Ireland
You also have the right to lodge a complaint with the Irish Data Protection Commission:
Data Protection Commission
21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
www.dataprotection.ie
Change your cookie preferences at any time:

