Privacy Policy

Last updated: 27 March 2026

1. Data Controller

The data controller for personal data is Gymnamo, operating the EncoreLeo platform accessible at ribbonroute.com.
Email: contact@gymnamo.com

2. Data We Collect

We collect the following categories of data:

  • Registration data: email address, username, name (optional), date of birth (for age verification)
  • Profile data: department/region, gymnastics club, biography, profile picture
  • Listing data: photos, descriptions, prices, leotard measurements
  • Messages: content of messages exchanged via the built-in messaging system (subject to moderation)
  • Transaction data: purchase and sale history, reviews and ratings
  • Technical data: IP address, browser type, operating system, pages visited, timestamps, device identifier
  • Cookies and analytics data: with your consent, browsing data collected via Google Analytics and Microsoft Clarity

3. Purposes of Processing

  • User account management and authentication
  • Publishing and managing listings
  • Messaging between buyers and sellers
  • Content moderation (listings and messages), including through automated tools and artificial intelligence
  • Fraud prevention and platform security
  • Age verification (18 years minimum)
  • Platform improvement (statistics and analytics)
  • Sending email notifications (transactional and, with your consent, promotional)
  • Compliance with legal obligations (including data retention for judicial authorities)
  • AI image generation for leotard presentation

4. Legal Basis for Processing

We process your data on the following legal bases:

  • Performance of a contract (Article 6(1)(b) GDPR / UK GDPR): necessary to provide our services (account, listings, messaging)
  • Consent (Article 6(1)(a) GDPR / UK GDPR): for analytics cookies, promotional communications
  • Legitimate interest (Article 6(1)(f) GDPR / UK GDPR): moderation, security, fraud prevention, platform improvement
  • Legal obligation (Article 6(1)(c) GDPR / UK GDPR): data retention required by law

5. Data Retention

  • Account data: retained as long as the account is active. Deleted 3 years after last login or upon your request
  • Listings: retained for 1 year after archival or sale
  • Messages: retained for 2 years for moderation and safety purposes
  • Technical logs: 12 months
  • Billing data: 10 years (French legal obligation, Article L.123-22 of the Commercial Code)
  • Cookie consent: 13 months (CNIL recommendation)

6. Data Sharing and Processors

We never sell your personal data. We share your data only with the following processors, necessary for the operation of the Platform:

  • Supabase (database hosting and authentication) — EU, GDPR compliant
  • Vercel (website hosting) — data processed in the United States, Standard Contractual Clauses (SCC)
  • Resend (transactional email delivery) — United States, SCC
  • Google (Gemini for AI image/description generation; Google Analytics for statistics) — United States, SCC. No personal data is transmitted for AI generation
  • Microsoft (Clarity for behavioural analysis) — United States, SCC

International transfers: Some of our processors are based in the United States. These transfers are governed by Standard Contractual Clauses (SCC) approved by the European Commission and, where applicable, the UK International Data Transfer Agreements (IDTA).

7. Cookies

EncoreLeo uses strictly necessary cookies for site functionality (authentication, language preferences, cookie consent). These cookies do not require your consent.

With your explicit consent, we also use analytics cookies (Google Analytics, Microsoft Clarity) to improve your experience. In accordance with CNIL recommendations and the ePrivacy Directive (as implemented in both French and UK law), you can accept or reject these cookies via the cookie banner displayed on your first visit. You can change your preferences at any time using the "Manage cookies" link in the footer.

Cookie consent is retained for 13 months in accordance with CNIL recommendations.

8. Your Rights

Under the General Data Protection Regulation (GDPR), UK GDPR, the French Informatique et Libertés Act, and the UK Data Protection Act 2018, you have the following rights:

  • Right of access: obtain a copy of your personal data
  • Right to rectification: correct inaccurate or incomplete data
  • Right to erasure ("right to be forgotten"): request deletion of your data
  • Right to data portability: receive your data in a structured, machine-readable format
  • Right to object: object to processing based on legitimate interest
  • Right to restriction: restrict processing in certain circumstances
  • Right to withdraw consent at any time, without affecting the lawfulness of prior processing

To exercise these rights, contact us at: contact@gymnamo.com. We will respond within 30 days (extendable to 60 days for complex requests).

Complaints: You may lodge a complaint with:

  • The CNIL (Commission Nationale de l'Informatique et des Libertés): www.cnil.fr
  • The ICO (Information Commissioner's Office, UK): ico.org.uk

9. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or alteration. This includes encryption of data in transit (HTTPS/TLS), secure authentication, and access controls. However, no data transmission over the Internet is completely secure, and we cannot guarantee absolute security.

10. Children

EncoreLeo is intended for persons aged 18 and over. We do not knowingly collect personal data from persons under 18. If we discover that we have collected data from a minor, we will delete it promptly. If you believe a minor has created an account, please contact us at contact@gymnamo.com.

11. Changes to this Policy

We may update this policy at any time. Changes will be posted on this page with an updated date. For substantial changes, we will notify you by email or through a notification on the Platform.

12. Contact

For any questions about data protection, contact us at:

Gymnamo
E-mail : contact@gymnamo.com

Last updated: 27 March 2026