Privacy Policy
This notice describes how M63 ("we", "our") collects, uses, and protects the personal data of users ("you" or "user"). This page is public and meets Google OAuth verification requirements.
Last updated: August 11, 2025
Who we are and how to contact us
Data Controller: M63. For any request or to exercise your data protection rights, please email us at hello@m63.club.
Data we collect
- Registration and profile data: email, first name, last name, profile photo, and other data made available via Google OAuth; optional profile information such as bio, LinkedIn URL, company name, and company website.
- Service usage data: preferences, invitations sent/received, matches, approval status, and account activity.
- Technical and usage data: pseudonymized analytics events (e.g., via PostHog), device information, and interactions with the application.
- Communications: email addresses of invitation recipients and match participants (for sending emails through our email provider).
How we collect data
- Directly from you: when you register, complete your profile, or use the app’s features.
- Via Google OAuth: with your consent, we receive the data from your Google account necessary for authentication and profile creation.
- Via analytics tools: PostHog to measure product usage and improve the user experience.
Purposes and legal bases
- Service delivery and authentication (GDPR art. 6.1.b): enabling Google login, managing your account, and providing M63’s core features.
- Invitations and notifications (GDPR art. 6.1.b and 6.1.f): sending invitations by email and notifications related to matches or account activity.
- Analytics and improvement (GDPR art. 6.1.f): pseudonymized product usage analysis to improve stability, performance, and UX.
- Legal obligations (GDPR art. 6.1.c): compliance with regulatory requirements and lawful requests from authorities.
Services and providers we use
- Authentication: Supabase (Google OAuth login) for secure identity and session management.
- Database: PostgreSQL managed through Prisma, to store profile data, invitations, and matches.
- Email: Loops (transactional) for sending invitations and match notifications by email.
- Analytics: PostHog to collect usage metrics in a pseudonymized form.
- Optional Google integrations: Google Calendar to create events related to matches when required by the app’s features.
Some providers may process data outside the European Economic Area. In such cases, we ensure that appropriate safeguards are in place (e.g., Standard Contractual Clauses) or another compliant transfer mechanism.
Cookies and similar technologies
We use strictly necessary cookies for app functionality (e.g., to maintain a session) and, under legitimate interest or consent where required, cookies/technologies for aggregated analytics via PostHog. You can manage your browser preferences to limit or block cookies; some features may not be available without essential cookies.
Data retention
- Account data: retained for the life of the account and deleted or anonymized within a reasonable period after a deletion request.
- Technical logs and usage data: retained for limited periods, typically no longer than 12 months, unless needed for security or legal obligations.
- Invitation and notification data: retained as needed for operations and audit, then deleted or anonymized.
Data sharing
We share personal data only with providers/partners who support our service (see list above) or when required by law. We do not sell your data.
Your rights
Under the GDPR, you have the right to access, rectification, erasure, restriction, portability, and objection to processing, where applicable. You can exercise these rights by contacting us at hello@m63.club. You also have the right to lodge a complaint with the competent supervisory authority.
Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or disclosure. However, no security measure is infallible; please use strong passwords and keep your devices up to date.
Children
The service is not intended for children under 16. If you believe a child has provided us with personal data, contact us and we will remove it.
Changes to this policy
We may update this policy to reflect legal or service changes. We will publish the latest version on this page with the updated date.
Contact
For privacy questions or requests, email hello@m63.club.