Legal & Transparency

Privacy Policy

How Match Analytics AI handles account, subscription and football-data records.

Pre-launch policy · Professional legal review pending · Updated 3 September 2026

1. Controller and contact

Operator: pending verification. Address: pending verification. A verified privacy request address must be supplied before Live launch. See Contact.

2. Data processed

The service stores account email addresses, one-way password hashes, database session tokens as one-way hashes, internal user IDs, Paddle customer/transaction/subscription IDs, membership state, billing timestamps and webhook audit hashes. Football records and operational request logs are also stored.

3. Payment boundary

Paddle provides hosted checkout. Match Analytics AI does not collect card numbers or security codes. Only identifiers and authorization data required for membership are retained by this application.

4. Sessions and diagnostics

An HttpOnly, SameSite account-session cookie is used for login. Browser membership signals are never an authorization source. Development checkout diagnostics are disabled in production and contain no card data.

5. Purposes and providers

Processing supports account access, subscription verification, security, football-data retrieval and troubleshooting. Football records come from API-Football / API-Sports; checkout uses Paddle. Production hosting, optional analytics and processing agreements must be confirmed before launch.

6. Retention and security

Expired login sessions can be revoked and payment-event audits are retained for verification. Production retention/deletion periods, backups and incident procedures remain deployment requirements. Server credentials are excluded from browser bundles and Git.

7. Rights

Applicable law may provide access, correction, deletion and other rights. A verified contact, lawful bases, retention periods and international-transfer arrangements require final professional review before production customer collection.