1. Who is responsible and how to contact us
Rhodos Club is operated by IMPACT ALPS, a French société par actions simplifiée (SAS), trading as Les Rhodos. SIREN: 978 140 432. SIRET: 978 140 432 00011. Registered and correspondence address: 18 Rue du Bourg, 74110 Morzine, France. Contact for the club, support and privacy requests: Carl Fithon, carl@morzinelets.com. Public website: https://www.rhodoshotelmorzine.com/. Publication director: Carl Fithon. This notice covers the customer app, its account and membership records, the staff workspace and public club legal/account-deletion pages. Separate hotel booking systems, payment tills and independent websites have their own notices.
2. Information collected and its sources
From you: email, password submitted to the authentication service, account identifier, first and last name, date of birth, phone and the customer group you choose, plus country if you elect to provide it. Email verification and password recovery generate authentication records. Passwords are handled by the authentication service and are not displayed in the customer directory.
Optional information: city and interests/hobbies. A profile photograph is not required for registration or account access, but is required to redeem membership benefits using a QR pass. Do not enter sensitive information or upload identity documents. A normal recognition photograph is used for staff identification, not biometric matching or facial recognition.
From staff: eligibility and group corrections, membership validity or revocation, relevant stay details if recorded, age-verification status and verifier, account status changes, offer redemptions, reversals and reasons. Staff accounts also have assigned roles, organization/venue scope and administrative actions.
From app activity: pass/session identifiers, short-lived QR validation records, venue and visit timestamps when a pass is scanned, flyer or referral batch and claim time, offer used, redemption time, usage counts and corrections. This records participation at a venue; it does not use GPS or continuously track your location. We can retain legacy purchases, item descriptions, quantities, prices and discounts where these were previously entered through the club. The current staff workspace does not provide a purchase or payment workflow.
From privacy choices: the document identifier and version, acceptance/acknowledgement or refusal, time of the event, platform and app version. The history permits us to establish which notice or terms you saw and which optional uses you selected. A new version does not automatically inherit your consent.
Technical and support information: session credentials stored on your device, operational requests and audit records, and information you send when seeking assistance. Hosting and authentication providers may process connection/security logs, including IP addresses, device/browser or request information. These logs are separate from the member profile and are subject to the provider arrangements and retention limitations explained below.
3. Purposes and legal bases
Membership administration: identifying your account, verifying email and eligibility for specific benefits, administering customer groups and benefits, authenticating passes, handling your requests and maintaining the history needed to deliver membership. Processing objectively necessary for the requested membership relies on performance of the membership agreement (GDPR Article 6(1)(b)). We use your phone number to contact you about an account problem, relevant incident or requested service. This does not authorize promotional calls or messages. Country is optional and is not used to determine membership eligibility. If you provide it, we use it to understand customer origins and plan Rhodos services and general marketing on the basis of our legitimate interest in understanding our customer base (Article 6(1)(f)), subject to your right to object. You may omit or clear it without losing membership. This does not authorize individually targeted marketing: using country or return visits to tailor promotions requires current personalization consent, and sending promotional email also requires current email-marketing consent. A country value is not a substitute for a telephone dialing code; include the dialing code in your phone number.
Profile display and QR recognition: city and hobbies are provided voluntarily and are not prerequisites for membership. A photograph is required for QR redemption so authorized staff can recognize the member presenting the pass. It is not required for registration or account access. These profile details are not used for advertising without a separate applicable choice. You may edit optional text fields in Account and request removal of a photograph through the privacy contact; account deletion removes the active photograph. Choosing a photograph does not authorize public advertising use.
Security and operational accountability: preventing stolen/shared passes, duplicate redemptions and abuse, maintaining access controls, investigating errors and keeping limited staff audit evidence. This relies on the legitimate interest in a secure, reliable membership service (Article 6(1)(f)), subject to necessity, proportionality and your rights. An objection will be assessed against the reasons for the processing; direct-marketing objections must be respected.
Legal obligations and claims: information may be processed when required by an identified legal obligation (Article 6(1)(c)), or where necessary for establishing, exercising or defending a claim under an applicable basis. This does not authorize indefinite retention of all club information. The club does not use its membership history as a substitute for separate statutory till/accounting records.
Email marketing: only with separate, current email marketing consent (Article 6(1)(a)). Providing an operational email or accepting terms does not authorize promotional messages. The app records this preference; a marketing campaign sender is not included in the current implementation.
Personalization: only with separate, current personalization consent (Article 6(1)(a)), for the purposes and information identified in the Personalization Notice. The retained compatibility reporting can calculate favorite products from historic recorded purchases for authorized administrators when this consent is current. The app has no third-party advertising or partner audience export feature. Any broader profiling workflow must be implemented and disclosed before use.
Giving hobbies, a photograph or contact details does not authorize unrestricted reuse. Unrelated purposes, SMS/WhatsApp marketing, push marketing, partner marketing, third-party advertising, sale of information and AI training are not authorized by these notices. A new processing purpose requires assessment, updated information and, where applicable, a separate freely given consent before it begins.
4. Required information, choices and consequences
Registration requires email, name, date of birth, phone and customer group; registration has no 18+ threshold. Without required details and email verification, membership cannot be activated. Optional country, city, hobbies, email marketing and personalization can be refused without losing core membership. A photograph can be refused for registration and account access, but QR redemption is unavailable without a membership photograph. You must accept the membership terms and acknowledge receipt of the Privacy Notice; acknowledgement is not a GDPR consent for necessary account processing.
In Account, you can change the email and personalization choices and save them, or withdraw all optional permissions. Withdrawal takes effect for subsequent optional processing when saved and does not make earlier lawful processing unlawful. Declining updated membership terms stops membership use; it does not itself erase an existing account. Data export, deletion and sign-out remain available through onboarding/account controls.
5. Access and recipients
Authorized workers can search the customer directory and view customer names, contact details, profile/group information, memberships, referrals and redemption records within the organization's permitted scope. This is wider than the information displayed for a single scan. Managers can correct permitted profile/group details and manage offers/content. Administrators have additional staff-management, audit and consent-history access; legacy purchase preference reports require current personalization consent. Accounts are not publicly searchable and member photographs are not public files.
Supabase provides the integrated account authentication, database, private photograph storage and server operations. The production database is hosted in Central EU (Frankfurt, eu-central-1), verified in the project dashboard on 29 September 2026. This region statement concerns the primary database, not every provider support, log or subprocessor location. Supabase receives the account, membership, activity and choice information necessary for these functions under its applicable processing arrangements.
Cloudflare hosts the public Rhodos Club support, legal and account-deletion pages at https://app.rhodoshotelmorzine.com/. These pages are publicly accessible over HTTPS. Website hosting processes requests, IP/request information and delivery/security logs; its support and infrastructure can involve subprocessors and international processing. The Supabase database region does not determine all website-processing locations. The separate hotel website is outside this notice.
Microsoft Outlook is used for operator contact and correspondence. Messages may contain your email address, name, the request you send and the minimum account information needed to respond. Account verification and password recovery are initiated through Supabase Auth and its configured email-delivery service; Outlook correspondence should not be taken to mean that Outlook sends those authentication messages. The specific authentication-email transport and business-mailbox retention settings have not yet been verified for this release; the privacy contact can provide updated recipient information.
Google Workspace/Sheets/Contacts, Google Ads customer audiences, Microsoft advertising audiences and additional CRM or spreadsheet exports are outside the scope of this release. No such integration was found in the reviewed app. The current choices do not authorize these transfers. Before adding a service, IMPACT ALPS must identify the product and contracting recipient, fields, purpose, legal basis, access and deletion controls, update the notice, and obtain any required separate consent. This also applies to manual exports; the absence of an automated integration does not make a manual transfer unrestricted.
We may appoint or replace hosting, communication, customer administration and security providers to carry out the purposes stated in this notice. They receive only the information needed for their assigned work, with appropriate contractual restrictions, access controls and transfer safeguards. We keep recipient information current and explain material changes before new processing where required. This flexibility does not permit an unrelated purpose or unrestricted onward use.
Morzine Lets is the domain used for the club contact address. This notice does not identify it as a separate authorized marketing recipient. The club records are controlled by IMPACT ALPS; its authorized staff may use them only for their assigned membership, service and administration duties. Sharing with another legal company for that company’s own promotion is outside the current release. Before such sharing, we will identify the company and purpose, explain its privacy information and provide the applicable separate choice. Common ownership, a shared brand or an email domain does not grant access for another company’s own purposes.
The club may disclose limited information to professional advisers or public authorities when justified by an applicable obligation or legal claim. We do not sell customer information. The reviewed app has no partner marketing export workflow; these choices do not authorize unidentified companies to conduct their own marketing. Separately maintained email, spreadsheet or contact copies must follow the same applicable purpose, access, withdrawal and deletion obligations. A separate hotel booking provider does not receive your club profile merely because you join the club.
6. International transfers and security
Supabase, website hosting and email services may involve support and subprocessors outside the EEA. Google export and advertising services are not included in this release. An EU database region alone does not establish EU-only processing. Any restricted transfer requires an applicable mechanism, such as a relevant adequacy decision or Standard Contractual Clauses with an appropriate transfer assessment and safeguards. Ask the privacy contact for the applicable recipients, countries and a copy or explanation of safeguards. Only the primary Supabase database region stated above has been verified; this notice does not claim that every provider location or transfer arrangement has been verified.
The application uses authenticated requests, role-based database access rules, server-side authorization, short-lived pass tokens and private photograph storage with time-limited access links. Staff receive access through assigned roles. No security measure eliminates all risk. Keep your device and credentials secure and report suspected misuse promptly.
7. Device permissions and local storage
The app stores the session needed to keep you signed in; native credentials use the platform's secure storage integration. Local session storage on the staff website serves authentication. These are necessary service functions, not advertising consent. Signing out ends local authenticated access; it does not delete server records.
When you choose to add a photograph, the app uses the operating system's photo picker/library permission. You can refuse and continue registration and account access without a photograph; a membership photograph is required for QR redemption. The selected image is re-encoded as JPEG before upload and displayed to authorized staff for recognition; the app does not upload your entire library. Staff camera access is used for scanning QR passes. The customer app does not use microphone, address book, background location or advertising identifiers for membership. Device permission is separate from GDPR consent and can be managed through device settings.
No advertising pixels, third-party behavioural analytics SDK, push marketing or cross-app tracking are integrated in the reviewed app. Fonts are packaged in the app. Opening external websites, calling or emailing the venue invokes separate device/provider services. Their own data practices apply. Any future nonessential tracker requires a separate assessment and any necessary opt-in before activation.
8. Retention and deletion: current implementation
Account/profile information, memberships, optional profile fields and ordinary consent history remain in the active system while the account exists. The active photograph is overwritten when replaced. Authenticated account deletion removes the authentication account, profile, photograph, memberships, referral claims, pass/session records and ordinary consent history through the deletion workflow and related database rules.
Operational visits, historic orders/discounts, redemptions and staff audit records can remain after deletion with direct member foreign-key links removed. The workflow clears member-containing order request payloads. Removal of an account link does not prove anonymization: timestamps, staff notes, reversal reasons and audit metadata can still permit identification. Such residual records remain subject to data-protection requirements and a justified retention limit; contact the privacy address to request review/removal of remaining personal information.
IMPACT ALPS adopted the following retention policy on 29 September 2026:
• Unverified or unfinished registrations: 30 days from registration.
• Account/profile information and memberships: while the account is active. Close an account after three years without qualifying user activity, following a 30-day service notice allowing the member to retain it. A staff action alone must not reset customer inactivity.
• Identifiable visits, flyer/referral activity and redeemed offers: up to 24 months from the activity. After that, retain only the minimum record needed to enforce an offer limit that is still valid, until that limit ends, or evidence covered by a specific legal obligation or claim.
• Routine security and administration audit records: six months from the event. Incident evidence may be isolated for a documented investigation or legal hold with restricted access and a review/end date.
• Expired QR and service-session detail: 24 hours after expiry or closure. Keep only any minimum evidence required by a linked redemption under the activity limit above; the expired token must not become reusable.
• Current terms and privacy choices: the life of the account. Superseded choices: up to three years after replacement, or account deletion if earlier, unless a documented legal requirement justifies retaining specific evidence separately.
• Optional preference reports: only the preceding 12 months of source activity and only while current personalization consent permits the use. Withdrawal stops further optional use. No separate stored derived profile is currently maintained; if one is introduced, erase it within 30 days after withdrawal unless earlier deletion applies.
These are the adopted limits, not a claim that automatic expiry is already operating. Scheduled retention cleanup and inactivity notices have not yet been enabled in the reviewed app. The existing account-deletion workflow remains available. Until the expiry workflow is operating, records may remain beyond the policy limits unless removed separately; contact the privacy address to request review and deletion. Adopting this policy does not itself remove existing data or make retention beyond necessity permissible.
The production project is on the Supabase Free plan, whose dashboard states that project backups are not included. This does not establish that provider-internal or externally created copies do not exist. Provider log retention and any external recovery copies remain unverified; deleting active data is not a promise of instantaneous removal from every provider system. Backup windows depend on the project plan and recovery configuration. Outlook deletion and any retention/hold policies are separate from deletion in the app. A contact exported to another database or mailbox is not erased merely by deleting the Supabase account. The operator must apply purpose-specific expiry to these copies and preserve only records covered by a justified, narrowly scoped legal hold.
Uninstalling the app, declining membership or withdrawing marketing consent does not delete operational account records. Optional withdrawal stops the permitted optional use, rather than erasing the minimum records still needed for membership and evidence of the choice. Before any campaigns are enabled, unsubscribe and suppression records, audience deletion and vendor retention must be defined and implemented. A legal hold must be limited to records necessary for the identified obligation/dispute, with restricted use and a review/end point.
9. Account deletion, access and other rights
In the app, open Account → Download my personal data for the available account export, or Account → Delete my account and verify your password to delete. The download includes the available profile, membership/stay, legal-choice and recorded activity information and active photograph. The automated export does not currently include every operational category, such as referral claims or provider logs; request additional information through the privacy contact. The public account-deletion request page is available at https://app.rhodoshotelmorzine.com/delete-account and can be used without signing in or reinstalling the app. Do not rely on the separate hotel website's privacy page as the Rhodos Club app notice or deletion service. Use the in-app account controls or contact carl@morzinelets.com if you cannot access them.
If you cannot sign in, contact the privacy address for assistance. We may ask for proportionate information to verify ownership; do not send identity documents unless a justified, secure process is provided. Active staff assignments must be removed by an administrator before self-service deletion. A deletion error is not a successful deletion; retry or contact support. Deleting your account ends access to its membership and pass.
Subject to applicable conditions, you can request access, correction, erasure, restriction, portability and object to processing based on legitimate interests. You can withdraw consent at any time and object to direct marketing, including related profiling. Contact the privacy address and specify the request. The statutory response period is normally one month; where a permitted extension is necessary, we must explain it within that first month. You need not accept marketing to exercise rights.
You may complain to the CNIL at https://www.cnil.fr/fr/plaintes or another competent supervisory authority. You can contact the authority directly without first contacting us. If UK GDPR applies to the confirmed operator/processing, the ICO may also be relevant: https://ico.org.uk/make-a-complaint/.
10. Automated checks, minors and changes
Membership registration has no 18+ threshold. Any age requirements for alcohol-related service or particular benefits are checked separately by staff. A date of birth or app pass is not official proof of age.
The app checks objective group, time, validity and usage rules to determine available offers. It does not implement decisions intended to have legal or similarly significant effects solely through automated profiling. Staff can review an incorrect eligibility outcome. Personalization does not determine statutory rights, creditworthiness, employment or access to essential services.
This notice is versioned. Updated required notices are presented for acknowledgement before continued membership access; optional permissions require the applicable current notice and a separate choice. Published text and your recorded choice identify the version relied upon. A changed notice does not authorize undisclosed past processing.