Last updated 18 September 2026
Amarelo is a small volunteer-run association, and this page explains what we do with personal data: yours as a visitor to this site, and yours as a student with an account in our dashboard. We collect what we need to run classes and nothing beyond that. We never sell data or track you across the web.
Verein Amarelo, Josefstrasse 186, 8005 Zürich, Switzerland, is responsible for the data described here. Write to forro@amarelo.ch with any question about it. Our full details are on the Legal Notice page.
You can read every public page without an account, and we store nothing about you when you do. This site runs no analytics and no advertising, and sets no tracking cookies.
Two parts of our pages are loaded from other companies, which means those companies see your IP address when they load. The map showing where we teach comes from Google Maps, and the spam check on our contact form comes from Cloudflare. Our hosting provider, Vercel, keeps short-lived server logs that include IP addresses, which is what lets us investigate errors and abuse.
The contact form sends us your name, your email address and your message as an email, delivered through our mail provider Resend. Nothing from the form is saved to our database. Your message stays in our inbox for as long as it is useful to the conversation.
If you take classes with us, you get an account. It holds your name, email address, phone number if you gave us one, your dance level for leading and following, your attendance, your payment plan and how many sessions it has left.
Teachers also keep teaching notes: level votes, short evaluations, and a record of when someone from our team last reached out to you. This is how we keep track of who is progressing and who we have not seen in a while. Other students never see any of it.
Your login is handled by Supabase, our database and authentication provider. If you use a password, it is stored by them in hashed form and we never see it. If you use a passkey, your device keeps the key and we only ever see the public half of it.
A profile photo is optional. It exists so whoever is working the door recognizes you, and only our staff can see it, never other students. You can replace or remove it from your profile page at any time.
If you apply for a reduced rate as a student, while unemployed, or with a KulturLegi card, you upload a document as proof. Those documents live in a separate private storage area that only you and our staff can open, through links that expire after a few minutes.
Online payments run through our payment provider, Payrexx. Your card or TWINT credentials go straight to them and never reach our servers. What we keep is the amount, the method, whether it succeeded, and a reference that ties it to your account. Your receipt comes from them, and they handle that data under their own privacy policy.
Payment records are also shared with the bookkeeper who prepares the association’s annual accounts. That is the only place outside this app and our inbox where student data goes.
Photos and videos are taken at classes and events and published on our social media and in print. As stated in our Code of Conduct, registering for a class or event means you consent to that. If something is published that you are not comfortable with, tell us and we will take it down.
We use a few service providers, each for one job and each bound to handle the data only on our instructions:
Our database, logins and uploaded files are hosted in Zürich, Switzerland. The website itself is served from Frankfurt, Germany, and our payment provider is a Swiss company. The providers handling our email, spam check and map operate internationally and may process data outside Switzerland and the EU, under contractual safeguards that hold them to an equivalent level of protection.
We do not delete accounts on a schedule. Your record stays with us while you dance here, and afterwards too, so that coming back years later means picking up where you left off rather than starting over.
You can end that at any time by deleting your account from your profile page, or by asking us to do it for you. Deleting removes your name, email address, phone number, profile photo, any documents you uploaded and your login. Your attendance and payment entries stay, with everything identifying stripped from them, because the association’s accounts still have to add up.
You can ask what we hold about you, get a copy of it, correct anything wrong, ask us to delete it, or object to how we use it. Write to forro@amarelo.ch and we will answer. If you think we have handled your data badly, you can complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC), or to the data protection authority where you live if that is in the EU.
We set no analytics or advertising cookies. When you log in, your browser keeps a login token in its local storage so that you stay signed in; clearing your browser data signs you out. The embedded map and the spam check may set cookies of their own when those parts of a page load.
The site runs over HTTPS, and Supabase hashes passwords so that we never hold yours. Inside the dashboard, access depends on your role: a student reaches only their own data, and staff reach only what running the school requires. Uploaded documents sit in private storage that nobody can reach through a public link.
If what we do with data changes, we update this page and the date at the top of it.