Privacy Policy

Last updated: July 2026

1. Data controller
OwnerLuis Antonio Cañas Arrones
NIF43206125G
Email addresshola@miequipostats.com
Server locationSpain (European Union)
2. Relationship with sports clubs

Player data is entered into the platform by coaches and coordinators of sports clubs. These clubs collect signed consent from the players (or their legal guardians in the case of minors) upon formalising club registration.

The club acts as the data controller for its players' data, and Luis Antonio Cañas Arrones, as the platform owner, acts as a data processor (art. 28 GDPR) by providing the technical tool that facilitates such management.

3. What data we collect and why
3.1 Registered user data (coaches and coordinators)
  • Full name, email, encrypted password — Account access and management (art. 6.1.b GDPR)
  • Role and assigned team — Permission configuration (art. 6.1.b GDPR)
  • IP address — System security (art. 6.1.f GDPR)
3.2 Player data

Entered by the coach or coordinator acting on behalf of the club. Consent has been previously collected by the club (art. 6.1.a GDPR).

  • Name, squad number, position, preferred foot, nationality
  • Date of birth, ID number
  • Address, telephone, email
  • Photograph
  • Legal guardian data (minors)
  • Sports statistics, evaluations and sanctions
3.3 Health and physical performance data (special category — art. 9 GDPR)

Recording injuries constitutes health data. Processing is based on explicit consent (art. 9.2.a GDPR) confirmed by the coach when recording the injury on the platform. The platform also allows physical test results to be recorded (speed, jump, endurance), handled with the same protection.

3.4 Content generated in the player portal

The platform offers players their own portal, with temporary access via ID number or email address. There they can post on the team forum, send private messages to the coaching staff, answer self-assessments and request corrections to their personal data. This content is provided by the data subject themselves and is kept while they remain linked to the team.

3.5 Publishing data outside the club

Certain features distribute data outside the club's private environment, and you should be aware of them:

  • Public live match section (/en-directo): accessible without registration. It may show the name, squad number and photograph of called-up players, as well as the goals and cards of the match.
  • Social media cards: downloadable images with name, squad number, photograph and statistics.
  • Squad announcement image: downloadable image with the names and squad numbers of called-up players.

These publications are governed by two controls the club manages on each player's record: image consent (without it the photograph is never published, only name and squad number) and exclusion from external publications (the person does not appear in any form). You may request either from your club, or directly at the contact address in this policy.

3.6 Subscription data

When a club takes out a paid plan, we process the data needed to manage the contract and billing: club identification, requested plan, start and expiry dates and the history of changes. The legal basis is performance of the contract (art. 6.1.b GDPR) and compliance with legal invoicing obligations (art. 6.1.c GDPR). Payments are handled by Stripe Payments Europe, Ltd. as a data processor: card details are entered on their platform and are never stored on our servers; we only keep the customer and subscription identifiers Stripe returns.

3.7 Demo requests

Anyone requesting a commercial demo from the website provides their name, email, phone number and club name, and may book a day and time. This data is processed for the sole purpose of handling that request and preparing the demo, based on the consent given when submitting the form (art. 6.1.a GDPR), together with the IP address for system security (art. 6.1.f GDPR). It is kept for as long as the commercial contact lasts and is deleted when the person asks or when it is no longer needed. You may request deletion at any time by writing to the contact address in this policy.

4. How long we keep data
  • User data: while the account is active, plus 30 days after deletion.
  • Player data: while the team is active on the platform. When a player leaves a team, the record is kept as club history unless erasure is requested.
  • Health and physical test data: the same period as the associated player data.
  • Forum content and messages: while the person remains linked to the team.
  • Social card download log: 12 months, for traceability purposes.
  • Subscription and invoicing data: for the periods required by tax and commercial law (up to 6 years).
  • Demo requests: for as long as the commercial contact lasts; deleted on request or when no longer necessary.
5. Data recipients

Data is neither sold nor shared for commercial purposes. Data is stored on servers located in Spain (EU). Only the following recipients are involved, strictly as needed to provide the service:

  • Hosting provider (Spain, EU), as data processor.
  • Email provider, for sending platform notifications.
  • Google Ireland Limited, if you accept analytics cookies on our home page, and for delivering web fonts. This may involve international transfers covered by the EU-US Data Privacy Framework. See the Cookie Policy.
  • Stripe Payments Europe, Ltd. (Ireland, EU), as processor of card payments for subscriptions.
  • Public authorities, where there is a legal obligation.

Beyond the above, please note that the features described in section 3.5 publish data to an indeterminate audience when the club chooses to use them.

6. Data subject rights (arts. 15-22 GDPR)

You may exercise your rights of access, rectification, erasure, objection, restriction of processing and portability by writing to hola@miequipostats.com. As player data is entered and governed by the club, we will forward your request to the responsible club where appropriate.

Players with portal access also have a direct channel within the platform itself to request corrections to their personal data, which the coaching staff resolves explicitly.

You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD).

7. Security measures
  • Passwords encrypted with bcrypt (cost 12)
  • Communications encrypted via HTTPS/TLS
  • CSRF protection on all forms
  • Sensitive fields (ID, address, telephone) hidden in API responses and never exposed in public sections
  • Photographs and documents served from private storage after permission checks
  • Role-based access control (coordinator/coach/observer) and per-module permissions for delegates
  • Logging of social media card downloads