MEMBRS
ITEN
← BACK
Privacy PolicyLAST UPDATED · 31 July 2026

Notice provided under Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018 (the "Italian Privacy Code").

This notice covers the membrs. service — the membrs.world website, the app.membrs.world platform and the MEMBRS mobile app.

The Italian text is the authoritative version. This English version is a courtesy translation.

1. Data controller

The data controller is:

Saba Events S.R.L. Via di Salicchi, 711/X — 55100 Lucca (LU), Italy VAT and tax code 04726940234 (VAT ID: IT04726940234) Certified email (PEC): sabaevents@pec.it — SDI recipient code: 9SUB64Q Email for anything in this notice and for exercising your rights: hello@membrs.world

Saba Events S.R.L. is the provider of the membrs. platform, the seller of the membership subscriptions (merchant of record) and the data controller for data processed through the platform.

Data Protection Officer (DPO): none appointed. Under Article 37 GDPR, appointing a DPO is mandatory only where processing is carried out by a public authority, where the controller's core activities consist of processing operations requiring regular and systematic monitoring of data subjects on a large scale, or where the core activities consist of large-scale processing of special categories of data or data relating to criminal convictions. Saba Events S.R.L. falls into none of these cases: it is not a public body, it does not process special categories of data (§3), and its core activity is providing a subscription service, not monitoring data subjects. For this reason no DPO has been appointed. The contact point for privacy matters remains hello@membrs.world (alternatively, PEC sabaevents@pec.it).

2. Who this notice applies to

This notice applies to:

  • Members (consumers) — anyone who subscribes to a club or format, holds a digital member card and books events;
  • Club staff and business users — owners, managers, door staff and PR/promoters using the venue panel, and the club contacts we deal with commercially;
  • Visitors to membrs.world — anyone browsing the public site without an account;
  • MEMBRS mobile app users (iOS and Android), both members and staff.

ops.membrs.world is an internal backoffice, accessible only to authorised Saba Events personnel. It is not a user-facing service: it is mentioned here because it is the tool through which our staff access data for support, administration and compliance.

If you are a member, the club you subscribe to also processes some of your data for its own purposes: see §6.

3. What data we process

3.1 Data you give us

  • Identity and contact: name, email address, phone number (optional), preferred language, profile photo (optional).
  • Login credentials: your password is handled by our authentication provider (Supabase Auth) and is not visible to us in clear text. You may alternatively sign in with Google or Apple (§3.4).
  • Age declaration: the date and time on which you declare you are at least 18 at sign-up. We do not collect your date of birth.
  • Messages and attachments: the content of the messages you exchange with a club in chat and the images you attach.
  • Club and staff data (business users): legal name, VAT number, billing email, address, phone, venue images, IBAN and account holder for payouts, staff accounts and roles, email addresses of the people you invite to your team.
  • Commercial contacts (leads): venue name, city, country, contact person, email, phone, capacity, notes and deal stage, when a club registers or gets in touch with us.

3.2 Data generated by your use of the platform

  • Membership and billing: the club and plan you hold, subscription status, start, renewal and end dates, payment history, Stripe identifiers (customer and subscription), refunds.
  • Member card and digital passes: the QR token and short entry code tied to your membership, and the Apple Wallet / Google Wallet passes that carry them.
  • Entry data (check-ins): the date and time your card is scanned at the door, with the context of the operation (event, outcome, device and staff member who performed the scan, including duplicate scans, manual entries and undone check-ins).
  • Bookings: events booked, waitlist position, booking status, cancellations.
  • PR attribution: which promoter brought your sign-up, tracked via the membrs_pr cookie (30 days) and attached to the membership at purchase.
  • Preferences and consents: consent to share email and phone with the club, opt-out from club broadcasts, light/dark theme, interface language, first-access tutorial state.
  • Push notification tokens: your browser's Web Push subscription endpoint and keys and, in the mobile app, the Expo push token tied to your device.
  • Personal referral code.
  • Data applied by the club: free-text labels (tags) the club attaches to you and any suspension (90 days) the club decides. See §6.
  • Lifetime spend at that club, computed from Stripe invoices and shown to the club.

3.3 Data collected automatically

  • Security logs (login_attempts): for every login attempt we record the email address typed, the IP address and the outcome, in order to limit unauthorised access attempts.
  • Audit log (audit_log): for significant administrative and technical actions (check-ins, team management, suspensions, refunds, payouts, exports, deletions) we record who acted, what they did, on what object, with the IP address and user agent and a timestamp.
  • Webhook log (webhook_log): we keep the full messages sent to us by Stripe and Resend, which may contain customer and subscription identifiers, amounts, recipients' email addresses and email delivery, open and click events for the emails we send you.
  • Infrastructure technical logs generated by our hosting and database providers.
  • Cookies and similar technologies: see §13 and the Cookie Policy.

In the mobile app, additionally: the camera is used only to scan QR codes at the door (no image is stored or transmitted, only the decoded code); the photo library is used only for the attachments you choose to send in chat; calendar access is used to save a booking on your device and stays local; biometric unlock (Face ID / fingerprint) is handled by the operating system — we neither receive nor store any biometric data. The app uses no analytics SDK, no crash reporting tool, and collects no advertising identifiers and no location.

Door staff devices keep a local copy of the event guest list (member name and entry code) so that check-in works without a connection.

3.4 Data we receive from third parties

  • Stripe: payment outcome, subscription status, invoices issued, refunds, customer identifiers. We receive the outcome, not the card details.
  • Google and Apple sign-in providers: if you sign in with Google or Apple, the provider gives us your email address and, if you share it, your name.
  • Resend (transactional email): delivery, bounce, open and click events for the emails we send you.
  • VIES (European Commission): the outcome of a club's VAT number validation.
  • OpenStreetMap / Nominatim: geographic coordinates derived from a club's address.

3.5 Two important clarifications

We do not process special categories of data under Article 9 GDPR: no data concerning health, sex life, political opinions, religious beliefs, trade union membership or ethnic origin, and no biometric or criminal-offence data. We do not ask for and do not store your date of birth. Note: chat messages and the tags a club attaches to you are free-text fields — if you voluntarily put information of this kind there, it ends up in our systems; please do not.

Payment card data never reaches our servers. Payment takes place on pages hosted by Stripe, to which you are redirected: card number, expiry and security code are collected and processed directly by Stripe. We only receive the outcome of the transaction and the identifiers needed to manage your subscription.

4. Purposes, legal bases and retention periods

#PurposeMain dataLegal basisRetention period
1Creating and managing your account: sign-up, login, profile, preferencesName, email, phone, language, profile photo, referral codeArt. 6(1)(b) GDPR — performance of a contract to which the data subject is partyFor the life of the account. If you request deletion: 30-day grace period, then anonymisation of the profile (§8)
2Verifying the 18+ requirementDate and time of your age declarationArt. 6(1)(f) — legitimate interest in keeping an adults-only nightlife service restricted to adults and being able to evidence itAs row 1; the timestamp alone survives anonymisation
3Providing the membership and handling payments, renewals, cancellations and refundsClub and plan, subscription status, billing history, Stripe identifiersArt. 6(1)(b) — performance of the contractFor the life of the subscription; payment documents follow row 4
4Accounting and tax obligations: invoices and receipts to members, refunds, payouts to clubs, mandatory booksBilling data, amounts, transaction identifiers, club tax data and IBANArt. 6(1)(c) — compliance with legal obligations (Art. 2220 Italian Civil Code; VAT and e-invoicing rules)10 years from the date of the last entry (Art. 2220 Italian Civil Code). After account deletion these records remain, linked to an anonymised profile (§8)
5Digital member card, Apple/Google Wallet passes and door access controlQR token and short code, name, club, plan; check-in timestamp and contextArt. 6(1)(b) — performance of the contractCredentials: for the life of the membership. Check-in history: for the life of the account and thereafter, linked to the anonymised profile, together with the membership records (row 4)
6Event bookings, waitlist management, remindersBookings, waitlist position, status, email and push tokens for remindersArt. 6(1)(b) — performance of the contractAs row 5
7Service communications by email and push notifications about your account, membership and bookingsEmail, name, Web Push / Expo tokensArt. 6(1)(b) — performance of the contractFor the life of the account. Push tokens are removed on deletion or when you revoke permission; delivery logs follow row 13
8Promotional messages sent by a club to its own members about that club's services (email and push broadcasts)Email, name, plan, segment and tags, global opt-outArt. 6(1)(f) — legitimate interest in informing one's own customers about services similar to those already subscribed, within the limits of Art. 130(4) of the Italian Privacy Code, with a free opt-out in every message. Sending beyond that perimeter requires consent (Art. 6(1)(a))Until you object. The send record (subject, body, segment, counts): 24 months
9Member-to-club messagingMessage content, attachments, read state, thread blockingArt. 6(1)(b) for the service function; Art. 6(1)(f) for evidential retention — legitimate interest in handling disputes and abuse reports24 months from the thread's last message. Messages are not automatically deleted when an account is closed: see §8
10Attributing sign-ups to PRs/promoters and measuring their contributionmembrs_pr cookie, promoter code, link to the membershipArt. 6(1)(f) — legitimate interest in correctly crediting promoters' work and settling accounts with clubsCookie: 30 days. The attribution recorded on the membership follows row 4
11Account security: rate limiting of login attempts, temporary lockout, suspicious-login alertsEmail typed, IP address, outcome and timestamp of the attemptArt. 6(1)(f) — legitimate interest in protecting accounts and infrastructure against unauthorised access and automated attacks12 months. The automatic deletion routine for these records is being rolled out: see §8
12Audit log of administrative and technical actionsActing user, action, object, IP address, user agent, timestampArt. 6(1)(f) — legitimate interest in being able to reconstruct who did what, for security, internal accountability and dispute handling24 months. The automatic deletion routine is being rolled out: see §8
13Log of messages received from providers (Stripe, Resend), to avoid duplicate processing, reconcile payments and diagnose errorsFull payloads, including customer and subscription identifiers, amounts, email addresses and delivery/open/click eventsArt. 6(1)(f) — legitimate interest in accounting accuracy and in service continuity and diagnostics24 months. The automatic deletion routine is being rolled out: see §8
14Statistical analysis of site and platform usage (Google Analytics 4)GA4 identifiers, event, URL, browser and device data, IP address in anonymised formArt. 6(1)(a) — consent, given through the cookie banner and withdrawable at any timeGoogle retains user and event data for the period set on the GA4 property and in any case no longer than 14 months, which is the maximum available for a standard GA4 property. Aggregated reports remain available without a time limit
15Handling complaints, disputes and chargebacks, and establishing, exercising or defending legal claimsWhatever data the specific case requiresArt. 6(1)(f) — legitimate interest in defending our rightsUntil the dispute is resolved and for the applicable limitation periods thereafter
16Managing the relationship with clubs: staff accounts and roles, invites, venue panel, calculating and settling payoutsClub and contact data, roles, invitees' emails, IBAN and account holderArt. 6(1)(b) — performance of the B2B contract; Art. 6(1)(c) for the related tax obligationsFor the life of the relationship; accounting data 10 years (row 4)
17Validating a club's VAT number (VIES) and geocoding the venue address (Nominatim)Club VAT number, address, city and countryArt. 6(1)(c) for the tax validation; Art. 6(1)(f) for geocoding — legitimate interest in showing the venue correctly to membersOutcome retained with the club record, for the life of the relationship
18B2B commercial contacts: lead management, offering the service to industry operatorsVenue name, city, country, contact person, email, phone, capacity, notes and deal stageArt. 6(1)(b) — steps taken at the data subject's request prior to entering a contract; Art. 6(1)(f) — legitimate interest in promoting the service to professional operatorsUnconverted leads: 24 months from the last contact. If the lead becomes a customer, row 16 applies
19Responding to data subject requests (Arts. 15-22 GDPR)Identification data and the content of the request, copy of the exported dataArt. 6(1)(c) — compliance with a legal obligationExports generated on request: signed link valid for 7 days. Record of the request: 24 months from closure

The periods stated in the table are our retention policy. For the security and diagnostic logs (login_attempts, audit_log, webhook_log) and for chat messages, the automatic deletion routines are being rolled out: until they are in place, deletion is carried out manually, and in the meantime that data remains subject to the same access controls described in §9. You can request its deletion under §10.

5. Processors and other recipients

We use the providers listed below, which process data on our behalf as processors under Article 28 GDPR (except where stated otherwise), under appropriate agreements.

ProviderWhat it does for usWhere / notes
StripePayments, subscriptions, invoicing, VAT determination (Stripe Tax)Saba Events S.R.L. is the merchant of record. Card data never passes through our servers. Transfers outside the EEA: see §7
SupabaseDatabase and authenticationHosted on AWS eu-west-1 (Ireland)
Google Cloud / Firebase App HostingHosting and compute for the platform (project sabaevents-membrs)Primary region us-east4 — Northern Virginia, United States: the application's hosting and compute run in the United States. Transfers outside the EEA: see §7
ResendSending transactional email and club broadcastsDelivery, open and click events flow into the webhook log (§3.3). Transfers outside the EEA: see §7
Google Analytics 4Usage statistics — only with consentExact consent behaviour described in §13. Transfers outside the EEA: see §7
Google WalletDigital member card on AndroidReceives the member's name and the card credential
Apple WalletDigital member card (.pkpass)The pass is generated and signed by our servers and delivered to your device
Expo (exp.host) and Apple APNs / Google FCM / browser push servicesPush notification deliveryNotification content and the device token transit these providers' infrastructure. Transfers outside the EEA: see §7
OpenStreetMap / NominatimGeocoding of club addressesVenue data, not member data
VIES (European Commission)Validation of clubs' VAT numbersVenue data, not member data. It is a public service we query, not a processor
VercelWeb Analytics on ops.membrs.world only (internal backoffice)Not active on membrs.world or app.membrs.world. Vercel is not the platform's hosting provider

Beyond these, data may be disclosed to: the clubs you subscribe to, within the limits described in §6; our professional advisers (accountant, lawyers) and, where necessary, public authorities, when disclosure is required by law or necessary to establish, exercise or defend a legal claim.

We do not sell your data and we do not pass it to third parties for their own marketing.

Our authorised personnel access data through the internal backoffice ops.membrs.world and the platform's administration tools, with named accounts and access recorded in the audit log (§3.3).

6. What the club sees

The club (or format) you subscribe to supplies the perks your plan promises, and needs some of your data to recognise you and honour them.

The club always sees: your name, the fact that you are one of its members, the plan you hold and its status, the date you first joined, your check-in activity (including your last entry and your history), your lifetime spend at that club, the tags the club itself has applied to you and any suspension. In chat it sees your name, your profile photo and the messages you send it. At the door, door staff see your name, your plan and the perks to honour.

The club sees your email address and phone number only if you switch those on yourself in your profile settings ("share email with the club", "share phone with the club"). They are off by default and you can change them at any time, on both web and app.

Two clarifications, for the sake of accuracy:

  • The club can send you email and push messages without seeing your address: sends go out from our systems, the club defines the recipients as a segment (plan, tag, join date) and receives only a count, never a list of addresses.
  • The venue panel's search function also matches the text you type against the email address: a club administrator who types an exact email address can therefore confirm whether that person is a member of their club, even without your opt-in. We are fixing this behaviour.

Controller relationship. Saba Events S.R.L. is the controller for the platform: it manages accounts, collects subscription payments, issues tax documents, sends service communications and keeps the technical logs. The club is an autonomous controller for what it does with your data for its own purposes: admission and access control in its own venue, its own customer-relationship activity and CRM, decisions on tags and suspensions, and the content of the messages it chooses to send you. The scope of what the club may do through the platform is governed by a data processing addendum (DPA) that forms an integral part of the club terms: it applies to every club by virtue of its acceptance of the club terms, with no separate act required. Collection and tracking of a signed copy of the addendum is being rolled out. To exercise your rights against the club you can contact the club directly; if you write to us, we will point you to the correct controller.

7. Transfers outside the European Economic Area

The database stays in the European Economic Area. Supabase hosts the database and authentication on AWS eu-west-1 (Ireland): that is where your data sits at rest.

Application hosting and processing, however, take place in the United States. The platform runs on Google Cloud / Firebase App Hosting in the primary region us-east4 (Northern Virginia, United States). Every request to the site and to the app is processed on US servers, which read from and write to the European database: your data is therefore also processed in the United States, in transit and in memory during processing. We do not claim that your data always stays in the EEA, because that would not be true.

The following providers are also non-EEA companies, or may process data outside the EEA: Stripe, Google (Google Cloud / Firebase App Hosting, Google Analytics 4, Google Wallet), Apple (Apple Wallet, APNs), Expo and Resend.

For those transfers we rely on the mechanisms provided by Chapter V GDPR, as follows:

  • Google (Google Cloud / Firebase App Hosting, Google Analytics 4, Google Wallet) and Stripe: certification under the EU-US Data Privacy Framework, covered by the European Commission's adequacy decision (Article 45 GDPR), together with the Standard Contractual Clauses (Article 46(2)(c) GDPR).
  • Apple, Resend and Expo: Standard Contractual Clauses adopted by the European Commission (Article 46(2)(c) GDPR), supplemented by the additional measures set out in the respective agreements.

You can ask us for a copy of the safeguards in place by writing to hello@membrs.world.

8. Account deletion: what happens and what survives

You can delete your account yourself, from your profile settings, without writing to us.

What happens immediately. All active memberships are cancelled immediately, with no refund of the remaining period. The account enters a 30-day grace period: within that window you can come back and restore it. Note: restoring reactivates the account, not the cancelled memberships — to be a member again you have to subscribe afresh.

What happens after 30 days. The profile is anonymised in place: name, email, phone, push tokens and the reference to your profile photo are removed or replaced, the sharing switches are reset, and your login identity is deleted from the authentication system. We do not, however, delete the linked records, because of accounting obligations and the defence of legal claims.

What survives deletion. We are explicit about this, because it is the part that matters:

What remainsWhyFor how long
Payment records, invoices, refunds and payoutsLegal obligation (Art. 2220 Italian Civil Code, VAT rules)10 years
Memberships, bookings and check-in historyThey form part of the accounting and service-delivery recordsTogether with the accounting records, 10 years, linked to the anonymised profile
Login security logs (login_attempts), which contain the email address typed and the IP addressAccount security and abuse prevention12 months. The automatic deletion routine is being rolled out; until then these records are not altered by anonymisation
Audit log (audit_log), with IP address and user agentTraceability of actions, accountability, dispute handling24 months. The automatic deletion routine is being rolled out
Webhook log (webhook_log), with the full messages received from Stripe and Resend, which may contain your real email address and email open and click eventsAccounting reconciliation, idempotency, diagnostics24 months. The automatic deletion routine is being rolled out
Chat message content and attachmentsEvidence of the member-club relationship, handling of disputes and reports24 months from the thread's last message. The automatic deletion routine is being rolled out; until then messages are neither deleted nor redacted by anonymisation
Tags applied by the club and the suspension recordData processed by the club as an autonomous controller (§6)Suspension: 90 days of effect. Retention of the tags and of the suspension record: 24 months
The profile photo file itselfNone: this is a current technical limitation, not a choice. Anonymisation removes the link to the file but does not delete the file from storage, which is public-read: anyone who knew the exact URL could still open itUntil manual removal. A fix is being implemented; you can ask for immediate deletion by writing to hello@membrs.world
Records on Stripe's side (customer, subscriptions, invoices)Accounting obligations and retention applied by Stripe as controller for its own purposesPer Stripe's policies and tax law

An honest note on anonymisation. For as long as the security logs and webhook logs exist, containing your email address in clear text, anonymisation of the profile is not irreversible in absolute terms: by cross-referencing those logs it would technically be possible to link the residual records back to you. That is why we treat them as personal data in full, with the same access controls, and are defining a retention period with automatic deletion for each. If you want those records deleted sooner, write to us: we assess the request under Article 17 GDPR and grant it unless a retention obligation applies or we need the data to defend a legal claim.

A platform administrator can also carry out the deletion at your request, skipping the grace period.

9. Security measures

We apply technical and organisational measures appropriate to the risk (Article 32 GDPR). Concretely, and without promising more than we do:

  • Encryption in transit: all traffic to the site, the platform and the APIs runs over HTTPS.
  • Managed infrastructure: the platform runs on Google Cloud / Firebase App Hosting (region us-east4, United States), the database and authentication on Supabase (AWS eu-west-1, Ireland); we rely on those providers' physical and logical security measures. On where data is located and the safeguards that apply, see §7.
  • Application secrets held in Google Secret Manager, not in the codebase.
  • Role-based access control: member, club owner, manager, door staff, PR and platform administrator have distinct permissions, checked server-side on every request; database row-level security rules act as an additional barrier.
  • Audit log of administrative actions, designed to be append-only: no update path.
  • Login rate limiting: 5 failed attempts within 15 minutes temporarily lock access and trigger an alert email to the address concerned.
  • Payment data: we do not process it. Collection happens on Stripe pages.
  • Confidentiality-separated storage: chat attachments, payout invoices and GDPR exports live in private storage, reachable only through expiring signed links (1 hour for attachments, 7 days for exports). Profile photos and venue images, by contrast, live in public-read storage: anyone who knows the URL can open them without authenticating.
  • Mobile app: session tokens are kept in the operating system keychain (iOS Keychain / Android Keystore). The local copy of the guest list on door staff devices is kept in the device's standard application storage, not in a dedicated encrypted store: this is something we are improving.

If a personal data breach occurs that poses a risk to your rights and freedoms, we notify the Garante within 72 hours and, where the risk is high, we also inform you, under Articles 33 and 34 GDPR.

10. Your rights

Under Articles 15-22 GDPR you may exercise the following rights at any time:

  • Access (Art. 15): obtain confirmation that we process your data and receive a copy of it.
  • Rectification (Art. 16): correct inaccurate data or complete incomplete data. Name, email, phone, language and photo can be changed directly in your profile.
  • Erasure (Art. 17): obtain deletion of your data, within the limits of the retention obligations described in §8.
  • Restriction (Art. 18): ask for processing to be restricted in the cases provided for.
  • Portability (Art. 20): receive the data you provided to us in a structured, commonly used and machine-readable format.
  • Objection (Art. 21): object to processing based on legitimate interests, on grounds relating to your particular situation; if you object to clubs' promotional messages, the objection is always granted with no need for a reason, including through the unsubscribe link present in every email.
  • Withdrawal of consent (Art. 7(3)): where processing is based on consent — usage statistics — you may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal. How to do so is described in the Cookie Policy.

Self-service tools. From your profile you can: download an export of your data, edit your personal details, turn sharing of your email and phone with the club on or off, unsubscribe from club broadcasts, and delete your account without writing to us. The self-service export covers profile, roles, memberships, bookings, refunds received and the log of actions on your account; to obtain a complete copy, including chat messages, push tokens, login logs and tags applied by the club, write to hello@membrs.world and we will prepare it for you.

How to exercise them. Write to hello@membrs.world (alternatively PEC: sabaevents@pec.it). We reply within one month of receiving the request; that period may be extended by two further months for particularly complex or numerous requests, in which case we tell you why within the first month. Where necessary we will ask for information to verify your identity, and for that purpose only.

Complaints. If you believe the processing of your data infringes the law, you may lodge a complaint with the

Garante per la protezione dei dati personali Piazza Venezia 11, 00187 Rome, Italy www.garanteprivacy.it

or with the supervisory authority of the Member State of your habitual residence, place of work or of the alleged infringement (Article 77 GDPR). Your right to an effective judicial remedy is unaffected.

11. Automated decision-making and profiling

We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR.

Some operations are automatic — subscription renewal, payment retries and the resulting suspension of access if a payment ultimately fails, the chronological ordering of waitlists, event capacity checks, and card validity at the moment of the scan — but these are the execution of predetermined contractual rules applied identically to everyone, not evaluations of your personal aspects. Discretionary decisions about you — a club suspension, a refund, closing an account — are always made by a person.

12. Minors

The service is for people aged 18 and over. It concerns nightlife venues that minors may not enter, so it is not intended for them and we do not promote it to them.

Age verification is based on a declaration made by the user at sign-up: we do not request identity documents and we do not store a date of birth, only the date and time the declaration was made. Not every sign-up path currently collects that declaration in the same way; we are aligning them.

If we learn that an account belongs to someone under 18, we cancel any memberships, close the account and delete or anonymise the data as quickly as possible, keeping only what is strictly necessary for the accounting obligations relating to payments already made. If you are a parent or guardian and believe a minor has given us their data, write to hello@membrs.world: we will act without asking you to justify the request.

13. Cookies and similar technologies

The full list of the cookies and local storage we use — name, purpose, duration — is in the Cookie Policy, which forms an integral part of this notice.

In short: we use necessary technical cookies for authentication, to remember which role you are acting in, and to store your cookie choice; a functional cookie for light/dark theme; a 30-day attribution cookie when you arrive from a promoter's link; and Google Analytics 4 for usage statistics, only with your consent. We use no advertising or profiling cookies.

Exactly how Analytics consent works. Google's gtag.js script loads on every page, regardless of your choice. What your choice controls is Google's Consent Mode v2, which keeps every form of storage denied until you accept: analytics_storage, ad_storage, ad_user_data and ad_personalization. In practice this means that before consent no analytics cookie is set and no identifier is stored on your device, but the script is nevertheless present on the page and Google may receive cookieless pings. If you accept, only analytics_storage is enabled: advertising signals stay denied in all cases, the IP address is processed in anonymised form, and Google Signals is disabled.

Push notifications. The platform automatically requests permission to send you push notifications as soon as you enter your personal area: you do not have to switch anything on — it is the browser or the operating system that asks you to allow or deny, and the choice is yours. If you deny, we do not ask again. You can revoke the permission at any time in your browser or device settings; from that moment the token becomes unusable and is removed from our systems. Service notifications about your membership and bookings rest on the contract; clubs' promotional notifications follow row 8 of the table in §4.

Payments. Payment and billing-management pages are hosted by Stripe, on Stripe domains: any cookies set during payment are Stripe's cookies, governed by Stripe's own notice, and are not set on our domains.

14. Changes to this notice

We update this notice when the service changes, when our providers change, or when the law changes.

The version in force is always published at membrs.world/legal/privacy, with the last-updated date at the bottom. If a change is material — for example a new purpose, a new legal basis, a new processor receiving your data, or a change to retention periods that is unfavourable to you — we tell you before it takes effect, by email to the address associated with your account and/or through a prominent notice in the platform. Where the change concerns processing based on consent, we ask for fresh consent.

Previous versions are available on request at hello@membrs.world.

15. Data controller — full details

Saba Events S.R.L. Via di Salicchi, 711/X — 55100 Lucca (LU), Italy VAT and tax code 04726940234 — VAT ID IT04726940234 PEC: sabaevents@pec.it — SDI recipient code: 9SUB64Q Email: hello@membrs.world Sites: membrs.world · app.membrs.world

Data Protection Officer: none appointed (see §1). Governing law: Italian law. In case of any discrepancy between the Italian version and this English translation, the Italian version prevails.