Skip to content
Paddle Plus

Privacy policy

How VTS Engineering OÜ collects, uses, stores and protects your personal data. This describes how Paddle Plus actually works rather than general phrases: every point can be checked against what the shop really does.

Last updated: September 29, 2026

1. Who is responsible for your data

The controller is VTS Engineering OÜ, registry code 14953637, VAT number EE102288445, address: Karikakra tee 52, 74117 Maardu, Harju maakond, Estonia.

Email for data protection questions: vts.juhendaja@gmail.com. Phone: +372 5800 7144. Website: Paddle Plus.

No Data Protection Officer has been appointed: the law requires one for large-scale systematic monitoring of people or large-scale processing of special categories of data, and we do neither. All requests are handled at the address above.

We work under Regulation (EU) 2016/679 (GDPR) and the Estonian Personal Data Protection Act (isikuandmete kaitse seadus).

2. What this policy covers

The Paddle Plus website and everything you can do on it: the player account, shop orders and their payment, tournament registration and participation, Gold club membership, friends and tournament invitations, notifications, racket rental, coach requests, product reviews and the contact forms.

It does not cover sites you reach through links from us — above all the payment provider's page, where its own policy applies.

3. What data we process

  • Account: first and last name, email, phone, gender, language and site theme, photo or chosen avatar icon, a few words about yourself, the playing level you assessed at sign-up, date of birth (optional), referral code, the date the account was created. The password is stored only as a hash — neither we nor anyone who obtains the database can read it.
  • Orders: first and last name, email, phone, delivery address or chosen parcel locker, the contents and total of the order, the order comment, language, order and refund history, invoices and credit notes.
  • Payment: the amount, the order number, the payment status and the payment method. The card number, expiry date and CVV are entered on the payment provider's side or in your online bank — they never reach our shop and are not in our database.
  • Tournaments and the club: entries, the method and state of the entry fee, the mark that you accepted the rules, attendance and no-shows, red cards, match results, ranking position and level points, Gold membership and its period, store credit and gift codes.
  • Friends and invitations: friend requests and their state, your friend list, tournament invitations and the answers to them, blocks, and the times of those events. On-site notifications — what about and from whom.
  • Rental and training: the rental request and agreement (name, email, phone, period, deposit, racket condition at handover and return, invoices), the coach request (name, email, phone, preferred date and time, place, number of players, level, type of training, message).
  • Reviews: the author's name, the rating, the title and the text of the review.
  • Contact forms: name, company (in a partnership enquiry), email, phone, subject and message.
  • Cookie consent: a random identifier, your choice, the version and the language. No IP address is recorded with it.
  • Sign-in and security: the sign-in session, the IP address and browser type of signed-in users, email confirmation codes, request-rate counters.
  • Analytics, only with your consent: anonymised events on our own server. Details are in the cookie policy.

What we do not collect: personal identification codes, copies of documents, bank card data, health information or other special categories of data.

4. Purposes and legal bases

  • Account, orders, delivery and returns, tournament registration and participation, Gold membership, rental and coach requests — performance of the contract with you or steps taken at your request before entering into it: Art. 6(1)(b) GDPR.
  • Invoices, credit notes and bookkeeping, the record that you accepted the terms of sale — a legal obligation: Art. 6(1)(c) GDPR.
  • Answering enquiries, resolving disputes, fraud prevention, protecting the site against password guessing and abuse — our legitimate interest: Art. 6(1)(f) GDPR. The interest is that the shop works and is not used for deception; the processing is limited to the minimum (the address you wrote from, a technical note about the request) and does not override your rights, because it builds no profile and affects neither prices nor decisions about you.
  • Tournament participant lists, the tournament table, the ranking and red cards — legitimate interest: a tournament cannot be run without an honest record of results and order. Other players see your name, photo or icon, gender, the words about yourself and your sporting results; phone, email, date of birth and address are shown to no participant.
  • Friends, invitations and notifications — performance of the contract: this is part of the service you use by your own choice and can turn off (friend requests are disabled by a single setting in the profile).
  • Product reviews — your consent: Art. 6(1)(a) GDPR.
  • News and offers by email — your consent: Art. 6(1)(a) GDPR.
  • The birthday gift — your consent: Art. 6(1)(a) GDPR. You may leave the date out; then the gift simply does not come.
  • Analytics and the memory of viewed products — your consent: Art. 6(1)(a) GDPR, withdrawn in the cookie settings.
  • Necessary cookies and session protection — necessary for the service you requested; the law requires no consent for them.

5. Who sees what about you on the site

  • A guest or any visitor: nothing from your account. Participant lists and the ranking table are open only to signed-in users.
  • Tournament participants: your name, photo or icon, gender and sporting results.
  • Gold club members: your player profile — name, photo or icon, gender, the words about yourself, ranking position, number of tournaments and the date you joined. No contacts are there.
  • Friends: the same as club members, plus the ability to invite you to a tournament. The site neither shows nor passes on a friend's email or phone.
  • The coach you asked for a session: name, email, phone and the content of the request — otherwise they cannot reach you.
  • Shop staff in the admin panel: order, request and participant data — as their work requires.

6. How long we keep data

The periods in the table are the same numbers the server uses to delete and anonymise records by itself; they are not copied into the text separately.

After an account is deleted, only what the law requires us to keep remains (invoices and accounting documents), plus what other people's results depend on: played matches stay in the tournament table without your name.

  • Account data

    Signing in, your profile and addressing you by name

    Kept for: while the account exists

  • Unconfirmed registration

    Waiting for email confirmation; after that the account is deleted entirely

    Kept for: 7 days

  • Orders

    Sales, delivery and returns; after the period the personal fields are anonymised

    Kept for: 7 years

  • Invoices and credit notes

    Obligation under the Estonian Accounting Act

    Kept for: 7 years

  • Tournament entries and results

    Running tournaments, the table and the ranking

    Kept for: while the account exists

  • Red cards

    Order at tournaments; expired ones no longer count

    Kept for: 2–3 months depending on the offence

  • Friends, requests and invitations

    Club social features

    Kept for: while the account exists

  • Rental agreements and their invoices

    Performing the contract and accounting

    Kept for: 7 years

  • Messages from site forms

    Answering you and sorting out disputes

    Kept for: 24 months

  • Consent to news by email

    Proof of consent; stored in the account with the date it changed

    Kept for: while the account exists

  • Cookie consent records

    Proof of consent (GDPR Art. 7(1))

    Kept for: 36 months

  • Analytics events

    Shop statistics; deleted at once when consent is withdrawn

    Kept for: 14 months

  • Sign-in sessions

    So you do not sign in again on every page

    Kept for: 30 days

  • Email confirmation codes

    Confirming the address at sign-up and sign-in

    Kept for: 10 minutes

  • Request-rate counters

    Protection against password and code guessing

    Kept for: 24 hours

7. Who receives your data

Data goes only to those without whom the service cannot be provided, and only to the extent needed. Each of them processes the data on our instructions, under a data processing agreement, and may not use it for their own purposes.

  • Montonio (payments): the amount, the order number, your email and name — to take the payment and return the money. Card data is handled by the provider and never reaches us.
  • Resend (sending email): your email address and the content of the letter about an order, account, tournament or refund.
  • Website hosting and the database: this is where the shop runs and its records are stored.
  • File storage: the photo you set as your avatar.
  • The carrier you chose (Omniva, Smartpost, DPD): name, phone and the delivery address or parcel locker — when we hand over the parcel.
  • The coach you asked for a session: name, email, phone and the text of the request.
  • The technical error monitoring service, if connected: technical details of the error without the request body, cookies or personal data.
  • Accountant and auditor — within mandatory bookkeeping; public authorities and courts — only where the law requires it.

We do not sell personal data and do not pass it to advertising networks.

8. Transfers outside the European Economic Area

Payments (Montonio) are processed in Estonia, that is, inside the EEA.

Some technical providers are companies established in the United States: the email sending service and the platform the site runs on. Transfers to such companies take place only under the safeguards of Chapter V GDPR: the EU standard contractual clauses and the European Commission's adequacy decision (the EU–US Data Privacy Framework) where the provider participates in it.

If you want to know which safeguards apply to a specific provider, write to vts.juhendaja@gmail.com — we will answer and show the documents.

9. Your rights

Under the GDPR you have the right to:

  • know what data about you is processed and why (Art. 15);
  • receive a copy of your data (Art. 15) and an export in a machine-readable form to move to another provider (Art. 20);
  • have inaccurate data corrected (Art. 16);
  • have data erased (Art. 17), except what we must keep by law;
  • restrict processing (Art. 18);
  • object to processing based on legitimate interest (Art. 21);
  • withdraw consent at any time (Art. 7(3)) — this does not make unlawful what was processed before the withdrawal;
  • not be subject to a decision based solely on automated processing (Art. 22);
  • lodge a complaint with a supervisory authority (Art. 77).

Much of this needs no request to us: name, phone and addresses are in «Profile» and «Addresses»; consent to news is a single checkbox there; the cookie choice is in the cookie settings; an export of all your data and account deletion are in «My account → Profile».

The date of birth can only be changed through us: the club gift is tied to it, and free editing would turn a yearly gift into a monthly one. Write to us and we will correct it.

10. How to contact us and what happens next

Write to vts.juhendaja@gmail.com from the address the account is registered to and say which right you want to use. If the letter does not make clear who you are, we will ask you to confirm your identity — otherwise someone else's data would go to whoever asked first.

We answer within one month. If the request is complex or there are several, the period may be extended by two more months — we will tell you about the extension and its reason within that first month.

If we refuse, we will explain why and remind you of the right to complain.

Supervisory authority: the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, info@aki.ee, +372 627 4135, aki.ee. You may complain straight away, though writing to us first is usually faster.

11. Cookies and analytics

Some cookies are necessary: without them the sign-in and the cart do not hold. Analytics and the memory of viewed products are switched on only with your consent, and there are no advertising or third-party tracking technologies on the site at all.

The full list with purposes and periods is in the cookie policy. Your choice is changed and withdrawn there as well.

12. Email and direct marketing

Service email goes without separate consent: email confirmation, order confirmation and dispatch, invoice and credit note, tournament reminder, its cancellation and the refund of the entry fee, the end of club membership. That is part of the service, not advertising.

News and offers go only with consent. The checkbox at sign-up is not pre-ticked, it is cleared in the profile in one click, and a refusal stops the mailing at once. No marketing mailing is running at the moment: the consent is collected for the future, and the first such letter will not arrive before the mailing exists.

The consent is stored in the account together with the date it changed, so we can show when and what you chose.

13. Automated decisions

We take no decisions about you based solely on automated processing that produce legal effects within the meaning of Art. 22 GDPR. There is no profiling for advertising.

Level points and the ranking position are calculated automatically — from tournament results entered by the organiser.

One rule is applied mechanically: five active red cards temporarily close tournament registration. The cards themselves are given by a person — the organiser — for a no-show without warning or for unsporting behaviour. A card lives two or three months depending on the offence, and the block lifts by itself as soon as the oldest one expires. If you disagree with a card, write to us and a person will review it.

14. Deleting your account

You delete the account yourself: «My account → Profile», confirmed with your password. Next to it is an export of all your data in a single file.

What is deleted: profile, addresses, wishlist, the words about yourself, photo, friends and requests, invitations, notifications, reviews, tournament entries, store credit and sessions.

What remains: invoices, credit notes and order data — 7 years, as the Accounting Act requires (after that the personal fields are anonymised); played matches stay in the tournament table without your name, because otherwise the other participants' results would fall apart.

15. How we protect data

  • The site works over HTTPS only; the sign-in cookie is out of reach of scripts (HttpOnly) and on the live site travels only over a secure connection.
  • Passwords are stored only as a hash produced by a deliberately slow function; secrets are compared in a way that resists timing attacks.
  • Email is confirmed by a code; the code lives 10 minutes, five attempts are allowed, and unconfirmed accounts are deleted after a week.
  • The rate of sign-ins, sign-ups and code requests is limited — against guessing.
  • The database is reachable only from the server side: the browser never talks to it, and every query goes through a permission check on the server.
  • The admin panel is open only to staff with the administrator role; the account area only to the account owner with a confirmed email.
  • Payment confirmations are accepted only with the provider's signature and are checked against the amount and order number; a repeated delivery of the same event changes nothing twice.
  • Error logs contain no cookies, headers, request bodies or address parameters; secret parts of links (the order token, the password reset token) are stripped.

No system is one hundred per cent secure, and we will not promise that. We do what is listed above and fix what we find.

16. If there is a data breach

If personal data does leak and this creates a risk to your rights, we will notify the Data Protection Inspectorate without undue delay and, where feasible, not later than 72 hours after becoming aware of it (Art. 33 GDPR).

If the risk to you is high, we will write to you as well — plainly, without general phrases: what happened, which data is affected and what you should do (Art. 34 GDPR).

17. Children and young people

The shop and the club are meant for adults. Estonian law allows a minor to give consent for information society services from the age of 13; below that, only with a parent's or guardian's consent.

We do not verify age at sign-up and ask for no documents. If it turns out that an account was created by a child under 13 without a parent's consent, we will delete the account and the data connected with it — write to vts.juhendaja@gmail.com.

Tournament participants under 18 are admitted to play with a parent's or guardian's consent, and at children's tournaments an accompanying adult is required; that is a tournament rule and concerns participation rather than data processing.

18. Changes to this policy

The version in force is always on this page, and the date of the last update is shown at the top.

If a change affects something you gave consent for, we will ask again rather than present you with a fact. We will announce material changes that concern signed-in users by email or by a visible notice on the site.