Legal
Privacy Policy
Effective date: July 31, 2026
If you are a Washington, Nevada, or Connecticut resident, please also read our Consumer Health Data Privacy Policy.
1. Who we are and how to reach us
This Privacy Policy explains how ScorePad ("ScorePad", "we", "us", "our") collects, uses, shares, and protects information when you use the ScorePad mobile application, the website at scorepad.me, the companion watch apps, and all related products, features, and services (collectively, the "Services").
ScorePad is the controller responsible for your personal information. For any privacy question, or to exercise your rights, contact us at privacy@scorepad.me. We aim to respond to every privacy request within the timeframes described in section 11.
This policy is written in English; any translation is provided for convenience and the English version controls in case of conflict.
2. The short version
• You control whether ScorePad accesses any health or fitness data. Health features are strictly opt-in, and you can turn them off or delete the data at any time.
• Your biometric data (heart rate, HRV, SpO2, skin temperature, strain, recovery, calories, and similar) is visible only to you. It is never shown to teammates, clubs, or other users.
• We never use health or fitness data for advertising, and we never sell it. We do not send health data to any AI feature.
• GPS route data you record can be shown to other participants of the same match (for example, a post-match movement map). You are asked to consent to this separately, and you can disable it.
• We use a small set of named service providers to run the app (listed in section 6). We require them to protect your data.
• Depending on where you live, you have rights to access, correct, delete, and export your data, and to withdraw consent. See sections 11–12.
• If you are a Washington, Nevada, or Connecticut resident, please also read our dedicated Consumer Health Data Privacy Policy at scorepad.me/health-data.
3. Information we collect
Account data. When you create an account we collect your email address, and — if you provide them — your name, username, profile photo, phone number, and authentication identifiers from any social sign-in provider you choose to use.
Match and app data. We collect the content you create in the app: match titles, scores, schedules, participants, teams, squads, clubs, tournaments, achievements, comments, and any statistics you enter or generate.
Device and diagnostic data. To keep the app stable and secure we collect technical data such as device model, operating-system version, app version, language, crash reports, and usage events. Crash and error data is processed by Sentry with personal identifiers minimised.
Purchase data. When you subscribe or buy an add-on, the transaction is processed by Apple or Google and recorded by our purchases provider (RevenueCat). We receive the subscription status and a pseudonymous purchaser identifier; we do not receive your full card number.
Health and fitness data. Only if you opt in, we access health and fitness data to show your activity and effort during matches. This data and its exact sources are described in detail in section 4.
Location data. If you enable movement tracking for a match, we collect GPS location samples (latitude, longitude, accuracy, and timestamps) from your phone or watch during that match, to build a track or movement map. Location tracking is per-match and off unless you turn it on.
4. Health, fitness, and location data (the important part)
Health and fitness data is among the most sensitive categories of personal information, so we treat it with extra care and describe it in full here.
It is always your choice. ScorePad does not read any health or fitness data unless you explicitly turn on health features and grant the underlying permission (through Apple Health, Android Health Connect, or by connecting a wearable account). You can revoke access at any time in your device settings or in ScorePad, and you can delete the data you have already shared (see section 7).
What we access, by source:
• Apple Health (iOS): step count, walking/running distance, active energy burned, heart rate, exercise time, workouts, and — if you enable movement tracking — workout GPS routes.
• Android Health Connect: steps, distance, heart rate, total and active calories burned, exercise sessions, and hydration.
• Whoop (if you connect it): recovery score, resting heart rate, heart-rate variability (HRV), blood-oxygen (SpO2), skin temperature, strain, average and maximum heart rate, and calories.
• Garmin (if you connect it): calories, distance, steps, heart rate, maximum heart rate, stress, and Body Battery (and, where available, HRV, VO2 max, SpO2, and respiration).
• Your phone or watch: GPS location samples during a match, if you enable movement tracking.
How we use it. We use this data only to show you your own activity and effort for the matches you choose to track — for example, calories and heart rate during a session, training-load and heart-rate-zone summaries, and an optional movement map. We do not use health or fitness data for advertising, profiling for marketing, or any purpose unrelated to showing you your activity.
Who can see it. Your biometric data (heart rate, HRV, SpO2, skin temperature, strain, recovery, calories, steps, distance, and derived metrics) is private to you and technically restricted so that no other user — including teammates, opponents, squad members, or club managers — can access it. The one exception is GPS movement tracks: if you enable movement tracking, the resulting track for a match can be shown to other participants of that same match (for example, a shared post-match heatmap). Because that is a form of sharing, we ask for your consent to it separately, and you can disable movement tracking at any time.
We never send health data to AI. ScorePad's AI features (such as match recaps) are built so that health and fitness data is never read by, or sent to, any AI provider. AI features receive only game data such as scores, participants, and statistics.
We never sell health data, and we never share it for cross-context advertising.
Not medical data. ScorePad is not a medical device and the health data it shows is for personal, informational, and fitness-tracking purposes only. It is not intended to diagnose, treat, or prevent any condition, and must not be relied on for medical, clinical, or emergency decisions. Metrics come from consumer sensors and third-party devices and may be inaccurate or delayed.
5. How we use information
We use personal information to: (a) provide and operate the Services (create and sync matches, invites, teams, notifications, and purchases); (b) secure accounts and prevent fraud and abuse; (c) diagnose and fix problems and improve the Services, using aggregated or de-identified data where possible; (d) show you your own health and activity for matches you track, where you have opted in; (e) communicate with you about the Services, including service and security notices; and (f) comply with law and enforce our Terms.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
6. How we share information, and our service providers
We share personal information only as described here. We do not sell it.
Service providers (processors) who help us run the Services, each under contractual data-protection obligations:
• Supabase — cloud database, authentication, and backend hosting (data hosted on Amazon Web Services infrastructure). Processes account, match, and — where you opt in — health data.
• RevenueCat — subscription and purchase management. Processes purchase status and a pseudonymous purchaser identifier.
• Sentry — crash and error diagnostics. Processes device and error data with identifiers minimised.
• OneSignal — push-notification delivery. Processes a device push token and notification content.
• Google (Gemini) — powers AI features such as match recaps. Receives only game data (scores, participants, statistics). Health and fitness data is never sent to Google's AI.
Independent parties who process data under their own terms:
• Apple and Google — app distribution and in-app purchases (as controllers of the store transaction).
• Whoop and Garmin — if you connect them, they provide the health data you authorise, under their own privacy policies.
Other sharing. We share information (a) with other users to the extent you choose (for example, match participants can see shared match data and, if you enable it, movement maps); (b) if required by law, legal process, or to protect rights, safety, and security; and (c) in connection with a merger, acquisition, or sale of assets, in which case we will notify you and this policy will continue to apply to the transferred data.
We maintain a current list of service providers and will update it as it changes. If you need it in writing, email privacy@scorepad.me.
7. Data retention and deletion
We keep personal information only for as long as we need it. Specifically:
• Account and match data: kept while your account is active. When you delete your account, this data is deleted or anonymised, and removed from active systems, with residual copies purged from encrypted backups within 30 days.
• Health and fitness data: kept until you delete it, disconnect the source, or delete your account. To delete your health data, you can delete your account, or email privacy@scorepad.me to request deletion of your health data specifically; we action such requests within 45 days. When you delete your account, all health data is deleted through the same 30-day backup-purge window.
• Wearable connection tokens (Whoop, Garmin): deleted immediately when you disconnect the wearable.
• Crash and diagnostic logs: retained for up to 90 days.
Disconnecting a wearable stops future imports and deletes the connection credentials; to also delete health data already imported, delete your account or email privacy@scorepad.me and we will action it within 45 days. We may retain limited information where the law requires it (for example, records of a purchase), for the period required.
8. Legal bases for processing (EEA/UK)
Where the EU or UK GDPR applies, we rely on the following legal bases:
• Contract (Art. 6(1)(b)): to provide the account, match, and core app features you request.
• Legitimate interests (Art. 6(1)(f)): to secure the Services, prevent abuse, and improve the product using aggregated or de-identified data. You may object to this processing.
• Consent (Art. 6(1)(a)): for optional features such as certain analytics.
• Explicit consent for health data (Art. 9(2)(a)): health and fitness data is special-category data, and we process it solely on the basis of your explicit consent, which you give when you enable health features and can withdraw at any time. Withdrawing consent does not affect processing carried out before withdrawal.
9. Security and breach notification
We protect personal information using encryption in transit (TLS), encryption at rest for our database, row-level access controls that restrict each user's data to that user, isolation of privileged credentials, and signature verification on data received from wearable providers. No method of transmission or storage is completely secure, so we cannot guarantee absolute security; please use a strong, unique password and protect your device.
If we become aware of a personal-data breach that is likely to affect you, we will notify the relevant supervisory authority and, where required, affected users, in accordance with GDPR Articles 33–34 and applicable US state breach-notification laws.
10. International data transfers
ScorePad is operated from Lebanon, and our service providers process data in the United States and other countries. This means your information may be transferred to, and processed in, countries whose data-protection laws differ from those where you live.
For transfers of personal data out of the EEA or UK, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) implemented by our processors, and, for health data specifically, on your explicit consent to the transfer (GDPR Art. 49(1)(a)). Lebanon has not received an EU adequacy decision; we therefore do not rely on adequacy for these transfers.
11. Your privacy rights
Depending on where you live, you may have the right to: access the personal information we hold about you; correct inaccurate data; delete your data; export/port your data; object to or restrict certain processing; and withdraw consent (including for health features) at any time.
How to exercise your rights. Email privacy@scorepad.me, or delete your account from within the app. We may need to verify your identity before acting. We will respond within one month (EEA/UK, extendable by two months for complex requests) and within 45 days (US state laws, extendable once where permitted).
You also have the right to lodge a complaint with your local data-protection authority. If you are in the EEA or UK and wish to contact our representative, email privacy@scorepad.me and we will direct your request appropriately.
12. United States state privacy rights
California (CCPA/CPRA). We collect the categories of personal information described in section 3, including sensitive personal information (precise geolocation and health data such as heart rate, HRV, and SpO2). We use and disclose sensitive personal information only to provide the Services you request and for the purposes described in this policy — not to infer characteristics about you. In the preceding 12 months we did not sell or share personal information for cross-context behavioural advertising. California residents may exercise the rights to know, delete, correct, and limit the use of sensitive personal information, and will not be discriminated against for doing so. To make a request, email privacy@scorepad.me. We do not sell or share your personal information; you do not need to opt out, but we honour any opt-out preference signals we are required to.
Washington, Nevada, and Connecticut consumer health data. Heart rate, HRV, SpO2, and related metrics are consumer health data under the Washington My Health My Data Act and similar Nevada and Connecticut laws. We describe how we handle that data, and the specific rights you have, in our separate Consumer Health Data Privacy Policy at scorepad.me/health-data.
Other states. Residents of other US states with comprehensive privacy laws have similar rights of access, correction, deletion, and portability, which they may exercise by emailing privacy@scorepad.me.
13. Children
The Services are not directed to children under 13 (or under the minimum digital-consent age in your country), and we do not knowingly collect personal information from them. Health and wearable features are restricted to users aged 16 or older, and we do not knowingly collect health or fitness data from anyone under 16.
If you believe a child has provided us personal information, contact privacy@scorepad.me and we will delete it.
14. Cookies and tracking
The ScorePad mobile app does not use advertising trackers and does not track you across other companies' apps or websites. Our website uses only the cookies strictly necessary for it to function; it does not use advertising or cross-site tracking cookies.
15. Changes to this policy
We may update this policy from time to time. When we do, we will revise the "Effective date" above and, where the changes are material, provide notice through the Services. For material changes to how we handle health or fitness data, we will ask you to review and, where required, re-consent before the change applies to that data.
16. Contact
Questions, requests, or complaints about privacy: privacy@scorepad.me. General support: support@scorepad.me.