KCL Football

Privacy

How KCL Football Tracker uses app data.

KCL Football Tracker is used by the club committee to run weekly football matches. This page explains what data the app uses, who can see it, and how to ask for deletion.

What we collect

We store the account details needed to sign you in, such as your Auth0 user ID, email address, and display name.

We store player profile, match availability, team, attendance, goals, assists, fines, match fee, and notification preference data so the club can run matches.

For payments, we store Stripe checkout session IDs and payment status. We do not store card details.

If you enable push notifications, we store the browser push subscription needed to send them.

If you connect Strava when that feature is available, we will store only the minimum data needed to link your activity to a match and calculate your own linked-match distance.

How we use it

We use this data to organise matches, track availability, publish teams, record attendance and stats, manage fines and match fees, and send the notifications you choose to receive.

If you connect Strava, we use your Strava access only to help you find and link your own activities to matches. Your individual runs are not shared across the app.

If an average-distance leaderboard is introduced, it will be opt-in and will show only aggregate average distance, not the runs behind it.

Who can see it

Club members can see the match, team, attendance, and leaderboard information needed to use the app.

Organisers and admins can manage players, matches, attendance, fines, match fees, and account linking.

Your individual Strava activities are visible only to you in the app. We do not sell your data.

Service providers

The app uses Auth0 for login, Vercel for hosting, Neon Postgres for database storage, Stripe for payments, and Strava only if you choose to connect Strava.

These providers process data only as needed to operate the app and the features you use.

Storage and deletion

Application data is stored in Postgres. Production hosting runs on Vercel.

When the Strava integration ships, Strava tokens will be encrypted at rest and disconnecting Strava will remove stored Strava tokens and Strava-derived activity rows.

For full account deletion or data questions, contact sports@kokniluton.co.uk.

Contact

For privacy questions or deletion requests, email sports@kokniluton.co.uk.