Privacy policy

Privacy policy

Last updated August 2026. This notice explains exactly what Paddle Time Bro stores, why, and what rights you have over it. It is written to meet the EU General Data Protection Regulation (GDPR) and the UK GDPR, and applies to everyone regardless of where you live.

1. Who is responsible for your data

The data controller for Paddle Time Bro (paddletimebro.com) is the operator of Paddle Time Bro, contactable at vsg78999@gmail.com. We are a small independent operation and are not required to appoint a Data Protection Officer, so that address reaches the person responsible directly.

2. There are no accounts

You do not register, and the site never asks for your name, email address, phone number, date of birth or password. There is no login and no marketing list.

3. What we collect, why, and the legal basis

DataPurposeLegal basis (Art. 6 GDPR)
Player names you type inLabelling teams and matches on the scoreboardConsent — you choose what to type (Art. 6(1)(a))
Teams, schedule, scores, session codeRunning the session and the live share linkPerformance of the service you requested (Art. 6(1)(b))
Anonymous device identifierKnowing which device is the scorer and may edit the sessionLegitimate interest in preventing tampering (Art. 6(1)(f))
Advertising cookies and identifiersServing and measuring ads that fund the siteConsent, collected before any ad loads (Art. 6(1)(a))

We collect no location data, no contacts, no photos, no IP-based analytics profile, and no special category data. We do not sell personal data, and no automated decision-making or profiling with legal effects takes place.

The player names you enter are the only free-text field. Because you decide what goes in it, please use first names or nicknames and do not enter anything sensitive.

4. Who else can see your session

Anyone holding a session's six-character code can view that session, including the player names in it. That is the purpose of the share link — it lets waiting players follow the score. Only the device that created the session can change scores. Treat the code as semi-public.

5. Processors we use

  • Google Firebase (Firestore, Authentication, Hosting) — stores sessions and serves the site.
  • Google AdSense — serves the advertising that funds the site.

Both are operated by Google. We have no other processors and share your data with no one else, except where we are legally obliged to.

6. International transfers

Session data is stored in Google Cloud Firestore in the asia-south1 region (Mumbai, India). If you are in the EEA, UK or Switzerland, this is a transfer outside your region. It is covered by the European Commission's Standard Contractual Clauses incorporated into Google Cloud's Data Processing Addendum. Advertising data may additionally be processed by Google in the United States under the same safeguards.

7. How long we keep it

  • Sessions: kept until you delete them, using the Delete session data button on the results screen. They are not expired automatically today; each one records an expiry date one year after its last update, which we intend to start acting on.
  • Local copy on your device: until you delete the session or clear your browser storage.
  • Advertising cookies: per Google's own retention periods, described in their policies linked below.

8. Cookies and advertising

This site is funded by Google AdSense. Google and its partners use cookies and similar technologies to serve and measure ads, and may show personalised ads based on your prior visits to this and other websites.

If you are in the EEA, the UK or Switzerland, you are shown a consent choice before any personalised advertising cookie is set. Declining does not stop you using the site — you will simply see non-personalised ads. You can change or withdraw that choice at any time through the privacy settings link in the ad consent banner, and withdrawing is as easy as giving it.

Further controls: Google Ads Settings, how Google uses data from sites that use its services, and aboutads.info/choices for third-party vendors.

Strictly necessary storage — the local copy of your own session — is not a tracking cookie and is required for the site to function offline.

9. Your rights

Under the GDPR and UK GDPR you have the right to: access your data; have it corrected; have it erased; restrict how it is processed; object to processing based on legitimate interests; receive it in a portable format; and withdraw consent at any time without affecting processing already carried out.

Most of these you can exercise yourself in seconds: Delete session data on the results screen erases a session from our server and from your device permanently. For anything else, email vsg78999@gmail.com with the session code and we will respond within one month, free of charge.

Because sessions carry no name, email or account, we may be unable to identify a session as yours without its code — please include it.

10. Complaints

If you believe your data has been mishandled you may complain to your local supervisory authority. In the EEA, find yours via the European Data Protection Board. In the UK, the Information Commissioner's Office. We would appreciate the chance to put it right first.

11. Security

The site is served exclusively over HTTPS. Access rules on the database permit only the device that created a session to modify it, and no administrative interface is exposed to the public internet.

12. Children

The site is not directed at children and we do not knowingly collect data from anyone under 16 (or the lower age set by your member state, minimum 13). If a child has entered names here, email us and we will delete the session.

Changes

Any material change to this policy will be reflected in the date at the top of this page.

Contact

Questions about this policy: vsg78999@gmail.com.

Advertisement