Privacy Policy

How Leagify collects, uses, shares and protects your personal data.

Last updated: 20 July 2026

Draft — pending legal review. This document describes how Leagify handles your data and is provided as a working draft. It has not yet been reviewed by a qualified legal adviser and does not yet constitute a final or binding policy. Sections marked [to be completed] need information only Leagify can supply.

Who we are

Leagify is a platform for running sports leagues — accounts, fixtures, results and standings, notifications, optional paid entry, and safeguarding features for younger players. Leagify is operated from the United Kingdom by Leagify Ltd (“Leagify”, “we”, “us”), the data controller for the personal data described here.

  • Registered address: [to be completed]
  • ICO registration number: [to be completed]
  • Privacy contact: privacy@leagify.co.uk

Note: where you take part in a league run by someone else, that league’s organiser also decides how your participation data is used within their league. This policy covers Leagify’s own processing of your data as the platform provider.

The data we collect, and why

We collect only what we need to run the service. The lawful basis under UK GDPR is shown for each category.

  • Your account — email address, display name, language/region, and (if you set one) an avatar. Your password is held by our authentication provider, never by us in readable form. Basis: contract.
  • Younger players (under 16) — date of birth (used only to work out whether you are a minor) and a guardian email address. Under-16s cannot make payments or have a public profile. Basis: contract, with safeguarding measures.
  • Payments — when a league charges an entry fee, payment is handled by Stripe. We do not store your card details; we keep only a payment reference, the amount and the status. Basis: contract and legal obligation (keeping transaction records).
  • League participation — results, line-ups, per-match statistics and ratings generated as you take part. League data is public by default (it can be set private or unlisted by the organiser). Basis: legitimate interests (running a competitive league).
  • Live streams (only if you opt in) — if a fixture you play in is streamed, your image and likeness are captured. This needs your image-rights consent (and explicit guardian consent for anyone under 18) before a stream can start. Basis: consent.
  • Analytics (only if you accept) — usage events and masked session recordings that help us improve the product. These stay off until you accept analytics cookies, and you can withdraw at any time. Basis: consent.
  • Security and audit — a log of significant actions (who did what, and when) for dispute resolution and security. It does not store snapshots of your personal data. Basis: legitimate interests and legal obligation.

Who we share it with

We do not sell your personal data. We share it only with the service providers that help us run Leagify, each under a data-processing agreement, and only as needed:

  • Supabase — database, authentication, realtime and file storage (EU region).
  • Amazon Web Services (AWS) — hosting, background jobs, transactional email, DNS, and live streaming (EU regions).
  • Stripe — payment processing (only where a league charges a fee).
  • Sentry — error monitoring (personal data is scrubbed; session replay is consent-gated and masks all text).
  • PostHog — product analytics and masked session replay, EU-hosted and off until you accept analytics cookies.
  • Google Places — venue look-ups initiated by organisers (no user personal data is shared).

Public league data (such as fixtures, results and standings) is, by design, visible to anyone unless the organiser makes the league private or unlisted.

Where your data is held

We use EU/UK regions wherever the provider offers them. Where a provider transfers data outside the UK/EU, that transfer is covered by Standard Contractual Clauses incorporated into our agreement with them.

How long we keep it

  • Your account — for as long as your account is active. When you delete it, we scrub your personal details immediately and remove residual records within 30 days.
  • League results and history — kept indefinitely as a historical record, but anonymised once the person who generated them deletes their account.
  • Activity/audit records — from 30 days (free leagues) up to 7 years (paid leagues); sensitive values within them are removed after 365 days.
  • Notifications — 90 days. Unaccepted invitations — 90 days after they expire.
  • Stream recordings — not retained on the free tier; retained on the paid tier until deleted.
  • Data-export archives — 7 days, then deleted.
  • Payment records — retained (without your card details) as long as tax and accounting law requires.

Your rights

Under UK GDPR you have the right to:

  • Access and portability — download a copy of your data. You can request an export yourself from your profile settings.
  • Erasure — delete your account and personal data from your profile settings; this also removes any stream recordings you appear in.
  • Rectification — correct your details by editing your profile.
  • Object or withdraw consent — turn analytics off at any time using the Cookie settings control.
  • Restriction — ask us to limit how we use your data.

To exercise a right, use the in-app controls where available or email privacy@leagify.co.uk. We respond to requests within one month. You also have the right to complain to the UK Information Commissioner’s Office (ico.org.uk), though we’d appreciate the chance to help first.

Children

Leagify is used by younger players. Where we know a player is under 16 we collect a guardian email, block payments and public profile visibility, and provide no in-app messaging. A player under 18 cannot appear in a live stream without explicit guardian image-rights consent. If you believe a child’s data has been handled incorrectly, contact privacy@leagify.co.uk and we will act promptly.

Live streams and image rights

Streaming is opt-in. If you (or, for under-18s, your guardian) ask us to remove a recording you appear in, we acknowledge the request within 24 hours and delete the recording within 72 hours of verifying who you are — well inside the one-month legal deadline. Requests go to the in-app control or privacy@leagify.co.uk.

Cookies

We use strictly-necessary cookies to keep you signed in and remember your cookie choice, and — only with your consent — analytics cookies. See our Cookie Policy for details.

Keeping data secure

We encrypt data in transit and at rest, require multi-factor authentication for the most sensitive administrative actions, and follow the controls in our internal security and data-protection assessments. No system is perfectly secure, but we work to protect your data and to notify you and the regulator where the law requires.

Changes to this policy

We’ll update this policy as the service evolves and post the new version here with a revised date. Material changes will be highlighted in the app.

Contact

Questions about your data or this policy? Email privacy@leagify.co.uk.