Privacy Policy
What we collect, why, and what you can do about it. Written to be read, not to be survived.
The short version. We count visits with a tool that sets no cookie and stores nothing on your device, and we do not track you. We do not use tracking cookies. We do not advertise, and we never sell or share your data for marketing. If you fill in the contact form we get your name, your email, roughly your level and your message, and we use it to answer you. If you book, we get what a booking needs: who you are, how to reach you and what you booked. If you pay online, Mollie handles the payment and your bank details never touch this site. That is it.
- Who we are
- What we collect
- Why, and on what legal basis
- Cookies and what your browser stores
- Who else sees your data
- How long we keep it
- Your rights
- Complaints
- Changes
1. Who we are
Amsterdam Padel Academy is run by Midge Visser and Ivo Hoedt, padel coaches working at Playershome Amsterdam. Under the GDPR we are the controller of the personal data described here.
| Contact | info@amsterdampadelacademy.nl |
|---|---|
| Where we coach | Playershome Amsterdam, Transformatorweg 35, 1014 AJ Amsterdam |
2. What we collect
When you use the contact form
Your name, your email address, the playing level you select, and whatever you write in the message. Nothing on that form is collected that you did not type.
When you message us on WhatsApp
Your phone number and your messages, held in WhatsApp itself. WhatsApp is operated by Meta and has its own privacy policy, which we do not control.
When you sign in with Google
Your email address, your name and, if your Google account has one, the address of your profile photo. The photo address is saved with your customer record so your coach sees your picture beside your name in our own booking tool, and it is refreshed each time you sign in. We never receive the image itself, only its address; the picture stays with Google. If your account has no photo, we show your initials instead.
When you simply read the site
Nothing that identifies you. There is no advertising pixel, no visitor profiling and no behavioural tracking of any kind. Two things are counted. On the website, our host Vercel counts page views for us (Vercel Web Analytics): which page, which page you came from, your country and whether you are on a phone, a tablet or a computer. It sets no cookie and stores nothing in your browser; to count a repeat view once it derives a salted hash from your request that changes every day and is never stored in a form that identifies you. And in the booking flow we count how many people reach each step, on our own server: which step, which coach, which lesson type and the time. Never who, never your IP address, and never anything that could be joined back to you. Our hosting provider also processes standard server request data, including your IP address, for security and to deliver the pages. We do not build profiles from any of it.
When you book a session
Your first and last name, your email address, your phone number, your Playtomic level if you know it (or the fact that you do not, or that you have not played yet), an optional line about what you want to work on, and the booking itself: which coach, which lesson type, the date, the time and the number of places. We use it to run your lesson and for nothing else: your coach reaches you on WhatsApp, and our own mail server sends you the emails that belong to a booking — the confirmation, a change, a cancellation, a refund. Never marketing.
All of it lives in our own booking system, in a database hosted for us by Supabase in the EU (Frankfurt).
If you pay online, the payment runs through Mollie, a Dutch payment provider, using iDEAL or Apple Pay. Your bank details never touch this site: we store the amount, the outcome and Mollie’s payment reference, and a refund goes back by the same route. If you settle with your coach directly, no payment details exist here at all.
If you book a session for a group and share your invite link, whoever opens that link sees your first name and the session’s details. That is what the link is for; share it with the people you mean to play with.
3. Why, and on what legal basis
| What | Why | Legal basis |
|---|---|---|
| Contact form details | To answer your question and, if you want one, arrange a session | Your consent, and steps taken at your request before entering a contract (Art. 6(1)(a) and (b)) |
| WhatsApp messages | Same | Same |
| Server request data | To serve the site and keep it secure | Legitimate interest (Art. 6(1)(f)) |
| Session and student notes, once you train with us | To coach you properly and track your progress | Performance of our contract with you (Art. 6(1)(b)) |
| Google sign-in details (email, name, profile photo address) | To show you your own bookings, and your photo beside your name in the coaches’ tool | Performance of our contract with you (Art. 6(1)(b)) |
| Booking details (name, email, phone, level, your goal) | To run the lesson you booked: confirm it, remind you, move it, cancel it, refund it | Performance of our contract with you (Art. 6(1)(b)) |
| Payment amount, outcome and reference | To take or return the payment for a booking, and to keep the books | Contract (Art. 6(1)(b)) and our legal bookkeeping obligation (Art. 6(1)(c)) |
We do not use your data for automated decision-making or profiling.
4. Cookies and what your browser stores
We set no tracking cookies. The visit counter above uses none and stores nothing on your device; there is no advertising, no profiling, and nothing that follows you anywhere. Three things on this site involve a cookie at all: the Google map on our contact page, which does not run until you say yes to it; a short-lived draft that carries your answers while you are mid-booking; and a single yes-or-no marker that appears only if you sign in to see your own bookings.
The map, and Google’s cookies
Our contact page can show a Google map. Google sets cookies when that map loads, so we do not load it until you have accepted. Until then nothing is requested from Google at all, and if you decline, nothing ever is: you get a plain panel with a directions link instead, which works just as well.
You are asked once, your answer is remembered, and you can change it at any time from the map itself. Declining is remembered exactly as long as accepting is.
| Set by | What | When |
|---|---|---|
| Cookies Google uses for Maps, described in their own cookie policy | Only after you accept the map |
While you are booking
Between the booking form and the review, your answers travel in one cookie:
| Name | What it is for | How long |
|---|---|---|
apa_draft | Holds what you typed on the booking form — name, email, phone, level — so the review screen can show it back to you before anything is saved. Signed by us, unreadable to any script, and deleted the moment the booking is made. | 30 minutes, or until the booking is made |
If you sign in to see your bookings
You never have to. Booking, being emailed and changing a booking all work without an account, and the link in your confirmation email keeps working. If you do sign in, one cookie is set:
| Name | What it is for | How long |
|---|---|---|
apa_acct | A single yes-or-no marker that says a session is open, so the navigation can show your bookings instead of a sign-in offer. It holds no name, no email and no identifier of any kind, and nothing is trusted on the strength of it. | 30 days, or until you sign out |
apa_customer | The session itself: the thing that actually knows it is you, so your bookings are yours and nobody else’s. Signed by us and marked so your browser will not show it to any script, including ours. It carries no more than is needed to recognise you, and it is set only because you chose to sign in. | 30 days, or until you sign out |
Signing out clears both. Neither is used to follow you anywhere: they exist to keep you signed in, which is the thing you asked for by signing in.
What your browser stores regardless
Three small values are kept locally in your own browser. They are not cookies, they are never sent to us, and they never leave your device:
| Name | What it is for | How long |
|---|---|---|
apa-seen | Remembers that you already saw the opening animation, so it does not replay | Until you close the tab |
apa-who | Only if you are signed in: your first name and, if your Google account has one, the address of your profile photo — so the navigation can show you as yourself the instant a page opens instead of changing a moment later. It is your own account information, kept on your own device, and it is never sent to us: unlike a cookie, browser storage travels nowhere. Signing out deletes it. | Until you sign out or clear your browser storage |
apa-consent | Remembers your answer about the map, so we stop asking | Until you clear your browser storage |
All three are strictly necessary to provide something you asked for, so under the ePrivacy rules and the Dutch Telecommunications Act they do not require consent. You can clear them at any time in your browser settings, and nothing breaks if you do: you will simply be asked about the map once more.
5. Who else sees your data
We keep the list short on purpose. Your browser loads a few things from other companies when it renders this site, which means those companies receive your IP address and basic request information:
| Who | What for | Where |
|---|---|---|
| Vercel | Hosting and delivering the site, and counting its visits (Vercel Web Analytics) | EU and US, under standard contractual clauses |
| Google Maps | The map on the contact page, only if you accept it | EU and US |
| jsDelivr and Cloudflare | Two animation libraries | Global CDN |
| Unsplash | Some photography | US |
| OpenStreetMap | The map on the contact page | EU |
| Your own profile picture in the navigation, only while you are signed in and only if your Google account has one | US |
None of these are given your name, your email or your message. The typefaces now come from our own domain, so Fontshare and Google Fonts no longer see you at all.
Two more companies work for us behind the site, on our instructions, and these do receive personal data:
| Who | What for | Where |
|---|---|---|
| Supabase | The database our booking system runs on: your bookings, your details and, if you sign in, your account live there | EU (Frankfurt) |
| Mollie | Online payments, only when you choose to pay online: they handle your iDEAL or Apple Pay payment and tell us the outcome | Netherlands |
We do not sell your data. We do not share it with advertisers. We do not hand it to anyone else unless the law requires it.
6. How long we keep it
- An enquiry that goes nowhere: removed when we next review our records — we review at least once a year.
- An enquiry that becomes a booking: kept while you train with us, so we can pick up where you left off; once you have been gone for about two years it is removed at the next review.
- Anything with a tax consequence, such as an invoice: 7 years, because Dutch law requires it.
7. Your rights
Under the GDPR you can ask us to: show you the data we hold, correct it, delete it, restrict what we do with it, hand it over in a portable format, or stop processing it. Where we rely on your consent, you can withdraw it at any time, and that does not affect anything we did before you withdrew it.
Email info@amsterdampadelacademy.nl and we will answer within 30 days. We will not ask you why.
8. Complaints
If you think we have handled your data badly, tell us first and we will try to fix it. You also have the right to complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, without going through us at all.
9. Changes
If this policy changes we update the date at the top. If a change is significant, for instance when booking and payment go live, we will say so clearly rather than hoping you re-read it.