Privacy Policy

Effective date: 7 August 2026 · Last updated: 7 August 2026

This policy explains what information Gully Cricket ("the App", "we", "us") collects, why, how it is stored and shared, and what rights you have over it. It applies to the mobile app, this website, and the services behind them.

It is written to describe what the App actually does. If something here doesn't match the App's behaviour, that's a fault in this document — please tell us.

1. Who we are

Data controllerWe Ingenious
Based inUnited Kingdom
Contact[email protected]

We are the "controller" of your personal data under the UK GDPR and the Data Protection Act 2018 — meaning we decide what data is collected and why. We have not appointed a Data Protection Officer, as we are not required to.

2. What we collect

We collect only what the App needs to work. We use Firebase Analytics to understand how the App is used — how many people finish setting up a match, which features are reached, where people give up. These are counts of actions, not records of you: no advertising SDKs, no ad networks, no cross-app tracking, no Mixpanel, no Amplitude, no Meta SDK. We do not sell your data to anyone, in any jurisdiction, and never have.

DataWhyStored off your device?
Email address, and a password (hashed by Firebase — we never see it)Account creation, sign-in, recoveryYes
Google account details, if you use "Sign in with Google"Alternative sign-inYes
Display name, Cricket ID (@handle), permanent numeric CricIDYour identity across matches; how friends find youYes
Phone number, date of birth, gender (optional)Your profile; phone lets friends find youYes — in a restricted record only you can read
Profile photo (optional)Personalising your profile and team sheetsYes
Location — a one-time fix, converted to a place name on your device (optional)Tagging your area or a match venueOnly the resulting place name (e.g. "Leeds, UK"). Raw GPS coordinates are never stored. No background or continuous tracking.
Contacts — name and phone number (optional)Finding friends who already use the AppMatching happens on your device. Contacts you explicitly add as friends are saved to your own private friends list, readable only by you. Your full address book is never uploaded.
Match data — scores, ball-by-ball history, player names, statisticsThe core function of the AppYes — see Section 5 on visibility
Push notification tokenMatch invites, scoring handoff requests, resultsYes — deleted when you sign out
Crash reports — error, stack trace, app version, device model, OS version, screenDiagnosing and fixing crashesYes — tied to a non-reversible identifier, not your account ID. Disabled in development builds.
Bug reports and feedback you send us — the name you type, your message, and the app version, device model and OS version; plus a crash report or recent log entries if you choose to attach themInvestigating and fixing what you reportYes — stored with your account ID, and also emailed to us through a third party (see Section 4)
Biometric unlock preferenceOptional app lockNo. Fingerprint and face matching happen entirely within your device's operating system; we receive only a yes/no result and never any biometric data.

3. Our lawful basis for using it

Under UK GDPR we must have a lawful basis for each purpose. Ours are:

PurposeLawful basis
Creating your account and providing scoring, teams, and scorecardsContract — necessary to deliver the service you asked for
Optional profile details, contacts access, location, notificationsConsent — you choose these, and can withdraw at any time
Crash diagnostics, security, and preventing abuseLegitimate interests — keeping the App working and secure, balanced against your privacy (the data is minimal and pseudonymised)
Responding to lawful requestsLegal obligation

Where we rely on consent, withdrawing it is straightforward: revoke the permission in your device settings, or clear the optional field in your profile. Withdrawing consent doesn't affect processing already carried out.

We do not carry out automated decision-making or profiling that produces legal or similarly significant effects.

4. Who we share it with

We do not sell your personal data, and we do not share it with advertisers or data brokers. Data is shared only with the infrastructure providers that run the App on our behalf ("processors"), who may act only on our instructions:

ProviderWhat they handle
Google FirebaseAuthentication, Firestore database, Cloud Storage, Cloud Messaging, Crashlytics, App Check, Cloud Functions
SupabaseLong-term archive of historical ball-by-ball match data, moved out of the live database once a match is complete
EmailJSDelivering the bug reports and feedback you submit in the App to our support inbox. The name and message you type pass through, and are retained in that provider's own sending history as well as in our inbox
CloudflareServing this website

We may also disclose information where required by law, or to protect the rights, safety, or property of our users or the public.

5. Match data is shared by design

This is the most important thing to understand about the App, so we'll be plain about it.

In practice:

6. Information about other people

The App lets you enter details about other people — teammates' and opponents' names, and how they performed in a match you're scoring. If you do that, you're responsible for having a proper reason to, such as being the designated scorer for a real match they're playing in.

If someone has recorded information about you and you'd like it corrected or removed, contact us at [email protected]. You have the same rights over that data as anyone else, whether or not you have an account.

7. Where your data is stored

Our infrastructure providers operate globally, so your data may be stored or processed outside the United Kingdom, including in the United States.

Where data leaves the UK or EEA, it is protected by the safeguards required under UK GDPR — the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses, as incorporated into our providers' data processing terms. You can request more detail using the contact address above.

8. How long we keep it

DataRetention
Account, profile, and identity recordsUntil you delete your account
Friends list, saved teams, scheduled matchesUntil you delete them, or delete your account
Push notification tokenCleared when you sign out
Ball-by-ball match detailHeld in the live database, then moved to long-term archive storage once the match is complete
Match records and scorecardsRetained after account deletion — see Section 9
Crash reportsPer Firebase Crashlytics' standard retention (up to 90 days)

9. Deleting your account

You can delete your account at any time in the App: Profile → Delete account, confirming your password. If you no longer have the App, email us and we'll complete it within 30 days. Full instructions are on the Data Deletion page.

Deleted: your profile and contact details, login credentials, Cricket ID and CricID mapping, profile photo, friends list, saved teams, scheduled matches, and notifications.

10. Your rights

Under UK GDPR you have the right to:

To exercise any of these, email [email protected]. We'll respond within one month. There's no charge, unless a request is manifestly unfounded or excessive.

Complaints: if you're unhappy with how we've handled your data, you can complain to the UK's Information Commissioner's Office — ico.org.uk/make-a-complaint, or 0303 123 1113. We'd appreciate the chance to put things right first.

11. If you're outside the UK

European Economic Area

We apply the same standards under the EU GDPR. You may complain to your national supervisory authority.

California

Under the CCPA/CPRA you may request access to, deletion of, or correction of your personal information, and you have the right not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined under California law, and have not done so in the preceding 12 months.

India

Under the Digital Personal Data Protection Act 2023 you may access, correct, and erase your personal data, nominate someone to exercise your rights on your behalf, and raise a grievance using the contact address above.

Everywhere else

We apply the rights described in Section 10 to all users, wherever you live. Contact us and we'll help.

12. Security

Data is encrypted in transit (HTTPS/TLS) and at rest by our infrastructure providers. Access to the database is governed by server-side security rules determining who can read and write each record — only you can edit your own profile, and only the assigned scorer can change a match score. Passwords are handled entirely by Firebase Authentication; we never store or see them.

No system is perfectly secure. If you believe you've found a vulnerability, please email us directly rather than disclosing it publicly, and we'll fix it.

13. Children

The App is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child under 13 has provided us data, contact us and we'll delete it.

Date of birth is an optional profile field and is not currently used to verify age.

14. Changes to this policy

We may update this policy. Material changes will be reflected in the "Last updated" date above and, where appropriate, notified in the App.

15. Contact

Questions about this policy, or to exercise any right described above: [email protected]