Kebijakan Privasi
Terakhir diperbarui: 7 Juli 2026
Dokumen ini disediakan dalam bahasa Inggris.
Padelyst is a padel scoring app for iPhone and Apple Watch and a set of free web tools at padelyst.app, operated by Mavens Lab (“we”, “us”). This policy explains what data Padelyst handles and why. The short version: you can score matches, save your history, and run tournaments anonymously, identified only by a random device identifier — no account needed. Signing in is optional; if you choose to, we store your email address so your history can sync across your devices. We never show ads and we never sell your data.
What we collect
In the app
- An anonymous device identifier. The app generates a random identifier (a UUID) and stores it in your device’s Keychain. Unless you choose to sign in (see below), it is not linked to your name, email, Apple ID, phone number, or any other personal identity. The identifier scopes your match history and player roster to your device.
- Match history. Scores, sets, points, timestamps, match settings, and any labels you enter yourself — player names, locations, and notes. These labels are stored exactly as you type them, so if you enter a real name it becomes part of your match data.
- Player roster. The list of player names you add in the app, associated with your device identifier.
Signing in (optional)
Scoring and history work fully anonymously. If you want your match history to sync across more than one device, you can optionally sign in with Apple, Google, Facebook, or a one-time email link. We use Firebase Authentication (a Google service) to verify your sign-in. When you sign in:
- We store your email address and an account identifier, and link the device(s) you sign in on to that account.
- Your match history and rosters become associated with your account, so they sync to every device where you sign in.
- We never receive your social-account password, and we never post anything to those accounts.
You can sign out at any time, which unlinks the device, or delete your account entirely from the app’s settings (see Your rights below). Authentication is handled by Google Firebase and is also subject to Google’s privacy policy.
Health and fitness (Apple Watch)
While you score a match on Apple Watch, the app can start a workout and read your live heart rate and active calories from Apple Health (HealthKit), and save the match as a workout so it counts toward your activity rings. This is optional and you control it through Apple’s Health permissions. These readings are used only to display them on your wrist during the match — they stay on your device and are never sent to our servers or included in your saved match data.
Live tournament sessions and leagues
When you create or join a live session (Americano, Mexicano, Round Robin) or a league (a multi-event competition with members, teams, and standings), the player names and scores entered into it are stored so that everyone involved sees the same standings. Live sessions are visible to anyone who has the session link or code. Treat them like a scoreboard at the club: use first names or nicknames if you would rather not show a full name. Live sessions are wiped from the live store after a period of inactivity; sessions that were finished with recorded results are archived so their final standings remain viewable at the same link.
On the website
The padelyst.app website uses PostHog analytics to understand how the site and tools are used. This captures page views, product events (for example, creating a session or reading a blog post), and errors/exceptions. Like any analytics service, it also receives technical information inherent to a web request: browser and device type, and an approximate location derived from your IP address. We use this data in aggregate to improve Padelyst — not to identify you. If you are in the EU/EEA, the UK, or Switzerland, analytics runs only if you allow it in the cookie banner — until you accept (or if you decline), nothing is captured and no analytics cookies are set. Elsewhere, including the United States, analytics runs by default and you can opt out at any time via the banner or Cookie settings in the footer. See Cookies and similar technologies below.
Crash and error reports (iPhone app)
The iPhone app sends crash and error reports to PostHog, our diagnostics provider, so we can find and fix bugs. A report contains technical details about the failure (such as the stack trace, app version, device model, and OS version) and, if you are signed in, your account identifier and email address so we can recognize repeat failures. These reports are used only to diagnose and fix problems — they are never used for advertising or cross-app tracking, and your health data and match history are never included in a report.
Launch waitlist
If you add your email address to the launch waitlist on our website, we store that email solely to notify you when Padelyst is available. It is not used for any other marketing, and you can ask us to remove it at any time.
Camera
The app requests camera access only to scan session QR codes. Scanning happens entirely on your device — camera images are never stored and never leave the device.
How we use your data
- To sync and display your match history and player roster.
- If you sign in, to link your devices to one account and sync your history between them.
- To run live tournament sessions and leagues and show shared standings to participants.
- To understand, in aggregate, how the website and tools are used and to fix errors.
- To respond when you contact support.
We do not sell your data, we do not show ads, and we do not share your data with third parties other than the infrastructure providers below, who process it on our behalf.
Cookies and similar technologies
The padelyst.app website sets no advertising cookies and no cross-site trackers. Browser storage falls into two categories, which you control through the cookie banner shown on your first visit and through Cookie settings in the footer:
- Strictly necessary (no consent required, per ePrivacy Article 5(3)): the record of your cookie choice itself; the anonymous device identifier (localStorage) that keeps your tournaments and match history in your browser; Firebase Authentication storage if you sign in; and Cloudflare Turnstile, which protects the waitlist form against bots. None of these track you across sites.
- Analytics: PostHog cookies and localStorage entries. If you are in the EU/EEA, the UK, or Switzerland, these are set only after you accept them in the cookie banner — until then (or if you decline) analytics runs in a fully disabled mode: no events are sent and nothing is stored in your browser. Everywhere else, analytics is on by default and the banner lets you opt out with one click. Opting out or withdrawing consent disables analytics and deletes the cookies and storage PostHog previously set. To determine which of the two applies, we look up the country of your IP address once and remember the result in your browser.
You can change your choice at any time via Cookie settings in the footer of every page. We also honor the Global Privacy Control (GPC) browser signal: if your browser sends it, analytics is treated as declined automatically, without you having to do anything.
Where your data is stored
Match history, player rosters, and archived sessions are stored on Cloudflare’s infrastructure (a D1 database running on Cloudflare’s global edge network, including locations in the EU). Live session state and the launch-waitlist list are held on the same Cloudflare network. If you sign in, your account record (email and account identifier) is managed by Google Firebase Authentication. Website analytics are processed by PostHog.
Retention
- Match history and rosters are kept until you delete them.
- Live sessions are wiped from the live store after a period of inactivity. Finished sessions are archived so results stay viewable.
- Account data (if you sign in) is kept until you sign out or delete your account.
- Waitlist emails are kept until launch or until you ask us to remove yours.
- Analytics data is retained according to our analytics provider’s standard retention settings.
Your rights
You can delete individual matches and players directly in the app, and you can delete all data associated with your device identifier from within the app’s settings. If you signed in, you can instead delete your entire account from the app’s settings — this erases your match history across every linked device and removes your sign-in record. You can also email us at support@padelyst.app to request access to, or deletion of, your data; if you are not signed in, you may need to share the device identifier shown in the app’s settings so we can locate it.
If you are in the EU/EEA or the UK, you additionally have the rights granted by the GDPR: access, rectification, erasure, restriction of processing, data portability, and objection. Where processing is based on your consent — website analytics is the only case — you can withdraw that consent at any time via Cookie settings in the footer, with effect for the future. To exercise any of these rights, contact us at the address above. You also have the right to lodge a complaint with your local data protection authority.
California privacy rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you specific rights over your personal information. This section is our notice at collection and explains how to exercise those rights.
What we collect. The categories of personal information we collect are: identifiers (a random device identifier; your email address and account identifier if you sign in or join the waitlist); customer-provided content (match history and the player names you type in); internet or network activity (website analytics events and error reports, which you can switch off at any time — see Cookies and similar technologies above); and coarse geolocation inherent to a web request (an approximate location derived from your IP address). We do not collect sensitive personal information as defined by the CPRA beyond what is listed here, and we collect nothing from data brokers.
We do not sell or share your personal information as those terms are defined by the CCPA/CPRA — no data is sold for money or other consideration, and none is shared for cross-context behavioral advertising. We have not done so in the preceding 12 months. Our infrastructure providers (Cloudflare, Google Firebase, PostHog) act as service providers under written contracts and may use your data only to provide their services to us. Because we do not sell or share, no opt-out is needed — but we still honor the Global Privacy Control signal and provide the Your privacy choices link in the footer, which lets you switch off analytics at any time.
Your rights. You have the right to know/access the personal information we hold about you, to delete it, to correct it, to data portability, to opt out of sale or sharing (not applicable, as described above), to limit the use of sensitive personal information (we use none beyond providing the service), and to not be discriminated against for exercising any of these rights — we never degrade the service based on a privacy choice.
How to exercise them. Delete data directly in the app (individual matches, all device data, or your whole account), or email us at support@padelyst.app. We verify requests using the email address or device identifier associated with the data; an authorized agent may submit a request on your behalf with proof of authorization. We respond within the timeframe the law requires (generally 45 days). We do not offer financial incentives in exchange for personal information.
Children
Padelyst is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has provided us data, contact us and we will delete it.
Changes to this policy
We may update this policy as Padelyst evolves. We will post the updated version on this page and revise the “last updated” date above.
Contact
Mavens Lab — support@padelyst.app