We use your data to manage your account and the matches you take part in. We do not sell personal information.
1. Controller and contact
BookBall is the controller of the data used to provide the service. To ask a question or exercise your rights, email soporte@bookball.app.
2. Data we process
- Account: email, official name, @handle, display name, telephone number, language and protected credentials. For registration we retain the timestamp, accepted Terms and Privacy versions, locale and the person’s minimum-age self-declaration; we do not request a date of birth.
- Player profile: photograph, position, rating, availability and invitation preferences.
- Activity: groups, pitches, call-ups, attendance, teams, results, votes, statistics, group or match chats, direct messages and vacancy-board applications.
- Guest players: name and contact details supplied by an authorised organiser.
- Technical data: session identifiers, notification tokens, security IP address, error logs and device information. Optional analytics use only coarse device and country data plus rotating pseudonymous identifiers; the raw IP address is never stored for analytics.
3. Purposes and legal basis
We process data to create and protect accounts, organise matches, provide group, match and direct chats, send operational communications, publish and fill places, generate teams, retain results, prevent abuse and resolve incidents. Our legal bases are performance of the requested service, consent where applicable and our legitimate interest in keeping BookBall secure.
4. Information shared within BookBall
Group members can see the sanitised profile needed to organise matches. Group and match chats are visible only to authorised registered people and may be moderated by their organisers. Each one-to-one direct conversation is visible only to its two participants: neither organisers nor the super administrator may silently access it, and there is no routine moderation unless a future explicit, auditable reporting flow is introduced. The global vacancy board exposes minimal match and applicant data; organisers and captains see only applications within their scope. Email, telephone number and official name are not public. Your sanitised profile appears globally only while “discoverable profile” is enabled.
5. Service providers
BookBall may use PHP/MySQL hosting and Google Firebase for authentication, synchronisation, storage and notifications. Depending on the administrator’s configuration, social data reside in MySQL, Firestore or both; idempotent synchronisation may keep one coherent copy of the same logical record in each store. We also use email services for account communications. OpenStreetMap displays pitches and maps; the tile provider may receive the viewport or coordinates shown and technical connection data. BookBall sends only explicitly submitted venue or address searches to Nominatim through its own proxy. Results are reused without identifiers for no more than 24 hours; expired files are removed on the next search or hourly maintenance run. Open-Meteo is used for forecasts and to geocode place names entered voluntarily. Each provider processes only the information needed for its role.
Payment data
Stripe processes card details. BookBall keeps only the technical identifiers and states needed to reconcile payments, refunds and disputes; the PHP site stores neither card numbers nor Stripe keys.
Location and marketplace retention
Device location is requested only after an explicit action. Search coordinates are used to return nearby pitches, are not stored in the user profile and are removed from short-lived operational logs under the published retention schedule.
Families, dependants and consent
An accountless dependant profile stores only a display name, an optional relationship and consent status; it does not request a date of birth, email address or telephone number. Access is relationship-scoped and consent may be revoked at any time; revocation immediately restricts further processing and visibility except where retention is legally required.
6. Transfers and retention
Some providers may process data outside the European Economic Area under the relevant legal safeguards. We retain data while the account is active and for necessary periods. When an author deletes a direct message, its text is cleared and a technical marker remains to preserve ordering and synchronisation; there is no separate automatic deadline for deleting the whole conversation. Terminal vacancy posts and their applications are deleted after 180 days. Optional analytics remain for no more than 13 months and backups follow their rotation cycle.
7. Security
We use HTTPS, robust password hashing, secure sessions, CSRF protection, prepared queries, role-based permissions and audit logs. Firebase App Check is monitored and rolled out gradually; it is enforced only where explicitly enabled, not universally. No system can guarantee zero risk, so you must also protect your credentials.
8. Your rights
You may request access, rectification, erasure, portability, restriction or objection by writing from your account email. You may also complain to the Spanish Data Protection Agency. A dedicated account deletion page is available.
9. Children
BookBall does not allow anyone under 16 to create their own account. During registration, the person declares that they meet the minimum age and accepts the current Terms and Privacy versions. We retain only the timestamp, those versions, the locale and the affirmative declaration; we do not request a date of birth. This self-declaration does not replace any applicable legal checks. An authorised guardian may manage an accountless dependant profile through the Family module.
10. Changes
We will publish material changes here and state when they take effect.