Privacy Policy
Version 1.2 — Last updated: 2026-05-11
At a Glance
A short, plain-language summary. The full policy below controls in case of conflict.
What we collect
- Your email, name, and password (stored as a bcrypt hash).
- Payment is handled by Stripe — we never see your card number.
- Match, tournament, league, club, and ranking data you create or participate in.
- Optional player photos and club logos you upload.
- Technical data: IP address, device type, push notification token, basic usage logs.
What we do with it
- Run the Service (host your tournaments, sync scores, send notifications, calculate rankings).
- Bill you for paid Plans through Stripe.
- Keep the Service secure, prevent abuse, and comply with law.
- Send transactional emails (verify, reset password, account alerts).
What we don't do
- We do not sell your personal data — ever.
- We do not run ads or share your data with advertisers.
- We do not use third-party analytics or tracking cookies at launch.
- We do not make automated decisions with legal effects about you.
Your controls
- Export your data: in-app at GET /api/users/me/export.
- Delete your account: in-app at DELETE /api/users/me.
- Email [email protected] to exercise any right under GDPR, CCPA/CPRA, or PIPEDA.
1. Effective Date and Version
This Privacy Policy is effective 2026-05-11 (Version 1.2). Earlier versions are archived and available on request.
2. Data Controller
The data controller responsible for processing your personal data is:
- South Lab Technologies (1242033 B.C. LTD.), a corporation incorporated under the laws of British Columbia, Canada
- Incorporation Number: BC1242033
- Business Number: 745146878 BC0001
- GST Registration: 745146878RT0001
- Registered office: Vancouver, British Columbia, Canada
- Privacy contact: [email protected]
- Legal contact: [email protected]
When required by Article 37 of the GDPR or by other applicable law, we will appoint a Data Protection Officer (DPO). If you are an EEA resident, you may direct DPO inquiries to [email protected] with the subject line "DPO".
3. Categories of Personal Data We Collect
We collect the following categories:
- Account data: email address, password hash (bcrypt), display name, language preference, time zone, role (player, club admin, etc.).
- Profile data: optional player photo, gender (where relevant for tournament categories), age category, nationality flag, club affiliation.
- Authentication data: session tokens, refresh tokens, optional TOTP 2FA secret (encrypted).
- Payment data: subscription status, Plan tier, billing email, billing address, last 4 digits and brand of card (held by Stripe). We never store full card numbers, CVCs, or bank details.
- Sport activity data: tournaments, leagues, matches, scores, sets, ELO and ranking history, club check-ins, match comments, scheduling.
- Media: club logos and player photos uploaded to Cloudflare R2.
- Technical data: IP address (used for rate limiting, audit logging, and abuse prevention), user-agent, device type, app version, operating system, timestamps.
- Push tokens: Expo push notification tokens for the mobile app, used to deliver match and tournament notifications.
- Communications: emails you send to support@ or legal@, and our replies.
- Audit logs: security-relevant events such as failed logins, account lockouts, password changes, and 2FA changes.
4. Sources of Data
- Directly from you: when you register, complete your profile, configure clubs/tournaments, upload media, or contact us.
- Automatically: from your device and browser when you use the Service (IP, user-agent, timestamps).
- From third parties: Stripe shares billing status and payment metadata.
5. Legal Bases for Processing (GDPR Art. 6)
We rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)): to create and operate your Account, deliver paid Plans, run tournaments, sync scores, and provide support.
- Legitimate interests (Art. 6(1)(f)): to keep the Service secure, prevent fraud and abuse, monitor errors via Sentry, aggregate logs via BetterStack, improve features, and communicate service changes.
- Consent (Art. 6(1)(a)): for optional features such as push notifications and certain marketing communications. You can withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)): to retain financial records under Canada Revenue Agency record-keeping requirements (Income Tax Act, generally six (6) years) and to respond to lawful requests.
For sensitive categories of data, we do not process them. We do not collect health, biometric, racial, political, religious, or sexual-orientation data. Gender is collected only where relevant for tournament categories, may be left blank, and is treated as ordinary data, not sensitive data.
6. Purposes of Processing
We process personal data to:
- Provide, operate, and maintain the Service;
- Authenticate Users and protect Accounts (including 2FA, brute-force protection, and account lockout);
- Deliver tournaments, leagues, matches, scores, rankings, and live updates;
- Send transactional emails (verification, password reset, billing receipts);
- Send push notifications you have opted into;
- Process subscriptions and billing through Stripe;
- Detect, investigate, and prevent abuse, fraud, and security incidents;
- Monitor errors and system health;
- Improve and develop new features;
- Comply with applicable law and respond to lawful requests.
7. Cookies and Similar Technologies
At launch we use a minimal set of strictly necessary storage:
- Authentication cookies / tokens (JWT access tokens, rotating refresh tokens) — required to keep you logged in.
- Local preferences: language, theme, default sport, default club. Stored in your browser/device.
- CSRF protection as needed.
We do not currently use third-party advertising cookies or analytics cookies. Sentry collects technical error context (stack traces, user-agent, route) when an error occurs; this may include limited identifiers tied to your Account for debugging purposes.
If we add non-essential cookies in the future, we will request your consent through a banner and allow you to decline without losing access to essential features.
8. Sharing with Third Parties (Sub-Processors)
We share personal data only with vetted sub-processors who act on our behalf under written agreements that include confidentiality, security, and (where applicable) GDPR Art. 28 and standard contractual clauses:
- Stripe (United States / Ireland) — payment processing.
- Amazon Web Services — Elastic Beanstalk (United States / Ireland) — application hosting.
- MongoDB Atlas (United States / Ireland) — database hosting.
- Cloudflare R2 (global) — storage of media (player photos, club logos).
- Expo (United States) — mobile push notification delivery.
- Sentry (United States) — error monitoring.
- BetterStack (European Union) — log aggregation.
- SMTP transactional email provider — account verification, password reset, and other transactional emails.
We may also share data:
- With competent authorities, where required by law, regulation, court order, or to protect rights, safety, or property;
- In connection with a corporate transaction (merger, acquisition, financing, or asset sale), subject to confidentiality and to this policy's protections;
- With your explicit consent.
We do not sell personal data and we do not "share" personal data for cross-context behavioral advertising as those terms are defined under California's CCPA/CPRA.
9. International Transfers
Racketify is operated by South Lab Technologies (1242033 B.C. LTD.) in British Columbia, Canada, and our sub-processors operate in multiple regions including the United States, the European Union, and globally distributed networks (Cloudflare). Your data may therefore be transferred to and processed in countries other than your own.
For transfers from the EEA, the United Kingdom, or Switzerland to countries without an adequacy decision, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by appropriate technical and organizational safeguards (encryption in transit and at rest, access controls).
For transfers from Canada, we ensure that comparable protections apply under contract.
10. Data Retention
We retain personal data only as long as necessary:
- Active Accounts: data is retained while your Account is active.
- Account deletion: when you delete your Account, we retain core Account data for up to 90 days for audit, dispute resolution, and abuse prevention, after which it is deleted or irreversibly anonymized.
- Soft deletion / right to be forgotten: to preserve referential integrity of historical match results and tournament records, your name in past matches may be replaced with an anonymous label (e.g., "Deleted Player"); your contact details, photo, login data, and identifiers are erased.
- Financial records: invoices, payment records, and tax documentation are retained for seven (7) years (a conservative ceiling above the six-year minimum under the Canada Revenue Agency record-keeping rules).
- Security and audit logs: retained for up to 24 months.
- Backups: data may persist in encrypted backups for up to 35 days after deletion, after which it is overwritten.
11. Your Rights
Depending on where you live, you have the following rights. We honor all of them globally where feasible.
11.1 GDPR / UK GDPR (EEA, UK, Switzerland)
- Right of access (Art. 15): obtain a copy of your data.
- Right to rectification (Art. 16): correct inaccurate data.
- Right to erasure / "right to be forgotten" (Art. 17).
- Right to restriction (Art. 18).
- Right to data portability (Art. 20): receive your data in a structured, machine-readable format.
- Right to object (Art. 21), including to processing based on legitimate interests.
- Right to withdraw consent (Art. 7).
- Right to lodge a complaint with your local supervisory authority.
11.2 CCPA / CPRA (California)
- Right to know what personal information we collect, use, disclose;
- Right to delete personal information;
- Right to correct inaccurate personal information;
- Right to opt out of sale or sharing — Racketify does not sell or share personal information for cross-context behavioral advertising;
- Right to limit use of sensitive personal information — we do not collect sensitive PI as defined under CPRA;
- Right to non-discrimination for exercising your rights.
11.3 PIPEDA and Provincial Equivalents (Canada)
Right of access, correction, and challenge of compliance, in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and equivalent provincial laws, including British Columbia's Personal Information Protection Act (PIPA BC, S.B.C. 2003, c. 63) and Quebec's Act respecting the protection of personal information in the private sector (Law 25). Residents of British Columbia may also contact the BC Office of the Information and Privacy Commissioner (OIPC).
11.4 How to Exercise Your Rights
- Self-service export: while logged in, call GET /api/users/me/export from the dashboard or app to download your data.
- Self-service deletion: call DELETE /api/users/me or use "Delete Account" in your settings.
- By email: write to [email protected] with the subject line "Privacy Request". We may need to verify your identity. We respond within 30 days (GDPR) or 45 days (CCPA), extendable as permitted by law.
You can also lodge a complaint with the Office of the Privacy Commissioner of Canada, with the British Columbia Office of the Information and Privacy Commissioner (OIPC), with your EEA national supervisory authority, with the UK Information Commissioner's Office (ICO), with the Chilean data-protection authority (currently the Consejo para la Transparencia, transitioning to the Agencia de Protección de Datos under Ley 21.719), or with your U.S. state Attorney General as applicable.
12. Security
We implement industry-standard technical and organizational measures, including:
- Password hashing with bcrypt (no plaintext storage);
- Encryption in transit via TLS 1.2+;
- Encryption at rest on managed services (MongoDB Atlas, Cloudflare R2, AWS);
- Rotating refresh tokens and short-lived access tokens;
- Optional TOTP-based two-factor authentication;
- Brute-force protection with account lockout after repeated failed logins;
- Audit logging of security-relevant events;
- Least-privilege access to production data, restricted to authorized personnel;
- Sub-processor due diligence and contractual safeguards.
No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and the competent authorities as required by law (within 72 hours under GDPR Art. 33 where applicable).
13. Children and Minors
The Service is not directed at individuals under the age of 13 creating their own Account (or under 16 in the EEA, UK, and Switzerland). Minors below those ages may participate in the Service only when their Account or Player profile is registered and managed on their behalf by a parent, legal guardian, or an authorized club administrator who has obtained the necessary parental consent under applicable law.
We do not knowingly collect personal data directly from minors creating their own Accounts. Photographs, birth dates, and contact details of minors registered through a guardian or club administrator are processed solely for tournament and club operations, minimized to what is strictly necessary, and deleted on request from the minor's parent or guardian or upon termination of the relevant club membership.
If you believe a minor has registered their own self-managed Account in violation of this section, contact [email protected] and we will investigate and, where appropriate, suspend or delete the Account promptly.
14. Automated Decision-Making
We do not engage in automated decision-making, including profiling, that produces legal or similarly significant effects about you, within the meaning of GDPR Art. 22. ELO and ranking calculations are deterministic statistical computations based on match results you participate in, and do not constitute such automated decision-making.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced by email to your registered address and via a banner in the dashboard at least fifteen (15) days before they take effect. The "Last updated" date at the top reflects the most recent revision. Older versions are available on request.
16. Contact
For privacy questions, complaints, or to exercise your rights:
- Privacy: [email protected]
- Legal: [email protected]
- Postal: South Lab Technologies, Vancouver, British Columbia, Canada
If you reside in Canada, you may also contact the Office of the Privacy Commissioner of Canada (federal) and/or your provincial Information and Privacy Commissioner (e.g., the British Columbia OIPC). If you reside in the EEA, UK, or Switzerland and believe your rights have been infringed, you may contact your national data protection authority. If you reside in Chile, you may contact the relevant national authority designated under Ley 21.719 (Agencia de Protección de Datos Personales) once operational, or the Consejo para la Transparencia in the interim.