Privacy policy
Last updated: 8 August 2026
The site scorbolt.com presents the Scorbolt service and its offers. Account creation, sign-in and payment of the subscription take place on the app.scorbolt.com application. This policy covers both: the technical data relating to merely browsing the site, and the account, subscription and billing data processed when you subscribe.
1. Data controller
Company name: C2SL (SAS)
Registered office: 6 rue Soutrane, 06560 Valbonne, France
Contact: [email protected]
2. Data processed and purposes
When you simply browse the site, only technical data is processed, strictly to the extent necessary for its operation:
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| IP address, connection data (date, page visited, browser) | Display the site, ensure its security and stability, prevent abuse | Legitimate interest (art. 6.1.f) |
| Anonymous audience measurement: page visited, referrer, country and approximate city, device type, browser family, language, technical errors | Measure site traffic and detect failures | Legitimate interest (art. 6.1.f) |
Audience measurement is provided by an in-house, anonymous, cookie-free solution hosted in Europe. Your IP address is only used, at the moment of the visit, to derive a country and an approximate location (never finer than a city): it is never stored. No identifier survives the closing of the tab, and the content you type is never collected.
On the pages of the site, we do not collect any identification data (no name, email or phone number): they contain no form.
When you create an account and take out a subscription on the application, the following data is added:
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Name, email address, password (stored in encrypted form, never in plain text) | Create and manage your account, identify you at each sign-in | Performance of the contract (art. 6.1.b) |
| Name of your club's workspace, role of each member, email address of the people you invite | Open your club's workspace and manage your team's access | Performance of the contract (art. 6.1.b) |
| Email address and temporary tokens | Verify your address, allow you to reset your password | Performance of the contract (art. 6.1.b) |
| IP address and browser associated with your session | Keep you signed in and detect abnormal access | Legitimate interest (art. 6.1.f) — security |
| Billing details (identity, address, VAT number where applicable), plan chosen, amount, payment history, brand, last four digits and expiry date of the card on file | Manage your subscription and its renewal, issue invoices | Performance of the contract (art. 6.1.b); legal obligation (art. 6.1.c) for accounting records |
| Date, wording of the authorisation accepted and IP address at the time you confirm your subscription | Evidence your agreement in the event of a dispute | Legitimate interest (art. 6.1.f) — evidence |
| Log of actions carried out in the club's workspace (who did what, and when) | Trace changes, identify the origin of an error or of abuse | Legitimate interest (art. 6.1.f) — security |
We neither see nor store any bank card number. Payment takes place entirely on a page hosted by our payment processor, Stripe: your card details are sent to it directly by your browser and never pass through our servers. All we receive in return is a payment identifier and enough to remind you which card is on file — its brand, its last four digits and its expiry date.
The data your club subsequently enters into the application to run its competitions — in particular players' names, nicknames and photographs — is processed on its behalf: Scorbolt then acts as a data processor within the meaning of Article 28 of the GDPR, and the club remains responsible for what it records there.
No data is used for profiling or advertising purposes, nor sold to third parties.
3. Recipients and processors
Your data is accessible only to authorised staff of C2SL and to the providers listed below, which act as data processors within the meaning of Article 28 of the GDPR, each for the sole purpose indicated:
- Cloudflare, Inc. — hosting and delivery of the site and of the application, protection against attacks.
- Neon, LLC (Databricks, Inc. group) — hosting of the service's database (accounts, subscriptions, competitions). The data is stored in a data centre located in Germany (Frankfurt).
- Stripe Payments Europe, Ltd. (Ireland) — payment processing and subscription management. Stripe receives your email address, your name where known, the amount and the reference of your subscription, as well as the details of the card you enter directly on its payment page.
- Sendinblue SAS, trading as Brevo (France) — sending the service's emails: verification of your address, password reset, invitation of a member. Brevo receives the recipient's email address and the content of the message.
- Boîte noire (
boite-noire.orila.co) — our in-house audience measurement and failure detection tool, hosted in Europe, present on the site as well as on the application. Your browser sends it directly the measurements described in section 2. This data is neither sold nor used for advertising. You can opt out in section 8.
Invoices are issued using C2SL's in-house invoicing tool, which receives your identity and billing details for that purpose.
Your data may also be disclosed to administrative or judicial authorities upon lawful request.
4. Transfers outside the European Union
The service's database is hosted in the European Union. Some of our providers are, however, established outside the European Union, or belong to groups that operate outside it:
- Cloudflare is a company established in the United States that operates a global network. Any transfers of data outside the European Union are governed by the European Commission's standard contractual clauses (2021/914) and Cloudflare's adherence to the EU–US Data Privacy Framework.
- Neon stores the data in Germany, but the company is established in the United States. Any access or transfers from that country are governed by the European Commission's standard contractual clauses.
- Stripe Payments Europe, Ltd. is established in Ireland, within the European Union. Any transfers within the Stripe group are governed by the European Commission's standard contractual clauses.
5. Retention periods
| Category | Duration |
|---|---|
| Account and club workspace (name, email address, members) | For as long as the account exists. Once it is closed, this data is no longer needed to operate the service and is deleted upon request, except for what the law requires us to keep |
| Session data (IP address, browser) | For the duration of the session, deleted automatically when it expires |
| Address verification and password reset tokens | Until they expire, from a few minutes to a few hours |
| Subscription and card on file (brand, last four digits, expiry date) | For the entire duration of the subscription |
| Invoices and accounting records | 10 years, in accordance with Article L. 123-22 of the French Commercial Code |
| Evidence of your agreement to the subscription (date, wording accepted, IP address) | For the duration of the subscription, then for as long as necessary to handle any dispute |
| Log of actions carried out in the club's workspace | For as long as the account exists |
| Encrypted database backups | A few weeks, on automatic rotation |
| Technical connection logs (host logs) | 12 months maximum |
6. Your rights
In accordance with Articles 15 to 22 of the GDPR, you have, in respect of all data concerning you — including your account, subscription and billing data — the right to access, rectify, erase, restrict, object to and port that data, as well as the right to set guidelines for its fate after your death.
Some of this data — your name, your email address, the members of your workspace — can be corrected directly from your account. For everything else, write to us at [email protected]: we reply within the one-month period provided for by the GDPR, which may be extended by two months if the request is complex. Proof of identity may be requested in case of reasonable doubt.
Some data cannot be erased at your request where the law requires us to keep it: this is the case for invoices, which the French Commercial Code requires us to retain for ten years.
7. Complaint to the CNIL
If, after contacting us, you consider that your rights are not being respected, you may lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL), or the data protection authority of your EU country of residence:
- Online: www.cnil.fr/fr/plaintes
- By mail: 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07
8. Cookies and trackers
The site does not set any cookies — neither for advertising nor for audience measurement. Traffic is measured by an in-house, anonymous, cookie-free solution hosted in Europe: no IP address is stored and no identifier survives the closing of the tab. The measurements are sent to our own tool, hosted in Europe at boite-noire.orila.co (see section 3); they are never sold or shared with any advertising third party. This measurement is therefore exempt from consent in accordance with CNIL recommendations. Only strictly necessary cookies, set by the host for security purposes, may otherwise be used; they are also exempt. No consent banner is therefore required.
| Category | Purpose | Consent required? |
|---|---|---|
| Strictly necessary cookies (security) | Protection against abuse, proper functioning | No (CNIL-exempt) |
| Audience measurement | In-house, anonymous and cookie-free | No (CNIL-exempt) |
| Sign-in session (application) | Keep you signed in to your account | No (strictly necessary) |
| Advertising / third-party cookies | None | — |
On the app.scorbolt.com application, once you are signed in, a strictly necessary cookie or token keeps your session open until you sign out or it expires. It serves that purpose only, does not track your browsing, and is likewise exempt from consent.
The typefaces are hosted on our own servers: displaying them does not trigger any request to a third-party service, nor any transfer of your IP address to a third party.
Opting out of audience measurement. Even though it is exempt from consent, you can switch it off at any time. Your choice is stored on your device only — it is never transmitted, and will have to be set again if you change browser or clear your browsing data.
·
9. Security
We implement appropriate technical measures to protect the site and the application: encryption of communications (HTTPS/TLS), network protection provided by the host, passwords stored in encrypted form and never in plain text, segregation of data between clubs, and database backups encrypted before they even leave the server.
10. Changes
This policy may be amended to reflect changes in regulation or in the service. The date of the last update appears at the top of this page; in the event of a significant change affecting your rights, account holders are informed.
← Back to home