game set engage
  • Solutions

    • Fan Engagement
    • Revenue Growth
    • Community Building
    • Data & Analytics

    By Fan Base

    • Local Up to 1K fans
    • City Up to 10K fans
    • National Up to 100K fans
    • Global Up to 1M fans

    Resources

    • Earnings Calculator New
    • Implementation Guide
    • Developers
    • Support Center
    See All Club Features 10+ seasons of experience
  • Venue Types

    • Sports Bars
    • Pubs & Restaurants
    • Entertainment Venues
    • Retail Partners

    Why Partner?

    Pay per check-in

    Simple per-visit pricing

    Quick approval

    Get listed in minutes

    More foot traffic

    Fans discover you via clubs

    See All Venue Features Partner with clubs & athletes
  • For Fans
  • Pricing
  • Learn

    • Blog
    • Use Cases
    • Guides & eBooks

    Support

    • Help Center
    • Developers
    • System Status
    • Contact Us
Sign In Start Engaging Free

Solutions

Fan Engagement Revenue Growth Community Building Data & Analytics

By Fan Base

LocalUp to 1K fans CityUp to 10K fans NationalUp to 100K fans GlobalUp to 1M fans

Resources

Earnings Calculator New Implementation Guide Developers

Venue Types

Sports Bars Pubs & Restaurants Entertainment Venues Retail Partners

Why Partner?

Pay per check-in
Quick approval
More foot traffic
See All Venue Features
For Fans Pricing

Learn

Blog Use Cases Guides & eBooks

Support

Help Center Developers System Status Contact Us
Start Engaging Free Sign In
Legal

GDPR Compliance

Our commitment to protecting the privacy and data rights of individuals under the EU General Data Protection Regulation and the UK GDPR.

Last updated: August 19, 2026

Privacy Policy Terms of Service Fan Terms Club Agreement Venue Agreement Cookie Policy GDPR

Our GDPR Commitment

Game Set Engage LLC ("GSE") is committed to protecting the privacy and data rights of all individuals, including those in the European Union and the United Kingdom. We have implemented comprehensive measures to ensure compliance with the General Data Protection Regulation (EU GDPR) and the UK General Data Protection Regulation (UK GDPR).

This page supplements our Privacy Policy, which applies to all users globally. If you are located in the EU or UK, the rights and protections described here apply to you in addition to those in our Privacy Policy.

Controller and Processor Roles

Understanding who controls and processes your data is important under GDPR:

  • GSE as Controller: For data we collect directly (account information, usage data, analytics), GSE acts as the data controller
  • GSE as Processor: When clubs use our platform to manage fan data, GSE acts as a data processor on behalf of the club (data controller). In this case, the club determines the purposes and means of processing, and GSE processes data on their instructions
  • Joint controllership: For certain activities (such as engagement points calculation and campaign analytics), GSE and the club may act as joint controllers under Article 26

Data Processing Agreements

Clubs operating in the EU/EEA or processing data of EU/EEA residents can request a Data Processing Addendum (DPA) that complies with GDPR Article 28 requirements. Contact dpo@gamesetengage.com to request a DPA.

Legal Basis for Processing

We process personal data based on the following legal grounds, mapped to specific processing activities:

Contract Performance (Article 6(1)(b))

  • Account creation and management
  • Processing subscription payments via Stripe
  • Delivering the Service (dashboard, events, campaigns)
  • Customer support and communication
  • Club-fan subscription management

Consent (Article 6(1)(a))

  • Collection of precise geolocation data during campaign check-ins
  • Marketing communications and newsletters (via SendGrid)
  • Non-essential cookies and analytics tracking (see our Cookie Policy)
  • Push notifications on mobile devices
  • Optional profile enrichment features

Legitimate Interests (Article 6(1)(f))

  • Platform security and fraud prevention (including detection of location spoofing)
  • Aggregated analytics and platform performance optimization
  • Marketing to existing customers (with easy opt-out)
  • Improving and developing new Service features

We have conducted legitimate interest assessments for each of the above activities and can provide these upon request.

Legal Obligation (Article 6(1)(c))

  • Tax record retention (billing data retained for 7 years)
  • Responding to law enforcement requests
  • Compliance with applicable regulations

Your Rights Under GDPR

As a data subject in the EU or UK, you have the following rights:

  • Right of Access (Article 15): Request a copy of all personal data we hold about you, including campaign participation records and engagement data
  • Right to Rectification (Article 16): Correct inaccurate or incomplete personal data. You can update most information directly in your account settings
  • Right to Erasure (Article 17): Request deletion of your personal data. Note: some data may be retained where we have a legal obligation
  • Right to Restrict Processing (Article 18): Limit how we process your data while we verify its accuracy or assess your objection
  • Right to Data Portability (Article 20): Receive your data in a structured, commonly used, machine-readable format (JSON or CSV)
  • Right to Object (Article 21): Object to processing based on legitimate interests, including profiling for engagement scoring

How to Exercise Your Rights

To exercise any of your GDPR rights, you can:

  • Contact our Data Protection Officer at dpo@gamesetengage.com
  • Use the privacy controls in your account settings (for access, rectification, and data export)
  • Submit a request through our support system with the subject "GDPR Request"

We will verify your identity before processing your request. We aim to respond within 30 days. For complex requests or a high volume of requests, we may extend this period by up to 60 days, and will notify you of any extension within the initial 30-day period, as permitted by GDPR.

There is no fee for exercising your rights. However, we may charge a reasonable fee or refuse requests that are manifestly unfounded or excessive.

Data Protection Measures

Technical Safeguards

  • TLS/SSL encryption for all data in transit
  • Encryption at rest for personal data in our Supabase PostgreSQL database
  • Hashed password storage (bcrypt via Devise)
  • Role-based access controls with seven distinct permission levels
  • JWT-based authentication for mobile API with token expiration
  • Regular security audits and penetration testing
  • Automated backup and disaster recovery systems

Organizational Safeguards

  • Privacy by design and by default principles applied in product development
  • Regular staff training on data protection obligations
  • Data Protection Impact Assessments (DPIAs) for high-risk processing activities
  • Vendor due diligence and data processing agreements with all sub-processors
  • Incident response and breach notification procedures
  • Records of Processing Activities maintained under Article 30

Data Protection Impact Assessments

We have conducted DPIAs for the following high-risk processing activities, as required by GDPR Article 35:

  • Location-based check-in campaigns: Collection and processing of precise geolocation data to determine fan presence at stadiums, partner venues, or home
  • Engagement scoring and profiling: Automated calculation of engagement points based on campaign participation, location, and activity patterns
  • Three-way data sharing: Data flows between clubs, fans, and partner venues through the campaign partnership model

DPIAs are reviewed annually or when significant changes are made to the relevant processing activities. Summaries are available upon request from our DPO.

Sub-Processors

We use the following sub-processors to deliver our Service. Each is bound by a data processing agreement:

Sub-Processor Purpose Data Location
Supabase Database hosting (PostgreSQL) United States
Amazon Web Services (AWS) File storage (S3 — avatars, uploads) United States
Stripe Payment processing, subscription billing United States
SendGrid (Twilio) Transactional and marketing email United States
Google (Places API) Address geocoding and location services United States
Redis (hosting provider) Caching, Action Cable real-time messaging United States

We will notify affected customers before adding new sub-processors or making material changes to existing ones, providing a reasonable opportunity to object.

International Data Transfers

GSE is based in the United States. When we transfer personal data from the EEA or UK to the United States or other countries without an adequacy decision, we ensure adequate protection through:

  • Standard Contractual Clauses (SCCs): We use the European Commission's standard contractual clauses (June 2021 version) for transfers to all sub-processors
  • UK International Data Transfer Addendum: For transfers of UK personal data, we supplement SCCs with the UK Addendum as required by the ICO
  • Transfer Impact Assessments: We have assessed the legal framework of each destination country and implemented supplementary technical measures where necessary
  • Adequacy decisions: Where the European Commission or UK Secretary of State has issued an adequacy decision for a destination country, we rely on that decision

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:

  • Account data: Until account deletion, which takes effect immediately and cannot be undone
  • Billing data: 7 years for tax and accounting obligations
  • Campaign participation data: Life of account; anonymized upon deletion
  • Marketing consent records: Until consent is withdrawn, or 3 years of inactivity
  • Analytics data: 26 months from collection
  • Server logs: 90 days

Automated Decision-Making and Profiling

We use automated processing in the following areas:

  • Engagement point calculation: Points are automatically calculated based on your check-in location (5x stadium, 3x venue, 1x home) and campaign type. This is based on objective rules and does not involve subjective profiling
  • Fraud prevention: Automated detection of location spoofing and suspicious check-in patterns. Flagged accounts are reviewed by a human before any action is taken
  • Content recommendations: Suggesting relevant clubs and campaigns based on your location and subscription history

None of these automated processes produce legal effects or similarly significantly affect you within the meaning of Article 22. You have the right to request human intervention in any automated decision-making process, express your point of view, and contest the decision by contacting our DPO.

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (Article 33)
  • Inform affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms (Article 34)
  • Provide clear information about the nature and scope of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken to address the breach
  • Document all breaches regardless of risk level, including those not reported to the supervisory authority, in our internal breach register

EU Representative

As GSE is established outside the EU, we have appointed an EU representative in accordance with GDPR Article 27. Our EU representative can be contacted for any GDPR-related matters:

EU Representative Email: eu-representative@gamesetengage.com For data subject requests and supervisory authority inquiries regarding EU GDPR

UK Representative

For individuals in the United Kingdom, we have appointed a UK representative in accordance with UK GDPR Article 27:

UK Representative Email: uk-representative@gamesetengage.com For data subject requests and ICO inquiries regarding UK GDPR

Supervisory Authority

You have the right to lodge a complaint with a supervisory authority if you believe we have not complied with GDPR requirements. You can contact:

  • EU residents: Your local data protection authority. A full list is available on the European Data Protection Board website
  • UK residents: The Information Commissioner's Office (ICO) at ico.org.uk

We encourage you to contact our DPO first so we can try to resolve your concern directly.

Records of Processing Activities

In accordance with Article 30, we maintain comprehensive records of our processing activities, including the purposes of processing, categories of data subjects and personal data, categories of recipients, international transfers, retention periods, and technical and organizational security measures. These records are available to supervisory authorities upon request.

Contact Our Data Protection Officer

For any GDPR-related questions, requests, or concerns, please contact our Data Protection Officer:

Data Protection Officer Game Set Engage LLC Email: dpo@gamesetengage.com Subject: GDPR Request — [Type of Request]

Game Set Engage

We help sports clubs know their fans, reward the ones who show up, and prove it to sponsors. Free to start.

Solutions

  • For Clubs
  • For Venues
  • For Fans
  • Fan Engagement
  • Revenue Growth
  • Community Building
  • Data & Analytics

Industries

  • College Athletics
  • Small Programs (D2/D3)
  • Sports Bars
  • Pubs & Restaurants
  • Entertainment
  • Retail Partners
  • Local Councils

Product

  • Pricing
  • Developers
  • naim AI
  • Use Cases
  • System Status

Resources

  • Fan Engagement Platform
  • What Is Fan Engagement?
  • Sports Fundraising Ideas
  • Blog
  • Compare
  • Guides & eBooks
  • The Data-Driven Fan
  • Help Center

Company

  • About Us
  • Careers
  • Contact
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • GDPR
  • Delete your account
© 2026 Game Set Engage Ltd. All rights reserved.

We use cookies to measure site performance and improve your experience. Cookie Policy.