Privacy Policy

Last updated: 16 April 2026

Statty ("we", "us", "our") is a grassroots sports team management platform operated from the United Kingdom. We take your privacy seriously and are committed to protecting the personal data of our users — including the young players whose clubs use this platform.

This policy explains what data we collect, why we collect it, how we protect it, and what rights you have. It applies to all Statty services: the web app, mobile apps, and this website (statty.club).

The short version: We collect only what's needed to run your club. We don't show ads. We don't sell your data. We don't track you across the web. We don't use your data to train AI models. Your club's data belongs to your club.

1. Who is responsible for your data?

The data controller is Statty, contactable at [email protected]. We are based in the United Kingdom and subject to the UK General Data Protection Regulation (UK GDPR) and the Privacy and Electronic Communications Regulations (PECR).

2. What data we collect

Account data

DataWhy
NameDisplay in the app & team roster
Email addressLogin, password resets, optional email notifications
PasswordStored as a one-way bcrypt hash — we never see or store your actual password
Phone number (optional)Only if you choose to add it to your profile
Profile photo (optional)Displayed on your profile within the team

Team & squad data

DataWhy
Team membership & roleAccess control (admin, staff, player, parent)
Player position & shirt numberLineups and squad display
Parent-child linksParents see only their linked child's profile
Player statisticsGoals, assists, appearances, MOTM, cards — displayed in player profiles

Activity data

DataWhy
RSVP responsesAttendance planning for matches & training
Chat messages & DMsTeam communication
Feed posts, comments & reactionsTeam news and social features
Photos & captionsTeam photo gallery
Lineup assignmentsMatch preparation
Match events (goals, cards, subs)Live match tracking
Fundraising contributionsTracking team fundraiser progress

Technical data

DataWhy
IP addressProcessed by Cloudflare for security & DDoS protection — not logged by us
Notification preferencesRespecting your choice of how to be notified

What we do NOT collect

3. Children's data

Statty is used by youth football clubs, which means some data relates to children (typically aged 10–16). We take this responsibility seriously:

If you are a parent and wish to have your child's data reviewed or removed, contact us at [email protected].

4. Legal basis for processing

Under UK GDPR, we process personal data on the following bases:

BasisApplies to
Legitimate interestRunning the platform: account management, team features, match tracking, squad stats. Our legitimate interest is providing the service your club signed up for.
ConsentOptional features: email notifications, push notifications, photo uploads. You can withdraw consent at any time via your notification preferences or by contacting us.
Contract performanceProviding the service as described when you create an account and join a team.

5. Who has access to your data

Within your club

Third-party processors

We use a small number of trusted services to operate the platform:

ServicePurposeData sharedLocation
HetznerServer hostingAll platform data (encrypted in transit)Germany (EU)
CloudflareDNS, SSL, DDoS protectionIP addresses, request metadataGlobal edge network
ResendTransactional email deliveryEmail address, notification contentUSA
Hetzner Storage BoxEncrypted file backupUploaded photos and attachmentsGermany (EU)

We do not share, sell, or provide your data to any advertisers, data brokers, social media platforms, or AI training services.

6. Cookies

Statty does not set any first-party cookies. We use token-based authentication stored in your browser's local storage (not cookies), which is not subject to cookie consent regulations.

Cloudflare may set strictly necessary cookies (__cf_bm) for bot protection. These are classified as essential under PECR and do not require consent.

We do not use any analytics, marketing, or preference cookies. No cookie consent banner is needed because there are no optional cookies to consent to.

7. Data security

8. Data retention

9. Your rights

Under UK GDPR, you have the right to:

To exercise any of these rights, email [email protected]. We will respond within 30 days.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe we have not handled your data correctly.

10. International transfers

Your data is primarily stored on servers in Germany (EU), which has equivalent data protection standards to the UK under the UK adequacy decision.

Cloudflare processes request metadata at global edge locations. Resend processes email delivery from the USA. Both operate under appropriate safeguards (Standard Contractual Clauses).

11. Changes to this policy

We may update this policy from time to time. If we make significant changes, we will notify active users via the platform. The "last updated" date at the top will always reflect the current version.

12. Contact

Email: [email protected]

Website: statty.club