Legal

Privacy Policy

What Scrimfield collects, why, and who it goes to — plus the choices and rights you actually have. We tried to write it so a person would read it: plain language, every third party named by name, no vague "we may share with partners" line hiding what really happens.

Effective [date] Last updated [date] Version [x] Applies to the Scrimfield mobile app
On this page

The short version

We collect what the app actually needs — your profile, a home location so we can tell you how far things are, and a one-off location check when you scan into a match. There's an optional toggle to share your live location with other players for a short window around a match, if you want it. Everything runs on Firebase and Google Cloud, and a handful of named services get a coarse or one-time location to draw maps, turn coordinates into a place name, route you somewhere, or check the weather. We don't sell anything that identifies you, and we don't run ads. We might publish aggregated stats nobody can trace back to a person, and never anything from a user under 18. You can see, fix, export, or delete your data whenever you want — section 9 has the details. This doesn't replace actually reading the sections below; it's just the gist.

01 Who we are #

Scrimfield is a mobile app for finding casual, in-person sport. It's run by [legal operator name — sole proprietor or registered company], based at [registered address] in Nepal — that's who “we,” “us,” and “Scrimfield” mean throughout this page, and who's responsible for the personal data described here. Got a question or a request? hello@scrimfield.com.

02 Information we collect #

You give us

  • At signup: your name, a username, your email, your main sport, date of birth, and your home location — we need that last one to finish setting up your account (more in section 3).
  • If you sign in with Google instead: just your name and email from them. Nothing more.
  • Whenever you feel like it: a profile photo, a short bio, a preferred position, or any venue listings you post.
  • If you email us: whatever you wrote, plus your address so we can reply.

We collect as you use the app

  • One more location reading, separate from your home location, when you scan a match's QR code to confirm you showed up (section 3 again).
  • Your live location and which way you're facing — but only if you've turned on live location sharing for that match (section 3).
  • The matches, guilds, guild battles, chats, and reviews you're part of. Your attendance and no-show record. Your XP, level, quests, and stats.
  • Whatever reviews other players at the same match write about you.
  • The basic technical stuff needed to keep the service running and safe: your IP address, what kind of device and OS you're on, your app version, and some app-integrity signals (that's the reCAPTCHA / App Check bit — more in section 5). We don't touch advertising identifiers, and there's no third-party ad or analytics code in the app at all.

03 Location data #

Location matters enough to this app that it gets its own section instead of hiding in a list above. There are three separate things we do with it:

  • Home location, saved at signup. This is how we match you with nearby games and work out your rough distance to venues and other adult users. Nobody else ever sees your exact coordinates or a pin on a map from this — Players Near You rounds it to the nearest 5 km, and what we send our weather provider is rounded to about 1 km. [Product decision: consider storing an area/neighbourhood rather than precise coordinates, since nothing in the app uses the precise value.]
  • Attendance scan, one time only. Scanning a match's QR code reads your device location once, just to confirm you were actually there. It gets deleted along with the rest of that match's data about a day later.
  • Live location sharing, opt-in and temporary. For a window around a match, or a guild battle, there's a toggle that broadcasts your current position, which way you're facing, and your username to whoever else in that match has also turned it on, so you can actually find each other near the venue. It's off unless you turn it on, you choose that fresh each time, you can switch it off whenever, and it shuts itself off the moment the window closes. Nobody outside that match sees it, and none of it is kept once the window ends.

If you're under 18, Players Near You isn't part of your app at all — you can't turn it on, and you never show up in anyone else's results. If you're an adult, there's a switch for it in Settings: flip it off and the trade is even, you stop seeing other players' distances the same moment you stop appearing in theirs.

04 How we use it, and our legal bases #

Mostly, your data runs the app: matching you with nearby, age-appropriate games, checking who showed up, running guilds, reviews, and messages between people who've friended each other. Where data-protection law wants us to name a specific legal basis for each purpose, here's the table:

PurposeBasis
Creating and running your account; matches, chat, guilds, reviewsPerformance of our contract with you (our Terms of Service)
Attendance verification, no-show limits, fraud and abuse prevention, app-integrity checks, keeping the service secureOur legitimate interest in a service that works and is safe to use
Players Near You distance displayOur legitimate interest in helping nearby players connect — you may object; see section 9
Live location sharingYour consent (the toggle), withdrawable at any time
Recording that a 13–17 user's parent or guardian gave consentLegal obligation / your consent
Responding to your messages and rights requestsLegitimate interest / legal obligation

We don't use any of this for advertising, and we don't sell anything that identifies you.

05 Who we share data with #

We only ever share what a feature genuinely can't work without, plus aggregated numbers nobody can trace back to a person. Every recipient gets named here, not hidden behind a general “partners” clause.

  • Firebase and Google Cloud (Google). Our hosting, database, login system, and file storage — everything in section 2 lives on their servers.
  • Google reCAPTCHA Enterprise and the platform's own app-attestation services (Apple App Attest, Google Play Integrity). These get device and usage signals to confirm a request is really coming from an unmodified copy of the app, not a bot or a tampered client. Google's own Privacy Policy governs what it does with reCAPTCHA data.
  • Google, again, but only if you sign in with it — just your name and email, to set up the account. Nothing else goes to them, and we never tell them what you do inside the app.
  • OpenStreetMap's Nominatim service. It sees your coordinates exactly once, at signup, so we can turn them into a place name like “Kathmandu” before we save anything. It never gets your name or your profile.
  • An OSRM routing server, which sees your live location and a venue's coordinates while the walking-directions screen is open, purely to work out the route.
  • OpenFreeMap, and Esri if you switch on satellite view, draw the map itself. They get the patch of map on your screen, not your identity or exact location.
  • Open-Meteo, our weather provider. It only ever gets a location rounded to about a kilometre, never exact, to return the forecast on your home screen and on match or venue cards. It doesn't know your name or your account.
  • Other users, as covered in section 6, plus your live location during a match window if you've opted into sharing it.
  • Whatever replaces any of the above. If we swap in a different map, geocoding, routing, weather, or attestation provider doing the same job, this paragraph already covers it — we won't send a separate announcement every time.
  • Authorities, if the law requires it, or if we genuinely believe it's necessary to prevent serious harm.
  • A buyer, in the event Scrimfield is ever sold or merged — your data would transfer to whoever takes over, still bound by this same policy, and we'd tell you before it happened.

Aggregated statistics

We might also publish, or hand to outside groups like venues, sports bodies, or city recreation programmes, aggregated numbers that have been stripped of anything identifying — how many players in a city play a given sport, say, or which nights fill up fastest. That never includes your profile, your name, your messages, or your exact location; it's rolled up across enough people that no individual comes back out of it. Data from anyone under 18 doesn't go into these numbers at all. And again: we don't sell anything that identifies you. If we ever bring in a genuinely new kind of recipient, we'll name it here.

06 What other users can see about you #

What's visible: your name, username, sport, position, bio, photo, your level/XP/wins/matches-played, your verified-attendance rate, which guild you're in, reviews written about you, your rough Players Near You distance if you're an adult, and — only while it's switched on for a match — your live position, heading, and username to the other players who opted in with you.

What's never visible: your date of birth, exact coordinates, email, phone or other contact details, attendance-scan locations, or a detailed history of every match you've played.

07 Where your data is processed #

Scrimfield runs on Google Cloud and Firebase, so depending on how Google's regions are configured, your data may sit on servers outside Nepal, including in the United States. If you're in the UK, the EEA, or Switzerland and your data leaves those regions, that transfer relies on Google's own Data Processing Addendum and Standard Contractual Clauses. [Confirm the Firestore/Storage region you selected and name it here.]

08 How long we keep it #

  • Match details, match chat, attendance-scan locations — gone automatically about a day after the match.
  • Live location shared during a match — not kept once the sharing window closes.
  • Your profile and account data — kept while your account exists, removed when you delete it (section 10).
  • Direct messages and reviews — around until you, the other person, or account deletion removes them.
  • Attendance and no-show history — kept while your account's active, since it's what powers no-show limits and your verified-attendance rate. [Set and state a defined retention period, e.g. rolling 12 months; indefinite retention needs a stated justification.]
  • Support emails — kept for up to [24] months, then deleted.
  • Anything we're legally required to keep, like a parental-consent record — for as long as the law says we have to.

09 Your rights and choices #

Here's what's actually available to you:

  • Access — ask for a copy of the personal data we hold on you.
  • Correct — fix anything that's wrong. Most of it you can edit straight from Settings; email us for whatever you can't.
  • Export — get your data out in a portable format.
  • Delete — your account and everything with it (section 10).
  • Object — to anything we're doing on a legitimate-interest basis, Players Near You included.
  • Withdraw consent — for anything you've opted into, turning off live location sharing, for instance.
  • Complain — to your local data-protection authority, if you're somewhere that has one. The UK and EEA both do.

To use any of these, email hello@scrimfield.com from the address on your account. We aim to get back to you within 30 days, and asking costs you nothing and changes nothing about how we treat you.

10 Deleting your account #

Delete your account any time, right from Settings, and it actually goes: your profile, date of birth, stored location, username, login, photo, every DM thread, the reviews and venue comments you wrote, any venues you posted. You come out of every attendance record, your guild spot frees up, and live location sharing ends immediately. Reviews other people wrote about you go too. Give it a little while to fully clear.

Two things stay on purpose: abuse reports you filed, kept as a safety record, and any aggregated stats we'd already produced (section 5), which never had your name attached in the first place.

11 Users aged 13–17 #

You need to be at least 13 to use Scrimfield. Between 13 and 17, a parent or guardian has to give consent during signup, and we keep a record that it happened. It's a consent record, not identity verification — there's genuinely no way to confirm online that it was actually a parent who filled it in, and we're not going to pretend there is.

Under-18 accounts collect the same data as adult ones, because the core matching and attendance features don't work without it. What's different is how that data gets used: no Players Near You, in either direction; nothing from a minor ever ends up in the aggregated statistics in section 5; and the same “never visible” list in section 6 applies to them too.

A parent or guardian can reach hello@scrimfield.com any time to look at, fix, or delete their child's data, or to pull consent altogether — which closes the account.

12 Security and data breaches #

We rely on the access controls, database rules, encrypted transport, and app-integrity checks the platform gives us, and we keep production data access tightly limited. No system is unbreakable, though. If a breach ever puts your personal data at real risk, we'll tell you, and tell the relevant authority too if the law requires it, without sitting on it.

13 Changes to this policy #

The “Last updated” date at the top moves whenever this policy changes. If a change actually matters — a new kind of data, a new recipient, a new reason we're using something — we'll put it in front of you again inside the app before you can keep going.

14 Contact #

Questions, a rights request, or anything else about this page: hello@scrimfield.com. By post: [registered address], Nepal.