Skip to main content
  • EN
  • ES
  • FR

Privacy Policy

Effective date: August 16, 2026

1. Introduction

Scoreboard is a multi-sport live scoring application for squash, pickleball, tennis, padel, and badminton. It lets you score matches, share them live with spectators through short viewer codes, referee remotely, broadcast matches to YouTube, manage clubs and teams, and keep a personal player profile.

This Privacy Policy explains what personal data Scoreboard collects, why we collect it, how it is stored and shared, and the choices and rights you have. It applies to the Scoreboard mobile app and its related backend services.

A note up front on what we do not do. Scoreboard contains no advertising, attribution, or third-party analytics software. We do not use advertising identifiers (such as IDFA), we do not track you across other apps or websites, and we do not sell or share your personal data with data brokers or ad networks. Under Apple's App Tracking Transparency framework, none of the data described below is used to "track" you.

2. Who we are

Scoreboard is operated by Christian Firmi ("we," "us," or "our"), the data controller responsible for the personal data described in this policy. If you have any questions or wish to exercise your privacy rights, contact us at christianfirmi@gmail.com.

3. Data we collect and why

We collect only the data needed to operate the app's features. Almost all of it is data you provide directly or that is created when you use a feature. The categories below map to the actual data the app handles.

3.1 Account and authentication data

  • Email address — When you sign in with Apple, Google, or email, we receive and store your email address to authenticate your account and, where applicable, to identify your billing customer record. Sign in with Apple requests your name and email; if you choose Apple's private relay email, we receive the relay address.
  • Account identifiers — We assign and store account identifiers used to operate the app: a Firebase user ID (your core account identity), and, where relevant, a Google account identifier, a billing customer identifier, and an Apple in-app-purchase transaction identifier. These let us resolve your subscription, enforce ownership and permissions, and link your account across the services we use.

3.2 Profile data

  • Name — Your first name, last name, and/or full name are used as your player identity. Your name may appear on your profile, in the in-app user directory that lets others find you for team and club invites, on live scoreboards, and on iOS Lock Screen / Dynamic Island Live Activities. Your full name is also stored in a searchable user index (see Section 4.3 on public exposure).
  • Profile photo / avatar — If you choose one from your photo library, we store it as your profile picture.
  • Sports profile and preferences — Gameplay preferences you enter, such as your playing hand/swing (left, right, ambidextrous), preferred wall/court side, the sports you play, and per-sport formats. These personalize your profile and pre-fill match setup, and may appear in your profile QR code and in match records.
  • "Plays in…" area — An optional location/area for your profile (see Section 3.8 on location).

3.3 Club and team data

If you create or belong to a club or team, we store the club/team roster and management data:

  • Membership and rosters — Member account IDs, team compositions, and invitations (including pending invites keyed to a user).
  • "Local players" — Names you enter for non-app participants so they can appear on rosters and scoreboards.
  • Club business details — A club's name, code, color, logo and banner images, and — kept private to the club — its street address, phone number, and location. The phone number powers a "Call" action and the address powers directions on the club screen.

3.4 Match and scoring content

When you create and run matches, we store and (for live sharing) transmit the match content: match configuration, live scoring state (points, games, sets, serving state), team and player names, results, and the short viewer/admin share codes. This powers live scoring, spectator "watch by code," remote refereeing, and Live Activity cards.

3.5 Purchase and subscription data

For the Pro/Club subscription, we store your subscription entitlement (tier, status, and expiry) and the identifiers needed to reconcile purchases — for example, a Stripe customer/subscription/price ID (for web / non-iOS billing) or an Apple product ID and original transaction ID (for iOS in-app purchases).

We do not collect or store your payment card details. Card and payment information is entered only on Stripe's hosted checkout page (opened in a web browser) or Apple's in-app purchase sheet. The app never sees, receives, or stores your card number.

3.6 YouTube / Google broadcasting data (Google OAuth)

If you connect a Google account to broadcast a match to YouTube, we request your authorization using the following OAuth scopes: openid, Google profile (userinfo.profile), Google email (userinfo.email), and YouTube (youtube).

Using this authorization, we:

  • read your basic Google account information (email, name, profile photo URL, and account ID) to identify the connected account, and
  • create and manage a live broadcast on your own YouTube channel — including setting the broadcast title, description, and thumbnail, and streaming your live match video and audio to YouTube.

Your Google access token and basic Google profile data are cached only on your device and are revoked and deleted when you disconnect, sign out, or delete your account.

Google Limited Use disclosure. Scoreboard's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide and improve the broadcasting features you request, we do not transfer or sell it for advertising, and we do not use it for any purpose other than delivering the features you enabled.

3.7 Camera, microphone, and photo library

  • Camera — Used to broadcast your match to YouTube and to scan QR codes (player, club, event, and team join codes). We access the camera only while you are using these features.
  • Microphone — Used to capture audio for your live YouTube broadcast.
  • Photo library — Used only to let you pick images: a profile avatar, a broadcast overlay logo, a club logo/banner, and a broadcast thumbnail.
  • Live camera and audio — Your live broadcast's video and audio are streamed in real time to YouTube; they are not recorded or stored by Scoreboard. The broadcast's visibility (public, unlisted, or private) is set by you.

3.8 Location data

With your permission, and only while you are actively using the app (foreground only — we never request background or "Always" location):

  • Precise location (GPS coordinates) — Used, when you choose, to tag where an event or match takes place, to auto-suggest an event name, and to set your profile "Plays in…" area.
  • Coarse / derived location — We convert coordinates into a human-readable place (such as city, region, country, or postal code) for events, clubs, and your profile. This reverse-geocoding is performed through your device's operating-system location provider.

Location is captured only when you take an action that uses it, and only if you grant the permission.

3.9 Push notifications and device tokens

If you enable notifications, we store push tokens so we can deliver alerts (for example, "a club or event is live") and update your iOS Live Activity Lock Screen cards. This includes an Expo push token and, for Live Activities, an Apple Push Notification service (APNs) device token. Tokens are registered only after you have granted notification permission.

3.10 Crash and diagnostic data

In release (non-development) builds, we collect crash reports and non-fatal error diagnostics to improve stability, using Firebase Crashlytics. We do not attach your account identity to these reports; Crashlytics uses its own installation identifier. As a result, this diagnostic data is generally not linked to your identity.

4. How your data is stored and shared

We store data on your device and in trusted third-party services that act as our processors/sub-processors. We share personal data only as described below and only to operate the app. We do not sell your personal data.

4.1 On your device

Certain data is cached locally on your device (for example, your profile, cached images, live match state, and subscription cache) to make the app fast and available. Local data is removed when you sign out or delete your account, or when you delete the app.

4.2 Service providers (sub-processors)

  • Google Firebase (Authentication, Realtime Database, Cloud Storage, Cloud Functions, Crashlytics, App Check, Remote Config) — our primary backend: identity/authentication, real-time match data, image storage, server logic, crash reporting, and anti-abuse attestation. Data involved: name, email, photos, precise and coarse location, account identifiers, push tokens, subscription/entitlement metadata, match/gameplay content, crash diagnostics.
  • Stripe — subscription billing on web / non-iOS (hosted checkout and webhooks). Data involved: customer email, account identifier (as subscription metadata), and subscription/price/customer IDs. Card details are entered on Stripe's page and are never seen by the app.
  • Apple (StoreKit In-App Purchase, App Store Server Notifications, APNs, Sign in with Apple) — iOS subscription purchases and server notifications; push notifications and Live Activity updates; Apple ID sign-in. Data involved: Apple ID name and email (at sign-in), in-app-purchase transaction and product IDs, APNs device tokens, and Live Activity content (scores, player/team names).
  • Google / YouTube Data API — creating and managing live broadcasts on your own YouTube channel and streaming match video. Data involved: OAuth token; your Google email, profile, and account ID; broadcast title/description/thumbnail; live camera and microphone video/audio.
  • Google Sign-In — native Google authentication for Pro sign-in and YouTube connection. Data involved: Google account email, display name, profile photo URL, and account ID.
  • Expo (EAS push service) — relays server-originated push notifications to your device. Data involved: Expo push token; notification title/body/data (for example, event names and deep-link IDs).

Each provider processes your data under its own privacy terms. We share only what is necessary for the feature you are using.

4.3 Public and shared visibility within Scoreboard

Some features make certain information visible to other people by design. Please keep this in mind when deciding what to enter:

  • User directory / name search — Your full name is stored in a search index that is readable by other signed-in users (including anonymous spectators) so they can find you for team and club invites.
  • Public events — When an event's visibility is set to public, its match content — including player and team names, scores, and any location you attached — can be read by anyone.
  • Viewer share codes — Anyone who has a match's 6-character viewer code can read that live event, including scores and participant names.
  • Club directory — A club's name, code, color, logo, and banner may be listed publicly. A club's address, phone number, and precise location are kept private to the club and are not published to the public directory.
  • YouTube broadcasts — Broadcasts you create may be public, unlisted, or private, according to the setting you choose.

5. Anonymous accounts

To let spectators watch live matches without signing up, Scoreboard automatically creates an anonymous account when needed. An anonymous account is not linked to your name or email. If you later sign in with Apple, Google, or email, your account is upgraded to a stable, signed-in account. Because anonymous access is available to anyone, any content marked public or shared via a viewer code should be treated as accessible to the general public.

6. Data retention and account deletion

We keep personal data for as long as your account is active and as needed to provide the app's features, then delete or de-identify it unless we are required to keep it (for example, for tax, accounting, or legal reasons).

Deleting your account. You can delete your account from within the app. Account deletion:

  • cancels any active subscription managed through Stripe,
  • removes your account record and stored personal data from our backend,
  • removes your name from the player search index so you are no longer findable by other users,
  • removes your club and team memberships,
  • deletes uploaded files tied to your account (profile photo and broadcast overlay logo), and
  • deletes your Firebase Authentication user.

Disconnecting a Google/YouTube connection, signing out, or deleting your account also revokes and wipes your Google/YouTube authorization and locally cached personal data on the device.

Please note:

  • Third-party records — Records held by billing and platform providers (for example, Stripe and Apple purchase records) are retained by those providers under their own policies and legal obligations.
  • Crash diagnostics — Because crash reports are not linked to your account identity, they are not removed as part of account deletion; they are retained by Firebase Crashlytics under its retention settings.
  • Already-shared content — Content you previously published or shared (for example, a public event or a YouTube broadcast) may persist according to those features' and platforms' settings.

7. Children's privacy

Scoreboard is a general-audience sports scoring app. It is not directed to children, and we do not knowingly collect personal data from children under the age required by your local law (for example, 13 in the United States under COPPA, or the applicable age of digital consent in your country). The app does not collect a birth date or age and has no features designed for children, and broadcasts created through the app are marked as not "made for kids."

If you believe a child has provided us personal data, contact us at christianfirmi@gmail.com and we will take appropriate steps to delete it.

8. Your privacy rights

Depending on where you live, you may have rights over your personal data, including the rights to:

  • Access the personal data we hold about you and obtain a copy;
  • Correct inaccurate or incomplete data (much of which you can edit directly in your profile);
  • Delete your data (you can delete your account in-app, as described in Section 6);
  • Restrict or object to certain processing;
  • Data portability — receive your data in a portable format; and
  • Withdraw consent at any time (for example, by turning off location, camera, microphone, photo, or notification permissions in your device settings, or by disconnecting YouTube).

EEA/UK (GDPR). Our legal bases for processing are: performance of our contract with you (to provide the app and its features), your consent (for example, for location, camera/microphone, photos, notifications, and YouTube access), our legitimate interests (for example, keeping the app stable and secure), and compliance with legal obligations.

California (CCPA/CPRA). We do not sell or share your personal data for cross-context behavioral advertising, and we do not use it for such advertising. You have the right to know, to delete, to correct, and to non-discrimination for exercising your rights.

To exercise any of these rights, contact us at christianfirmi@gmail.com. We will respond within the time required by applicable law. You also have the right to lodge a complaint with your local data-protection authority.

9. International data transfers

We and our service providers may process and store your data in countries other than the one in which you live, including the United States. Where required, we rely on appropriate safeguards (such as the European Commission's Standard Contractual Clauses) for international transfers. By using Scoreboard, you understand that your data may be transferred to and processed in these locations.

10. Security

We use industry-standard measures to protect your data, including transport encryption, authenticated access, backend security rules, and anti-abuse attestation. No method of transmission or storage is completely secure, but we work to protect your personal data and to limit access to it.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, provide additional notice in the app. The current version is always available at https://thescoreboard-web.com/privacy.

12. Contact us

If you have questions, requests, or concerns about this Privacy Policy or your personal data, contact:

Christian Firmi
Email: christianfirmi@gmail.com
Governing jurisdiction: Canada