PeachMe Sports

Privacy Policy

2026-09-10

§1 Controller

Controller within the meaning of the GDPR is:

PeachMe Sports GmbH Rosa-Bavarese-Str. 3 D-80639 Munich, Germany Phone: +49 151 68153269 Email: [email protected] Managing Director: Fei Liu

A Data Protection Officer has not been appointed, as the statutory thresholds under § 38 BDSG are not met. For data-protection enquiries, please contact us directly at [email protected].

§2 Data Collection on Our Website

(1) When you visit our website, the following data is automatically collected by our hosting provider and stored in server log files: - IP address (truncated after 7 days) - Date and time of the request - HTTP method and requested URL - HTTP status code and response size - Referrer URL (if provided) - User-agent string (browser and operating system)

(2) Legal basis: Art. 6 (1) (f) GDPR — our legitimate interest in operating a secure and stable website. Logs are retained for a maximum of 7 days and then deleted or anonymised, except where retention is required to investigate a specific security incident.

(3) Hosting: The website is hosted by Railway Corp., 2261 Market Street, Suite 4382, San Francisco, CA 94114, USA. A data processing agreement (Art. 28 GDPR) including EU Standard Contractual Clauses is in place to safeguard transfers.

(4) Anti-abuse: Public forms are protected by Cloudflare Turnstile (Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA). Turnstile evaluates browser characteristics to detect automated abuse; no analytics or behavioural profiling occurs. Legal basis: Art. 6 (1) (f) GDPR.

§3 Cookies

We use cookies and similar storage technologies only where they are necessary for requested functions or where you have made an explicit privacy choice.

Current examples on the public site include: - peachme-locale: remembers your manually selected language for up to 12 months. - peachme-cart-session: is created after an active cart or checkout interaction so a guest cart can be continued for up to 30 days. - peachme-member-session: keeps a signed-in member session active for up to 60 days or until you sign out. - peachme-consent: stores your privacy settings when you save or update them in the privacy settings dialog for up to 6 months. - peachme-plan-nav-collapsed: remembers whether you hid the investor reader's chapter navigation on this browser.

The public booking flow also offers an optional live Google Maps enhancement that stays disabled until you allow external media and services. Public lead forms may use Cloudflare Turnstile anti-abuse verification when configured; this protection is required to submit the form and is not controlled by the optional external media setting.

§4 Order Processing & Payment

(1) When you place an order, we process the following data to perform the purchase contract: name, billing/shipping address, email, phone (optional), order details, and payment metadata. Legal basis: Art. 6 (1) (b) GDPR (contract performance).

(2) Payment processing is handled by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland ("Stripe"). Stripe receives the data necessary to process the payment (name, billing address, email, amount, and payment-method details). Card data is entered directly into Stripe's PCI-DSS-compliant infrastructure and is not stored on our servers. Stripe's privacy policy: https://stripe.com/privacy. Where Stripe transfers data to its US-based group companies, EU Standard Contractual Clauses apply.

(3) Transactional email is delivered through Resend (Plus Five Five, Inc.). Resend processes the recipient's email address, name, and the content of the message solely for transactional delivery. Legal basis: Art. 6 (1) (b) and (f) GDPR.

(4) Tax retention: Invoices and order data must be retained for 10 years under § 147 AO and § 257 HGB. Until expiry of these periods, the right to erasure (Art. 17 GDPR) is restricted accordingly.

§5 Shipping

(1) To deliver your order, we transmit your shipping address, name, and (optionally) email/phone to our shipping partners: - Sendcloud B.V., Stationsplein 32, 5211 AP 's-Hertogenbosch, Netherlands — for label generation and tracking aggregation. Privacy policy: https://www.sendcloud.com/privacy-policy/ - DHL Paket (Deutsche Post AG, Charles-de-Gaulle-Str. 20, 53113 Bonn, Germany) — for physical delivery and tracking. Privacy policy: https://www.dhl.de/de/privatkunden/footer/datenschutz.html

(2) Legal basis: Art. 6 (1) (b) GDPR (contract performance). Email address and phone are passed on only if you have provided them, in order to receive delivery notifications and arrange handover; this is based on Art. 6 (1) (f) GDPR (legitimate interest in smooth delivery).

§6 Machine-Session Bookings at Partner Venues

(1) When you book or use a PeachMe machine session at a partner club or venue, we process the data needed to run the rental: your member account or booking reference, renter name, email address, phone number where provided, booked venue, machine, date, time, session status, payment or cash-collection status, and handover/return information. Legal basis: Art. 6 (1) (b) GDPR (contract performance) and, where needed for venue operations and abuse prevention, Art. 6 (1) (f) GDPR.

(2) The partner club or venue operator and its authorised venue managers receive only the limited subset needed for their assigned venue — the renter's first name, a pseudonymous booking/member reference, and the booking data (venue, machine, date, time, session and payment status). They do not receive the renter's email address, phone number, or full name. They use this data only to prepare and perform machine handover and return, verify booking entitlement, coordinate local availability, handle on-site cash collection where applicable, and document operational issues.

(3) Where a partner club or venue operator performs these tasks for PeachMe, it acts as a processor under a data processing agreement in accordance with Art. 28 GDPR. PeachMe remains the controller and limits access to the venues and sessions assigned to the relevant venue manager.

§7 Member Custom-Practice History

(1) When a signed-in member successfully starts one of their own custom practices in the PeachMe mobile app, we record one play-start event after the machine start sequence and safety delay have completed. The record contains the time; a technical practice ID and revision timestamp; privacy-minimised authored and effective setup snapshots and their stable hashes; and the app version, build, and platform. This play-start record does not contain the practice name, your name or email address, a raw Bluetooth identifier, a fleet machine ID, raw command bytes, free text, or precise location.

(2) We process this history to provide your member-facing custom-practice play count and recency, preserve the setup associated with a play after later practice edits or deletion, and operate the training-history feature. Legal basis: Art. 6 (1) (b) GDPR (performance of the member-account service). This record is created for signed-in members without a separate diagnostics or analytics opt-in. The optional BLE diagnostics described below remain an independent, consent-based support feature.

(3) Your member summary is available only within your authenticated account. Authorised PeachMe personnel may access role-gated practice summaries where needed to operate the service. For product improvement we use only de-identified cross-member setup aggregates, suppress every grouping with fewer than 10 distinct members, and include no member or practice identifiers. To the extent personal data is processed before aggregation, this is based on Art. 6 (1) (f) GDPR and our legitimate interest in improving the training product with data-minimisation safeguards.

(4) Identifiable play-start records are stored until you delete your account. Deleting an individual practice does not delete its historical play records. Account deletion removes the identifiable play-start records linked to your account. De-identified aggregate results that can no longer be linked to you or a practice may remain. Hosting and international-transfer safeguards are described in §2.

§8 Practice Session History

(1) When an authenticated member uses the PeachMe app to start and control a machine session, the app may store and upload practice-session history linked to the member account. This history may contain account-bound session and run IDs, timestamps for session and run start, pause, resume, interruption, and end lifecycle events, the access kind, machine or venue references reported by the app with server verification recorded separately, optional managed-access session references, technical practice setup references, source-completeness flags, and raw BLE readings such as ball-counter and runtime-counter values.

(2) Trainer mode records coaching activity separately from personal play history. Coaching summaries show observed coaching time, machine running time, balls fed and drills; they do not attribute activity to individual students. Coaching history follows the same account-lifetime retention and account-deletion rules. We process this history to operate member practice history, help you distinguish app lifecycle records from local BLE observations, and build later daily, weekly, and monthly statistics from verifiable source records. Legal basis: Art. 6 (1) (b) GDPR (performance of the member-account service). This history uses dedicated app records. Optional BLE support diagnostics use a separate consent setting and data pipeline.

(3) The history does not contain your name or email address inside the uploaded mobile records, raw Bluetooth peripheral identifiers, device handles, camera frames, QR-code credentials, free-form notes, or precise geographic coordinates. Server-side protected diagnostics may resolve account, registered machine, venue, or managed-access references only for authorised operational review.

(4) Identifiable practice-session history is stored until you delete your account. Account deletion removes the server-side session history linked to your account and the app's local pending session-history records for that account. Source-completeness flags may show that a local history was partial or that upload delivery was incomplete; those flags are evidence quality indicators and do not by themselves prove play time or ball counts. Hosting and international-transfer safeguards are described in §2.

§9 Optional Mobile BLE Command Diagnostics

(1) If you explicitly enable Send-to-machine diagnostics in the PeachMe mobile app, the app uploads a diagnostic record for each Bluetooth command sent to a machine. The record may contain the timestamp; exact command bytes; the effective point configuration including target IDs, speed, height, direction, and interval; detected and encoded machine series; the canonical PeachMe fleet machine ID from the app's activation or session context (omitted if Bluetooth detects a conflicting machine series); a pseudonymous BLE device fingerprint (never the raw Bluetooth peripheral identifier); Bluetooth service, characteristic, write mode, result, and duration; configuration, preset, and target-map versions; and app version, build, platform, and operating-system version.

(2) The server links the record to your signed-in member account so authorised PeachMe support staff can investigate repeated calibration changes, stale configuration, and failed command delivery. The mobile request and diagnostic event do not contain your email address; the restricted superadmin viewer resolves the current account email separately. A successful native Bluetooth write does not prove that the machine applied the command.

(3) Purpose and legal basis: troubleshooting app-to-machine communication and calibration regressions on the basis of your consent under Art. 6 (1) (a) GDPR. Diagnostics remain off until you opt in. You may withdraw consent at any time in the app without affecting prior lawful processing; disabling diagnostics deletes the pending local upload queue.

(4) Pending records are held locally only for bounded retry. Server records become inaccessible to support once they reach 30 days old. Physical deletion runs on every upload and in an hourly maintenance sweep, so under normal operation an expired record is removed by the next hourly sweep; an interrupted scheduler can delay deletion until the next successful sweep. Diagnostic records linked to a member account are deleted with that account. Server access is limited to authorised superadmins. Hosting and international-transfer safeguards are described in §2.

§10 Machine Connection History

(1) When a signed-in member connects the PeachMe mobile app to a registered PeachMe machine over Bluetooth, we record one connection entry: the member account, the machine's PeachMe fleet ID, the time the link was established and ended, whether the machine was used directly or through a managed venue programme, and, where one exists, a reference to the related managed-access session, Practice Pass rental, test loan, or booking. When the link ends, we also record why it ended (for example, disconnected by the member or lost unexpectedly), the last measured Bluetooth signal strength, a numeric Bluetooth error code, whether the app was open or in the background, and whether a drill was running. If the app connects to a machine that is not yet registered, we record only the time and a keyed one-way hash of the machine's hardware address so that unregistered machines can be counted; the raw Bluetooth address is not stored. No command content, practice data, free text, or location is part of this record. If the machine reports a mechanical fault (for example a ball jam) while you are connected, we also record the fault code, when it started and ended, and the machine's ball and runtime counters at that moment as part of the machine's maintenance history; that fault record carries no member reference of its own and is linked to your connection entry only until that entry is deleted.

(2) We process this history to support members and venue partners when a machine misbehaves, to keep machine handovers, rentals, and loans accountable, and to understand how the fleet is used. Legal basis: Art. 6 (1) (f) GDPR (our legitimate interest in operating, securing, and improving the machine fleet). You may object to this processing at any time (see §12); the member-account service itself does not depend on it.

(3) Access is limited to authorised PeachMe operations and administration staff. Members do not currently see this history in the app; you can request a copy under your right of access.

(4) Identifiable connection entries are deleted 365 days after the connection. Before deletion, per-machine daily totals (number of connections and number of distinct members) are retained without any member reference. Account deletion removes all identifiable connection entries linked to your account immediately. Hosting and international-transfer safeguards are described in §2.

§11 AI Drill Assistant (Mobile App)

(1) If you use the "Describe your drill" assistant in the PeachMe mobile app, the text you enter is sent to our server together with the drill context (sport, machine type, machine placement, handedness, app language) and processed by OpenAI (OpenAI Ireland Ltd.) under its API data-processing terms to turn it into a structured drill proposal. If you hold the Talk button instead, the app records your voice only while the button is held (at most 45 seconds); the recording is sent through our server to OpenAI for transcription and discarded immediately afterwards. Neither we nor OpenAI store the audio, and API inputs are not used to train OpenAI models. The assistant never controls a machine; it only fills the practice form, which you review before saving.

(2) We store each request for 30 days, linked to your member account: the entered or transcribed text, the recording length, the structured proposal, whether you applied or discarded it, which fields you changed afterwards (field names only, no values), optional thumbs-up/down feedback, and, if you choose to leave one after a thumbs-down, a short free-text comment. We use this to support you when a proposal was wrong and to improve the assistant. Legal basis: Art. 6 (1) (b) GDPR for producing the proposal you asked for, and Art. 6 (1) (f) GDPR (our legitimate interest in improving the assistant) for the 30-day retention. You may object to the retention at any time (see §12).

(3) Access is limited to authorised PeachMe operations and administration staff. The assistant is not available while Kids Mode is active.

(4) Requests are deleted 30 days after they were made and immediately when your account is deleted. Hosting and international-transfer safeguards are described in §2.

§12 Your Rights

You have the following rights regarding your personal data: - Right of access (Art. 15 GDPR): obtain confirmation whether we process data about you, and a copy of that data. - Right to rectification (Art. 16 GDPR): have inaccurate data corrected. - Right to erasure (Art. 17 GDPR): have data deleted where the legal grounds allow. - Right to restriction (Art. 18 GDPR): require restriction of processing under specific conditions. - Right to data portability (Art. 20 GDPR): receive data you provided to us in a structured, machine-readable format. - Right to object (Art. 21 GDPR): object to processing based on legitimate interests at any time. - Right to withdraw consent (Art. 7 (3) GDPR): withdraw any consent at any time, without affecting the lawfulness of processing before withdrawal.

To exercise these rights, contact us at [email protected].

You also have the right to lodge a complaint with a data-protection supervisory authority. The authority competent for us is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 18, 91522 Ansbach, Germany https://www.lda.bayern.de

§13 Contact for Data Protection

For data protection inquiries, contact us at: [email protected]

Privacy settings

Choose what PeachMe can load

We use essential cookies to keep language, sign-in, and cart flows working. Optional analytics, embedded maps, videos, or third-party services stay off until you allow them here.

Read privacy policy