Privacy Policy
Last updated: 2 July 2026
Thank you for your interest in Matchday Manager. Protecting your personal data matters to us. Below we explain which data we process when you use our apps (football and hockey) and this website, for which purposes and on which legal basis.
1. Controller
The controller responsible for the data processing within the meaning of the General Data Protection Regulation (GDPR) is:
Production Build
Owner: Raphael Stäbler
Bischofsweg 31
60598 Frankfurt am Main
Deutschland
Email: [email protected]
Phone: +49 173 4557788
We have not appointed a statutorily required data protection officer; if you have any questions about data protection, you can reach us at any time at the email address above.
2. Principles
We process personal data only to the extent necessary to provide the game or where you have given your consent. Matchday Manager is deliberately built to minimise data: this website sets no tracking cookies and embeds no third-party analytics or advertising services. In the app we refrain from advertising tracking and we do not sell data.
3. Which data we process
When you use the app, we process the following categories of data depending on the feature:
- Account data: your email address, the manager name you choose yourself and your preferred language.
- Login codes: We use passwordless login via a one-time code (OTP) that we send you by email. The code is stored only briefly and is invalidated after expiry or redemption.
- Social login (optional): If you register using "Sign in with Apple" or "Sign in with Google", we receive a unique user identifier (subject ID) from Apple or Google and — if you agree to it — your email address. We never store a password.
- Game data: the team name you choose yourself, your squad, line-ups, transfers, captain and chip decisions, points scored as well as your participation in private and public leagues and the rankings calculated from them. Your team name (as well as your manager name) is moderated automatically, see Section 4.
- Push tokens: If you enable push notifications, we store the device identifier (push token) so that we can deliver notifications to you.
- Feedback: content that you send us via the in-app feedback form or by email.
- Technical data: when you access our servers, usual connection data is generated (e.g. IP address, time, the feature accessed, error logs), which we need in order to provide, secure and troubleshoot the service.
- Crash and diagnostic data: when the app crashes or hits a serious error, we collect technical diagnostic data via Firebase Crashlytics (e.g. device type, operating-system version, stack trace, time) together with a pseudonymous identifier, in order to detect and fix errors.
4. Purposes and legal bases
We process your data for the following purposes and on the following legal bases:
- Provision of the game and account management (registration, line-up, rankings, leagues) — to perform the usage contract, Art. 6(1)(b) GDPR.
- Sending login codes — to perform the usage contract, Art. 6(1)(b) GDPR.
- Game-related notifications (e.g. goal/assist alerts, deadline and captain reminders, price changes) by push and/or email — on the basis of your consent or the settings you have chosen, Art. 6(1)(a) GDPR. You can disable them at any time in the app settings or at device level.
- Handling feedback and support requests — to perform the contract or on the basis of our legitimate interest in responding to your request, Art. 6(1)(b) or (f) GDPR.
- Operation, security and stability (server logs, crash reports via Firebase Crashlytics, abuse and error detection) — on the basis of our legitimate interest in a secure and functional service, Art. 6(1)(f) GDPR.
- Automated moderation of chosen names — We automatically check (with the help of AI) the team name and manager name you choose for insults, hate speech, sexual or discriminatory content and impersonation of other people. The legal basis is our legitimate interest as well as the legitimate interest of other users in being protected from abusive content and impersonation and in safeguarding the community and our brand, Art. 6(1)(f) GDPR. If the automated check results in a rejection, the name is temporarily hidden from other users (it is not deleted; you continue to see it and are asked to change it). You can choose a new name at any time and request a manual review and approval by us.
5. Recipients and processors
To provide the service we use carefully selected service providers that act on our behalf and on the basis of data-processing agreements (Art. 28 GDPR):
- OVHcloud (OVH SAS, France) — hosting and operation of our servers (compute, API) in a data centre within the EU.
- MongoDB Atlas (MongoDB) — managed database for storing the account and game data, operated in a region within the EU.
- Amazon Web Services (Amazon SES) — sending transactional emails (login codes, notifications, feedback forwarding). Europe region (Frankfurt, eu-central-1).
- Amazon Web Services (Amazon Bedrock) — automated, AI-assisted content check of the team and manager names you choose (see Section 4). Only the string to be checked (the name itself) is transmitted; no other personal data (in particular email address, user identifier or similar) is transmitted. The processing takes place in AWS regions within the EU (Frankfurt, eu-central-1). The names are not used to train AI models and are not passed on to the model provider.
- Google (Firebase Cloud Messaging) — delivery of Android push notifications.
- Google (Firebase Crashlytics) — collection of crash and error-diagnostics data to improve the stability of the app.
- Apple (Apple Push Notification service) — delivery of iOS push notifications.
If you obtain the app via the Apple App Store or Google Play, Apple or Google process data as independent controllers in connection with download, installation and — where offered in future — purchases. Their privacy policies apply in that respect.
6. Transfers to third countries
In the context of push delivery (Apple, Google), crash diagnostics (Google Firebase Crashlytics) and possibly during social login, data may be transferred to providers in the USA. This transfer takes place on the basis of appropriate safeguards, in particular the EU standard contractual clauses or — where certified — the EU-US Data Privacy Framework.
7. Retention period
We store account and game data for as long as your account exists. Login codes are deleted after a few minutes (at the latest after expiry or redemption). We keep server logs and technical connection data for 30 days as a rule and then delete or anonymise them, unless they are needed to investigate a specific security incident. Backups of our database are kept on a rolling basis for a limited period. After deletion of your account, we remove or anonymise the associated data, to the extent that there is no legal obligation to retain it further.
8. Deleting your account and data
You can delete your account and all associated data yourself at any time: in the app under Profile → Account & Privacy → Delete account. Alternatively, write to us at [email protected] from the email address you used at registration, and we will delete your account. You can find further information on our support page.
9. Your rights
Within the limits of the statutory requirements, you have the right at any time to:
- access to the data stored about you (Art. 15 GDPR),
- rectification of inaccurate data (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR) as well as
- object to processing that is based on a legitimate interest (Art. 21 GDPR).
You can withdraw consent you have given (e.g. for notifications) at any time with effect for the future. To exercise your rights, a message to [email protected] is sufficient.
10. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. As we are a provider based in Frankfurt am Main, the Hessian Commissioner for Data Protection and Freedom of Information is responsible; however, you can also contact the supervisory authority of your place of residence. Users in Switzerland can additionally contact the Federal Data Protection and Information Commissioner (FDPIC).
11. Changes to this privacy policy
We adapt this privacy policy when the data processing or the legal situation changes. The current version published here, with the date stated above, applies in each case.