Privacy Policy

Last updated: October 1, 2026

This policy explains what personal data Matchday (“we”, “us”) collects, why, and how it is handled, across the matchday.dev website and the Matchday platform and applications (the “Service”).

1. Two roles, two kinds of data

2. What we collect

ContextDataPurpose
Demo request formName, work email, organization, organization type, optional messageResponding to your request and following up about the Service
Account & sign-inName, email, role, organization; sign-in is by email and password (we store only a salted hash of the password), Sign in with Apple, or GoogleAuthentication, authorization and account administration
Platform content (on behalf of organizations)Rosters and player profiles, schedules, travel details, documents (e.g. passports, medical clearances), form and wellness responses, policy acknowledgmentsProviding the team-operations features the organization uses
Security & auditIP address, user agent, timestamps of security-relevant actionsAccount security, abuse prevention, audit trail for organizations
Service telemetryTechnical logs and error reportsOperating, debugging and improving the Service
Mobile app (if you allow notifications)Push notification token, device modelDelivering operational notifications about your team — see section 4

We do not sell personal data, and we do not use platform content for advertising.

3. Cookies

The Service uses strictly necessary cookies only: a session cookie for signing in and a preference cookie (such as language). We do not run third-party advertising or tracking cookies on this website.

4. The Matchday mobile app

The Matchday app for iPhone is another way into the same account — there is no separate app account, and no sign-up inside the app. You sign in inside the app with your email and password or Sign in with Apple; only “Continue with Google” opens your system browser. The resulting session credential is stored in the iOS Keychain.

5. Sensitive data and minors

6. Who processes data for us (subprocessors)

We use a small set of infrastructure providers to run the Service: cloud hosting and content delivery (Vercel), managed database (Neon), file storage (Cloudinary), sign-in (Apple and Google), transactional email (Resend), push notifications to the iPhone app (Expo), and error reports from the website (Sentry, hosted in the EU, with no screen recording and no names, emails or form contents attached). When a manager uses the optional club lookup on the roster, the player's name is sent through Bright Data to Transfermarkt to find the player's club. AI is used only in two optional features on the website, never in the iPhone app, and never for receipt or passport photos: where an organization enables the AI assistant, the queried data is processed by the selected AI provider (such as OpenAI, Anthropic, Google or Groq) to generate the response; and when a manager shares a schedule or trip document with translation turned on, the activity titles and places they typed may be translated by such a provider. AI features can be disabled per organization. These providers process data only as needed to provide their function.

7. International transfers

Our infrastructure providers may store or process data in data centers in different countries. Where required, transfers rely on the providers’ standard safeguards (such as standard contractual clauses).

8. Retention

9. Deleting your account

Matchday accounts are provisioned by an organization — a club, academy or federation — and there is no public sign-up, so account deletion runs through that organization.

10. Security

Data is encrypted in transit; access is protected by role- and permission-based controls with organization-level isolation enforced in the application and database layers; security-relevant actions are logged. No system is perfectly secure, but security issues are treated with priority, and reports are welcome at hello@matchday.dev.

11. Your rights

Depending on your jurisdiction, you may have rights to access, correct, export, restrict or delete your personal data, and to object to certain processing. For data we control, email hello@matchday.dev and we will respond within a reasonable period. For data managed by your club or federation, we will route your request to them and support their response.

12. Changes

We may update this policy; material changes will be announced on this page with an updated date.

13. Contact

Privacy questions and requests: hello@matchday.dev. Help with the app, sign-in problems and account-deletion requests: support@matchday.dev (see Support).

Organizations that need a data-processing agreement (DPA), a subprocessor list for procurement, or answers to a security questionnaire: contact us and we’ll provide them.