Introduction
Welcome to Sportflare. We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you visit or use our application.
Information We Collect
We collect several types of information to provide and improve our Service:
- Personal data. When you sign up, complete onboarding, or link an OAuth provider, we may ask for personally identifiable information such as your email address, name, and profile details.
- Usage data. We may collect information on how the Service is accessed and used — including your device’s IP address, browser type, pages visited, and time spent on the platform.
- Billing data. When you purchase a membership, our payment processor (Stripe) collects and processes your payment details. We never receive or store your full card number — we only retain limited information such as the card brand, last four digits, and your subscription status.
- Safety data. When you report someone, block someone, or are the subject of a moderation decision, we record what that involved. Section 5 sets this out in full, because it is the one part of this policy where we hold information about you that you did not choose to give us.
How We Use Your Data
Sportflare uses the collected data for the following purposes:
- To provide and maintain the Service, including your personalized dashboard.
- To manage your account and onboarding status.
- To notify you about changes to our Service or community updates.
- To provide customer support.
- To detect, prevent, and address technical issues and protect against spam and abuse.
- To keep people safe at real-world meetups — reviewing reports, deciding whether someone has broken our rules, and reviewing appeals against those decisions.
- To process membership payments, manage subscriptions and renewals, and prevent payment fraud.
Third-Party Processors
We use third-party companies to facilitate our Service. These third parties access your personal data only to perform tasks on our behalf:
- Supabase. Used for secure user authentication, OAuth handling, and database management.
- Stripe. Used to process membership payments and manage subscriptions. Stripe handles your card details directly as a PCI-DSS compliant payment processor; its use is subject to the Stripe Privacy Policy.
- Google reCAPTCHA. Used to protect our application from spam and abuse. Use of reCAPTCHA is subject to the Google Privacy Policy and Terms of Service.
Safety and Moderation Data
Sportflare is used to arrange meeting strangers in person, so we take reports of unsafe or abusive behaviour seriously and keep records of what we did about them. This section explains what those records contain, why we are allowed to hold them, and how long they last.
What we record
- Reports. When you report a profile, message, activity, venue or rating, we store the reason you chose, any details you write, and a copy of the reported content as it appeared at that moment. For a reported chat message, that copy includes the few messages either side of it — a single message out of context usually cannot be judged fairly. We also store a one-way, salted hash of your IP address, which lets us recognise one person operating several accounts without us keeping the address itself.
- Images in a report. If the reported content includes a picture — a profile photo, a venue photo — we save a copy of that image at the moment the report is filed, so a moderator reviews what was actually reported rather than whatever has replaced it since. These copies are private, readable only by a moderator reviewing the case, and they are deleted on the same clock as the report itself.
- Blocks. Who you have blocked, when, and the private note you may add. The person you block is never told.
- Moderation decisions. If a moderator warns, restricts, suspends or bans an account, we record the decision, the reason, the message sent to that person, an internal note for other moderators, and when it starts and ends.
- Appeals. If you appeal a decision, we store what you wrote, the outcome, and the reviewer’s explanation.
Why we are allowed to hold it
Our lawful basis is legitimate interests (Article 6(1)(f) GDPR): keeping our users safe from harassment, fraud and unsafe conduct, and being able to justify the decisions we make about accounts. We cannot ask a person’s consent to be reported without defeating the purpose of reporting, and a safety record that could be withdrawn on request would not be a safety record.
Who can see it
Only our moderation team, through an admin console that requires two-factor authentication, and every action they take is logged. Reports are never shown to the person reported, and we never disclose who reported someone. If you file a report, you are told that it was received and, once it is closed, whether action was taken — never what that action was.
How long we keep it
- Dismissed reports: deleted after 90 days, along with the copy of the content they were about.
- Reports that led to action: kept for 2 years. After that the stored copy of the content is redacted, while the record that a decision was made remains — we cannot justify a standing ban if we have deleted the reason for it.
- IP hashes: deleted with the report they belong to.
Automated screening, and the limits of it
Text you post — messages, profile details, activity descriptions — is checked automatically against a list of patterns before it is published. Content matching the most serious of those is refused at the point of posting, and a record of the attempt is kept for a moderator to review. Other matches are published normally and quietly queued for a human to look at.
Sanctions are decided by people, with one narrow exception. The number of reports against someone affects only the order in which a moderator looks at them — never the outcome. No warning, suspension or ban is ever applied automatically.
The exception: sending the same message to five or more separate conversations within ten minutes pauses your ability to post in chats for 24 hours. Nothing else about your account changes, you are told immediately, and you can appeal it straight away — an appeal a person reads. We treat this narrowly because it is the one pattern that is almost never accidental.
If an account is permanently closed
When we permanently close an account for serious misconduct, we keep a one-way scrambled version of its email address for two years, so that the same address cannot immediately register again. We do not keep the address itself, and the scrambled value cannot be turned back into one — it only answers whether a given address matches. We do not record IP addresses or device fingerprints for this purpose, which means somebody determined to return with a different address can. That is a limit we accept, because the alternatives catch households and shared connections along with the person we are keeping out.
Deleting your account
Deleting your account removes your personal information from these records: your details are scrubbed from any stored copies of content and the IP hash is cleared. Where we have permanently removed an account for serious misconduct, we keep the minimum needed to enforce that decision, so that the ban cannot be undone simply by signing up again. Section 7 explains how to exercise this and your other rights.
Data Security
The security of your data matters to us. We follow industry-standard practices — including Supabase’s secure authentication infrastructure — to protect your data. No method of transmission over the internet or electronic storage is 100% secure, so we cannot guarantee absolute security.
Your Data Rights
Depending on your location (e.g. under GDPR or CCPA), you may have the following rights regarding your data:
- The right to access, update, or delete the information we have on you.
- The right of rectification (correcting inaccurate information).
- The right to object to, or restrict, our processing of your personal data.
- The right to data portability.
These rights are not absolute. Where we hold safety records under legitimate interests (Section 5), we may keep the minimum necessary to protect other users — for example, the record that an account was permanently removed — and will tell you when we do.
To exercise these rights, contact us at support@sportflare.net.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the updated policy on this page and revising the “Effective Date”.
Questions?
Reach our team at support@sportflare.net