Back to home

Privacy Policy

Last updated: March 2026

Overview

evest.io UG (haftungsbeschränkt), operating as OnSand ("OnSand", "we", "us"), takes the protection of your personal data seriously. This privacy policy explains what data we collect when you use the OnSand app and website, how we use it, and what rights you have regarding your data.

This policy applies to all OnSand services, including our mobile application and website (onsand.app).

Data Controller

The data controller responsible for processing your personal data is:

evest.io UG (haftungsbeschränkt), Karolinenstraße 21b, 13507 Berlin, Germany

Email: [email protected]

Data Protection Officer

You can reach our Data Protection Officer at:

Email: [email protected]

Data We Collect

Account Data: When you create an account, we collect your name, email address, and optionally your profile photo and skill level.

Game Data: We collect data about games you create, join, or score, including location, time, participants, and match results.

Usage Data: We collect information about how you interact with our app, including features used, pages visited, and actions taken.

Device Data: We collect device type, operating system, app version, and a unique device identifier for crash reporting and analytics.

Location Data: With your permission, we collect your location to show nearby games and courts. You can disable this at any time in your device settings.

How We Use Your Data

We use your data to: provide and improve our services, show you relevant games and players near you, calculate skill ratings and maintain leaderboards, send you notifications about games and updates (with your consent), ensure the security and integrity of our platform, and comply with legal obligations.

Legal Basis for Processing (GDPR Art. 6)

Contract Performance (Art. 6(1)(b)): Processing necessary to provide our services when you create an account and use the app.

Legitimate Interest (Art. 6(1)(f)): Processing for analytics, security, and service improvement where our interests do not override your rights.

Consent (Art. 6(1)(a)): Processing based on your explicit consent, such as location data and push notifications. You may withdraw consent at any time.

Legal Obligation (Art. 6(1)(c)): Processing necessary to comply with applicable laws.

Cookies and Tracking

Our website uses technically necessary cookies to ensure proper functionality. These do not require your consent under the EU ePrivacy Directive.

Non-essential cookies (such as analytics or marketing cookies) are only placed with your explicit prior consent, in accordance with the EU ePrivacy Directive (2002/58/EC) and the GDPR. You can manage or withdraw your consent at any time via the cookie settings on our website or through your browser settings.

For detailed information about the specific cookies we use, their purposes, and retention periods, please refer to the cookie banner displayed on your first visit.

Third-Party Services

We use third-party services that may process your data, including cloud hosting providers for data storage, analytics services for usage statistics, push notification services, and payment processors for club subscriptions.

All third-party processors are bound by data processing agreements in accordance with GDPR Art. 28.

Data Retention

We retain your personal data only as long as necessary for the purposes described in this policy or as required by law. When you delete your account, your personal data will be removed within 30 days. Anonymized game statistics may be retained for analytical purposes.

Your Rights

Under the GDPR, you have the following rights: the right to access your personal data (Art. 15), the right to rectification of inaccurate data (Art. 16), the right to erasure of your data (Art. 17), the right to restrict processing (Art. 18), the right to data portability (Art. 20), and the right to object to processing (Art. 21).

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or place of the alleged infringement.

Automated Decision-Making and Profiling

OnSand uses automated processing to calculate skill tiers and match you with players of similar ability. This profiling is based on your match results and game history.

This processing does not produce legal effects or similarly significantly affect you within the meaning of GDPR Art. 22. It is used solely to enhance your game experience. You have the right to object to this profiling at any time by contacting us at [email protected].

International Data Transfers

Your data may be processed in countries outside the European Economic Area (EEA). In such cases, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of the breach, in accordance with GDPR Art. 33.

If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, in accordance with GDPR Art. 34.

Children's Privacy

OnSand is not intended for children under 16 years of age. We do not knowingly collect personal data from children under 16. If we become aware that we have collected data from a child under 16, we will delete it promptly.

Changes to This Policy

We may update this privacy policy from time to time. We will notify you of material changes through the app or by email. The current version is always available on our website.

Contact

For questions about this privacy policy or your personal data, contact us at:

evest.io UG (haftungsbeschränkt), Karolinenstraße 21b, 13507 Berlin, Germany

Email: [email protected]

© 2026 OnSand. All rights reserved.

We use analytics to improve the app. Data is stored in the EU and never shared with third parties.