Privacy Policy
Last updated: 27 August 2026 · English is the authoritative language version of this document.
This policy explains what personal data we process when you use WhistleBank, why we process it, who we share it with, and the rights you have. It is written to meet the EU General Data Protection Regulation (GDPR) and applies to users everywhere in the world.
1. Who is the controller
The controller of your personal data is [[COMPANY LEGAL NAME, d.o.o.]], operating the service under the name WhistleBank, [[REGISTERED STREET ADDRESS, POSTCODE, CITY]], Slovenia, EU. Registration number: [[MATIČNA ŠTEVILKA / REGISTRATION NUMBER]]. VAT: [[VAT ID — e.g. SI12345678, or state: not VAT registered]].
Privacy contact: [[PRIVACY@YOURDOMAIN.COM]]. Data protection officer: [[DATA PROTECTION OFFICER NAME AND CONTACT, or: no DPO appointed]].
2. What data we process
- Account data — email address (kept private), password (stored only as a secure hash by our authentication provider), public username, account role, account creation and update timestamps, and account status (active, blocked).
- Social sign-in data — if you choose Google or Apple sign-in, we receive the identifier and email address released by that provider. We never receive your password. Apple users may use Apple's private relay email address.
- Learning data — practice, learn-mode and test attempts, answers given, correctness, timestamps, session results, statistics, saved questions, daily streaks and (unless you opt out) your leaderboard position.
- Community data — comments, replies, likes/dislikes, questions you send to the officiating team, and reports you submit about questions.
- Device data — a random identifier generated by your browser and stored on your device, plus a device label and last-seen timestamp, used solely to enforce the limit of two active devices per account. We do not perform invasive device fingerprinting.
- Subscription and payment data — plan, billing interval, subscription status, renewal or cancellation dates, and the identifiers of your customer and subscription records at our payment provider. Card numbers are processed by the payment provider and never reach our servers.
- Promo code data — codes you redeem and the access they grant.
- Technical data — IP address, browser and operating-system information, and error/security logs generated when you use the service.
3. Why we process it and on what legal basis
- Providing the service (accounts, questions, statistics, comments, device limit, premium "New Rules" and case-study content) — performance of our contract with you (Art. 6(1)(b) GDPR).
- Payments, invoicing, subscription management and statutory bookkeeping — contract and legal obligation (Art. 6(1)(b) and (c) GDPR).
- Security, abuse prevention, licence enforcement (device limit), moderation — our legitimate interest in a secure, fairly used service (Art. 6(1)(f) GDPR).
- Service emails (confirmation, password reset, billing, important changes) — contract and legal obligation.
- Marketing emails and non-essential cookies / third-party embeds — your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time.
4. Who we share data with (processors and services)
We use the following providers, only for the purposes described:
- Lovable — application hosting and the managed cloud backend (database, authentication, file storage) on which your account and learning data is stored, with infrastructure operated by its sub-processors.
- Stripe — payment processing, subscription billing, the billing portal and payment-related emails. Stripe acts as an independent controller for fraud prevention and regulatory purposes.
- Google — only if you choose Google sign-in, and (with your cookie consent) YouTube when a case-study video is loaded.
- Apple — only if you choose Apple sign-in.
We may also disclose data to professional advisers or authorities where legally required. We do not sell personal data and we do not use it for advertising profiling.
[[LIST ANY FURTHER PROCESSORS ACTUALLY USED — e.g. transactional email provider, analytics or support tooling — before publishing.]]
5. International data transfers
Our providers may process data outside the European Economic Area, including in the United States. Where that happens, the transfer is protected by an appropriate safeguard under Chapter V GDPR — normally the European Commission's Standard Contractual Clauses combined with supplementary technical measures, or an adequacy decision (for example the EU–US Data Privacy Framework where the recipient is certified). You may request a copy of the relevant safeguard by writing to [[PRIVACY@YOURDOMAIN.COM]].
6. How long we keep data
- Account, learning and community data: for as long as your account exists.
- After account deletion: erased or anonymised without undue delay, except where we must keep records longer.
- Invoices and accounting records: retained for the statutory period required by Slovenian tax and accounting law.
- Security and error logs: [[LOG RETENTION PERIOD, e.g. 12 months]].
7. Your rights
Under the GDPR you have the right of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal. You can exercise these rights by writing to [[PRIVACY@YOURDOMAIN.COM]]; we respond within one month.
You may lodge a complaint with your local supervisory authority, or with ours: Informacijski pooblaščenec (Information Commissioner of the Republic of Slovenia), Dunajska cesta 22, 1000 Ljubljana, Slovenia — gp.ip@ip-rs.si.
Some data is public by design: your username, and your comments and leaderboard entry (which you can hide in your account settings). Your email address is never shown to other users.
8. Users outside the EU/EEA
We apply the standard described above to all users worldwide. In addition, mandatory data protection and privacy rights under the law of your own country of residence may give you further or different rights — for example under the UK GDPR, Switzerland's FADP, Türkiye's KVKK, India's DPDP Act, Japan's APPI, South Korea's PIPA, Singapore's PDPA, or applicable US state privacy laws. Nothing in this policy limits those mandatory rights. Contact us at [[PRIVACY@YOURDOMAIN.COM]] to exercise them.
9. Children
The service is intended for referees and officials aged 16 or over, or the minimum age of digital consent in your country if that is higher. If we learn that we hold data about a child in breach of applicable law, we delete it.
10. Security
Data is transmitted over encrypted connections, access to production data is restricted, passwords are hashed by our authentication provider, and database access is governed by row-level security rules so that each account can only reach its own records. No system can be guaranteed to be completely secure.
11. Cookies
See the Cookie Policy for details of the storage we use and how to change your choices.
12. Changes
We may update this policy. Material changes will be announced in the app or by email before they take effect.