Privacy Policy
Effective date: July 13, 2026
This page is maintained by Galardo Enterprises LLC to explain how we handle personal information when you use MatchScale. It describes the data we collect, why we collect it, who we share it with, how long we keep it, and the rights you have.
1. Who we are (Controller)
The data controller responsible for your personal information is:
- Entity: Galardo Enterprises LLC
- Address: [Registered business address — update before publishing]
- Privacy contact: privacy@matchscale.app
EU / UK representative: If we offer MatchScale to residents of the European Economic Area or the United Kingdom, we will appoint an Article 27 representative and list their name and contact here before EU/UK launch. Until then, EU/UK residents can reach us at the privacy contact above.
2. Information we collect
- Profile information: name, email, birthdate, gender, location, bio, photos, and preferences you enter.
- Activity data: likes, matches, messages, feedback requests, tier progress, feature usage.
- Device and log data: IP address, device type, operating system, app version, crash logs.
- Payment data: subscription status and transaction history handled by our payment provider; we do not store full card numbers.
- Sensitive / special-category data: photos, sexual orientation, and relationship preferences you choose to share. We process these only with your explicit consent (GDPR Art. 9) and treat them as Sensitive Personal Information under CCPA.
3. How we use your information and legal bases (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Provide matching, discovery, chat, tier features | Performance of contract (Art. 6(1)(b)) |
| Process payments and manage subscriptions | Performance of contract (Art. 6(1)(b)) |
| Publish sensitive profile data (photos, orientation) | Explicit consent (Art. 6(1)(a) + Art. 9(2)(a)) |
| Service emails, safety alerts | Legitimate interests / contract |
| Optional product updates and marketing | Consent (Art. 6(1)(a)) |
| Fraud, abuse, and safety detection | Legitimate interests (Art. 6(1)(f)) |
| Tax, accounting, legal obligations | Legal obligation (Art. 6(1)(c)) |
| Product analytics (aggregated) | Consent via cookie banner |
You can withdraw any consent-based processing at any time via the cookie preferences panel or by contacting us; withdrawal doesn't affect the lawfulness of processing carried out before withdrawal.
4. CCPA — categories of personal information
In the past 12 months we have collected the following statutory CCPA categories. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
- Identifiers: name, email, account ID, IP address.
- Customer records: billing details handled by our payment provider.
- Commercial information: subscription and transaction history.
- Internet/network activity: app usage, feature interactions, crash logs.
- Geolocation: approximate location you enter or derived from IP (not precise GPS unless you provide it).
- Visual information: profile photos you upload.
- Inferences: match compatibility signals derived from your profile and activity.
- Sensitive Personal Information (SPI): account credentials, precise geolocation (if provided), sexual orientation, and content of private messages. You have the right to limit our use of SPI to what is necessary to provide the service — contact us to exercise this right.
5. Who we share data with (subprocessors)
- Lovable Cloud: backend infrastructure, authentication, database, storage.
- Stripe: subscription billing and tax handling.
- Lovable AI Gateway: AI feedback features (invoked only when you request them).
- Legal / safety recipients: when required by law, court order, or to protect user safety.
We enter into GDPR Art. 28 data-processing agreements with each subprocessor. We do not include the Meta Pixel, Facebook SDK, Conversions API, or any Meta / Google Ads / TikTok / Snap / X / LinkedIn advertising tracker by default. If you opt in via the cookie banner and we later enable an ad tracker, this list will be updated first.
6. Data retention
| Data category | Retention period |
|---|---|
| Profile and account data | Until account deletion + up to 30 days for backup purge |
| Messages and match history | Up to 12 months after deletion, for safety review |
| Payment and transaction records | 7 years, to meet tax and accounting obligations |
| Server and security logs | 90 days |
| Fraud / abuse records | Up to 24 months for repeat-offender protection |
| Marketing consent records | Until consent is withdrawn + 24 months (proof of consent) |
7. Your rights and how to exercise them
Depending on where you live, you have some or all of the following rights:
- Access — request a copy of the data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure ("right to be forgotten") — delete your account and personal data.
- Restriction of processing — ask us to pause certain processing.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests, including profiling.
- Withdraw consent — for any consent-based processing (marketing, sensitive data), at any time.
- Automated decision-making — our matching algorithm suggests profiles but does not make legal or similarly significant decisions about you; you can request human review of any outcome that affects you.
- CCPA — Know, Delete, Correct, Opt-out of sale/share, Limit use of SPI, Non-discrimination for California residents.
- Lodge a complaint — EU/UK residents may complain to their local supervisory authority.
How to request: email privacy@matchscale.app from the address on your account (or provide reasonable identity verification). An authorized agent may act on your behalf with written proof.
Response timelines: we respond to GDPR requests within one month (extendable by up to two further months for complex requests, with notice), and to CCPA requests within 45 days (extendable once by 45 days, with notice). Requests are free unless manifestly unfounded or excessive.
8. Cookies and tracking
We use strictly-necessary storage for authentication and security. Analytics and marketing categories (including any Meta Pixel, should it be enabled) are opt-in via our cookie banner. You can change your preferences at any time using the cookie icon in the bottom-left corner.
9. Security
We use industry-standard measures including encrypted connections, access controls, and row-level security in our database. If a breach affects your personal data, we will notify affected users and, where required, supervisory authorities without undue delay in line with GDPR Art. 33/34.
10. Children's privacy
MatchScale is not intended for anyone under 18. We do not knowingly collect personal information from children and will delete any such data we discover.
11. International transfers
MatchScale is operated from the United States. Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK IDTA / Addendum.
12. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the app or by email before the changes take effect.
13. Contact us
Questions about this Privacy Policy or how we handle your data?
privacy@matchscale.app