Skip to content

Privacy policy

Last updated: 19 September 2026

This policy explains which personal data RaketRadar — the app for organising tennis and padel matches — and this website process, why, and what rights you have. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR). In case of discrepancy, the Italian version prevails.

Data controller

Althera di Castelluccio Francesco, Largo Caleotto 15, Lecco (LC) 23900, Italy. VAT IT03818440137.

For anything concerning this data, including exercising your rights: info@althera.it.

No Data Protection Officer has been appointed: the cases listed in Art. 37 GDPR do not apply.

What we process

The data comes from you, when you sign up and use the app:

  • Sign-up data: first name, surname, email address, mobile number, date of birth, gender. Your password is only stored hashed, never in clear text.
  • Playing profile: tennis level (NTRP scale), padel level (0-7 scale), any FITP ranking, preferred format, level tolerance, sports played.
  • Availability and preferences: free time slots, maximum travel radius, gender and age preferences, notification settings and quiet hours.
  • Location: the town with postcode and the starting point you choose, used to compute distances to courts. We do not track your movements and never collect location in the background.
  • Profile photo (optional): it goes through an automatic check that only verifies whether a face is present and properly framed. We do not perform face recognition: no biometric template is extracted and nobody is identified from the photo. It is therefore not processing under Art. 9 GDPR.
  • Content you generate: messages in the chats of confirmed matches, post-match level ratings, reports, optional decline reasons, friends, groups, favourite and blocked players.
  • Technical app data: server request logs (IP address, timestamp, endpoint, outcome) and usage events drawn from a closed list of types, with no free text, to understand which features are used.
  • Browsing data on this website: see the dedicated section below.

Why we process it, and on what legal basis

  • Creating and running your account, proposing compatible matches, handling invitations, opening match chats and calendar events: performance of the contract, Art. 6(1)(b) GDPR. Without this data the service cannot work.
  • Verifying your email and mobile number with a one-time code (OTP): performance of the contract and our legitimate interest in preventing fake sign-ups, Art. 6(1)(b) and 6(1)(f).
  • Automatic photo check, handling reports, blocking abuse, reliability score: legitimate interest in keeping the environment safe and usable, Art. 6(1)(f). We introduce people who do not know each other, so we consider this interest to prevail — you can always object by writing to us.
  • Aggregate usage statistics to improve the service: legitimate interest, Art. 6(1)(f), with data kept to a minimum.
  • Complying with legal obligations (tax, accounting, requests from authorities): Art. 6(1)(c).

Who can see your data

Other players see a reduced public profile: first name, photo if you uploaded one, level, reference town and the availability relevant to the match. They never see your surname, email, phone number or address.

Outside the app, data is processed only by suppliers appointed as processors under Art. 28 GDPR, and only for the part needed to run the service:

  • the hosting provider running the application, with data centres in the European Union;
  • email and SMS providers, for verification codes and service messages;
  • the app stores (Google Play, App Store) for distributing the app and any notification services.

An up-to-date list of processors is available on request at info@althera.it. We do not sell your data and never hand it to advertisers.

Transfers outside the European Union

We prefer suppliers with European infrastructure. Where an SMS, email or notification provider processes data outside the EU, the transfer happens only towards countries covered by an adequacy decision, or under the European Commission's Standard Contractual Clauses with supplementary measures where needed. You may ask us for a copy of the safeguards in place.

How long we keep it

  • Account and profile data: as long as the account exists.
  • After a deletion request: erased within 30 days, except as noted below.
  • Server technical logs: 90 days, for security and troubleshooting.
  • Messages in match chats: they stay visible to the other players of that match, stripped of the link to your profile.
  • Reports received about misconduct: as long as needed to protect other users, kept to a minimum.
  • Data we need for tax obligations or to defend a legal claim: for the periods set by law.

Your rights

At any time you can ask us for access to your data, rectification, erasure, restriction of processing, portability in a machine-readable format, and you can object to processing based on legitimate interest. Where processing is based on consent, you can withdraw it at any time without affecting what happened before.

Write to info@althera.it from the address you signed up with: we answer within one month. For account deletion there is a dedicated page on this website, which also works if you have already uninstalled the app.

If you believe the processing breaches the GDPR, you may lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or with the authority of the EU country where you live.

Minors

The service is restricted to adults. Date of birth is required at sign-up and accounts for minors are not created. If we discover an account belonging to a minor, we delete it.

Security

Traffic between app and server is encrypted (HTTPS). Passwords are stored as hashes. Database access is limited to the people who have to administer it. In case of a data breach involving a risk to your rights, we will inform you and notify the supervisory authority within the deadlines of Art. 33 GDPR.

This website

The site uses no profiling cookies and shows no banner because it does not need one. For visit statistics we use Umami, installed on our own server: it sets no cookies, creates no persistent identifiers and does not track users across sites. The data collected is aggregate (page viewed, referrer, device type, country) and cannot be traced back to a person.

The deletion form records what you type, the date of the request and a shortened, hashed version of your IP address, used only to limit abuse of the form.

Changes

If we change this policy we update the date at the top and, when the changes are significant, we tell you in the app or by email before they take effect.