Notice provided under Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018 (the "Italian Privacy Code").
This notice covers the membrs. service — the membrs.world website, the app.membrs.world platform and the MEMBRS mobile app.
The Italian text is the authoritative version. This English version is a courtesy translation.
The data controller is:
Saba Events S.R.L. Via di Salicchi, 711/X — 55100 Lucca (LU), Italy VAT and tax code 04726940234 (VAT ID: IT04726940234) Certified email (PEC): sabaevents@pec.it — SDI recipient code: 9SUB64Q Email for anything in this notice and for exercising your rights: hello@membrs.world
Saba Events S.R.L. is the provider of the membrs. platform, the seller of the membership subscriptions (merchant of record) and the data controller for data processed through the platform.
Data Protection Officer (DPO): none appointed. Under Article 37 GDPR, appointing a DPO is mandatory only where processing is carried out by a public authority, where the controller's core activities consist of processing operations requiring regular and systematic monitoring of data subjects on a large scale, or where the core activities consist of large-scale processing of special categories of data or data relating to criminal convictions. Saba Events S.R.L. falls into none of these cases: it is not a public body, it does not process special categories of data (§3), and its core activity is providing a subscription service, not monitoring data subjects. For this reason no DPO has been appointed. The contact point for privacy matters remains hello@membrs.world (alternatively, PEC sabaevents@pec.it).
This notice applies to:
membrs.world — anyone browsing the public site without an account;ops.membrs.world is an internal backoffice, accessible only to authorised Saba Events personnel. It is not a user-facing service: it is mentioned here because it is the tool through which our staff access data for support, administration and compliance.
If you are a member, the club you subscribe to also processes some of your data for its own purposes: see §6.
membrs_pr cookie (30 days) and attached to the membership at purchase.login_attempts): for every login attempt we record the email address typed, the IP address and the outcome, in order to limit unauthorised access attempts.audit_log): for significant administrative and technical actions (check-ins, team management, suspensions, refunds, payouts, exports, deletions) we record who acted, what they did, on what object, with the IP address and user agent and a timestamp.webhook_log): we keep the full messages sent to us by Stripe and Resend, which may contain customer and subscription identifiers, amounts, recipients' email addresses and email delivery, open and click events for the emails we send you.In the mobile app, additionally: the camera is used only to scan QR codes at the door (no image is stored or transmitted, only the decoded code); the photo library is used only for the attachments you choose to send in chat; calendar access is used to save a booking on your device and stays local; biometric unlock (Face ID / fingerprint) is handled by the operating system — we neither receive nor store any biometric data. The app uses no analytics SDK, no crash reporting tool, and collects no advertising identifiers and no location.
Door staff devices keep a local copy of the event guest list (member name and entry code) so that check-in works without a connection.
We do not process special categories of data under Article 9 GDPR: no data concerning health, sex life, political opinions, religious beliefs, trade union membership or ethnic origin, and no biometric or criminal-offence data. We do not ask for and do not store your date of birth. Note: chat messages and the tags a club attaches to you are free-text fields — if you voluntarily put information of this kind there, it ends up in our systems; please do not.
Payment card data never reaches our servers. Payment takes place on pages hosted by Stripe, to which you are redirected: card number, expiry and security code are collected and processed directly by Stripe. We only receive the outcome of the transaction and the identifiers needed to manage your subscription.
| # | Purpose | Main data | Legal basis | Retention period |
|---|---|---|---|---|
| 1 | Creating and managing your account: sign-up, login, profile, preferences | Name, email, phone, language, profile photo, referral code | Art. 6(1)(b) GDPR — performance of a contract to which the data subject is party | For the life of the account. If you request deletion: 30-day grace period, then anonymisation of the profile (§8) |
| 2 | Verifying the 18+ requirement | Date and time of your age declaration | Art. 6(1)(f) — legitimate interest in keeping an adults-only nightlife service restricted to adults and being able to evidence it | As row 1; the timestamp alone survives anonymisation |
| 3 | Providing the membership and handling payments, renewals, cancellations and refunds | Club and plan, subscription status, billing history, Stripe identifiers | Art. 6(1)(b) — performance of the contract | For the life of the subscription; payment documents follow row 4 |
| 4 | Accounting and tax obligations: invoices and receipts to members, refunds, payouts to clubs, mandatory books | Billing data, amounts, transaction identifiers, club tax data and IBAN | Art. 6(1)(c) — compliance with legal obligations (Art. 2220 Italian Civil Code; VAT and e-invoicing rules) | 10 years from the date of the last entry (Art. 2220 Italian Civil Code). After account deletion these records remain, linked to an anonymised profile (§8) |
| 5 | Digital member card, Apple/Google Wallet passes and door access control | QR token and short code, name, club, plan; check-in timestamp and context | Art. 6(1)(b) — performance of the contract | Credentials: for the life of the membership. Check-in history: for the life of the account and thereafter, linked to the anonymised profile, together with the membership records (row 4) |
| 6 | Event bookings, waitlist management, reminders | Bookings, waitlist position, status, email and push tokens for reminders | Art. 6(1)(b) — performance of the contract | As row 5 |
| 7 | Service communications by email and push notifications about your account, membership and bookings | Email, name, Web Push / Expo tokens | Art. 6(1)(b) — performance of the contract | For the life of the account. Push tokens are removed on deletion or when you revoke permission; delivery logs follow row 13 |
| 8 | Promotional messages sent by a club to its own members about that club's services (email and push broadcasts) | Email, name, plan, segment and tags, global opt-out | Art. 6(1)(f) — legitimate interest in informing one's own customers about services similar to those already subscribed, within the limits of Art. 130(4) of the Italian Privacy Code, with a free opt-out in every message. Sending beyond that perimeter requires consent (Art. 6(1)(a)) | Until you object. The send record (subject, body, segment, counts): 24 months |
| 9 | Member-to-club messaging | Message content, attachments, read state, thread blocking | Art. 6(1)(b) for the service function; Art. 6(1)(f) for evidential retention — legitimate interest in handling disputes and abuse reports | 24 months from the thread's last message. Messages are not automatically deleted when an account is closed: see §8 |
| 10 | Attributing sign-ups to PRs/promoters and measuring their contribution | membrs_pr cookie, promoter code, link to the membership | Art. 6(1)(f) — legitimate interest in correctly crediting promoters' work and settling accounts with clubs | Cookie: 30 days. The attribution recorded on the membership follows row 4 |
| 11 | Account security: rate limiting of login attempts, temporary lockout, suspicious-login alerts | Email typed, IP address, outcome and timestamp of the attempt | Art. 6(1)(f) — legitimate interest in protecting accounts and infrastructure against unauthorised access and automated attacks | 12 months. The automatic deletion routine for these records is being rolled out: see §8 |
| 12 | Audit log of administrative and technical actions | Acting user, action, object, IP address, user agent, timestamp | Art. 6(1)(f) — legitimate interest in being able to reconstruct who did what, for security, internal accountability and dispute handling | 24 months. The automatic deletion routine is being rolled out: see §8 |
| 13 | Log of messages received from providers (Stripe, Resend), to avoid duplicate processing, reconcile payments and diagnose errors | Full payloads, including customer and subscription identifiers, amounts, email addresses and delivery/open/click events | Art. 6(1)(f) — legitimate interest in accounting accuracy and in service continuity and diagnostics | 24 months. The automatic deletion routine is being rolled out: see §8 |
| 14 | Statistical analysis of site and platform usage (Google Analytics 4) | GA4 identifiers, event, URL, browser and device data, IP address in anonymised form | Art. 6(1)(a) — consent, given through the cookie banner and withdrawable at any time | Google retains user and event data for the period set on the GA4 property and in any case no longer than 14 months, which is the maximum available for a standard GA4 property. Aggregated reports remain available without a time limit |
| 15 | Handling complaints, disputes and chargebacks, and establishing, exercising or defending legal claims | Whatever data the specific case requires | Art. 6(1)(f) — legitimate interest in defending our rights | Until the dispute is resolved and for the applicable limitation periods thereafter |
| 16 | Managing the relationship with clubs: staff accounts and roles, invites, venue panel, calculating and settling payouts | Club and contact data, roles, invitees' emails, IBAN and account holder | Art. 6(1)(b) — performance of the B2B contract; Art. 6(1)(c) for the related tax obligations | For the life of the relationship; accounting data 10 years (row 4) |
| 17 | Validating a club's VAT number (VIES) and geocoding the venue address (Nominatim) | Club VAT number, address, city and country | Art. 6(1)(c) for the tax validation; Art. 6(1)(f) for geocoding — legitimate interest in showing the venue correctly to members | Outcome retained with the club record, for the life of the relationship |
| 18 | B2B commercial contacts: lead management, offering the service to industry operators | Venue name, city, country, contact person, email, phone, capacity, notes and deal stage | Art. 6(1)(b) — steps taken at the data subject's request prior to entering a contract; Art. 6(1)(f) — legitimate interest in promoting the service to professional operators | Unconverted leads: 24 months from the last contact. If the lead becomes a customer, row 16 applies |
| 19 | Responding to data subject requests (Arts. 15-22 GDPR) | Identification data and the content of the request, copy of the exported data | Art. 6(1)(c) — compliance with a legal obligation | Exports generated on request: signed link valid for 7 days. Record of the request: 24 months from closure |
The periods stated in the table are our retention policy. For the security and diagnostic logs (login_attempts, audit_log, webhook_log) and for chat messages, the automatic deletion routines are being rolled out: until they are in place, deletion is carried out manually, and in the meantime that data remains subject to the same access controls described in §9. You can request its deletion under §10.
We use the providers listed below, which process data on our behalf as processors under Article 28 GDPR (except where stated otherwise), under appropriate agreements.
| Provider | What it does for us | Where / notes |
|---|---|---|
| Stripe | Payments, subscriptions, invoicing, VAT determination (Stripe Tax) | Saba Events S.R.L. is the merchant of record. Card data never passes through our servers. Transfers outside the EEA: see §7 |
| Supabase | Database and authentication | Hosted on AWS eu-west-1 (Ireland) |
| Google Cloud / Firebase App Hosting | Hosting and compute for the platform (project sabaevents-membrs) | Primary region us-east4 — Northern Virginia, United States: the application's hosting and compute run in the United States. Transfers outside the EEA: see §7 |
| Resend | Sending transactional email and club broadcasts | Delivery, open and click events flow into the webhook log (§3.3). Transfers outside the EEA: see §7 |
| Google Analytics 4 | Usage statistics — only with consent | Exact consent behaviour described in §13. Transfers outside the EEA: see §7 |
| Google Wallet | Digital member card on Android | Receives the member's name and the card credential |
| Apple Wallet | Digital member card (.pkpass) | The pass is generated and signed by our servers and delivered to your device |
Expo (exp.host) and Apple APNs / Google FCM / browser push services | Push notification delivery | Notification content and the device token transit these providers' infrastructure. Transfers outside the EEA: see §7 |
| OpenStreetMap / Nominatim | Geocoding of club addresses | Venue data, not member data |
| VIES (European Commission) | Validation of clubs' VAT numbers | Venue data, not member data. It is a public service we query, not a processor |
| Vercel | Web Analytics on ops.membrs.world only (internal backoffice) | Not active on membrs.world or app.membrs.world. Vercel is not the platform's hosting provider |
Beyond these, data may be disclosed to: the clubs you subscribe to, within the limits described in §6; our professional advisers (accountant, lawyers) and, where necessary, public authorities, when disclosure is required by law or necessary to establish, exercise or defend a legal claim.
We do not sell your data and we do not pass it to third parties for their own marketing.
Our authorised personnel access data through the internal backoffice ops.membrs.world and the platform's administration tools, with named accounts and access recorded in the audit log (§3.3).
The club (or format) you subscribe to supplies the perks your plan promises, and needs some of your data to recognise you and honour them.
The club always sees: your name, the fact that you are one of its members, the plan you hold and its status, the date you first joined, your check-in activity (including your last entry and your history), your lifetime spend at that club, the tags the club itself has applied to you and any suspension. In chat it sees your name, your profile photo and the messages you send it. At the door, door staff see your name, your plan and the perks to honour.
The club sees your email address and phone number only if you switch those on yourself in your profile settings ("share email with the club", "share phone with the club"). They are off by default and you can change them at any time, on both web and app.
Two clarifications, for the sake of accuracy:
Controller relationship. Saba Events S.R.L. is the controller for the platform: it manages accounts, collects subscription payments, issues tax documents, sends service communications and keeps the technical logs. The club is an autonomous controller for what it does with your data for its own purposes: admission and access control in its own venue, its own customer-relationship activity and CRM, decisions on tags and suspensions, and the content of the messages it chooses to send you. The scope of what the club may do through the platform is governed by a data processing addendum (DPA) that forms an integral part of the club terms: it applies to every club by virtue of its acceptance of the club terms, with no separate act required. Collection and tracking of a signed copy of the addendum is being rolled out. To exercise your rights against the club you can contact the club directly; if you write to us, we will point you to the correct controller.
The database stays in the European Economic Area. Supabase hosts the database and authentication on AWS eu-west-1 (Ireland): that is where your data sits at rest.
Application hosting and processing, however, take place in the United States. The platform runs on Google Cloud / Firebase App Hosting in the primary region us-east4 (Northern Virginia, United States). Every request to the site and to the app is processed on US servers, which read from and write to the European database: your data is therefore also processed in the United States, in transit and in memory during processing. We do not claim that your data always stays in the EEA, because that would not be true.
The following providers are also non-EEA companies, or may process data outside the EEA: Stripe, Google (Google Cloud / Firebase App Hosting, Google Analytics 4, Google Wallet), Apple (Apple Wallet, APNs), Expo and Resend.
For those transfers we rely on the mechanisms provided by Chapter V GDPR, as follows:
You can ask us for a copy of the safeguards in place by writing to hello@membrs.world.
You can delete your account yourself, from your profile settings, without writing to us.
What happens immediately. All active memberships are cancelled immediately, with no refund of the remaining period. The account enters a 30-day grace period: within that window you can come back and restore it. Note: restoring reactivates the account, not the cancelled memberships — to be a member again you have to subscribe afresh.
What happens after 30 days. The profile is anonymised in place: name, email, phone, push tokens and the reference to your profile photo are removed or replaced, the sharing switches are reset, and your login identity is deleted from the authentication system. We do not, however, delete the linked records, because of accounting obligations and the defence of legal claims.
What survives deletion. We are explicit about this, because it is the part that matters:
| What remains | Why | For how long |
|---|---|---|
| Payment records, invoices, refunds and payouts | Legal obligation (Art. 2220 Italian Civil Code, VAT rules) | 10 years |
| Memberships, bookings and check-in history | They form part of the accounting and service-delivery records | Together with the accounting records, 10 years, linked to the anonymised profile |
Login security logs (login_attempts), which contain the email address typed and the IP address | Account security and abuse prevention | 12 months. The automatic deletion routine is being rolled out; until then these records are not altered by anonymisation |
Audit log (audit_log), with IP address and user agent | Traceability of actions, accountability, dispute handling | 24 months. The automatic deletion routine is being rolled out |
Webhook log (webhook_log), with the full messages received from Stripe and Resend, which may contain your real email address and email open and click events | Accounting reconciliation, idempotency, diagnostics | 24 months. The automatic deletion routine is being rolled out |
| Chat message content and attachments | Evidence of the member-club relationship, handling of disputes and reports | 24 months from the thread's last message. The automatic deletion routine is being rolled out; until then messages are neither deleted nor redacted by anonymisation |
| Tags applied by the club and the suspension record | Data processed by the club as an autonomous controller (§6) | Suspension: 90 days of effect. Retention of the tags and of the suspension record: 24 months |
| The profile photo file itself | None: this is a current technical limitation, not a choice. Anonymisation removes the link to the file but does not delete the file from storage, which is public-read: anyone who knew the exact URL could still open it | Until manual removal. A fix is being implemented; you can ask for immediate deletion by writing to hello@membrs.world |
| Records on Stripe's side (customer, subscriptions, invoices) | Accounting obligations and retention applied by Stripe as controller for its own purposes | Per Stripe's policies and tax law |
An honest note on anonymisation. For as long as the security logs and webhook logs exist, containing your email address in clear text, anonymisation of the profile is not irreversible in absolute terms: by cross-referencing those logs it would technically be possible to link the residual records back to you. That is why we treat them as personal data in full, with the same access controls, and are defining a retention period with automatic deletion for each. If you want those records deleted sooner, write to us: we assess the request under Article 17 GDPR and grant it unless a retention obligation applies or we need the data to defend a legal claim.
A platform administrator can also carry out the deletion at your request, skipping the grace period.
We apply technical and organisational measures appropriate to the risk (Article 32 GDPR). Concretely, and without promising more than we do:
us-east4, United States), the database and authentication on Supabase (AWS eu-west-1, Ireland); we rely on those providers' physical and logical security measures. On where data is located and the safeguards that apply, see §7.If a personal data breach occurs that poses a risk to your rights and freedoms, we notify the Garante within 72 hours and, where the risk is high, we also inform you, under Articles 33 and 34 GDPR.
Under Articles 15-22 GDPR you may exercise the following rights at any time:
Self-service tools. From your profile you can: download an export of your data, edit your personal details, turn sharing of your email and phone with the club on or off, unsubscribe from club broadcasts, and delete your account without writing to us. The self-service export covers profile, roles, memberships, bookings, refunds received and the log of actions on your account; to obtain a complete copy, including chat messages, push tokens, login logs and tags applied by the club, write to hello@membrs.world and we will prepare it for you.
How to exercise them. Write to hello@membrs.world (alternatively PEC: sabaevents@pec.it). We reply within one month of receiving the request; that period may be extended by two further months for particularly complex or numerous requests, in which case we tell you why within the first month. Where necessary we will ask for information to verify your identity, and for that purpose only.
Complaints. If you believe the processing of your data infringes the law, you may lodge a complaint with the
Garante per la protezione dei dati personali Piazza Venezia 11, 00187 Rome, Italy www.garanteprivacy.it
or with the supervisory authority of the Member State of your habitual residence, place of work or of the alleged infringement (Article 77 GDPR). Your right to an effective judicial remedy is unaffected.
We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR.
Some operations are automatic — subscription renewal, payment retries and the resulting suspension of access if a payment ultimately fails, the chronological ordering of waitlists, event capacity checks, and card validity at the moment of the scan — but these are the execution of predetermined contractual rules applied identically to everyone, not evaluations of your personal aspects. Discretionary decisions about you — a club suspension, a refund, closing an account — are always made by a person.
The service is for people aged 18 and over. It concerns nightlife venues that minors may not enter, so it is not intended for them and we do not promote it to them.
Age verification is based on a declaration made by the user at sign-up: we do not request identity documents and we do not store a date of birth, only the date and time the declaration was made. Not every sign-up path currently collects that declaration in the same way; we are aligning them.
If we learn that an account belongs to someone under 18, we cancel any memberships, close the account and delete or anonymise the data as quickly as possible, keeping only what is strictly necessary for the accounting obligations relating to payments already made. If you are a parent or guardian and believe a minor has given us their data, write to hello@membrs.world: we will act without asking you to justify the request.
The full list of the cookies and local storage we use — name, purpose, duration — is in the Cookie Policy, which forms an integral part of this notice.
In short: we use necessary technical cookies for authentication, to remember which role you are acting in, and to store your cookie choice; a functional cookie for light/dark theme; a 30-day attribution cookie when you arrive from a promoter's link; and Google Analytics 4 for usage statistics, only with your consent. We use no advertising or profiling cookies.
Exactly how Analytics consent works. Google's gtag.js script loads on every page, regardless of your choice. What your choice controls is Google's Consent Mode v2, which keeps every form of storage denied until you accept: analytics_storage, ad_storage, ad_user_data and ad_personalization. In practice this means that before consent no analytics cookie is set and no identifier is stored on your device, but the script is nevertheless present on the page and Google may receive cookieless pings. If you accept, only analytics_storage is enabled: advertising signals stay denied in all cases, the IP address is processed in anonymised form, and Google Signals is disabled.
Push notifications. The platform automatically requests permission to send you push notifications as soon as you enter your personal area: you do not have to switch anything on — it is the browser or the operating system that asks you to allow or deny, and the choice is yours. If you deny, we do not ask again. You can revoke the permission at any time in your browser or device settings; from that moment the token becomes unusable and is removed from our systems. Service notifications about your membership and bookings rest on the contract; clubs' promotional notifications follow row 8 of the table in §4.
Payments. Payment and billing-management pages are hosted by Stripe, on Stripe domains: any cookies set during payment are Stripe's cookies, governed by Stripe's own notice, and are not set on our domains.
We update this notice when the service changes, when our providers change, or when the law changes.
The version in force is always published at membrs.world/legal/privacy, with the last-updated date at the bottom. If a change is material — for example a new purpose, a new legal basis, a new processor receiving your data, or a change to retention periods that is unfavourable to you — we tell you before it takes effect, by email to the address associated with your account and/or through a prominent notice in the platform. Where the change concerns processing based on consent, we ask for fresh consent.
Previous versions are available on request at hello@membrs.world.
Saba Events S.R.L. Via di Salicchi, 711/X — 55100 Lucca (LU), Italy VAT and tax code 04726940234 — VAT ID IT04726940234 PEC: sabaevents@pec.it — SDI recipient code: 9SUB64Q Email: hello@membrs.world Sites: membrs.world · app.membrs.world
Data Protection Officer: none appointed (see §1). Governing law: Italian law. In case of any discrepancy between the Italian version and this English translation, the Italian version prevails.