Privacy Policy
Last updated: 25 July 2026
1. Who we are
Gala Finder (galafinder.vibingfun.com) is operated by Britrik. For the purposes of UK data protection law, Britrik is the data controller. You can contact us at info@vibingfun.com.
2. What personal data we collect
- Email address — collected when you create an account or sign in, used for authentication and to send entry-open reminder emails you opt into.
- Account profile — your display name and preferred Swim England region and filter settings, stored against your account.
- Saved meets — swimming galas you save to your personal calendar within the app, and whether you've asked for an email reminder for each one.
- Swimmer profiles (optional) — if you use the "My Swimmers" feature, you may enter a swimmer's display name, gender, date of birth, and Swim England membership number, plus personal-best swim times (entered manually or imported from that swimmer's own public Swim England rankings page, via paste or bookmarklet, at your initiation). This data is provided by you, the account holder, about a swimmer you are responsible for — it is not collected directly from the swimmer. See §8 for swimmers who are children.
- Technical and security logs — our edge hosting provider (Cloudflare, Inc., via Lovable) and database provider process technical data such as IP address, browser/device information, timestamps, and request metadata. We use this only for security, reliability, and troubleshooting — never for advertising or behavioural profiling.
We do not collect payment information or health data. Date of birth, gender, and swim-performance data are used solely to determine event eligibility (age/gender categories, qualifying times) and are not special category data under UK GDPR.
3. How we use your data
| Purpose | Legal basis (UK GDPR Art. 6) |
|---|---|
| Providing the Gala Finder service (account, saved meets, swimmer profiles, eligibility matching) | Contract — Art. 6(1)(b) |
| Sending day-before entry-open reminder emails (opted into per meet) | Consent — Art. 6(1)(a) |
| Security, fraud prevention, debugging | Legitimate interests — Art. 6(1)(f) |
| Complying with legal obligations | Legal obligation — Art. 6(1)(c) |
4. Third-party processors
- Supabase, Inc. (supabase.com) — database, authentication, and storage of your account, saved meets, and swimmer data. Our database is hosted in the European Union (AWS
eu-west-1, Ireland), so this data is stored within the EEA. Supabase operates under a Data Processing Agreement; any incidental access by Supabase's US-based staff for support or administration is covered by that DPA and Supabase's certification under the EU–US Data Privacy Framework. - Cloudflare, Inc. (cloudflare.com) — edge hosting, CDN, TLS termination, and DDoS protection for the site itself, provided as part of Lovable's infrastructure. Cloudflare processes request metadata (IP address, headers, timestamps) solely to deliver and secure the site, and is certified under the EU–US Data Privacy Framework.
- Lovable (lovable.dev) — hosts our cloud infrastructure (running on Cloudflare, above) and provides the "Continue with Google" sign-in option. If you use it, your name, email address and profile photo are shared with us by Google via Lovable's authentication service for the sole purpose of signing you in.
- Resend, Inc. (resend.com) — transactional email delivery for reminder emails. Processes your email address only to send the email you requested.
- Exa AI / Parallel AI — server-side web search used admin-side to enrich public meet data, and used to help import swimmer personal-best times you choose to paste or fetch from a public Swim England rankings page. Your account email and profile data are never passed to these services.
We do not sell, rent, or share your personal data with any third party for marketing purposes.
5. Cookies and local storage
Gala Finder stores a small amount of data in your browser's localStorage, including your region preference (key galafinder.region) and, once you sign in, your authentication session (managed by Supabase Auth). None of this is used for advertising, tracking, or analytics, and no third-party advertising cookies are set.
6. Data retention
- Account data (email, preferences, saved meets, swimmer profiles) — retained while your account is active. Email info@vibingfun.com to request deletion of your account and associated data.
- Server logs — kept only as long as needed for security and debugging, then deleted.
- Email delivery records — retained by Resend per their standard retention period (see resend.com's own privacy policy).
7. Your rights
Under UK GDPR and the Data Protection Act 2018 you have the right to access, rectify, erase, restrict processing of, request portability of, and object to processing of your personal data. You can view and edit most of your data directly in Settings and My Swimmers, and you can withdraw consent for a meet's entry-open reminder at any time by turning off its email toggle in My Calendar.
Email info@vibingfun.com to exercise any right. We will respond within one calendar month.
8. Children and swimmer profiles
Gala Finder accounts are intended for adults (coaches, parents, and club administrators) — we do not knowingly allow a child to create an account or sign in directly. However, the My Swimmers feature lets an adult account holder enter data about a swimmer they are responsible for, who may be a child. Where the swimmer is a child, you confirm that you are their parent, guardian, or coach with authority to provide this information on their behalf, and that you will only enter the minimum data needed to check meet eligibility (name, date of birth, gender, membership number, and times). We do not use swimmer profile or personal-best data for advertising, behavioural profiling, or automated decision-making — it is used solely to match a swimmer against meet eligibility rules.
Contact info@vibingfun.com if you are a parent or guardian and want to review or delete a swimmer profile, or if you believe a child has created their own account — we will act promptly.
9. Security
All data is transmitted over HTTPS/TLS. Our primary data store is located in the European Union (Ireland); any access from outside the EEA by Supabase for support or administration is governed by their Data Processing Agreement. Database access is protected by Supabase Row Level Security (RLS) policies ensuring users can only access their own account, swimmers, and saved meets. Service-role keys are never exposed client-side.
10. Changes to this policy
We may update this policy when the service changes. The "Last updated" date at the top reflects the current version. For material changes we will notify signed-in users by email.
11. Complaints
You have the right to complain to the UK's supervisory authority:
Information Commissioner's Office (ICO)Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
ico.org.uk/make-a-complaint | 0303 123 1113