MAD Members ClubMAD

Legal

Privacy Policy

MAD Members Club is operated by WE ARE MAD GUIDE S.L. · Madrid, Spain. Version 2 · Last updated 7 August 2026. This policy is governed by the GDPR (Regulation EU 2016/679) and the Spanish LOPDGDD.

1. Data Controller

The controller of your personal data is WE ARE MAD GUIDE S.L. ("MAD MEMBERS CLUB", "we", "us"), a company registered in Spain with Tax Identification Number (NIF) B67837211 and registered office at Calle Justiniano 12, Bajo izquierda 2, 28004 Madrid, Spain. For any question about this policy or your data, contact us at contact@madmembersclub.com.

2. Data We Collect

We collect only the data we need to provide the membership and concierge service:

  • Identity and contact details: name, email address and phone number.
  • Date of birth: to confirm eligibility (18+), apply venue age requirements, and offer the birthday service and greetings.
  • Membership and payment status: your tier, status and billing history. Payments are processed by Stripe — we never receive or store your full card number.
  • Concierge communications: the messages you exchange with us on WhatsApp and by email, and the reservation, guest-list and event requests you make.
  • Member portal data (Lifestyle): your account, class bookings, perk redemptions, attendance and your membership QR pass code.
  • Technical data: strictly necessary session/authentication cookies and basic security logs (see our Cookie Policy).

3. Why We Use It, and Our Legal Basis

We process your data for the following purposes and on the following legal bases under Article 6 GDPR:

  • To provide the service — manage your membership, place you on guest lists, arrange tables and reservations, and run the member portal: performance of our contract with you.
  • To process payments and keep accounting records: performance of our contract and compliance with a legal obligation.
  • To send you operational messages about your membership and bookings by email and WhatsApp: performance of our contract.
  • To send birthday greetings and, if you opt in, news and offers: your consent, which you can withdraw at any time.
  • To prevent fraud and misuse, keep the service secure, and improve it: our legitimate interest in operating a safe, reliable service.
  • To comply with legal, tax and accounting obligations: compliance with a legal obligation.

4. Who We Share It With

We do not sell your data. We share it only with service providers who process it on our behalf under a data-processing agreement, and only as needed:

  • Stripe — payment processing (Stripe Payments Europe, Ltd.).
  • Sanity and Vercel — hosting of the website and member records.
  • Supabase — authentication and data for the Lifestyle member portal.
  • Resend and Brevo — sending transactional and membership emails.
  • Respond.io and WhatsApp / Meta — delivering the WhatsApp concierge conversation.
  • Google — only if you choose to sign in to the portal with Google.
  • Partner venues and studios — we share what the venue needs to honour the benefit you request: your name for a guest list, and your name and email address on the class or event you book, so the studio can see who is coming and check you in. We never share your date of birth, phone number or payment details with them.

We may also disclose data where required by law or to protect our legal rights.

5. International Transfers

Most of our providers process data within the European Economic Area (EEA). Where a provider (such as WhatsApp / Meta or Google) transfers data outside the EEA, that transfer is protected by an adequacy decision of the European Commission or by Standard Contractual Clauses, together with additional safeguards where required.

6. How Long We Keep It

We keep your data only as long as necessary: for the life of your membership and while you interact with us; billing and accounting records for the period required by Spanish commercial and tax law (generally up to six years); and marketing data until you object or withdraw consent. After that, we delete or anonymise your data.

7. Your Rights

Under the GDPR and the Spanish LOPDGDD you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data (right to be forgotten), where applicable.
  • Restrict or object to certain processing.
  • Data portability — receive your data in a structured, machine-readable format.
  • Withdraw consent at any time, without affecting processing already carried out.

To exercise any of these rights, email contact@madmembersclub.com (we may ask you to confirm your identity). You also have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD — www.aepd.es) if you believe your data has been handled unlawfully.

8. Data Security

We apply appropriate technical and organisational measures to protect your data: encrypted connections, access controls, trusted processors, and payment handling delegated to Stripe so your card data never reaches our systems. No system is perfectly secure, but we work to keep your data safe and to notify you and the authorities of any breach as required by law.

9. Minors

Our services are intended only for adults aged 18 or over. We do not knowingly collect data from minors. If you believe a minor has provided us data, contact us and we will delete it.

10. Cookies

We use only strictly necessary cookies to keep the site and the member portal working. We do not use advertising or tracking cookies. Full details are in our Cookie Policy at madmembersclub.com/legal/cookies.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will publish the updated version here and, where a change materially affects you, notify you by email.