← Back to FixturePrivacy policy

FixturePrivacy Policy

Last updated Account-based · synced, with visibility controls

Fixture is a shared app — matches, teams and ledgers involve other people — so some of your data is visible to them by design. This policy sets out exactly which parts, and what you control.

The short version

Fixture holds an account, a profile, and the sporting record you build by playing. Teammates and captains see the parts that a competition requires them to see; you control who can discover and invite you. We do not sell your data, run ads, or track you across other apps.

Who we are

Fixture is operated by Divyansh Karan, trading as Stelr Studio (Remote · India), the data controller for the purposes of the UK GDPR and GDPR. Contact: karandivyansh01@gmail.com.

Account information

What you give us to have an account at all.

DataWhyRequired
Email addressTo create your account, sign you in and send password resetsYes
PasswordStored only as a salted hash by our authentication provider — we never see itYes
Display nameShown to teammates, on scorecards and in invitationsYes
Profile photoShown on your profile and to people in your clubsOptional
CityTo surface local matches and nearby competitionsOptional
Sports you playTo match you with the right fixturesOptional

Sporting and activity data

This is the substance of the app, and all of it comes from matches you take part in:

  • Match records — fixtures, lineups, ball-by-ball or point-by-point scoring, and final scorecards
  • Per-player statistics — runs, wickets, goals, points, ratings and match history
  • Reliability — how often you turned up after saying yes. Captains rely on this, and it is visible to them
  • Club and team memberships, invitations sent and received, and availability
  • Auction and draft records — what you were bought for and by whom
  • Ledger entries — what a match cost, who paid, and what is outstanding
  • Messages you send in match and club chats

Location

Fixture stores the city you enter in your profile, so it can show you local competitions. It does not request or read your device's GPS location, and does no background location tracking.

What we never collect

None of the following is collected, by design:

  • Advertising identifiers, or any data used for advertising or profiling
  • Contacts, calendar, SMS or call logs
  • Data bought from, or shared with, data brokers
  • Any cross-app or cross-site tracking

How we use it

Your data is used to run the app and nothing else:

We do not use your data for advertising, we do not sell it, and we do not share it with data brokers.

  • Provide fixtures, scoring, standings, auctions, tournaments and the ledger
  • Sign you in and keep you signed in
  • Show your record and statistics to you and to the teams you belong to
  • Deliver notifications you have turned on
  • Respond when you contact support

Who can see what

Fixture is a shared app, so some visibility is inherent to it:

  • Teammates and captains in clubs you join see your display name, photo, sporting statistics and reliability record.
  • Anyone in a match you played sees your contribution to the scorecard.
  • People in a club's ledger see what you owe or paid for that club.
  • Chat participants see the messages you send in that conversation.

Your visibility controls

Settings → Privacy governs discovery, and takes effect on the server rather than only in the interface:

  • Captains nearby can invite you when they are short.
  • Only people in teams you belong to can invite you.
  • Nobody can invite you — you will only see matches you go looking for.

Who we share data with

We use these processors, and share your data with no one else except where legally required.

ProcessorWhat it handlesTheir policy
SupabaseDatabase, authentication and file storage — account, sporting, social and ledger datasupabase.com/privacy
Expo / EASApp builds and updates. No personal data.expo.dev/privacy

Where your data is stored

Your data is stored on Supabase infrastructure in the project's configured region. If you are in the UK or EEA and that region is outside it, the transfer relies on the processor's Standard Contractual Clauses.

How long we keep it

  • While your account exists — as long as you keep it.
  • When you delete your account — immediately, as described below.
  • Database backups may retain deleted data until they rotate out on the hosting plan's retention schedule.

Security

The protections actually in place:

No system is perfectly secure. If you find a vulnerability, email karandivyansh01@gmail.com — we will acknowledge within five working days.

  • All traffic between the app and our servers uses HTTPS/TLS.
  • Passwords are stored only as a salted hash by the authentication provider — we never see them.
  • Session tokens are held in the device's hardware-backed secure storage (Keychain on iOS, encrypted storage on Android), never in plain app storage.
  • Row-level security is enforced at the database level, so one account's queries cannot read or modify another account's rows.
  • Sign-in uses the PKCE authorization-code flow.
  • Profile photos are stored in a private bucket and served only through short-lived signed links.

Your rights

Wherever you live, you can exercise all of the following. If you are in the UK or EEA these are your rights under the UK GDPR and GDPR; in California, under the CCPA/CPRA.

To exercise any right, email karandivyansh01@gmail.com. We respond within 30 days.

  • Access — everything we hold is visible inside the app.
  • Correct — edit any entry or profile field directly.
  • Export — request a machine-readable copy of your data.
  • Delete — Settings → Delete account, described below.
  • Withdraw consent for anything optional, by removing the data or revoking the permission in your device settings.
  • Object or restrict processing, and lodge a complaint with your data protection authority (in the UK, the ICO at ico.org.uk).

Deleting your account

Settings → Privacy → Delete account. This cannot be undone: your profile, ratings, statistics, invitations and messages are removed.

Scorecards from matches you played stay, without your name. A completed match is a shared record belonging to everyone who played it, and erasing one player would falsify the others' history — so your contribution is anonymised rather than deleted. This is the one thing account deletion does not erase, and it is called out in the app before you confirm.

If you cannot access the app, email karandivyansh01@gmail.com from your registered address and we will delete the account within 30 days.

Exporting your data

Settings → Privacy → Export produces a machine-readable copy of your profile, statistics and match history.

Children

Fixture is not intended for children under 13. We do not knowingly collect data from children. If you believe a child has created an account, email karandivyansh01@gmail.com and we will delete it.

Changes to this policy

If this policy changes, the updated version ships with the Fixture release it applies to and the date at the top changes. Material changes are surfaced in the app before they take effect.

Contact

Questions about this policy, or about the data the app holds on you, go to karandivyansh01@gmail.com. The data controller is Divyansh Karan, trading as Stelr Studio (Remote · India).

This policy covers Fixture only. Other Stelr apps have their own policies, listed on the apps page.