Privacy Policy
Your privacy and data protection rights
Last updated: November 22, 2025
1. Data Controller
The service is operated by an individual established in France.
Contact: hello@lineup-experience.com
Identification details are disclosed in the legally required Mentions légales.
2. Data Collected
Lineup collects only the data necessary for the operation of the service:
- Email address (account creation)
- Authentication data (BetterAuth + Supabase)
- User-generated content: surf sessions, notes, pictures
- Analytics: usage data via PostHog (pages viewed, interactions, device type, performance metrics)
- Technical logs (security, performance, error tracking)
Geolocation is not stored.
3. Legal Bases (RGPD)
- Contractual necessity: account creation, access to the service
- Legitimate interest: security, fraud prevention, analytics for registered users to improve service quality
- Consent: analytics for anonymous visitors, uploading pictures or optional personal data
Note: Page views are always tracked for conversion analysis (legitimate interest). Registered users are fully tracked for service improvement. Anonymous visitors can opt out of detailed behavioral tracking via the cookie banner.
4. Purposes of Processing
Data is processed to:
- maintain user accounts
- operate platform features (session logs, matching rating)
- improve service performance
- ensure platform security
- provide customer support
5. Data Retention
Data is retained only as long as necessary for service operation:
- Account data: until account deletion
- Analytics: limited retention as configured in PostHog
- Pictures and surf logs: until user deletes them or deletes their account
6. Data Sharing
Data may be shared with:
- Vercel (hosting provider)
- Supabase (database + authentication)
- PostHog (analytics)
All providers are GDPR-compliant or offer adequate protection mechanisms.
Data is never sold.
7. User Rights
Under the RGPD, users may request:
- access to their data
- correction of inaccurate data
- deletion of their account
- restriction or objection to processing
- portability of data
Requests: hello@lineup-experience.com
8. Security Measures
Lineup uses HTTPS, access controls, authentication protection, and secured infrastructure via Vercel and Supabase. No method is fully error-free, but industry-standard safeguards are applied.
9. International Transfers
Some providers may process data outside the EU. Transfers rely on GDPR adequacy decisions or Standard Contractual Clauses (SCCs).
10. Updates
This policy may be updated to reflect service evolution. Significant changes will be communicated via the website.