How we handle your data
Updated 18 September 2026
RacketDay is a platform for racket sports tournaments. This page says what data the product collects, why, who sees it and how to delete it.
We wrote this text ourselves and no lawyer has reviewed it. It describes what the code does, not what we would like to promise.
Who is responsible
The data controller is Aleksandr Shibaev, a private individual: there is no company behind the app, and RacketDay is the name of the product. The organizer of a tournament answers for their own purposes: for entering your contact into a lineup, and for their own announcements. You may lodge a complaint with the supervisory authority of your country; in Portugal, where the first tournaments are held, that is CNPD.
What is collected
Only what a tournament cannot be run without.
- Your account: first and family name, phone number or email address, and — if you sign in through Telegram — your Telegram id. The rest only if you entered it yourself: gender (needed when the organizer restricted the category), year of birth (age categories such as U18 and 40+), playing hand and court side (this is what pairs are built from).
- Taking part: signups, pairings, schedule, match scores, standings and rating.
- Signing in: one-time codes and links — as hashes, not as you saw them — sessions, a fingerprint of the device you signed in from, and your IP address: it counts sign-in attempts so the door cannot be brute-forced. The counter keeps the address for a day; the service log keeps only a hash of it.
- Notifications: the push address of your device, the platform, and the phone name the phone reports itself.
- Running the service: a command log — who did what, when, and how it ended. It is what makes a failure possible to investigate.
- App screen openings: which device, which screen and how many times a day — one number per device, screen and day. Which tournament or whose page you opened, the counter does not know: it holds no request, no response and no address.
The product collects no photos, no health data, no payment details and no location. There are no ads in it, and no tracking of you across other sites either: not a single third-party advertising or analytics tag is installed — only our own counter of screen openings, described above.
Why, and on what basis
Signups, schedule, signing in and notifications about your own games are the performance of the contract to take part. Match results and the cross-tournament rating rest on the legitimate interest of sports record-keeping: a result belongs to your opponents and to the tournament table as well. Organization news is sent on consent only, and consent can be withdrawn. The command log is a legitimate interest: without it a failure cannot be investigated. The counter of screen openings is a legitimate interest too: we need to know whether the app gets opened, and a number is enough for that.
What everyone can see
Tournament and organization pages are public: the name of a participant, match scores, standings and a player rating. Phone numbers, email addresses and device push addresses are never public — the tournament organizer and we see them. The phone number of a participant is visible to the organizer of their tournament, in the app as well.
Who else sees the data
Only those the service cannot run without.
- DigitalOcean — where the app runs and the database lives, in Frankfurt.
- Postmark — the email with a sign-in link.
- Twilio — the SMS with a sign-in code. Sent to European destinations only: a number from anywhere else is refused before the provider is called.
- Telegram — the bot’s messages: your Telegram id and the text of the message.
- Expo, and through it Apple and Google — delivering a notification to your phone: the device address, the title and the text.
- Sentry — crash reports: what broke and where in the code. Your name, phone, email and personal links are stripped before the report is sent. Reports are kept in Frankfurt for thirty days and then deleted.
Data is not sold and not handed to advertisers. This list changes only together with this page.
Transfers outside the EEA
The app and the database run in Frankfurt, that is, inside the EEA. What leaves it: Telegram messages, email through Postmark, and notifications through Expo, Apple and Google. The last one cannot be opted out of: there is no other route to a phone screen for a push — it is the infrastructure of the operating systems themselves.
How long it is kept
Your account — until you delete it. After a deletion request you get 30 days to change your mind, then the profile is anonymized: the phone number, email and device addresses are erased, the password is forgotten, first and family name become “Player #N”, and year of birth, gender, playing hand and court side are erased. Match results and rating stay — they belong to your opponents too. Sign-in codes and links live for hours, the command log for 24 months, the counter of screen openings for 30 days; when a profile is anonymized, the rows of your devices are erased without waiting for that term.
Your rights
You may get a copy of your data, correct it, delete it, restrict processing, object to processing based on legitimate interest, and complain to a supervisory authority.
You can delete your profile yourself — in profile settings, both in the browser and in the app. For anything else, write to us.
Children
The product is meant for adults and is not directed at children. If a child ended up in a lineup because an organizer entered them, write to us and we will delete it.
Changes
If something material changes — a new recipient of data, or a new purpose — we will change this page and its date. The date is at the top.
Getting in touch
Write to privacy@racket.day about anything to do with your data, deletion and complaints included.