Privacy Policy
Effective date: 7 August 2026 · Last updated: 7 August 2026
This policy describes how the App actually handles data. It has not been reviewed by a solicitor — worth doing before relying on it for a store submission.
This policy explains what information Gully Cricket ("the App", "we", "us") collects, why, how it is stored and shared, and what rights you have over it. It applies to the mobile app, this website, and the services behind them.
It is written to describe what the App actually does. If something here doesn't match the App's behaviour, that's a fault in this document — please tell us.
1. Who we are
| Data controller | We Ingenious |
|---|---|
| Based in | United Kingdom |
| Contact | [email protected] |
We are the "controller" of your personal data under the UK GDPR and the Data Protection Act 2018 — meaning we decide what data is collected and why. We have not appointed a Data Protection Officer, as we are not required to.
2. What we collect
We collect only what the App needs to work. We use Firebase Analytics to understand how the App is used — how many people finish setting up a match, which features are reached, where people give up. These are counts of actions, not records of you: no advertising SDKs, no ad networks, no cross-app tracking, no Mixpanel, no Amplitude, no Meta SDK. We do not sell your data to anyone, in any jurisdiction, and never have.
| Data | Why | Stored off your device? |
|---|---|---|
| Email address, and a password (hashed by Firebase — we never see it) | Account creation, sign-in, recovery | Yes |
| Google account details, if you use "Sign in with Google" | Alternative sign-in | Yes |
| Display name, Cricket ID (@handle), permanent numeric CricID | Your identity across matches; how friends find you | Yes |
| Phone number, date of birth, gender (optional) | Your profile; phone lets friends find you | Yes — in a restricted record only you can read |
| Profile photo (optional) | Personalising your profile and team sheets | Yes |
| Location — a one-time fix, converted to a place name on your device (optional) | Tagging your area or a match venue | Only the resulting place name (e.g. "Leeds, UK"). Raw GPS coordinates are never stored. No background or continuous tracking. |
| Contacts — name and phone number (optional) | Finding friends who already use the App | Matching happens on your device. Contacts you explicitly add as friends are saved to your own private friends list, readable only by you. Your full address book is never uploaded. |
| Match data — scores, ball-by-ball history, player names, statistics | The core function of the App | Yes — see Section 5 on visibility |
| Push notification token | Match invites, scoring handoff requests, results | Yes — deleted when you sign out |
| Crash reports — error, stack trace, app version, device model, OS version, screen | Diagnosing and fixing crashes | Yes — tied to a non-reversible identifier, not your account ID. Disabled in development builds. |
| Bug reports and feedback you send us — the name you type, your message, and the app version, device model and OS version; plus a crash report or recent log entries if you choose to attach them | Investigating and fixing what you report | Yes — stored with your account ID, and also emailed to us through a third party (see Section 4) |
| Biometric unlock preference | Optional app lock | No. Fingerprint and face matching happen entirely within your device's operating system; we receive only a yes/no result and never any biometric data. |
3. Our lawful basis for using it
Under UK GDPR we must have a lawful basis for each purpose. Ours are:
| Purpose | Lawful basis |
|---|---|
| Creating your account and providing scoring, teams, and scorecards | Contract — necessary to deliver the service you asked for |
| Optional profile details, contacts access, location, notifications | Consent — you choose these, and can withdraw at any time |
| Crash diagnostics, security, and preventing abuse | Legitimate interests — keeping the App working and secure, balanced against your privacy (the data is minimal and pseudonymised) |
| Responding to lawful requests | Legal obligation |
Where we rely on consent, withdrawing it is straightforward: revoke the permission in your device settings, or clear the optional field in your profile. Withdrawing consent doesn't affect processing already carried out.
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects.
4. Who we share it with
We do not sell your personal data, and we do not share it with advertisers or data brokers. Data is shared only with the infrastructure providers that run the App on our behalf ("processors"), who may act only on our instructions:
| Provider | What they handle |
|---|---|
| Google Firebase | Authentication, Firestore database, Cloud Storage, Cloud Messaging, Crashlytics, App Check, Cloud Functions |
| Supabase | Long-term archive of historical ball-by-ball match data, moved out of the live database once a match is complete |
| EmailJS | Delivering the bug reports and feedback you submit in the App to our support inbox. The name and message you type pass through, and are retained in that provider's own sending history as well as in our inbox |
| Cloudflare | Serving this website |
We may also disclose information where required by law, or to protect the rights, safety, or property of our users or the public.
5. Match data is shared by design
This is the most important thing to understand about the App, so we'll be plain about it.
Cricket scoring is inherently a shared record. A match involves batters, bowlers, a scorer, and spectators. Match data — including player names, scores, and statistics — is visible to everyone taking part in that match, and to anyone the scorer shares the scorecard or a live-score link with. Shared scorecards can be viewed without signing in.
In practice:
- Your name and playing statistics in a match are visible to other participants and to anyone given the scorecard.
- Your contact details are not part of that shared record — phone number, email, and date of birth stay in a restricted profile record only you can read.
- Your profile photo is visible to other signed-in users, not to the general public.
6. Information about other people
The App lets you enter details about other people — teammates' and opponents' names, and how they performed in a match you're scoring. If you do that, you're responsible for having a proper reason to, such as being the designated scorer for a real match they're playing in.
If someone has recorded information about you and you'd like it corrected or removed, contact us at [email protected]. You have the same rights over that data as anyone else, whether or not you have an account.
7. Where your data is stored
Our infrastructure providers operate globally, so your data may be stored or processed outside the United Kingdom, including in the United States.
Where data leaves the UK or EEA, it is protected by the safeguards required under UK GDPR — the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses, as incorporated into our providers' data processing terms. You can request more detail using the contact address above.
8. How long we keep it
| Data | Retention |
|---|---|
| Account, profile, and identity records | Until you delete your account |
| Friends list, saved teams, scheduled matches | Until you delete them, or delete your account |
| Push notification token | Cleared when you sign out |
| Ball-by-ball match detail | Held in the live database, then moved to long-term archive storage once the match is complete |
| Match records and scorecards | Retained after account deletion — see Section 9 |
| Crash reports | Per Firebase Crashlytics' standard retention (up to 90 days) |
9. Deleting your account
You can delete your account at any time in the App: Profile → Delete account, confirming your password. If you no longer have the App, email us and we'll complete it within 30 days. Full instructions are on the Data Deletion page.
Deleted: your profile and contact details, login credentials, Cricket ID and CricID mapping, profile photo, friends list, saved teams, scheduled matches, and notifications.
Retained: matches you scored or played in are not deleted, because they are shared records other participants rely on for their own scorecards and statistics — a cricket match doesn't belong to one player alone. These records are disassociated from your deleted profile. If you want a specific match record removed, contact us and we'll consider it (for example where you were the only participant, or where everyone involved agrees).
10. Your rights
Under UK GDPR you have the right to:
- Access — get a copy of the personal data we hold about you
- Rectification — have inaccurate data corrected
- Erasure — have your data deleted (subject to Section 9 on shared match records)
- Restriction — ask us to limit how we use your data
- Portability — receive your data in a machine-readable format, or have it sent to another provider
- Object — object to processing based on legitimate interests
- Withdraw consent — at any time, where consent is the basis
To exercise any of these, email [email protected]. We'll respond within one month. There's no charge, unless a request is manifestly unfounded or excessive.
Complaints: if you're unhappy with how we've handled your data, you can complain to the UK's Information Commissioner's Office — ico.org.uk/make-a-complaint, or 0303 123 1113. We'd appreciate the chance to put things right first.
11. If you're outside the UK
European Economic Area
We apply the same standards under the EU GDPR. You may complain to your national supervisory authority.
California
Under the CCPA/CPRA you may request access to, deletion of, or correction of your personal information, and you have the right not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined under California law, and have not done so in the preceding 12 months.
India
Under the Digital Personal Data Protection Act 2023 you may access, correct, and erase your personal data, nominate someone to exercise your rights on your behalf, and raise a grievance using the contact address above.
Everywhere else
We apply the rights described in Section 10 to all users, wherever you live. Contact us and we'll help.
12. Security
Data is encrypted in transit (HTTPS/TLS) and at rest by our infrastructure providers. Access to the database is governed by server-side security rules determining who can read and write each record — only you can edit your own profile, and only the assigned scorer can change a match score. Passwords are handled entirely by Firebase Authentication; we never store or see them.
No system is perfectly secure. If you believe you've found a vulnerability, please email us directly rather than disclosing it publicly, and we'll fix it.
13. Children
The App is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child under 13 has provided us data, contact us and we'll delete it.
Date of birth is an optional profile field and is not currently used to verify age.
14. Changes to this policy
We may update this policy. Material changes will be reflected in the "Last updated" date above and, where appropriate, notified in the App.
15. Contact
Questions about this policy, or to exercise any right described above: [email protected]