Skip to main content
Lux Pro

Privacy · GDPR · Luxembourg

Privacy Policy

GDPR compliant

On this page

Lux Pro (“we”, “our”, “us”) is the data controller for the Lux Pro application. We are established in Luxembourg and operate under the General Data Protection Regulation (GDPR) and Luxembourg data-protection law. This policy explains what personal data we collect, why we collect it, how it is stored and protected, and what rights you have as a data subject.

Data We Collect

We collect only the data necessary to operate the app. We do not collect billing or card details, contacts, calendar data, audio files, or web-browsing history.

Account identifiers (Firebase Authentication) — when you sign up, we collect your phone number (required for OTP-based phone sign-up) and/or your email address (required for email/password sign-up). We also store the Firebase User ID assigned to your account. Phone number is optional if you choose the email/password sign-up path.

Profile data — you may optionally provide a display name, profile photo/avatar, biography, sport interests, spoken languages, and age range. This information is stored against your account and is visible to other users of the app according to your privacy settings.

Photos and media — you may optionally upload a profile photo, a club banner image, or attachments to match posts. No videos or audio files are collected.

In-app messages and activity — if you use in-app chat (within matches or clubs), the messages you send are stored. Chat is optional — if you never use it, no messages are collected. We also record the matches, clubs, and events you join or create, and other user-generated content such as match results and club posts.

Device location — we request location permission to enable venue and activity filtering. Both approximate location (city-level) and precise location are optional and permission-gated — the app functions without location access, and you can deny or revoke the permission at any time in your device settings. Precise location is only accessed when you explicitly opt in to a location-dependent feature.

Push token (device identifier) — we collect the Firebase Cloud Messaging (FCM) token assigned to your device to deliver push notifications (e.g. match invitations, club updates). This identifier is tied to your account and replaced when you reinstall or reset the app.

Crash logs and diagnostics — we collect crash reports and diagnostic data via Firebase Crashlytics to identify and fix bugs. This data includes stack traces, device model, OS version, and app version. It does not include the content of your messages or profile fields.

Why We Collect It

Account management and authentication — to create, secure, and recover your account (name, email, phone number, Firebase UID, push token).

App functionality — to let you find and join nearby clubs, matches, and community events; to display your profile to other members; to deliver in-app notifications; and to enable chat within matches and clubs.

Location-based features — to filter matches and venues by proximity. Location is requested only when you use a feature that needs it, and only with your prior permission.

Crash diagnostics and stability — to detect and resolve application errors, improving the experience for all users.

Organizer Applications

Becoming an organizer is not automatic. If you want the organizer role you fill in the form at lux-pro.app/organizer and a person at Lux Pro decides by hand. This section covers that form only — if you never apply, none of it applies to you.

What the form collects — the name you give, your email address, your phone number, the city or area you organize in, and a free-text description of what you want to organize and roughly how often. If you opened the form from inside the app it also carries your Lux Pro account identifier (the Firebase User ID), so the application can be tied to the right account. We ask for your phone number even though your account already has one: the two together are how a person checks, by hand, that the applicant is the account holder.

Why we collect it — to decide whether to grant you the organizer role, and to reach you about that decision. Organizers create activities that other people commit to and turn up for, so we verify before granting the role rather than after.

Lawful basis — your consent (GDPR Article 6(1)(a)), given by ticking the consent box on the form. The form cannot be submitted without it, the box is never pre-ticked, and it is not bundled with anything else. You may withdraw your consent at any time by writing to privacy@lux-pro.app; withdrawal stops us considering the application and does not affect processing carried out before you withdrew.

Who processes it — the application is stored on the same Google Firebase infrastructure as the rest of your data (see “Where Data Is Stored and Who Processes It”), and the alert telling us an application has arrived is delivered over the Telegram Bot API, as described in that section. It is read by Lux Pro staff only: it is never published, never shown to other users of the app, and never used for marketing.

How long we keep it — if we grant the role, the application is kept for as long as your account holds it, as the record of why it was granted. If we decline it, or if you withdraw your consent, we delete it within 6 months. Deleting your Lux Pro account deletes any application attached to it.

If you would rather not use the form, write to privacy@lux-pro.app instead. We will ask for the same details and the same rules apply.

Where Data Is Stored and Who Processes It

All data is stored on Google Firebase infrastructure (Firebase Authentication, Firestore, Cloud Storage, Cloud Functions, Firebase Cloud Messaging, and Firebase Crashlytics). Location-related features use the Google Maps Platform (Maps SDK and Places API). Google acts as our data processor under a Data Processing Agreement with Google LLC.

Google is our processor for everything described above. One further processor is involved, and only for organizer applications (see “Organizer Applications”): the alert that tells the Lux Pro operator a new application has arrived is delivered through the Telegram Bot API, operated by Telegram FZ-LLC, and that alert contains the applicant’s name, email address and phone number. The application record itself is stored on Firebase; Telegram carries and retains the notification message. No other feature of the app routes any data through it.

We use no advertising SDKs, no analytics platforms other than those listed above, and no other third-party services. We do not sell your data.

Encryption in transit: all communication between the app and Firebase or Google Maps services uses HTTPS. No unencrypted network connections are made.

Encryption at rest: data stored in Firestore and Cloud Storage is encrypted at rest by Google’s default infrastructure. On-device preferences are stored in encrypted storage.

Data Retention

We retain your personal data for as long as your account is active. When you delete your account (see “How to Delete Your Data”), your data is removed from our systems within approximately 30 days of the deletion request being processed. Crash logs retained by Firebase Crashlytics follow Google’s standard retention settings.

Your GDPR Rights

As a data subject under the GDPR you have the following rights, which you may exercise by contacting us at privacy@lux-pro.app:

  • Right of access — you may request a copy of the personal data we hold about you.
  • Right to rectification — you may ask us to correct inaccurate or incomplete personal data.
  • Right to erasure (“right to be forgotten”) — you may request deletion of your personal data. The in-app account-deletion flow is the fastest way to exercise this right.
  • Right to restriction of processing — you may ask us to limit how we use your data in certain circumstances.
  • Right to data portability — you may request your personal data in a structured, commonly used, machine-readable format.
  • Right to object — you may object to processing of your personal data where we rely on legitimate interests as the legal basis.

You also have the right to lodge a complaint with a supervisory authority. The competent authority in Luxembourg is the Commission nationale pour la protection des données (CNPD): 15, Boulevard du Jazz, L-4370 Belvaux, Luxembourg — cnpd.public.lu.

How to Delete Your Data

In-app deletion (recommended): open the app and go to Settings → Account → Delete account. Confirming this action permanently deletes your profile, all uploads (profile photo, club banners, match attachments), and your authentication account. This cascade runs automatically and cannot be undone.

By email: if you cannot access the app, send a deletion request to privacy@lux-pro.app from the email address associated with your account. We will process the request and confirm deletion within 30 days.

Children

Lux Pro is intended for users aged 16 and older. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has registered, please contact us at privacy@lux-pro.app and we will delete the account promptly.

Changes to This Policy

We may update this policy from time to time. The “Last updated” date at the top of this page reflects the most recent revision. We will notify users of material changes through an in-app notice or by updating this page.

Contact

Data controller: Lux Pro. Privacy enquiries and GDPR data-subject requests: privacy@lux-pro.app.