IKSU Badminton

Privacy Policy

Last updated: 24 August 2026

Notice version: 2026-08-24

1. Who is responsible for the data

This application is operated by IKSU Badminton ("we", "us") to run the club's badminton ladder competitions. We decide how personal data is processed in the app and are responsible for that processing under applicable data-protection law, including the EU General Data Protection Regulation (GDPR) where it applies.

2. What information we process

Depending on how you use the app, we may process:

  • Account information managed by our authentication provider (including email address and sign-in credentials). We do not store your password ourselves; authentication is handled by Supabase Auth.
  • Identity: first name, last name, and display alias.
  • Contact details: email address and phone number (where supplied).
  • Ladder participation: category (singles/doubles), status (for example active, inactive or pending), division, and related administration fields needed to run the ladder.
  • Ratings: Elo ratings and TrueSkill-related rating data used for long-term strength estimates.
  • Match and competition data: schedules, results, set scores, standings, rating-match invitations and outcomes.
  • Peer ratings: skill estimates (and “don't know” answers) that players submit to help place new members.
  • Privacy-notice acknowledgment: for self-signup, the policy version you acknowledged and a database timestamp of that acknowledgment.
  • Operational records needed to administer the service (for example audit logs of certain admin actions).

3. Why we process it

We process personal data to operate the club ladder service, including to:

  • register and manage participants;
  • arrange and record matches;
  • calculate ratings and standings;
  • let relevant active players contact each other to schedule matches;
  • administer divisions, membership and the application;
  • support security, troubleshooting and backups.

Creating an account requires confirming that you have read this privacy notice. That confirmation is an acknowledgment of the notice. It is not blanket consent to every kind of processing described here, and it is not the same as the separate phone-sharing setting described below.

Where GDPR applies, processing is generally necessary to provide the ladder service you request and to operate the club competition in a practical way. We do not use personal data for advertising, and we do not sell it.

4. Who can see what

Visitors who are not signed in

Public pages may show:

  • display alias;
  • ladder/category, division and status where those surfaces are public;
  • public Elo/rating information;
  • match results and current or historical standings/results.

Logged-out visitors do not receive legal first or last names, email addresses, phone numbers, skip/leave or similar admin-only metadata, or raw TrueSkill μ/σ values. Historical public views use aliases. Permanently deleted players appear as Deleted player in history where a player identity would otherwise be shown.

Signed-in members

Signed-in members may see real player names where the application provides them (for example in member directories and historical identity views designed for members).

Administrators

Club administrators have broader access needed to operate the ladder, including information that is not shown in ordinary member screens (for example raw TrueSkill values and other administration fields). Do not assume that information invisible in the normal UI is invisible to administrators with database access permitted by the application.

5. Contact details and phone visibility

Contact details are available through the ladder contact directory when the viewer is active in that ladder category (singles or doubles). Access is at category level; it is not limited to players in the same division or the same period.

  • Email for active players in that category is available to other active players in the category. There is no separate email “hide from directory” toggle.
  • Phone is shared with other active players in the category only when phone sharing is enabled. Sharing is on by default. You can turn it off under your profile (/me). Turning it off hides your phone from ordinary active-player directory users. Administrators may still access phone data where needed for administration.
  • Pending or inactive players cannot load the contact directory for that category.

6. Ratings and peer ratings

Elo ratings are shown on public and member ladder surfaces as part of the competition. Raw TrueSkill μ/σ values are not shown in ordinary member or public UI; administrators may see them when operating ratings.

Individual peer ratings are not shown to other players. The normal administration interface uses aggregated results, but authorized administrators may access underlying records when necessary for moderation, troubleshooting or administration.

7. Archived and permanently deleted players

Archive

Archiving removes a player from current and public participation lists. Relevant match history and identity data are preserved so historical results remain understandable. Signed-in members may still see historical real identity where the application is designed to show it. Archiving is not the same as full erasure. As part of administration we attempt to unlink and remove the related login account, but we do not promise that every related account step completes instantly in every case.

Permanent deletion

Permanent deletion removes the player and related current data according to the deletion logic implemented in the application. Identifying snapshot fields on historical final standings for that player are cleared. History then displays Deleted player where that identity would have appeared. Permanent deletion does not mean every copy disappears instantly from backups or third-party operational logs (see retention below).

8. Privacy-policy acknowledgment

Self-signup requires confirming that you have read this privacy notice (the checkbox on the registration form). When registration succeeds, we store an acknowledgment record with the notice version and a timestamp generated by the database. That record shows you were shown the notice at signup. It is not blanket consent to all processing.

Acknowledgment history is kept with the login account and is removed when that Auth account is deleted. Existing accounts were not artificially backfilled with acknowledgments when this recording started. Claiming a player profile while already logged in does not create an acknowledgment; creating a new account (including to claim a profile) does, because the signup form and checkbox are used.

9. Service providers and external services

We use the following providers and services in connection with the application:

  • Supabase — database, authentication and related backend infrastructure.
  • Vercel — application hosting and server-side runtime.
  • Resend — transactional and authentication-related email delivery used in production.
  • GitHub / GitHub Actions — encrypted database backups. Backup artifacts are currently retained for up to 30 days.
  • Sentry — when enabled in the deployed environment, error monitoring so we can diagnose failures. Error reports may include limited technical context about a request or session.

WhatsApp is an external communication channel linked from the app (club ladder groups). Messages and content you send in WhatsApp are handled under WhatsApp/Meta's own terms and privacy practices. WhatsApp is not part of our application database.

10. Retention and deletion

  • Live account and ladder data are kept while needed for your participation and for club administration of the competition.
  • Archived player data and history may be retained as described above.
  • Permanent deletion removes or anonymizes data according to the implemented deletion behaviour.
  • Privacy-notice acknowledgments are tied to Auth accounts and are removed when the Auth account is deleted.
  • Encrypted backups may still contain data after it has been deleted from the live system until the backup expires. Current GitHub Actions backup artifact retention is up to 30 days.
  • Where we use third-party email, hosting or error-monitoring services, their own operational logs may follow those providers' retention rules.

We do not claim that deletion from the live application instantly removes every copy from every backup or provider log.

11. Your rights

Depending on applicable law, you may have rights to ask about the personal data we hold, to request correction or deletion, and to request restriction of or object to certain processing. You may also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se.

Contact IKSU Badminton (for example via badminton@iksu.se or a club administrator) if you have questions or wish to exercise these rights. Some requests are handled manually; the app does not automate every data-protection request.

12. Security

Access is protected by authentication, database access controls (including row-level security where configured) and encryption in transit (TLS). Sign-in credentials are handled by Supabase Auth.

13. Changes to this notice

We may update this notice when the service or our data handling changes. The current version and last-updated date are shown at the top of this page. Questions about this notice can be sent to badminton@iksu.se.