Privacy Policy
Last updated: August 8, 2026
This policy explains what personal data Matchday (“we”, “us”) collects, why, and how it is handled, across the matchday.dev website and the Matchday platform and applications (the “Service”).
1. Two roles, two kinds of data
- Data we control. When you visit this website, book a demo, or contact us, we decide how that data is used; we act as the data controller.
- Data we process for organizations. Inside the platform, clubs, academies and federations manage their own rosters, schedules, documents and forms. That data belongs to the organization; we process it on the organization’s behalf and under its instructions. Questions about how a specific club handles your data should go to that club first, and we will support them in answering.
2. What we collect
| Context | Data | Purpose |
|---|---|---|
| Demo request form | Name, work email, organization, organization type, optional message | Responding to your request and following up about the Service |
| Account & sign-in | Name, email, role, organization; sign-in is via Google, so we do not store passwords for Google accounts | Authentication, authorization and account administration |
| Platform content (on behalf of organizations) | Rosters and player profiles, schedules, travel details, documents (e.g. passports, medical clearances), form and wellness responses, policy acknowledgments | Providing the team-operations features the organization uses |
| Security & audit | IP address, user agent, timestamps of security-relevant actions | Account security, abuse prevention, audit trail for organizations |
| Service telemetry | Technical logs and error reports | Operating, debugging and improving the Service |
| Mobile app (if you allow notifications) | Push notification token, device model | Delivering operational notifications about your team — see section 4 |
We do not sell personal data, and we do not use platform content for advertising.
3. Cookies
The Service uses strictly necessary cookies only: a session cookie for signing in and a preference cookie (such as language). We do not run third-party advertising or tracking cookies on this website.
4. The Matchday mobile app
The Matchday app for iPhone is another way into the same account — there is no separate app account, and no sign-up inside the app. Signing in opens your system browser to complete authentication, and the resulting session credential is stored in the iOS Keychain.
- Notifications. If you grant notification permission, the app registers a push token and your device model so notifications can be delivered. These are used only for operational messages about your own team — a form to fill in, a policy to acknowledge, a published schedule, a change to a booking you are part of. We do not send marketing push notifications. Turning notifications off in iOS Settings stops delivery, and signing out removes the device registration.
- No tracking, no advertising. The app contains no advertising SDK and no third-party analytics SDK. It does not collect the advertising identifier (IDFA) and does not track you across other apps or websites, which is why it never asks for tracking permission.
- Device permissions. Notifications are the only operating-system permission the app requests. It does not access your camera, photo library, location, contacts or microphone.
5. Sensitive data and minors
- Organizations may store identity documents, medical clearances and wellness responses in the platform. Access to these is restricted by per-feature permissions; medical form answers are additionally gated to authorized medical-permission holders, and sensitive fields are masked for view-only roles.
- Where an organization manages youth players, the organization is responsible for the legal basis (such as guardian consent) for those players’ data. Player accounts are provisioned by the organization; players cannot self-register from the public website.
6. Who processes data for us (subprocessors)
We use a small set of infrastructure providers to run the Service: cloud hosting and content delivery (Vercel), managed database (Neon), file storage (Cloudinary), sign-in (Google), and transactional email (Resend). Where organizations enable the optional AI assistant, the queried data is processed by the selected AI provider (such as OpenAI, Anthropic, Google or Groq) to generate the response; AI features can be disabled per organization. These providers process data only as needed to provide their function.
7. International transfers
Our infrastructure providers may store or process data in data centers in different countries. Where required, transfers rely on the providers’ standard safeguards (such as standard contractual clauses).
8. Retention
- Demo-request details: kept while we are in contact about the Service, then deleted.
- Account and platform content: kept while the organization’s account is active; deleted on verified request after closure, subject to legal obligations and fixed backup roll-off.
- Security and audit logs: kept for a limited period appropriate to security and compliance purposes.
9. Deleting your account
Matchday accounts are provisioned by an organization — a club, academy or federation — and there is no public sign-up, so account deletion runs through that organization.
- You can start a deletion request from inside the app, under Account → Delete my account, which opens a pre-filled email. You can also email support@matchday.dev directly, from the address you sign in with.
- Because the organization is the controller of the roster, document and form data it holds, we verify the request with them before acting, and they may be required to retain certain records — for example safeguarding or financial records — for a period set by law or by their governing body.
- We respond to deletion requests within 30 days. Deleting your account ends your access to the Service; organization-held content is then handled under the retention rules in section 8.
10. Security
Data is encrypted in transit; access is protected by role- and permission-based controls with organization-level isolation enforced in the application and database layers; security-relevant actions are logged. No system is perfectly secure, but security issues are treated with priority, and reports are welcome at hello@matchday.dev.
11. Your rights
Depending on your jurisdiction, you may have rights to access, correct, export, restrict or delete your personal data, and to object to certain processing. For data we control, email hello@matchday.dev and we will respond within a reasonable period. For data managed by your club or federation, we will route your request to them and support their response.
12. Changes
We may update this policy; material changes will be announced on this page with an updated date.
13. Contact
Privacy questions and requests: hello@matchday.dev. Help with the app, sign-in problems and account-deletion requests: support@matchday.dev (see Support).