Privacy Policy
Last updated: January 15, 2026
1. Introduction
ouibu ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and website (collectively, the "Service").
We comply with the General Data Protection Regulation (GDPR) and other applicable data protection laws. By using our Service, you agree to the collection and use of information in accordance with this policy.
2. Data Controller
The data controller responsible for your personal data is:
Charlotte DI Ltd.
27 - mi Yuli, 19, fl. 2, apt. 4
9000 Varna, Bulgaria
Email: webmaster@ouibu.de
3. Information We Collect
3.1 Information You Provide
- Account Information: When you create an account, we collect your email address, name, and profile information.
- Profile Data: Fitness preferences, sport activities, location preferences, and profile photos you choose to share.
- Communications: Messages you send to other users through the platform.
- Support Requests: Information you provide when contacting our support team.
3.2 Information Collected Automatically
- Device Information: Device type, operating system, unique device identifiers.
- Usage Data: How you interact with our Service, features used, and time spent.
- Location Data: With your consent, we collect precise or approximate location to help you find workout partners nearby.
- Log Data: IP address, browser type, pages visited, and access times.
3.3 Cookies and Tracking Technologies
We use cookies and similar tracking technologies to track activity on our Service. See our Cookie Policy for more details.
4. Legal Basis for Processing (GDPR)
We process your personal data based on the following legal grounds:
- Contract Performance: Processing necessary to provide our Service to you.
- Legitimate Interests: For improving our Service, security, and fraud prevention.
- Consent: Where you have given explicit consent (e.g., location data, marketing communications).
- Legal Obligations: Where required by applicable law.
5. How We Use Your Information
We use the collected information for:
- Providing and maintaining our Service
- Connecting you with potential workout partners based on your preferences and location
- Personalizing your experience
- Processing transactions (for ouibu Pro subscriptions)
- Sending service-related communications
- Improving our Service through analytics
- Ensuring safety and security of our platform
- Complying with legal obligations
6. Data Sharing and Disclosure
We may share your information with:
- Other Users: Your profile information is visible to other users to facilitate connections.
- Service Providers: Third-party companies that help us operate our Service:
- Supabase: Our backend infrastructure provider for database, authentication, and storage services (located in EU/US with appropriate safeguards).
- Analytics providers
- Payment processors (for Pro subscriptions)
- Legal Requirements: When required by law or to protect our rights.
- Business Transfers: In connection with a merger, acquisition, or sale of assets.
We do not sell your personal data to third parties.
7. International Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA). When we transfer data outside the EEA, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by the European Commission
- Transfers to countries with adequate data protection (adequacy decisions)
- Other legally approved transfer mechanisms
8. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required by law. When you delete your account, we will delete or anonymize your personal data within 30 days, except where we need to retain it for legal purposes.
9. Your Rights (GDPR)
Under GDPR, you have the following rights:
- Right of Access: Request a copy of your personal data.
- Right to Rectification: Request correction of inaccurate data.
- Right to Erasure: Request deletion of your personal data ("right to be forgotten").
- Right to Restrict Processing: Request limitation of how we use your data.
- Right to Data Portability: Receive your data in a structured, machine-readable format.
- Right to Object: Object to processing based on legitimate interests or for marketing.
- Right to Withdraw Consent: Where processing is based on consent, you can withdraw it at any time.
To exercise these rights, contact us at webmaster@ouibu.de. We will respond within 30 days.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Secure authentication mechanisms
- Regular security assessments
- Access controls and authentication
- Regular backups
Our backend is powered by Supabase, which maintains SOC 2 Type II compliance and implements industry-standard security practices.
11. Children's Privacy
Our Service is not intended for users under 16 years of age. We do not knowingly collect personal data from children under 16. If we become aware that we have collected data from a child under 16, we will delete it promptly.
12. Third-Party Links
Our Service may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last updated" date. For material changes, we may also notify you via email or in-app notification.
14. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:
- Email: webmaster@ouibu.de
- Address: Charlotte DI Ltd., 27 - mi Yuli, 19, fl. 2, apt. 4, 9000 Varna, Bulgaria
15. Supervisory Authority
If you are in the EU/EEA and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection supervisory authority.