Privacy Policy

Last updated: August 8, 2026

This policy explains what personal data Matchday (“we”, “us”) collects, why, and how it is handled, across the matchday.dev website and the Matchday platform and applications (the “Service”).

1. Two roles, two kinds of data

2. What we collect

ContextDataPurpose
Demo request formName, work email, organization, organization type, optional messageResponding to your request and following up about the Service
Account & sign-inName, email, role, organization; sign-in is via Google, so we do not store passwords for Google accountsAuthentication, authorization and account administration
Platform content (on behalf of organizations)Rosters and player profiles, schedules, travel details, documents (e.g. passports, medical clearances), form and wellness responses, policy acknowledgmentsProviding the team-operations features the organization uses
Security & auditIP address, user agent, timestamps of security-relevant actionsAccount security, abuse prevention, audit trail for organizations
Service telemetryTechnical logs and error reportsOperating, debugging and improving the Service
Mobile app (if you allow notifications)Push notification token, device modelDelivering operational notifications about your team — see section 4

We do not sell personal data, and we do not use platform content for advertising.

3. Cookies

The Service uses strictly necessary cookies only: a session cookie for signing in and a preference cookie (such as language). We do not run third-party advertising or tracking cookies on this website.

4. The Matchday mobile app

The Matchday app for iPhone is another way into the same account — there is no separate app account, and no sign-up inside the app. Signing in opens your system browser to complete authentication, and the resulting session credential is stored in the iOS Keychain.

5. Sensitive data and minors

6. Who processes data for us (subprocessors)

We use a small set of infrastructure providers to run the Service: cloud hosting and content delivery (Vercel), managed database (Neon), file storage (Cloudinary), sign-in (Google), and transactional email (Resend). Where organizations enable the optional AI assistant, the queried data is processed by the selected AI provider (such as OpenAI, Anthropic, Google or Groq) to generate the response; AI features can be disabled per organization. These providers process data only as needed to provide their function.

7. International transfers

Our infrastructure providers may store or process data in data centers in different countries. Where required, transfers rely on the providers’ standard safeguards (such as standard contractual clauses).

8. Retention

9. Deleting your account

Matchday accounts are provisioned by an organization — a club, academy or federation — and there is no public sign-up, so account deletion runs through that organization.

10. Security

Data is encrypted in transit; access is protected by role- and permission-based controls with organization-level isolation enforced in the application and database layers; security-relevant actions are logged. No system is perfectly secure, but security issues are treated with priority, and reports are welcome at hello@matchday.dev.

11. Your rights

Depending on your jurisdiction, you may have rights to access, correct, export, restrict or delete your personal data, and to object to certain processing. For data we control, email hello@matchday.dev and we will respond within a reasonable period. For data managed by your club or federation, we will route your request to them and support their response.

12. Changes

We may update this policy; material changes will be announced on this page with an updated date.

13. Contact

Privacy questions and requests: hello@matchday.dev. Help with the app, sign-in problems and account-deletion requests: support@matchday.dev (see Support).

Organizations that need a data-processing agreement (DPA), a subprocessor list for procurement, or answers to a security questionnaire: contact us and we’ll provide them.