Privacy Policy

Last updated: 25 August 2026

This policy explains how Matchkit (“we”) processes personal data when you use www.matchkit.app, our progressive web app, or native apps. We designed Matchkit for amateur football clubs in Europe and we handle data under the GDPR.

Who is responsible

The controller for Matchkit is the operator of matchkit.app. For privacy requests email support@matchkit.app. Hosting is in the EU (application servers and a self-hosted Supabase database).

Data we collect

Account data: name, email, password hash or Google account identifiers, language, optional birthdate and avatar. Team data you enter: club and team names, roster, fixtures, availability, lineups, match events, messages, polls, duties, dues status, photos you upload, and public pages you choose to publish. Technical data: login sessions, push subscription endpoints, approximate device type, and (only if you accept analytics cookies) aggregated usage via Google Analytics. Payment data: if you subscribe to PRO, Stripe processes card details. We store Stripe customer and subscription IDs, not full card numbers.

How we use data

We use data to run the product: accounts, invitations, matchday tools, notifications (email and push), billing, abuse prevention, and support. Public team, competition, and match pages only show information you choose to make public.

Legal bases (GDPR)

Contract: providing the service you signed up for. Legitimate interests: keeping the service secure, understanding product usage in aggregate, and contacting you about service issues. Consent: optional analytics cookies, marketing emails if we ever send them (we currently send transactional mail only), and push notifications you enable. Legal obligation: invoices and accounting for paid plans.

Who we share data with

We do not sell personal data. Processors that help us run Matchkit include: our EU host, email delivery (Resend), payments (Stripe), optional Google sign-in, optional Google Analytics (only with cookie consent), and push providers (web push / FCM for native apps). AI match reports and fixture import send match or calendar text you submit to the configured AI provider when those features are enabled.

How long we keep data

We keep account and team data while your account is active. You can delete your account from profile settings; we then remove or anonymise personal data that is no longer needed, except records we must keep for legal or billing reasons. Calendar feed tokens and invitations expire or can be rotated by team staff.

Your rights

If you are in the EEA/UK you can access, correct, delete, or export your data, restrict or object to certain processing, and withdraw consent. Email support@matchkit.app. You can also complain to your local data protection authority (in Belgium: Gegevensbeschermingsautoriteit / APD).

Cookies

Essential cookies keep you signed in, remember language, and protect the session. Analytics cookies (Google Analytics) load only after you accept them in the cookie banner. You can change this anytime by clearing site data or using the banner again after reset.

Children and youth teams

Matchkit is used by amateur clubs that may include minors on a roster. Accounts should be created by an adult manager, parent, or the player if they are old enough to consent. Do not publish a public team page with a minor’s private contact details or birthdate. Birthdays on calendar feeds use display names, not email addresses.

Security

We use encrypted connections (HTTPS), hashed passwords via Supabase Auth, role-based access in the app, and database row-level security. No method of transmission is 100% secure; please use a unique password and keep invitation links private.

Changes

We may update this policy. The date at the top will change. Continued use after an update means you accept the revised policy where allowed by law.

Questions: support@matchkit.app