Privacy Policy UNDER REVIEW

Status: DRAFT v1.0 — Under Legal Review
Draft Date: April 8, 2026
Last Updated: April 8, 2026
Applicable Law: Swiss Federal Act on Data Protection (FADP / nFADP)
Expected Finalization: 2-3 weeks after attorney review

⚠️ UNDER LEGAL REVIEW

This Privacy Policy is currently under review by a qualified Swiss attorney for compliance with the Swiss Federal Act on Data Protection (FADP). It has not yet been finalized or approved for production use. This is a DRAFT version for internal review purposes only.

Status: Draft v1.0 — Awaiting attorney approval
Expected Completion: 2-3 weeks

Your Privacy Matters

2paraglide is committed to protecting your personal data. This Privacy Policy explains what information we collect, how we use it, and your rights under Swiss law. We operate as a marketplace platform connecting you with independent paragliding service providers.

Table of Contents

  1. Who We Are & How to Contact Us
  2. What Personal Data We Collect
  3. How We Use Your Personal Data
  4. Legal Basis for Processing
  5. Who We Share Your Data With
  6. International Data Transfers
  7. How Long We Keep Your Data
  8. Your Rights Under Swiss Law
  9. Cookies & Tracking Technologies
  10. Security Measures
  11. Children's Privacy
  12. Changes to This Policy
  13. Complaints & Supervisory Authority

1. Who We Are & How to Contact Us

1.1 Data Controller

The data controller responsible for your personal data is:

2paraglide GmbH
[Address Line 1]
[Postal Code] Zurich
Switzerland

Swiss Business Registration: CHE-XXX.XXX.XXX
Email: privacy@2paraglide.com
Phone: +41 XX XXX XX XX

1.2 Our Role as a Marketplace Platform

Important: 2paraglide operates as a marketplace platform (similar to Uber or Airbnb). We connect customers with independent paragliding service providers (pilots/operations).

  • 2paraglide processes your data for booking, payment, and platform services
  • Pilots process your data for providing the flight service
  • Both 2paraglide and pilots are separate data controllers for their respective activities
  • This Privacy Policy covers only 2paraglide's data processing
  • Each pilot has their own privacy obligations (ask them directly for their privacy practices)

2. What Personal Data We Collect

2.1 Information You Provide Directly

When You Create an Account:

  • Name: First and last name
  • Email address: For account login and communications
  • Phone number: For booking confirmations and pilot contact
  • Password: Encrypted and stored securely
  • Profile photo: Optional, if you choose to upload one

When You Make a Booking:

  • Passenger details: Names, ages, weights (required for flight safety)
  • Medical information: Health conditions, medications (pilot safety assessment)
  • Special requirements: Disabilities, accessibility needs, dietary restrictions
  • Emergency contact: Name and phone number of emergency contact person
  • Booking preferences: Flight date, time, package, number of passengers

Payment Information:

  • Payment details: Credit/debit card information (processed by our payment provider)
  • Billing address: Name, address, postal code, country
  • Transaction history: Booking amounts, refunds, platform credits

Note: We do NOT store your full credit card numbers. Our payment processor (Stripe/similar) handles all card data securely according to PCI-DSS standards.

Communications:

  • Customer support messages: Your inquiries, complaints, feedback
  • Reviews: Ratings and reviews you leave for pilots
  • Survey responses: If you participate in customer surveys

2.2 Information We Collect Automatically

Technical & Usage Data:

  • Device information: Device type, operating system, browser type
  • IP address: For security, fraud prevention, and approximate location
  • Log data: Pages visited, time spent, clicks, search queries
  • Cookies: See our Cookie Policy for details
  • Location data: Approximate location from IP (not precise GPS tracking)

Analytics & Performance:

  • Google Analytics: Website traffic, user behavior (if you consent)
  • Performance metrics: Page load times, errors, crashes
  • Conversion tracking: Booking completions, funnel drop-offs

2.3 Information from Third Parties

  • Social login: If you sign up with Google/Apple, we receive your name, email, and profile photo
  • Payment processors: Transaction confirmation, payment status
  • Pilots: Feedback about your flight experience (for quality control)
  • Fraud prevention services: Risk scores to prevent fraudulent bookings

3. How We Use Your Personal Data

To Provide Our Platform Services

  • Create and manage your account
  • Process your bookings and payments
  • Connect you with pilots
  • Send booking confirmations, reminders, updates
  • Facilitate communication between you and pilots
  • Process refunds and cancellations
  • Provide customer support

For Safety, Security & Fraud Prevention

  • Verify pilot credentials and insurance
  • Detect and prevent fraudulent bookings
  • Protect against payment fraud
  • Ensure platform security (prevent hacking, attacks)
  • Comply with legal obligations (AML, anti-terrorism)
  • Investigate disputes and complaints

To Improve Our Services

  • Analyze website usage and performance
  • Understand customer preferences and behavior
  • Test new features and improvements
  • Conduct customer satisfaction surveys
  • Personalize your experience (e.g., remember language preference)

For Marketing & Communications (With Your Consent)

  • Send promotional emails about special offers, new pilots, discounts
  • Show personalized ads on social media (Facebook, Instagram)
  • Send push notifications (if you enable them)
  • Invite you to refer friends (referral program)

You can opt out anytime: Click "unsubscribe" in emails or adjust settings in your account.

For Legal Compliance

  • Comply with Swiss laws and regulations
  • Respond to legal requests (court orders, subpoenas)
  • Enforce our Terms of Service
  • Resolve disputes and legal claims
  • Maintain records for tax and accounting (10 years per Swiss law)

4. Legal Basis for Processing (FADP)

Under Swiss law (FADP), we must have a legal basis to process your personal data. Here are the legal bases we rely on:

Processing Activity Legal Basis
Account creation, bookings, payments Contract performance (Art. 31 para. 2 lit. a FADP)
Fraud prevention, security, platform integrity Legitimate interest (Art. 31 para. 1 FADP)
Marketing emails, personalized ads, analytics Consent (Art. 31 para. 1 FADP)
Tax records, legal compliance, disputes Legal obligation (Art. 31 para. 2 lit. b FADP)
Medical info (pilot safety assessment) Explicit consent (Art. 34 FADP - special category data)
What this means: We only process your data when we have a legal right to do so under Swiss law. For marketing and analytics, we always ask your permission first.

5. Who We Share Your Data With

We share your personal data only when necessary to provide our services or comply with the law. We never sell your data to third parties.

Paragliding Pilots/Service Providers

What we share: Your name, phone number, email, booking details, passenger information (names, ages, weights), medical information (for safety assessment)

Why: Pilots need this information to contact you, prepare for your flight, and assess safety requirements

Note: Pilots are independent data controllers. They have their own privacy obligations. Ask your pilot directly about their privacy practices.

Payment Processors

Who: Stripe (or similar payment processor)

What we share: Name, email, billing address, payment amount

Why: To process your payment securely

Payment processors are PCI-DSS certified and handle your card data securely. We never see your full card number.

Service Providers & Infrastructure

We use trusted service providers to operate our platform:

  • Cloud hosting: AWS, Google Cloud, or similar (data storage and servers)
  • Email services: SendGrid, Mailgun, or similar (booking confirmations, notifications)
  • Analytics: Google Analytics (website traffic analysis, with your consent)
  • Customer support: Zendesk, Intercom, or similar (support ticket management)
  • Security: Cloudflare (DDoS protection, security)

All service providers are bound by data processing agreements (DPAs) and must comply with Swiss/EU data protection standards.

Legal Authorities & Law Enforcement

When: Only when legally required or to protect rights

  • Court orders, subpoenas, legal requests
  • Compliance with Swiss tax and accounting laws
  • Investigation of fraud, illegal activity, or safety threats
  • Protection of our legal rights in disputes

Business Transfers

If 2paraglide is acquired, merged, or undergoes a business reorganization, your personal data may be transferred to the new entity. We will notify you of any such change and your data will remain protected under this Privacy Policy (or an equivalent).

6. International Data Transfers

2paraglide is based in Switzerland. However, some of our service providers (e.g., cloud hosting, analytics) may process data outside Switzerland, including in:

  • European Union (EU/EEA): Adequate protection under Swiss law
  • United States: Under EU-US Data Privacy Framework or Standard Contractual Clauses (SCCs)
  • Other countries: Only with adequate safeguards (SCCs, binding corporate rules)

Safeguards for International Transfers

When we transfer data outside Switzerland, we ensure adequate protection through:

  • Standard Contractual Clauses (SCCs): EU-approved contract terms with service providers
  • Adequacy decisions: Swiss FDPIC recognizes certain countries as having adequate protection (e.g., EU, UK)
  • Data Processing Agreements (DPAs): Legal contracts requiring data protection
  • EU-US Data Privacy Framework: For US-based processors (if applicable)

Your rights apply worldwide: Even if your data is processed outside Switzerland, you retain all your rights under Swiss FADP.

7. How Long We Keep Your Data

We keep your personal data only as long as necessary for the purposes outlined in this Privacy Policy, or as required by Swiss law.

Data Type Retention Period Reason
Account information Until you delete account + 30 days Allow account recovery
Booking records 10 years after booking Swiss accounting law (Art. 958f CO)
Payment transactions 10 years after transaction Swiss tax and accounting law
Marketing consent Until you withdraw consent Respect your preferences
Customer support logs 3 years Resolve disputes, improve service
Medical information Deleted after flight completion Minimize sensitive data storage
Analytics data 26 months (Google Analytics default) Platform improvement
Security logs (fraud prevention) 2 years Detect fraud patterns
Data Deletion: After the retention period expires, we securely delete or anonymize your data. You can also request deletion at any time (see Section 8 - Your Rights).

8. Your Rights Under Swiss Law (FADP)

Under the Swiss Federal Act on Data Protection (FADP), you have the following rights regarding your personal data:

1. Right to Access (Art. 25 FADP)

What it means: You can request a copy of all personal data we hold about you.

How to exercise: Log into your account → Settings → "Download my data" OR email privacy@2paraglide.com

Response time: Within 30 days (free of charge for first request per year)

2. Right to Rectification (Art. 32 FADP)

What it means: You can correct inaccurate or incomplete personal data.

How to exercise: Log into your account → Settings → Edit profile OR email privacy@2paraglide.com

3. Right to Deletion / "Right to be Forgotten" (Art. 32 FADP)

What it means: You can request deletion of your personal data in certain circumstances.

How to exercise: Log into your account → Settings → "Delete my account" OR email privacy@2paraglide.com

Limitations: We may need to retain certain data for legal compliance (e.g., financial records for 10 years per Swiss law) or to resolve disputes.

4. Right to Data Portability (Art. 28 FADP)

What it means: You can receive your data in a structured, commonly used format (e.g., CSV, JSON) and transfer it to another service.

How to exercise: Email privacy@2paraglide.com with your request

5. Right to Object to Processing

What it means: You can object to processing based on legitimate interests (e.g., marketing, profiling).

How to exercise: For marketing: Click "unsubscribe" in emails OR account settings → "Communication preferences"

For other processing: Email privacy@2paraglide.com

6. Right to Withdraw Consent

What it means: If processing is based on your consent (e.g., marketing, analytics), you can withdraw it anytime.

How to exercise: Account settings → "Privacy preferences" → Manage consents (cookies, analytics, marketing)

Note: Withdrawing consent doesn't affect the lawfulness of processing before withdrawal.

7. Right to Restriction of Processing

What it means: You can request that we temporarily stop processing your data in certain circumstances (e.g., while we verify accuracy).

How to exercise: Email privacy@2paraglide.com with your specific request

How to Exercise Your Rights

To exercise any of your data protection rights:

  1. Log into your account → Settings → Privacy & Data (for most requests)
  2. OR email us: privacy@2paraglide.com with:
    • Your full name and email address (for verification)
    • Description of your request (e.g., "I request deletion of my account")
    • Any supporting information
  3. We will respond within 30 days (or explain why we need more time)

Identity verification: For security, we may ask you to verify your identity before processing certain requests (e.g., data access, deletion).

9. Cookies & Tracking Technologies

We use cookies and similar tracking technologies to improve your experience, analyze site usage, and deliver personalized content.

What are cookies?

Cookies are small text files stored on your device when you visit our website. They help us remember your preferences, keep you logged in, and understand how you use our platform.

For Complete Cookie Information

For detailed information about the cookies we use, how they work, and how to manage them, please see our:

View Cookie Policy

Quick Summary:

  • Essential cookies: Required for site functionality (login, bookings) — no consent needed
  • Analytics cookies: Google Analytics, performance tracking — consent required
  • Marketing cookies: Facebook Pixel, ad retargeting — consent required
  • You control cookies: Manage preferences in our cookie banner or browser settings

10. Security Measures

We take the security of your personal data seriously and implement industry-standard technical and organizational measures to protect it.

Technical Security Measures

  • Encryption: All data transmitted via HTTPS/TLS encryption (SSL certificates)
  • Password protection: Passwords hashed with bcrypt/Argon2 (never stored in plain text)
  • Payment security: PCI-DSS compliant payment processors (we don't store card numbers)
  • Firewall protection: Network firewalls and intrusion detection systems
  • DDoS protection: Cloudflare or similar to prevent attacks
  • Data backups: Regular encrypted backups stored securely

Organizational Security Measures

  • Access control: Only authorized employees can access personal data (need-to-know basis)
  • Employee training: Staff trained on data protection and security best practices
  • Confidentiality agreements: All employees sign confidentiality/NDA agreements
  • Security audits: Regular security assessments and penetration testing
  • Incident response plan: Procedures for data breach notification and response

Your Security Responsibility

Help us protect your account:

  • Use a strong, unique password (min. 8 characters, mix of letters/numbers/symbols)
  • Don't share your password with anyone
  • Log out from shared computers
  • Enable two-factor authentication (2FA) if available
  • Report suspicious activity immediately: security@2paraglide.com
Data Breach Notification

In the unlikely event of a data breach affecting your personal data, we will notify you and the Swiss Federal Data Protection Commissioner (FDPIC) without undue delay, as required by Swiss law (Art. 24 FADP).

11. Children's Privacy

Age Requirement: Our platform is intended for users aged 16 years and older.

We do not knowingly collect personal data from children under 16 without parental consent. If you are under 16:

  • You must have a parent/legal guardian create an account on your behalf
  • Your parent/guardian must provide consent for your paragliding flight
  • We collect the minimum necessary information for safety purposes only

Parents/Guardians: If you believe your child has provided personal data without your consent, please contact us immediately at privacy@2paraglide.com and we will delete it promptly.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other operational needs.

How We Notify You of Changes

  • Material changes: We will notify you by email and/or prominent notice on our website at least 30 days before changes take effect
  • Minor changes: We will update the "Last Updated" date at the top of this policy
  • Your continued use: By continuing to use 2paraglide after changes take effect, you accept the updated Privacy Policy

We recommend reviewing this Privacy Policy periodically to stay informed about how we protect your data.

13. Complaints & Supervisory Authority

We are committed to resolving any concerns you have about our privacy practices. If you have a complaint:

Step 1: Contact Us First

Please contact our Data Protection Officer first:

Email: privacy@2paraglide.com
Subject Line: "Privacy Complaint"
Response Time: Within 7 business days

Step 2: Swiss Supervisory Authority

If you are not satisfied with our response, you have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC):

Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)
Federal Data Protection and Information Commissioner (FDPIC)

Feldeggweg 1
3003 Bern
Switzerland

Phone: +41 58 462 43 95
Email: info@edoeb.admin.ch
Website: www.edoeb.admin.ch

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Company Information

2paraglide GmbH
[Address Line 1]
[Postal Code] Zurich
Switzerland
CHE-XXX.XXX.XXX

Data Protection

Privacy inquiries:
privacy@2paraglide.com

Data Protection Officer:
dpo@2paraglide.com

Support

General support:
support@2paraglide.com

Phone:
+41 XX XXX XX XX
Mon-Fri: 09:00-18:00 CET

Legal Compliance

This Privacy Policy complies with the Swiss Federal Act on Data Protection (FADP / nFADP, effective September 1, 2023). We are committed to protecting your privacy rights and handling your personal data responsibly in accordance with Swiss law.

⚠️ IMPORTANT LEGAL DISCLAIMER

This is a DRAFT document under legal review. This Privacy Policy has been prepared by 2paraglide GmbH and is currently being reviewed by a qualified Swiss attorney specializing in data protection law (FADP). It should NOT be considered legally binding or in effect until:

  • Review and approval by Swiss legal counsel
  • Implementation of any recommended changes
  • Official publication with "Effective Date"
  • User notification of the finalized policy

DO NOT rely on this draft for legal purposes. For questions, contact: legal@2paraglide.com

DRAFT

2paraglide GmbH
Switzerland's #1 Tandem Paragliding Marketplace Platform
Connecting adventurers with certified pilots since 2024

⚠️ DRAFT STATUS: Under Legal Review
Privacy Policy Version: Draft v1.0
Draft Date: April 8, 2026
Last Updated: April 8, 2026
Expected Finalization: 2-3 weeks after attorney approval