EvenSide — Privacy Policy
1. Introduction
1.1. This Privacy Policy explains how [company legal name] (“EvenSide”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects your personal data when you use the EvenSide mobile application and related services (the “Platform”).
1.2. We are committed to protecting your privacy and handling your data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and all other applicable data protection legislation.
1.3. By using the Platform, you acknowledge that you have read and understood this Privacy Policy.
2. Data Controller
2.1. The data controller responsible for your personal data is:
[company legal name]
Registered Address: [registered address]
Company Number: [company number]
2.2. Data Protection Officer (DPO):
Email: [DPO email, e.g. dpo@evenside.gg]
For any questions or requests regarding your personal data, please contact our DPO at the email address above.
3. Data We Collect
We collect the following categories of personal data:
3.1. Account and Profile Data
| Data | Purpose | Legal Basis |
|---|---|---|
| Email address | Account creation, authentication, communications | Contract |
| Password (hashed) | Account security | Contract |
| Display name / Username | Profile identification | Contract |
| Avatar / Profile picture | Profile personalisation (optional) | Consent |
| Football position preference | Match organisation | Consent |
| Bio | Profile personalisation (optional) | Consent |
3.2. Location Data
| Data | Purpose | Legal Basis |
|---|---|---|
| GPS coordinates (latitude/longitude) | Finding nearby matches and venues | Consent |
| Reverse-geocoded location (city/country) | Displaying relevant content | Consent |
Note: Location data is collected only when you grant permission through your device settings. We use location data in real-time to show nearby matches and venues. GPS coordinates are not stored permanently on our servers.
3.3. Payment Data
| Data | Purpose | Legal Basis |
|---|---|---|
| Payment method details | Processing transactions | Contract |
| Transaction amounts and history | Booking records and refunds | Contract / Legal obligation |
| EvenSide fee records | Billing transparency | Contract |
| Refund status | Payment reconciliation | Contract |
Note: Payment card details are processed and stored by our payment processor, Stripe. We do not store your full card number on our servers. See Section 7 for details.
3.4. Match and Booking Data
| Data | Purpose | Legal Basis |
|---|---|---|
| Match details (title, format, date, time, price) | Match organisation | Contract |
| Participation records | Match management | Contract |
| Booking requests and status | Venue booking facilitation | Contract |
| OpenActive order data | Third-party venue booking | Contract |
3.5. Social and Communication Data
| Data | Purpose | Legal Basis |
|---|---|---|
| Friend requests and friendships | Social features | Consent |
| Chat messages (direct and group) | User communication | Contract |
| Group membership | Chat organisation | Contract |
3.6. Voting and Performance Data
| Data | Purpose | Legal Basis |
|---|---|---|
| Match votes (winner, MVP, elite players) | Match result determination | Contract |
| Player Skill Rating (PSR) | Player ranking and matchmaking | Legitimate interest |
| Fairplay score | Community safety | Legitimate interest |
| Commendations and avoidances | Player feedback system | Legitimate interest |
3.7. Notification Data
| Data | Purpose | Legal Basis |
|---|---|---|
| Push notification tokens | Delivering notifications | Consent |
| Notification preferences | Respecting your choices | Consent |
3.8. Administrative Data
| Data | Purpose | Legal Basis |
|---|---|---|
| Account tier and entitlements | Service delivery | Contract |
| Ban status and reason (if applicable) | Platform safety | Legitimate interest |
| Audit logs of admin actions | Accountability and dispute resolution | Legitimate interest |
3.9. Image Data
| Data | Purpose | Legal Basis |
|---|---|---|
| Avatar images | Profile display | Consent |
| Facility photos (admin only) | Venue information | Legitimate interest |
Note: Images are validated (max 5 MB, formats: JPEG, PNG, WebP, min 200x200 pixels) and automatically compressed (to approximately 1 MB) before storage.
3.10. Device and Local Data
| Data | Purpose | Legal Basis |
|---|---|---|
| Filter preferences | Personalised experience | Legitimate interest |
| App usage preferences | User interface state | Legitimate interest |
Note: This data is stored locally on your device using AsyncStorage and is not transmitted to our servers.
4. How We Use Your Data
We use your personal data for the following purposes:
4.1. Service Delivery (Legal Basis: Contract)
- Creating and managing your account
- Facilitating match creation, joining, and management
- Processing payments and refunds
- Booking venue slots on your behalf
- Enabling chat and social features
4.2. Platform Improvement (Legal Basis: Legitimate Interest)
- Maintaining and improving the Platform
- Analysing usage patterns to enhance features
- Debugging and resolving technical issues
- Ensuring platform security and preventing abuse
4.3. Communications (Legal Basis: Consent / Contract)
- Sending push notifications about matches, messages, and bookings
- Sending transactional emails (booking confirmations, refund notices)
- Responding to your support requests
4.4. Safety and Compliance (Legal Basis: Legitimate Interest / Legal Obligation)
- Enforcing our Terms of Service and Community Guidelines
- Investigating reports of misconduct
- Maintaining fairplay scores and ban records
- Complying with legal and regulatory obligations
5. Legal Bases for Processing
Under the UK GDPR, we process your data based on the following legal bases:
| Legal Basis | When We Rely on It |
|---|---|
| Contract | When processing is necessary to provide our services to you (account management, bookings, payments, chat) |
| Consent | When you opt in to specific processing (location services, push notifications, avatar upload, marketing) |
| Legitimate Interest | When processing is in our legitimate interests and does not override your rights (security, analytics, fairplay, PSR rankings) |
| Legal Obligation | When we are legally required to process data (tax records, regulatory compliance, fraud prevention) |
You may withdraw consent at any time (see Section 10). Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
6. Data Retention
We retain your personal data for the following periods:
| Data Category | Retention Period | Reason |
|---|---|---|
| Account and profile data | Duration of account + 3 years | Service delivery and legitimate business records |
| Payment and transaction records | 7 years after transaction | UK tax and accounting obligations (HMRC) |
| Chat messages | Duration of account + 1 year | Service delivery; users may delete individual chats |
| Match and booking records | 3 years after match date | Dispute resolution and records |
| Voting and performance data (PSR) | Duration of account + 1 year | Ranking integrity |
| Fairplay and ban records | Duration of account + 3 years | Community safety |
| Audit logs | 3 years | Accountability and compliance |
| Push notification tokens | Until sign-out or account deletion | Service delivery |
| Location data | Not stored permanently | Used in real-time only |
| Local device data (AsyncStorage) | Until app is uninstalled | Stored on your device only |
After the retention period, data is securely deleted or anonymised so that it can no longer be associated with you.
7. Third-Party Data Processors
We share your data with the following third-party service providers who process data on our behalf:
7.1. Supabase (Database, Authentication, Storage)
- Data shared: All account data, match data, chat messages, images
- Purpose: Backend infrastructure and data storage
- Location: [Supabase hosting region, e.g. EU (London)]
- Safeguards: Data Processing Agreement in place; Supabase complies with SOC 2 Type II
7.2. Stripe (Payment Processing)
- Data shared: Payment method details, transaction amounts, customer identity
- Purpose: Payment processing and fraud prevention
- Location: United States (with EU data processing)
- Safeguards: PCI DSS Level 1 certified; Data Processing Agreement in place; Standard Contractual Clauses for international transfers
7.3. Expo / Expo Application Services (Push Notifications, Build)
- Data shared: Push notification tokens, notification content
- Purpose: Delivering push notifications to your device
- Location: United States
- Safeguards: Data Processing Agreement; Standard Contractual Clauses
7.4. OpenActive / EveryoneActive (Venue Booking)
- Data shared: Your name, email address, booking details
- Purpose: Facilitating venue slot bookings
- Location: United Kingdom
- Safeguards: Data shared only when you initiate a booking; OpenActive standard compliance
7.5. Firebase / Google (Push Notification Delivery)
- Data shared: Device push tokens (for notification routing)
- Purpose: Push notification delivery via Firebase Cloud Messaging
- Location: United States (with EU processing)
- Safeguards: Google Data Processing Agreement; Standard Contractual Clauses
7.6. Sentry (Crash & Error Analytics)
- Data shared: Technical diagnostics (device model, OS version, app version, stack traces) and a pseudonymous user identifier (your account ID). We do not send your IP address (storage is disabled and the IP is masked), email, name, or message content — these are scrubbed before transmission.
- Purpose: Capturing crash reports and error logs to diagnose and fix app stability issues
- Location: European Union (Frankfurt, Germany) data region; limited account-level metadata may be processed in the United States
- Safeguards: Data Processing Agreement in place; for residual US processing we rely on the UK Extension to the EU–US Data Privacy Framework (the UK–US “data bridge”), with EU/UK Standard Contractual Clauses and the ICO International Data Transfer Addendum as a fallback. Events are retained per Sentry’s published, plan-dependent schedule (up to 90 days; 30 days on the free Developer plan).
8. International Data Transfers
8.1. Some of our third-party processors are located outside the United Kingdom, primarily in the United States (Stripe, Expo, Firebase).
8.2. Where data is transferred outside the UK, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner’s Office (ICO)
- Data Processing Agreements (DPAs) with each processor
- Assessment of the data protection laws in the recipient country
8.3. You can request a copy of the safeguards in place by contacting our DPO.
9. Data Security
9.1. We implement appropriate technical and organisational measures to protect your personal data, including:
- Encryption of data in transit (TLS/SSL)
- Password hashing (passwords are never stored in plain text)
- Row-Level Security (RLS) policies on our database to prevent unauthorised access
- JWT-based authentication with automatic token refresh
- Role-based access controls for administrative functions
- Regular security reviews
9.2. While we take reasonable precautions, no system is completely secure. We cannot guarantee the absolute security of your data.
9.3. In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the ICO within 72 hours as required by the UK GDPR.
10. Your Rights Under UK GDPR
You have the following rights regarding your personal data:
| Right | Description |
|---|---|
| Access | Request a copy of the personal data we hold about you |
| Rectification | Request correction of inaccurate or incomplete data |
| Erasure (“Right to be Forgotten”) | Request deletion of your personal data, subject to legal retention requirements |
| Restriction | Request that we limit how we process your data |
| Data Portability | Request your data in a structured, commonly used, machine-readable format |
| Object | Object to processing based on legitimate interest |
| Withdraw Consent | Withdraw consent for processing based on consent at any time |
| Complaint | Lodge a complaint with the Information Commissioner’s Office (ICO) |
How to Exercise Your Rights
- Email: [DPO email]
- Response time: We will respond to your request within 30 days
- Verification: We may need to verify your identity before processing your request
- Free of charge: Exercising your rights is free, unless requests are manifestly unfounded or excessive
ICO Contact Details
If you are not satisfied with our response, you have the right to complain to:
Information Commissioner’s Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Tel: 0303 123 1113
Website: https://ico.org.uk
11. Children’s Data
11.1. The Platform is not intended for children under the age of 13. We do not knowingly collect personal data from children under 13.
11.2. Users aged 13 to 17 may use the Platform only with verifiable parental or guardian consent. The parent or guardian is responsible for the minor’s data and account activity.
11.3. If we become aware that we have collected personal data from a child under 13 without appropriate consent, we will take steps to delete that data promptly.
11.4. If you believe we have inadvertently collected data from a child under 13, please contact our DPO immediately.
12. Automated Decision-Making
12.1. The Platform uses automated processing in the following areas:
- Player Skill Rating (PSR): Automatically calculated based on match results and peer votes
- Fairplay Score: Automatically adjusted based on player feedback
- Payment Recovery: Automatic retry of failed payment authorisations
12.2. These automated processes do not constitute solely automated decision-making that produces legal effects or similarly significant effects on you. Human oversight is maintained for all account sanctions and bans.
12.3. You have the right to request human review of any automated decision that significantly affects you.
13. Changes to This Policy
13.1. We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements.
13.2. We will notify you of material changes via the App or email before they take effect.
13.3. Your continued use of the Platform after the updated Privacy Policy takes effect constitutes your acceptance of the changes.
13.4. We encourage you to review this Privacy Policy periodically.
14. Contact Us
For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact:
- Data Protection Officer: [DPO email, e.g. dpo@evenside.gg]
- General enquiries: [support email]
- Address: [registered address]
- Website: https://www.evenside.gg