MyStableOS information
Privacy policy
How data is used across the website, professional app and MyStableOS rider portal.
Updated Version 1.1 · Last updated: 15 August 2026
1. Who processes your data?
MyStableOS is responsible for account, security, service operation, SaaS subscription, support and legal-compliance processing. The service is marketed to stables outside France; a parent living in France may use the portal of an eligible stable. The stable generally determines the purposes of its staff, rider, guardian, horse, scheduling, care and sales data, while MyStableOS provides the platform on its behalf. Privacy contact: support@mystableos.com.
2. Categories and sources
Depending on use: account, identity, language, role, staff, availability, riders and guardians, date of birth, level, bookings, attendance, optional health notes, horses and care, tasks, messages, announcements, invoices, payments, expenses, documents, photos, exports, preferences, push tokens, IP address, device, security logs and support exchanges. Data comes from you, the stable, a guardian, authorised users and authentication or payment providers.
3. Purposes and legal grounds
Data is used to perform the contract and requested journeys, synchronise devices, manage roles, secure the service, process payments, send selected notifications, provide support and comply with law. Depending on the context, the legal ground is contract, legitimate security and continuity interests, a legal obligation, consent — including optional health data — or the stable’s instructions under the ground it has selected.
4. Minors and health data
A portal account belongs to an adult rider or the minor’s legal guardian, who confirms authority to register the minor. Health notes are optional and sensitive and must be limited to information useful for safe participation. Their processing relies on the explicit agreement recorded in the journey and on the stable’s responsibilities.
5. Recipients
Access is limited to authorised stable users according to role, linked riders or guardians, authorised MyStableOS operators for service, security and support, advisers or authorities where required, and necessary providers. A request involving business data may be forwarded to the responsible stable.
6. Technical providers
Main providers are Supabase (data, authentication, storage and server functions), PowerSync/JourneyApps (offline synchronisation), Stripe (subscriptions and Connect direct charges for the stable), Vercel (website and Vercel Web Analytics), Resend (transactional email), Google/Firebase (push), and Google or Apple when their sign-in is selected. They receive only what is needed for their service, subject to their own legal obligations.
7. International transfers
Some providers or subprocessors may process data outside the EEA. Depending on the service, safeguards rely on an adequacy decision, a recognised framework or Standard Contractual Clauses and supplementary measures. Details may be requested from the privacy contact.
8. Device storage and cookies
The app may store a synchronised local database, session, language, security settings and a temporary journey handoff. Platform secure storage is used where available. The public site has no targeted advertising or marketing profiling. It uses Vercel Web Analytics, without cookies, for aggregated and anonymised page-view statistics; the tool may process the URL, referrer, approximate location, operating system, browser, device type and timestamp. MyStableOS does not send account identifiers or custom business events to it. Web storage outside this tool is used only for authentication, security, language or a requested operation.
9. Retention
Account data is kept while the service is used and then deleted or anonymised, subject to legal exceptions. Business data follows the stable relationship and obligations. Financial records may be retained for the legal period, including ten years in Belgium where applicable. A personal export remains available for 15 minutes, a stable export for 2 hours and a finance export for 30 days. Temporary links expire automatically; selected failure or security logs may be retained for up to 180 days. Backups follow provider rotation cycles.
10. Security
MyStableOS uses role and stable access controls, authenticated sessions, encrypted transport, private storage, temporary download links, reauthorisation for sensitive actions and server checks for payments and business writes. No system is risk-free; report suspected unauthorised access immediately to support@mystableos.com.
11. Your rights
Depending on the processing, you may request access, a copy, correction, erasure, restriction, portability, objection, consent withdrawal and not to be subject to a solely automated decision with legal effect. The app provides export and deletion after reauthentication. You may also contact support; reasonable proof of identity or authority may be requested. Responses are normally provided within one month under GDPR rules.
12. Payments
Stripe collects full card data in its interfaces. MyStableOS receives only identifiers, amounts, statuses and technical information required to create, reconcile, refund and evidence payments. For a Connect direct charge, the stable is the seller and processes transaction, refund and chargeback information with Stripe. MyStableOS prepares the technical case for the stable without handling the commercial dispute.
13. Advertising and automated decisions
MyStableOS does not sell or rent personal data to advertisers and does not perform advertising profiling. The service does not make a decision with legal effect solely by algorithm. Automated rules may enforce capacity, deadlines, access rights or security checks set by the stable or required for the service.
14. Updates and complaints
A material privacy update will be announced appropriately. To exercise a right, email support@mystableos.com. You may also complain to the Belgian Data Protection Authority, Rue de la Presse 35, 1000 Brussels, at dataprotectionauthority.be, or to the competent authority where you live or work.