EvenSideEvenSide.gg
TermsPrivacy

EvenSide — Privacy Policy

Last Updated: 4 August 2026

Effective Date: 4 August 2026


Related Policies

This Privacy Policy is supplemented by:

  • Data Storage & Cookies Policy
  • Terms of Service
  • Cancellation & Refund Policy
  • Community Guidelines

1. Introduction

1.1. This Privacy Policy explains how EVENSIDE.GG LIMITED (“EvenSide”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects your personal data when you use the EvenSide mobile application and related services (the “Platform”).

1.2. We are committed to protecting your privacy and handling your data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and all other applicable data protection legislation.

1.3. By using the Platform, you acknowledge that you have read and understood this Privacy Policy.

2. Data Controller

2.1. The data controller responsible for your personal data is:

EVENSIDE.GG LIMITED
Registered Address: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
Company Number: 16900383

2.2. Privacy contact:

Email: privacy@evenside.gg

For any questions or requests regarding your personal data, please contact us at the email address above.

3. Data We Collect

We collect the following categories of personal data:

3.1. Account and Profile Data

DataPurposeLegal Basis
Email addressAccount creation, authentication, communicationsContract
Mobile phone numberAccount creation and sign-in verification (SMS one-time codes)Contract
Password (hashed)Account securityContract
Display name / UsernameProfile identificationContract
Avatar / Profile pictureProfile personalisation (optional)Consent
Football position preferenceMatch organisationConsent
BioProfile personalisation (optional)Consent

3.2. Location Data

DataPurposeLegal Basis
GPS coordinates (latitude/longitude)Finding nearby matches and venuesConsent
Reverse-geocoded location (city/country)Displaying relevant contentConsent

Note: Location data is collected only when you grant permission through your device settings. We use location data in real-time to show nearby matches and venues. GPS coordinates are not stored permanently on our servers.

3.3. Payment Data

DataPurposeLegal Basis
Payment method detailsProcessing transactionsContract
Transaction amounts and historyBooking records and refundsContract / Legal obligation
EvenSide fee recordsBilling transparencyContract
Refund statusPayment reconciliationContract

Note: Payment card details are processed and stored by our payment processor, Stripe. We do not store your full card number on our servers. See Section 7 for details.

3.4. Match and Booking Data

DataPurposeLegal Basis
Match details (title, format, date, time, price)Match organisationContract
Participation recordsMatch managementContract
Booking requests and statusVenue booking facilitationContract
Venue availability lookupsShowing published venue availabilityLegitimate interest

3.5. Social and Communication Data

DataPurposeLegal Basis
Friend requests and friendshipsSocial featuresConsent
Chat messages (direct and group)User communicationContract
Group membershipChat organisationContract

3.6. Voting and Performance Data

DataPurposeLegal Basis
Match votes (winner, MVP, elite players)Match result determinationContract
Player Skill Rating (PSR)Player ranking and matchmakingLegitimate interest
Fairplay scoreCommunity safetyLegitimate interest
Commendations and avoidancesPlayer feedback systemLegitimate interest

3.7. Notification Data

DataPurposeLegal Basis
Push notification tokensDelivering notificationsConsent
Notification preferencesRespecting your choicesConsent

3.8. Administrative Data

DataPurposeLegal Basis
Account tier and entitlementsService deliveryContract
Ban status and reason (if applicable)Platform safetyLegitimate interest
Audit logs of admin actionsAccountability and dispute resolutionLegitimate interest

3.9. Image Data

DataPurposeLegal Basis
Avatar imagesProfile displayConsent
Facility photos (admin only)Venue informationLegitimate interest

Note: Images are validated (max 5 MB, formats: JPEG, PNG, WebP, min 200x200 pixels) and automatically compressed (to approximately 1 MB) before storage.

3.10. Device and Local Data

DataPurposeLegal Basis
Filter preferencesPersonalised experienceLegitimate interest
App usage preferencesUser interface stateLegitimate interest

Note: This data is stored locally on your device using AsyncStorage and is not transmitted to our servers.

3.11. Product Analytics Data

DataPurposeLegal Basis
Usage events (screens viewed, features used, actions such as creating or joining a match)Understanding and improving the PlatformLegitimate interest
Device model, operating system and app versionDiagnosing usage patterns across devicesLegitimate interest
Pseudonymous user identifier (your account ID)Linking events into usage patternsLegitimate interest

Note: Analytics events never include your message content, precise location, or payment details, and analytics event data is stored in the EU. See Section 7.6.

4. How We Use Your Data

We use your personal data for the following purposes:

4.1. Service Delivery (Legal Basis: Contract)

  • Creating and managing your account
  • Facilitating match creation, joining, and management
  • Processing payments and refunds
  • Booking venue slots on your behalf
  • Enabling chat and social features

4.2. Platform Improvement (Legal Basis: Legitimate Interest)

  • Maintaining and improving the Platform
  • Analysing usage patterns to enhance features, including through EU-hosted product analytics (PostHog — see Section 7.6)
  • Debugging and resolving technical issues
  • Ensuring platform security and preventing abuse

4.3. Communications (Legal Basis: Consent / Contract)

  • Sending push notifications about matches, messages, and bookings
  • Sending transactional emails (booking confirmations, refund notices)
  • Responding to your support requests

4.4. Safety and Compliance (Legal Basis: Legitimate Interest / Legal Obligation)

  • Enforcing our Terms of Service and Community Guidelines
  • Investigating reports of misconduct
  • Maintaining fairplay scores and ban records
  • Complying with legal and regulatory obligations

5. Legal Bases for Processing

Under the UK GDPR, we process your data based on the following legal bases:

Legal BasisWhen We Rely on It
ContractWhen processing is necessary to provide our services to you (account management, bookings, payments, chat)
ConsentWhen you opt in to specific processing (location services, push notifications, avatar upload, marketing)
Legitimate InterestWhen processing is in our legitimate interests and does not override your rights (security, analytics, fairplay, PSR rankings)
Legal ObligationWhen we are legally required to process data (tax records, regulatory compliance, fraud prevention)

You may withdraw consent at any time (see Section 10). Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

6. Data Retention

We retain your personal data for the following periods:

Data CategoryRetention PeriodReason
Account and profile dataDuration of account + 3 yearsService delivery and legitimate business records
Payment and transaction records7 years after transactionUK tax and accounting obligations (HMRC)
Chat messagesDuration of account + 1 yearService delivery; users may delete individual chats
Match and booking records3 years after match dateDispute resolution and records
Voting and performance data (PSR)Duration of account + 1 yearRanking integrity
Fairplay and ban recordsDuration of account + 3 yearsCommunity safety
Audit logs3 yearsAccountability and compliance
Push notification tokensUntil sign-out or account deletionService delivery
Location dataNot stored permanentlyUsed in real-time only
Product analytics eventsUp to 12 monthsProduct improvement; events are pseudonymous
Local device data (AsyncStorage)Until app is uninstalledStored on your device only

After the retention period, data is securely deleted or anonymised so that it can no longer be associated with you.

7. Third-Party Data Processors

We share your data with the following third-party service providers who process data on our behalf:

7.1. Supabase (Database, Authentication, Storage)

  • Data shared: All account data, match data, chat messages, images
  • Purpose: Backend infrastructure and data storage
  • Location: EU (Stockholm), Sweden
  • Safeguards: Data Processing Agreement in place; Supabase complies with SOC 2 Type II

7.2. Stripe (Payment Processing)

  • Data shared: Payment method details, transaction amounts, customer identity
  • Purpose: Payment processing and fraud prevention
  • Location: United States (with EU data processing)
  • Safeguards: PCI DSS Level 1 certified; Data Processing Agreement in place; Standard Contractual Clauses for international transfers

7.3. Expo / Expo Application Services (Push Notifications, Build)

  • Data shared: Push notification tokens, notification content
  • Purpose: Delivering push notifications to your device
  • Location: United States
  • Safeguards: Data Processing Agreement; Standard Contractual Clauses

7.4. Firebase / Google (Push Notification Delivery)

  • Data shared: Device push tokens (for notification routing)
  • Purpose: Push notification delivery via Firebase Cloud Messaging
  • Location: United States (with EU processing)
  • Safeguards: Google Data Processing Agreement; Standard Contractual Clauses

7.5. Sentry (Crash & Error Analytics)

  • Data shared: Technical diagnostics (device model, OS version, app version, stack traces) and a pseudonymous user identifier (your account ID). We do not send your IP address (storage is disabled and the IP is masked), email, name, or message content — these are scrubbed before transmission.
  • Purpose: Capturing crash reports and error logs to diagnose and fix app stability issues
  • Location: European Union (Frankfurt, Germany) data region; limited account-level metadata may be processed in the United States
  • Safeguards: Data Processing Agreement in place; for residual US processing we rely on the UK Extension to the EU–US Data Privacy Framework (the UK–US “data bridge”), with EU/UK Standard Contractual Clauses and the ICO International Data Transfer Addendum as a fallback. Events are retained per Sentry’s published, plan-dependent schedule (up to 90 days; 30 days on the free Developer plan).

7.6. PostHog (Product Analytics)

  • Data shared: Usage events (screens viewed, features used, actions such as creating or joining a match), device model, operating system and app version, and a pseudonymous user identifier (your account ID). We do not send message content, precise location, or payment details.
  • Purpose: Understanding how the Platform is used so we can improve it
  • Location: European Union (Frankfurt, Germany) — PostHog EU Cloud; analytics event data is stored in the EU
  • Safeguards: Data Processing Agreement executed with PostHog Inc.; EU data residency for event data; events retained up to 12 months

7.7. Twilio (SMS Delivery)

  • Data shared: Your mobile phone number, the content of sign-in text messages (your one-time code), and delivery metadata
  • Purpose: Delivering SMS one-time codes for account creation and sign-in
  • Location: United States
  • Safeguards: Data Processing Agreement incorporating EU/UK Standard Contractual Clauses and the UK International Data Transfer Addendum

8. International Data Transfers

8.1. Some of our third-party processors are located outside the United Kingdom, primarily in the United States (Stripe, Expo, Firebase, Twilio).

8.2. Where data is transferred outside the UK, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner’s Office (ICO)
  • Data Processing Agreements (DPAs) with each processor
  • Assessment of the data protection laws in the recipient country

8.3. You can request a copy of the safeguards in place by contacting us.

9. Data Security

9.1. We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encryption of data in transit (TLS/SSL)
  • Password hashing (passwords are never stored in plain text)
  • Row-Level Security (RLS) policies on our database to prevent unauthorised access
  • JWT-based authentication with automatic token refresh
  • Role-based access controls for administrative functions
  • Regular security reviews

9.2. While we take reasonable precautions, no system is completely secure. We cannot guarantee the absolute security of your data.

9.3. In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the ICO within 72 hours as required by the UK GDPR.

10. Your Rights Under UK GDPR

You have the following rights regarding your personal data:

RightDescription
AccessRequest a copy of the personal data we hold about you
RectificationRequest correction of inaccurate or incomplete data
Erasure (“Right to be Forgotten”)Request deletion of your personal data, subject to legal retention requirements
RestrictionRequest that we limit how we process your data
Data PortabilityRequest your data in a structured, commonly used, machine-readable format
ObjectObject to processing based on legitimate interest
Withdraw ConsentWithdraw consent for processing based on consent at any time
ComplaintLodge a complaint with the Information Commissioner’s Office (ICO)

How to Exercise Your Rights

  • Email: privacy@evenside.gg
  • Response time: We will respond to your request within 30 days
  • Verification: We may need to verify your identity before processing your request
  • Free of charge: Exercising your rights is free, unless requests are manifestly unfounded or excessive

ICO Contact Details

If you are not satisfied with our response, you have the right to complain to:

Information Commissioner’s Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Tel: 0303 123 1113
Website: https://ico.org.uk

11. Children’s Data

11.1. The Platform is intended for adults only. You must be at least 18 to create an account.

11.2. We do not knowingly collect personal data from anyone under 18.

11.3. If we become aware that we have collected personal data from a person under 18, we will close the account and take steps to delete that data promptly.

11.4. If you believe we have inadvertently collected data from a person under 18, please contact us immediately (Section 10).

12. Automated Decision-Making

12.1. The Platform uses automated processing in the following areas:

  • Player Skill Rating (PSR): Automatically calculated based on match results and peer votes
  • Fairplay Score: Automatically adjusted based on player feedback
  • Payment Recovery: Automatic retry of failed payment authorisations

12.2. These automated processes do not constitute solely automated decision-making that produces legal effects or similarly significant effects on you. Human oversight is maintained for all account sanctions and bans.

12.3. You have the right to request human review of any automated decision that significantly affects you.

13. Changes to This Policy

13.1. We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements.

13.2. We will notify you of material changes via the App or email before they take effect.

13.3. Your continued use of the Platform after the updated Privacy Policy takes effect constitutes your acceptance of the changes.

13.4. We encourage you to review this Privacy Policy periodically.

14. Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact:

  • Privacy contact: privacy@evenside.gg
  • General enquiries: support@evenside.gg
  • Address: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
  • Website: https://www.evenside.gg

This Privacy Policy was last updated on 4 August 2026.

TermsPrivacyCookiesCancellationCommunity GuidelinesSupport

© 2026 EvenSide.gg Limited