Privacy Policy
This Policy explains what personal data PITCH YOUR GAME processes in the app, website and Pitch Your Game Control, why it is needed and what rights you have.
1. Controller
Marvin Neumann
Provider of PITCH YOUR GAME
Folkets Parksgatan 8
582 46 Linköping
Sweden
Email: support@pitchyourgame.de
No data protection officer has been appointed. Send privacy requests directly to the email address above.
2. Scope
This Policy applies to the PITCH YOUR GAME iOS app, pitchyourgame.de including its waitlist, and the access-restricted Pitch Your Game Control administration tool. PITCH YOUR GAME is an account-based football network. Profiles and published content are intended to be found and viewed by other signed-in users.
It also covers data processed when entering into, performing, terminating or withdrawing from the PITCH YOUR GAME user contract and when handling privacy or Digital Services Act requests.
3. Data we process
| Area | Data | Purpose |
|---|---|---|
| Account | Email address, Firebase UID, sign-in provider, verification and security status; for email sign-in, a password hash managed by Firebase | Registration, sign-in, recovery and account security |
| Age and acceptance | Date of birth, age-gate time, time and version of accepted Terms | Verify the minimum age of 16 and document the contract; the date of birth remains private |
| Profile and Pitch Card | Name, username, role, club, position, league, town, country, bio, strengths, attributes, shirt number, profile photo and other voluntary details | Display profiles and enable search and sporting connections |
| Posts and media | Text, photos, video, thumbnails, tags, mentions, co-authors, timestamps and technical media data | Provide feed, profile, post display and upload |
| Interactions | Follows, ratings, likes, comments, replies, blocks and timestamps | Social features and abuse prevention |
| Messages | Chat participants, request status, message text, read and send times | Provide direct messages and message requests |
| Reports and support | Reporter, reported content or chat, reason, free text, status and moderation decision; support also includes contact and app data | Review rights violations, abuse, appeals and support requests |
| Contract and privacy requests | Contact data, account identifier, content and time of withdrawal, termination, access or other request and handling records | Identify, answer and evidence the handling of requests |
| Notifications | Push token, Firebase installation reference, preferences and necessary preview text | Deliver requested notifications through Firebase Cloud Messaging and Apple Push Notification Service |
| Security and diagnostics | App Check attestations, IP address and technical logs; for crashes, data may include time, stack trace, app and OS version, device model, installation and crash identifiers | Protect the backend, detect faults and improve stability |
| Admin audit | Admin UID, role, action, target, time and outcome | Trace security-relevant administration and moderation access |
| Waitlist | Email address, signup time and technical anti-abuse data | Send beta and launch information |
4. Sources
Most data comes directly from you or is generated through use. Other users may provide information about you when they mention you, invite you as a co-author, follow you, message you or report content. Apple or Google provides the identity data needed for the selected sign-in method. Security and diagnostic data is generated automatically during operation.
5. Visibility and recipients
Other signed-in users
Your profile, Pitch Card, profile photo, voluntary profile fields and visible social connections are intended to be visible to signed-in PITCH YOUR GAME users. For posts, you choose an audience of all signed-in members, your followers or people you follow; comments and ratings are accessible only with their post. Email, date of birth, settings, push token, block list and private messages are not displayed on your profile.
Chats, support and moderation
Messages are visible to chat participants. Authorised support and moderation roles may read support conversations with the participant “pitch-team”. Admins cannot browse private user-to-user chats generally. A conversation may be reviewed only when an open report exists for that exact chat; access is role-restricted and logged with reason, administrator and time.
Service providers
We use Google Firebase and Google Cloud as processors for Authentication, Firestore, Cloud Storage, Cloud Functions, Hosting, App Check, Cloud Messaging and Crashlytics. Resend processes recipient addresses and email content to deliver confirmation, security, waitlist and withdrawal emails. Apple Push Notification Service delivers push messages. Apple and Google privacy information also applies to their respective sign-in process.
Nick and other specifically authorised helpers receive only the access required for their role. They act under Marvin's responsibility, are bound to confidentiality and may not use data for their own purposes. Administrative and moderation access is role-restricted and security-relevant operations are logged.
We also disclose data where required by law, needed to defend rights or necessary to address a specific danger. We do not sell personal data.
6. Purposes and legal bases
| Processing | Legal basis |
|---|---|
| Account, age gate, profile, posts, interactions, chats and requested push functions | Contract performance and steps before entering into a contract, Article 6(1)(b) GDPR |
| Waitlist and voluntary contact | Consent, Article 6(1)(a) GDPR; withdrawable at any time for the future |
| Abuse prevention, App Check, technical security logs and service security | Legitimate interest in a secure and reliable service, Article 6(1)(f) GDPR |
| Optional transmission of crash reports to Firebase Crashlytics | Consent, Article 6(1)(a) GDPR; withdrawable without disadvantage at any time under Settings → Privacy |
| Reports, moderation, case-specific chat review and defence of rights | Legitimate interests in protecting users and rights, Article 6(1)(f) GDPR, and legal duties, Article 6(1)(c) GDPR |
| Withdrawal, termination, privacy and DSA requests | Contract performance or termination, Article 6(1)(b) GDPR, and legal duties, Article 6(1)(c) GDPR |
| Compliance with official or court orders | Legal obligation, Article 6(1)(c) GDPR |
Where processing relies on legitimate interests, you may object for reasons arising from your particular situation. We will balance your interests against compelling legitimate grounds.
7. Required and voluntary data
Optional usage analytics: After separate consent under Settings → Privacy, the app sends the fixed events app opened, search opened and post published through Firebase Functions. No search terms, messages, post text, profile fields or advertising identifiers are sent as analytics parameters. Daily event totals are retained for 90 days; daily cleanup may delay removal until its next run. Your account is technically used for authentication. A hash of the user ID and random event IDs prevent duplicate counting and abuse; these helper records become due for daily deletion no later than the end of the following day and are removed when the account is deleted. Technical security logs may arise. Optional analytics relies on Article 6(1)(a) GDPR. You can withdraw consent on this device at any time without disadvantage; daily totals that have already been combined without account attribution cannot be individually reversed.
Automatic Crashlytics reporting is disabled. Cached crash reports are sent to Firebase Crashlytics at app launch only if you have enabled optional diagnostics on this device. We do not attach profile identifiers, messages or post text. The app works without consent. Changing your choice schedules unsent reports for deletion; the switch does not recall reports already transmitted. Technical crash information may be created locally on your device even when transmission is disabled.
An email address or supported sign-in provider, date of birth, acceptance of the current Terms, name, username and role are required for an account and core functions. We cannot provide a usable account without them. Club, position, location, bio, media and most Pitch Card information is voluntary. Push notifications are voluntary and can be disabled in iOS or PITCH YOUR GAME.
8. Retention and deletion
- Account, profile, content and chats: until you delete them, delete your account or they are no longer needed for the service.
- Replaced and abandoned media: technically cleaned up after detection.
- Support, withdrawal, privacy and moderation cases: until closure and then only while needed for security, evidence, legal duties or defence against claims, based on severity, repeat risk and limitation periods.
- Admin and security audits: while needed to trace security-relevant events and defend rights.
- Crashlytics: according to Google's current Firebase documentation, crash stack traces and associated identifiers are retained for 90 days before removal starts from live and backup systems.
- Hosting access data: according to Google, IP-related Firebase Hosting data is retained for a few months.
- Waitlist: until the announced launch information is sent, consent is withdrawn or no invitation will be made.
- Backups: deleted data may remain until the technical backup rotation expires. It is not used in normal operation and deletions must be re-applied following a restore.
You can delete your account under Profile → Settings → Delete account. This covers the authentication account, profile, your posts and media, chats, push tokens and other account-related live data. Data exceptionally retained for a legal duty or defence of rights is restricted and removed when that purpose ends.
9. International transfers
PITCH YOUR GAME configures Firestore and Cloud Functions in europe-west3 (Frankfurt). This does not mean every Firebase service operates only there. According to Google, Firebase Authentication operates from US data centres, while global services such as Crashlytics, Cloud Messaging, App Check, Storage and Hosting may involve processing worldwide.
For US transfers, Google and Resend rely where applicable on appropriate safeguards such as certification under the EU-US Data Privacy Framework and/or EU Standard Contractual Clauses. EU Standard Contractual Clauses also form part of the Firebase data-processing terms. You may request information about the safeguards from us.
10. Website and local storage
The public website uses no analytics or advertising cookies and loads no external web fonts. Firebase Hosting processes technically necessary access data such as IP address, time and requested file for delivery and attack prevention. The app stores necessary preferences such as language, onboarding and session state locally on the device. No advertising or tracking consent is needed for this storage.
11. Automated decisions
PITCH YOUR GAME currently makes no solely automated decision with legal or similarly significant effects under Article 22 GDPR. The feed mainly displays recent posts chronologically; search and contact suggestions may consider search input, profile details, role and follow or contact relationships. Authorised humans generally review moderation and suspension decisions. Technical systems may restrict uploads, access or requests under fixed security rules.
12. Your rights
Subject to legal requirements, you have rights of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18), portability (Article 20) and objection (Article 21). You may withdraw consent at any time for the future without affecting prior lawful processing.
Email support@pitchyourgame.de. We may request reasonable proof of identity to protect your account. You may also complain to a data-protection authority, particularly where you live, work or believe an infringement occurred. German authorities are listed at bfdi.bund.de; Sweden's authority is the Integritetsskyddsmyndigheten (IMY).
13. Security and changes
We use role-restricted access, multi-factor protection for Pitch Your Game Control, Firestore and Storage rules, App Check, transport encryption and audit logs. No system is risk-free. We respond to and notify data breaches as required by law.
We update this Policy when data flows, providers or the legal position materially changes. We will notify you of material changes in the app or through the email address on the account.