# Privacy Policy
**Last updated:** April 11, 2026
**Version:** 1.0
---
## 1. Data Controller
The data controller for the Football Buddy application ("Application") is the individual developer **Özge Erdoğan**.
**Contact:** [email protected]
This Privacy Policy explains what personal data we collect, why we collect it, how we use it, who we share it with, how long we retain it, and what rights you have over your data.
---
## 2. Data We Collect
### 2.1 Registration and Profile Information
- First and last name
- Email address
- Profile photo (optional)
- Playing position (optional)
- Trust score and rating information
### 2.2 Activity and Usage Information
- Created listings and join requests
- Participation status (pending, accepted, rejected)
- Favorited listings
- In-app messaging content
### 2.3 Technical and Device Information
- Device type and operating system version
- IP address
- Application usage logs and error reports
- Firebase Cloud Messaging (FCM) token (for push notifications)
### 2.4 Location Information
- City and district (entered by the user when creating a listing)
- Map-selected location coordinates (optional, associated with listing)
---
## 3. How We Use Your Data
We use the collected data for the following purposes:
- **Account creation and management:** User registration, profile creation, and updates
- **Service delivery:** Operating match listing, participation management, and messaging features
- **Push notifications:** Participation requests, acceptance/rejection notifications, and match reminders
- **Security:** Detecting fake accounts and preventing abuse
- **Application improvement:** Error detection, performance analysis, and enhancing user experience
- **Legal compliance:** Fulfilling legal obligations
---
## 4. Legal Bases for Processing
We process your personal data under the following legal bases:
| Purpose | Legal Basis |
|---------|-------------|
| Account creation and service delivery | Performance of a contract |
| Push notifications | Consent |
| Security and verification | Legitimate interests |
| Legal compliance | Legal obligation |
| Application improvement | Legitimate interests |
---
## 5. Sharing Your Data
### 5.1 Third-Party Service Providers
We share data with the following service providers to operate the Application:
- **Google Firebase** (Firestore database, authentication, push notifications, storage) — Google LLC, USA
- **Google Maps Platform** — Google LLC, USA
These providers are bound by data processing agreements and are obligated to protect your data. Google LLC participates in the EU-US Data Privacy Framework.
### 5.2 Legal Requirements
We may disclose your data to competent authorities when required by law, regulation, or legal process.
### 5.3 We Do Not Sell Your Data
We do not sell, rent, or trade your personal data to any third party for commercial purposes.
---
## 6. Data Retention
| Data Category | Retention Period |
|---------------|-----------------|
| Account and profile information | Until account deletion |
| Messaging content | Until account deletion |
| Listing and participation data | Until account deletion |
| Technical logs and error reports | 6 months |
| Feedback submissions | 1 year |
| Data related to legal disputes | Until dispute resolution |
When you delete your account, your personal data is permanently removed from our systems within the periods above. Removal from backup systems is completed within 30 days.
---
## 7. Cookies and Similar Technologies
As a mobile application, Football Buddy does not use traditional browser cookies. However, the Firebase SDK may use local storage mechanisms for session management and analytics purposes.
---
## 8. Data Security
We implement the following technical and administrative measures to protect your personal data:
- **Encrypted communication:** All data transmission is encrypted using HTTPS/TLS protocols
- **Firebase security rules:** Access to the Firestore database is restricted through user authentication
- **Authentication:** Secure session management via Firebase Authentication
- **Access control:** Data is accessible only to authorized personnel
- **Regular security assessments:** Security vulnerabilities are continuously monitored
In the event of a data breach, we will notify the relevant supervisory authority and affected users as required by applicable law.
---
## 9. Your Privacy Rights
Depending on your location, you may have the following rights:
- **Right to know:** Learn whether your personal data is being processed
- **Right of access:** Request access to the personal data we hold about you
- **Right to rectification:** Request correction of inaccurate or incomplete data
- **Right to erasure:** Request deletion of your personal data
- **Right to restrict processing:** Request that we limit how we use your data under certain conditions
- **Right to object:** Object to processing based on legitimate interests
- **Right to data portability:** Request your data in a structured, machine-readable format
- **Right to withdraw consent:** Withdraw consent at any time where processing is based on consent
### How to Exercise Your Rights
To exercise your rights, please contact us through the feedback form within the Application or by email at **[email protected]**. Requests will be responded to within 30 days. Please include your name, contact information, and a description of your request.
---
## 10. Children's Privacy
Our Application is not intended for individuals under the age of 16. We do not knowingly collect personal data from users under 16. If we become aware of this, we will promptly delete the relevant data.
---
## 11. Third-Party Links
The Application may contain links to third-party websites or services. We are not responsible for the privacy practices of sites accessed through these links.
---
## 12. International Data Transfers
Your data may be transferred to and processed in countries outside your country of residence, including the United States, where our service providers (such as Google Firebase) operate. We ensure that such transfers comply with applicable data protection laws through appropriate safeguards such as standard contractual clauses or participation in recognized frameworks.
---
## 13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Important changes will be announced via in-app notifications. You can always review the current policy within the Application.
---
## 14. Contact
For questions about our privacy practices, please contact us through the feedback form within the Application or by email at **[email protected]**.
---
*Football Buddy — Your data is safe, your game is on the field.*