PRIVACY POLICY
Lees deze privacyverklaring in het Nederlands →
Last updated: 27 July 2026
This Privacy Policy explains how we handle personal data when you visit our website sandit.club, use the SANDIT mobile app, or use the connected SANDIT hardware device (together, the “Services”).
1. WHO WE ARE
The controller for your personal data is:
Arjodima Holding B.V.
Van Bleiswijkstraat 188
2582 LJ Den Haag
The Netherlands
Chamber of Commerce (KvK): 27286447
VAT (BTW): NL8154.87.769.B.02
crew@sandit.club
We are established in the Netherlands and process personal data in accordance with the General Data Protection Regulation (GDPR) and the Dutch Telecommunications Act (Telecommunicatiewet). We have not appointed a Data Protection Officer, as we are not required to do so; privacy questions go to the address above.
2. WHAT WE COLLECT
2.1 When you visit the website
- Technical and usage data: IP address, browser type and version, operating system, device type, referring URL, pages viewed, time on page, and clicks. Collected through our analytics and advertising tools (see section 4).
- Session recordings and heatmaps: a reconstruction of how you moved, scrolled and clicked on a page, captured by Microsoft Clarity. Text you type into form fields is masked by Clarity and is not recorded.
- Reservation data: your email address, and the fact, time and version of the authorisation you gave when placing a founder reservation.
2.2 When you place an order or reservation
- Contact and order data: email address, name, shipping address, order and reservation history.
- Payment data: handled entirely by Stripe. We receive a payment reference, the status of your payment method and the last four digits and brand of your card. We never see or store your full card number.
2.3 When you use the app and hardware
- Account and profile data: name or nickname, email address, profile photo.
- Location and sensor data: GPS coordinates, altitude, timestamps, speed, acceleration (G-force) and gyroscopic data, from your phone’s sensors and/or the hardware device over Bluetooth or WiFi. Used to calculate performance metrics such as jump height, hang time and route maps.
- User-generated content: session photos, descriptions, comments and profile pictures you upload.
- Device and diagnostic data: IP address, device identifiers, app version, access times, crash and log data.
You control location access through your device settings and in the app. If you switch location off, features such as route mapping and some performance metrics will not work.
If your session visibility is set to “Public”, your username, profile photo, session metrics and map route are visible to other users on global leaderboards and community feeds. You control this per session in the app.
3. WHY WE USE IT, AND ON WHAT LEGAL BASIS
We only process personal data where we have a legal basis under Article 6 GDPR:
| Purpose | Legal basis | We keep it for |
|---|---|---|
| Providing the app and hardware features you asked for (sessions, metrics, maps) | Performance of a contract (Art. 6(1)(b)) | Until you delete your account |
| Handling your reservation, order, payment mandate, shipping and support | Performance of a contract (Art. 6(1)(b)) | Duration of the contract, then the tax period below |
| Financial and tax administration | Legal obligation (Art. 6(1)(c)) | 7 years (Dutch tax law) |
| Keeping the Services secure, preventing fraud and abuse | Legitimate interest (Art. 6(1)(f)) — running a secure service | Up to 12 months for logs |
| Website analytics, session recording, and measuring and targeting our advertising (see section 4) | Consent (Art. 6(1)(a)) and Art. 11.7a Telecommunicatiewet | See the cookie table in section 4 |
| Service emails about your reservation or order (confirmations, shipping, payment issues) | Performance of a contract (Art. 6(1)(b)) | Duration of the contract |
| Marketing emails and product updates | Consent, or the existing-customer exception in Art. 11.7 Telecommunicatiewet. Every message has an unsubscribe link. | Until you unsubscribe |
Where we rely on consent, you can withdraw it at any time. Withdrawing consent does not affect processing that already took place. Where we rely on legitimate interest, you have the right to object — see section 8.
4. COOKIES AND SIMILAR TECHNOLOGIES
Our website uses cookies and comparable techniques that store or read information on your device. Strictly necessary cookies are needed to make the site work and cannot be switched off. All other cookies — analytics, session recording and advertising — are only placed with your consent.
| Provider | Category | What it does | Storage |
|---|---|---|---|
| Google Analytics 4 Google Ireland Ltd. |
Analytics | Measures how many people visit, which pages they read and where they came from. Cookies _ga, _ga_*. |
Up to 2 years |
| Meta Pixel Meta Platforms Ireland Ltd. |
Advertising | Measures which of our Facebook and Instagram ads lead to reservations, and lets us show ads to relevant audiences. Cookies _fbp, _fbc. |
Up to 3 months |
| Microsoft Clarity Microsoft Ireland Operations Ltd. |
Analytics | Records session replays and heatmaps so we can see where the site confuses people. Form input is masked. Cookies _clck, _clsk. |
1 day to 1 year |
| Stripe Stripe Payments Europe Ltd. |
Strictly necessary | Processes your payment mandate and detects fraudulent transactions during checkout. | Session to 1 year |
| Mapbox Mapbox Inc. |
Functional | Renders the interactive spot map on our homepage. Loads only when you scroll to the map. | Session |
You can also control tracking independently of us: through your browser’s cookie settings, through Meta’s ad preferences, through Google’s Analytics opt-out add-on, or via the opt-out described in the Microsoft privacy statement.
Meta joint controllership. For the data collected by the Meta Pixel and sent to Meta, SANDIT and Meta Platforms Ireland Ltd. are joint controllers within the meaning of Article 26 GDPR. We are jointly responsible for that collection and transmission; Meta is solely responsible for what it does with the data afterwards. The essence of our arrangement is set out in Meta’s Controller Addendum. You can exercise your rights against either of us.
5. WHO WE SHARE IT WITH
We do not sell your personal data. We share it only with providers that process it on our behalf under a data processing agreement, and only as far as they need it:
- Google Firebase / Google Cloud — hosting, authentication, database and file storage.
- Stripe — payment processing and subscription billing.
- Mapbox — map rendering and route visualisation.
- Google Analytics 4 — website analytics.
- Microsoft Clarity — session replay and heatmaps.
- Meta Platforms — advertising measurement and targeting (joint controller, see section 4).
We may also disclose data where we are legally required to do so, or where it is necessary to establish, exercise or defend legal claims.
6. TRANSFERS OUTSIDE THE EUROPEAN ECONOMIC AREA
Some of the providers above are US-based or process data outside the EEA. Where that happens, the transfer is covered by one or both of the following safeguards:
- EU–US Data Privacy Framework: Google, Microsoft, Meta and Stripe are certified under the framework, for which the European Commission has issued an adequacy decision.
- Standard Contractual Clauses: the model clauses approved by the European Commission, combined with additional technical and organisational measures where needed.
You can request a copy of the safeguards that apply to a specific transfer by emailing crew@sandit.club.
7. HOW LONG WE KEEP IT
We keep personal data no longer than necessary for the purpose it was collected for. The specific periods are in the table in section 3 and the cookie table in section 4. In short:
- Account, session and sensor data: until you delete your account, then removed from our live systems. Backups roll off within 90 days.
- Order, reservation and invoice records: 7 years, because Dutch tax law requires it.
- Reservations that never converted: 24 months after the last contact, then deleted.
- Support email: 24 months after the conversation closes.
- Server and security logs: up to 12 months.
8. YOUR RIGHTS
Under the GDPR you have the following rights. They are free to exercise, and we respond within one month.
- Access (Art. 15): get a copy of the personal data we hold about you.
- Rectification (Art. 16): have inaccurate or incomplete data corrected.
- Erasure (Art. 17): have your data deleted. You can do this yourself for your account — see Delete Account.
- Restriction (Art. 18): have us pause processing while a dispute about accuracy or legitimacy is resolved.
- Data portability (Art. 20): receive the data you gave us in a structured, machine-readable format, or have it sent to another provider.
- Objection (Art. 21): object to processing based on our legitimate interest. You can object to direct marketing at any time, and we will always stop.
- Withdraw consent (Art. 7(3)): withdraw consent for cookies or marketing at any time, as easily as you gave it.
- Automated decision-making (Art. 22): we do not make decisions with legal or similarly significant effects about you by automated means, and we do not profile you for those purposes.
To exercise any of these, email crew@sandit.club. We may ask you to confirm your identity before we act, so that we do not hand your data to someone else.
Complaints. If you think we are handling your data wrongly, please tell us first so we can put it right. You also have the right to lodge a complaint with the Dutch data protection authority: Autoriteit Persoonsgegevens, Postbus 93374, 2509 AJ Den Haag. If you live in another EU country, you may complain to your local authority instead.
9. SECURITY
We use appropriate technical and organisational measures to protect your data, including encryption in transit (HTTPS/TLS), encryption at rest with our hosting provider, access control on administrative tooling, and payment handling that keeps card data entirely within Stripe’s PCI-DSS environment. No system is perfectly secure, but if a data breach is likely to put your rights at risk, we will inform you and the Autoriteit Persoonsgegevens as the GDPR requires.
10. CHILDREN
The Services are not directed at children under 16. We do not knowingly collect their personal data. If you believe a child has given us data, contact us and we will delete it.
11. CHANGES TO THIS POLICY
We may update this policy as the Services change. The date at the top always shows the current version. If a change materially affects you, we will make it clear on the website or by email before it takes effect.
12. CONTACT
Questions about this policy or about your data:
Arjodima Holding B.V.
Van Bleiswijkstraat 188
2582 LJ Den Haag
The Netherlands
crew@sandit.club
Looking for returns, cancellation or the founder reservation terms? See the founder pre-order policy.