Legal
Privacy Policy
As of: September 19, 2026
This translation is provided for convenience only. In the event of any discrepancy or conflict between this English version and the German original, the German version shall prevail and be the sole legally binding version.
This privacy policy applies to the website https://tsv-battenberg-padel.de including the online court booking offered there for the padel court of TSV Battenberg 1912 e.V.
1. Responsible person
The person responsible within the meaning of the General Data Protection Regulation (GDPR) is:
TSV Battenberg 1912 e.V.
represented by the board, Burkhard Specht
Birkenstrasse 11
35088 Battenberg (Eder)
Germany
Telephone: (0162) 3900644
Email: verein@tsv-battenberg.de
Association register number: VR 3516, district court [add district court]
For all questions about booking courts, you can reach the padel department at: kontakt@tsv-battenberg-padel.de
Data protection officer: We are not legally obliged to appoint a data protection officer. If you have any data protection concerns, please use the contact details listed above.
2. Basics
We process personal data exclusively within the framework of the applicable data protection regulations, in particular the GDPR, the Federal Data Protection Act (BDSG) and the Telecommunications Digital Services Data Protection Act (TDDDG).
Personal data is any information that relates to an identified or identifiable natural person - for example your name, email address or payment details.
We only collect and use your data to the extent necessary to provide the website, carry out your booking and fulfill our legal obligations. Processing for advertising purposes, selling your data or passing it on to third parties for their own purposes takes place not instead of.
Legal bases at a glance
Depending on the processing, we rely on the following legal bases:
- Art. 6 Paragraph 1 Letter a GDPR (consent): Voluntary information, non-essential services
- Art. 6 Paragraph 1 Letter b GDPR (contract / pre-contractual measures): Seat booking, payment processing, cancellation, access code dispatch
- Art. 6 Paragraph 1 Letter c GDPR (legal obligation): Tax retention obligations, accounting
- Art. 6 Paragraph 1 Letter f GDPR (legitimate interest): Technical operations, IT security, abuse and fraud prevention, assertion of claims
- § 25 paragraph 2 TDDDG: Storage of technically necessary information on your device
3. Accessing the website and hosting
3.1 Hosting Service Providers
This website is on the platform Lovable operated.
Provider is:
Lovable Labs AB, Regeringsgatan 25, 111 53 Stockholm, Sweden
Data protection contact: dpo@lovable.dev
Data protection declaration: https://lovable.dev/privacy
Lovable provides the technical infrastructure (web server, database, storage, delivery via a content delivery network) and processes personal data on our behalf. Processing takes place exclusively in accordance with our instructions and for the purposes stated in this data protection declaration.
Lovable, for its part, uses sub-processors. The database, authentication and storage services of our application are based on the infrastructure ofSupabase operated (Supabase, Inc.; data protection declaration: https://supabase.com/privacy). In addition, providers of cloud infrastructure and content delivery services are used. Lovable provides a current overview of the approved sub-processors with name, location and processing purpose at https://trust.lovable.dev.
Legal basis: Art. 6 Para. 1 lit. f GDPR (legitimate interest in the secure, stable and efficient provision of our online offering) as well as Art. 6 Para. 1 lit. b GDPR, insofar as the hosting serves to carry out the booking.
Storage period: Lovable stores the customer data processed on our behalf for the duration of the contractual relationship. After a deletion request or termination of the contractual relationship, the data will be deleted within 30 days; Backups can continue to contain data for up to 90 days.
3.2 Server log files
When you access our website, the hosting provider automatically collects information that your browser transmits. These are:
- IP address of the requesting device
- Date and time of access
- Name and URL of the retrieved file or page
- amount of data transferred and notification of the success of the retrieval
- Referrer URL (previously visited page)
- Browser used, browser version and operating system
We cannot assign this data to specific individuals and will not combine it with other data sources.
Purpose: Ensuring trouble-free connection establishment, comfortable use, evaluation of system security and stability as well as defense and detection of attacks.
Legal basis: Art. 6 Paragraph 1 Letter f GDPR. Our legitimate interest lies in the technical provision and IT security of our offer.
Storage period: The log data collected by our hosting provider is stored for a period ofup to 90 days stored and then deleted, unless, in exceptional cases, they are needed longer to clarify a specific security incident or due to legal requirements.
3.3 SSL/TLS encryption
This website uses SSL/TLS encryption for security reasons and to protect the transmission of confidential content. You can recognize an encrypted connection when your browser's address line begins with "https://" and a lock symbol is displayed. If encryption is active, the data you transmit to us cannot be read by third parties.
4. Cookies and storage on your device
Our website uses exclusively technically necessary Cookies or comparable storage technologies (e.g. local storage / session storage). These are necessary for the booking process to work - for example, to save your selection of date, duration and number of players across the individual steps of the booking form and to ensure the security of payment.
In addition, our payment service provider Stripe sets its own cookies during the payment process that are necessary for payment processing and fraud prevention (see Section 6).
Legal basis: § 25 Para. 2 No. 2 TDDDG (absolutely necessary for the provision of the service you expressly request) as well as Art. 6 Para. 1 lit. b and lit. f GDPR for subsequent processing. Consent is not required for this.
We bet no Cookies for analysis, tracking or advertising purposes and do not integrate tracking services (e.g. Google Analytics, meta pixels).
You can set your browser so that you are informed about the setting of cookies, only allow cookies in individual cases or generally exclude them. If cookies are deactivated, the functionality of the booking may be restricted.
[Important: If you integrate analysis, reach or marketing tools in the future, a consent banner with prior consent is mandatory and this section must be adjusted.]
5. Online seat booking
5.1 What data we collect
If you book a padel court via our website, we process the following data:
Booking data
- selected date, start time and duration (60 / 90 / 120 minutes)
- Number of players
- Indication of how many of the players are members of the padel division (for price calculation)
- desired racket rental
- Booking number and booking status
Contact details
- First and Last Name
- E-mail address
- [Phone number, if collected]
Payment details
- Invoice amount, currency, selected payment method, transaction/payment status
- The actual payment information (e.g. credit card number) is not processed by us, but only by the payment service provider (see section 6).
Technical data
- Time of booking, IP address at time of booking (to prevent misuse)
5.2 Purposes and legal bases
- Carrying out and managing your seat booking, reserving the slot — Art. 6 Paragraph 1 Letter b GDPR
- Price calculation based on number of players and membership status — Art. 6 Paragraph 1 Letter b GDPR
- Sending booking confirmation, access code and cancellation information — Art. 6 Paragraph 1 Letter b GDPR
- Payment processing, refunds, receivables management — Art. 6 Paragraph 1 Letter b and Letter f GDPR
- Storage of booking and payment receipts — Art. 6 Paragraph 1 Letter c GDPR i. V. m. § 147 AO
- Avoidance of double bookings, misuse and fraud, traceability of space usage in the event of damage — Art. 6 Paragraph 1 Letter f GDPR
Requirement: Providing your name, email address and payment details is required to conclude and execute the booking contract. Without this information we cannot accept a booking. There is no legal obligation to provide it.
5.3 Access code for the key safe
24 hours before your booked time, we will send you the access code for the key safe, which changes daily, as well as instructions for use by email. For this purpose, we process your email address and booking data.
Legal basis: Art. 6 Paragraph 1 Letter b GDPR (fulfillment of the booking contract).
The access code is personal and only intended for your booked time. Please do not pass it on to uninvolved third parties.
5.4 Cancellation
You can cancel a booking via our cancellation page. For this purpose, we process the information required to identify the booking ([e.g. booking number and/or email address]) as well as the payment data necessary for the refund. The charging of a processing fee in accordance with our cancellation conditions is also processed on this basis.
Legal basis: Art. 6 Paragraph 1 Letter b GDPR.
5.5 Weather approval by the club
If we activate the weather option due to severe weather or unplayable pitch conditions, we will process your contact and booking details to inform you and provide you with a personal link to rebook or cancel free of charge. In the event of a cancellation, we will process the payment details for a refund minus the processing fee; There will be no refund for transfer bookings that are still unpaid.
Legal basis: Art. 6 Paragraph 1 Letter b GDPR.
5.6 Storage period
Booking data is stored for the duration of the contract processing. We then store the data relating to booking and payment receipts in accordance with the statutory retention periods - in particularten years according to Section 147 Paragraph 3 AO for booking documents as well six years for received and sent commercial or business letters. During this time, processing is limited to fulfilling the retention obligation.
We delete data that is not subject to retention requirements at the latest [e.g. B. 12 months] after completion of the booking, provided that no further claims can be made.
6. Payment Processing
6.1 Stripe
We use the payment service provider to process payments Stripe a.
The provider for users in the European Economic Area is:
Stripe Payments Europe Limited
1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland
Data protection declaration: https://stripe.com/de/privacy
Privacy Center: https://stripe.com/privacy-center/legal
If you choose a payment method offered via Stripe, the data required for payment will be transmitted to Stripe or recorded by you directly in a secure input mask provided by Stripe. Depending on the payment method, this includes in particular:
- Name of the card or account holder
- Payment method details (e.g. card number, period of validity, check digit, IBAN)
- Invoice amount, currency, transaction number and time
- E-mail address
- IP address, device and browser information, and behavioral characteristics for fraud detection
Important: The complete payment method data (e.g. your credit card number) is collected and processed by Stripe. We ourselves receive and store this datanot. We are only informed whether and when the payment was successful, as well as the key details of the transaction necessary for assignment.
Role of Stripe: Stripe processes some of the data on our behalf; In addition, Stripe is responsible for payment processing, fraud prevention (Stripe Radar) and the fulfillment of its own regulatory, money laundering and financial obligationsindependently responsible within the meaning of the GDPR. Stripe’s privacy policy applies to this processing.
Legal basis: Art. 6 Para. 1 lit. b GDPR (implementation of the contract), Art. 6 Para. 1 lit. f GDPR (legitimate interest in secure and fraud-free payment processing) and Art. 6 Para. 1 lit. c GDPR, insofar as Stripe fulfills legal obligations.
Third country transfer: Stripe Payments Europe Limited is based in Ireland (EU). A transfer to the parent company Stripe, Inc. in the USA and to other affiliated companies is possible. Stripe has implemented measures for international data transfers based on the EU standard contractual clauses of the European Commission (Art. 46 Para. 2 lit. c GDPR). Further information can be found at https://stripe.com/privacy-center/legal.
6.2 PayPal
If you choose the PayPal payment method, payment will be processed via:
PayPal (Europe) S.à r.l. et Cie, S.C.A.
22-24 Boulevard Royal
L-2449 Luxembourg
Data protection declaration: https://www.paypal.com/de/legalhub/privacy-full
If you select this payment method, you will be redirected to the PayPal website. The data required for payment will be transmitted, in particular your name, your email address, the invoice amount, the currency, the transaction number and a reference to your booking. You only provide PayPal with the login details of your PayPal account and your payment methods stored there; we receive no knowledge of this. We are only informed about the payment status.
PayPal is responsible for processing as part of payment processing and for fulfilling its own regulatory, money laundering and financial obligationsindependently responsible within the meaning of the GDPR. In this respect, PayPal’s data protection declaration applies. PayPal can process data to prevent fraud and abuse and in this context also pass it on to affiliated companies and service providers.
Legal basis: Art. 6 Para. 1 lit. b GDPR (implementation of the contract), Art. 6 Para. 1 lit. f GDPR (legitimate interest in secure payment processing) and Art. 6 Para. 1 lit. c GDPR, insofar as PayPal fulfills legal obligations.
Third country transfer: PayPal (Europe) S.à r.l. et Cie, S.C.A. is based in Luxembourg (EU). A transfer to affiliated companies outside the EEA, in particular to the USA, is possible; PayPal bases this on the EU standard contractual clauses (Art. 46 para. 2 lit. c GDPR).
6.3 Transfer
If you choose to pay by bank transfer, we will send you the club's bank details. We receive your payment data (in particular name, IBAN and intended use) when the payment is received on our club account at Sparkasse Marburg-Biedenkopf. We process this data to assign the payment to your booking and for accounting purposes.
Legal basis: Art. 6 Para. 1 lit. b GDPR and Art. 6 Para. 1 lit. c GDPR i. V. m. § 147 AO.
7. Email dispatch (booking confirmation, access code, notifications)
Booking confirmations, access codes, cancellation and cancellation notifications are sent via our own domain using the email services ofIONOS.
Provider is:
IONOS SE
Elgendorfer Straße 57
56410 Montabaur
Germany
Data protection declaration: https://www.ionos.de/terms-gtc/terms-privacy
IONOS provides the mail server infrastructure and processes your email address, your name and the content of the messages sent (in particular booking data and access code) on our behalf. With IONOS there is aContract for order processing according to Art. 28 GDPR.
The processing takes place on servers in Germany or within the European Union. In this respect, data will not be transferred to third countries.
Legal basis: Art. 6 Paragraph 1 Letter b GDPR (fulfillment of the booking contract).
Storage period: Messages sent remain in our mailbox as long as this is necessary to trace the booking and are then deleted within the deadlines specified in Section 14.
8. Contact us
If you contact us by email (e.g. to kontakt@tsv-battenberg-padel.de or verein@tsv-battenberg.de) or by telephone, we will process your information (name, contact details, content of your message) to process your request. The reception and storage of incoming emails takes place via the IONOS infrastructure mentioned in section 7 on servers within the European Union.
Legal basis: Art. 6 Paragraph 1 Letter b GDPR, if your request is related to a booking or a contract; otherwise Art. 6 Para. 1 lit. f GDPR (legitimate interest in answering inquiries).
Storage period: We will delete your request as soon as it has been finally processed and there are no legal retention obligations to the contrary.
Email security note: Unencrypted emails are sent over the Internet and cannot be considered completely secure. Please do not send us particularly sensitive data via unencrypted email.
9. Membership application
You can download a PDF form for joining the padel division on our website and fill it out and send it back to us by email. We process the data transmitted (including name, address, date of birth, bank details for collecting contributions) to establish and manage your club membership.
Legal basis: Art. 6 Para. 1 lit. b GDPR (membership relationship) and Art. 6 Para. 1 lit. c GDPR for storage under association and tax law.
Storage period: For the duration of the membership and beyond the statutory retention periods (usually up to ten years for documents relevant to contributions).
The form is made available on a club portal server. When downloading, the data protection information of the respective provider applies.
10. Donation Requests
If you contact us about a donation, we process your contact details and - in the case of a donation receipt - the necessary information (name, address, donation amount, date).
Legal basis: Art. 6 Para. 1 lit. b GDPR and Art. 6 Para. 1 lit. c GDPR i. V. m. the tax law requirements for issuing donation confirmations (§ 50 EStDV). We retain donation confirmations and the underlying records in accordance with the statutory deadlines.
11. External links and social media
11.1 Links
Our website contains links to external offers, including:
- Instagram (Instagram/Meta Platforms Ireland Ltd., Merrion Road, Dublin 4, Ireland)
- WhatsApp community (WhatsApp Ireland Limited, Merrion Road, Dublin 4, Ireland)
- Google Maps (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland)
- Club portal to download the membership application
It is a matter of simple links, no embedded content. Data will only be transferred to these providers when you actively click on the respective link. From this point on, the data protection regulations of the respective provider apply exclusively, and we have no influence on their content or compliance.
11.2 WhatsApp Community
If you join our WhatsApp community, WhatsApp Ireland Limited processes your data - in particular your telephone number, your profile and your messages - under its own responsibility. Your phone number is visible to other members of the group. Participation is voluntary and not required to book a place. A transfer of data to third countries, especially the USA, is possible when using WhatsApp.
Legal basis: Art. 6 Para. 1 lit. a GDPR (your consent through voluntary membership) or Art. 6 Para. 1 lit. f GDPR.
12. Recipients of your data
Your data will only be passed on to the following categories of recipients:
- Lovable Labs AB, Sweden — Hosting, database, provision of the website — Processor (Article 28 GDPR)
- Supabase, Inc. (as a sub-processor of Lovable) — Database, Authentication, Storage — Sub-processor
- IONOS SE, Germany — Email infrastructure, sending confirmations and access codes — Processor (Article 28 GDPR)
- Stripe Payments Europe Ltd., Ireland — Payment processing, fraud prevention — partly processor, partly independently responsible
- PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg — Payment processing — independently responsible person
- Sparkasse Marburg-Biedenkopf — Payment transactions — independently responsible person
- Tax advice / financial audit of the association — Accounting, auditing — Contract processors or persons responsible for professional secrecy
- Authorities and courts — Fulfillment of legal obligations — independently responsible person
Within the club, only those people who need it to fulfill their tasks (in particular the board and those responsible for the padel division) have access to your data. These people are obliged to maintain confidentiality.
Your data will not be passed on for advertising purposes or sold.
13. Data transfer to third countries
Your data will generally be processed within the European Union or the European Economic Area.
To the extent that service providers can process or access data in third countries - in particular the USA - (this applies in particular to Stripe and possible sub-processors of Lovable), this is done on the basis of appropriate guarantees in accordance with Chapter V of the GDPR. These include in particular:
- the Standard contractual clauses the European Commission (Art. 46 Para. 2 lit. c GDPR), supplemented by additional technical and organizational protective measures, as well
- where relevant, a certification of the recipient under the EU-U.S. Data Privacy Framework based on the adequacy decision of the European Commission of July 10, 2023 (Art. 45 GDPR).
We would like to point out that third countries may not have a level of data protection equivalent to European law and, in particular, government access to data cannot be ruled out to the same extent. You can request a copy of the respective existing guarantees using the contact details mentioned in section 1.
14. General storage period
We only store personal data for as long as necessary for the respective purposes. The following are relevant:
- the duration of the contractual relationship or processing of your request,
- statutory retention obligations (in particular ten years according to Section 147 AO for booking documents, six years for business letters),
- the limitation periods for possible claims (usually three years according to Sections 195, 199 BGB, calculated from the end of the year in which the claim arose).
After the relevant deadlines have expired, the data will be deleted or anonymized.
15. No automated decision making
We do not carry out automated decision-making, including profiling, with regard to you with legal effect or similarly significant impairment within the meaning of Article 22 GDPR.
The payment service provider Stripe uses automated procedures to assess the risk of transactions to prevent fraud. For more information, please see Stripe's privacy policy.
16. Data Security
We take appropriate technical and organizational measures in accordance with Art. 32 GDPR to protect your data against loss, destruction, manipulation and unauthorized access. This includes, in particular, encryption of data transmission (TLS), encrypted storage, restrictive allocation of access rights and regular reviews of our protective measures. Our security measures are continually adapted in line with technological developments.
17. Minors
Our offer is aimed at adults. Minors should only make a booking with the consent of their legal guardian. We do not knowingly collect information from children under 16 without appropriate consent. If you discover that a child has provided us with information without consent, please contact us and we will delete this information immediately.
18. Your rights as a data subject
You have the following rights towards us regarding your personal data:
- Information (Art. 15 GDPR): You can request information about whether and what data we process about you, as well as receive a copy of this data.
- Correction (Art. 16 GDPR): You can request that incorrect data be corrected or incomplete data be completed.
- deletion (Art. 17 GDPR): You can request the deletion of your data, provided there is no legal retention requirement or another reason for exclusion.
- Restriction of processing (Article 18 GDPR).
- Data portability (Art. 20 GDPR): You can request to receive the data you have provided in a structured, common and machine-readable format or to have it transmitted to another person responsible.
- Revocation of consent (Art. 7 Para. 3 GDPR): You can revoke your consent at any time with effect for the future. The lawfulness of the processing carried out until the revocation remains unaffected.
- Complaint to a supervisory authority (Art. 77 GDPR).
To exercise your rights, an informal message to the contact details mentioned in section 1 is sufficient.
Right to object according to Art. 21 GDPR
If we process your personal data on the basis of legitimate interests in accordance with Article 6 Paragraph 1 Letter f of the GDPR, you have the right to object to this processing at any time for reasons arising from your particular situation. We will then no longer process the data concerned unless we can demonstrate compelling legitimate reasons for the processing that outweigh your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.
Competent supervisory authority
Without prejudice to other legal remedies, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence, your place of work or the place of the alleged violation. Responsible for us:
The Hessian Commissioner for Data Protection and Freedom of Information
Gustav Stresemann Ring 1
65189 Wiesbaden
Telephone: 0611 1408-0
Email: poststelle@datenschutz.hessen.de
Website: https://datenschutz.hessen.de
19. Changes to this Privacy Policy
We reserve the right to adapt this data protection declaration so that it always complies with current legal requirements or to implement changes to our services - for example when introducing new functions or changing service providers. When you visit again, the current version will apply, available at https://tsv-battenberg-padel.de/datenschutz.
