Privacy Policy — Squadra (سكوادرا)
Last updated / Effective date: July 29, 2026 · Version: 1.4
1. Introduction & Scope
Squadra ("we", "us", or "the App") respects your privacy. This policy explains how we collect, use, and protect your personal data when you use the Squadra app — a platform for organizing matches, splitting teams, booking venues, managing clubs and groups, player cards, and academies.
This policy applies to all users: players, venue owners/partners, academy participants and their guardians, and visitors. It is governed by the Personal Data Protection Law (PDPL) of the Kingdom of Saudi Arabia and its implementing regulations issued by the Saudi Data & AI Authority (SDAIA).
By using the App, you acknowledge that you have read this policy.
2. Controller Identity & Contact
- Data controller: Squadra
- National address: Riyadh, Al-Yarmouk District, Malwi Street, Kingdom of Saudi Arabia
- Contact & privacy requests: info@squadrasa.net
To exercise your rights or for any privacy enquiry, contact us at the email above.
3. Definitions
- Personal data: any data that identifies you or makes you identifiable.
- Sensitive data: data of a special nature under the law, including the optional health and fitness data described in Section 4(h).
- Processing: any operation performed on data (collection, storage, use, disclosure, destruction).
- Guardian: the legal guardian of a minor or their lawful representative.
- Partner/Host: the owner of a venue or academy listed on the platform.
4. Data We Collect
We collect only what is necessary to operate the App:
a) Account & identity data: name (first/last/display), username, email, phone number, and password (hashed/encrypted by our authentication provider). When you sign in via Google or Apple, we receive your name and email from the sign-in provider.
b) Sports profile data: city, position, preferred foot, goalkeeping ability, height and weight (optional), profile photo, your private notes, and your player card and its stats.
c) Social data: friend requests and connections, club and group memberships, and contact numbers — only if you enable "phone matching" (an optional feature to match your contacts, performed locally; we do not reveal your number without your consent).
d) Activity & booking data: trainings, matches and attendance, bookings (dates, times, status, amount, notes), ratings and reviews.
e) Partner/venue data: venue name, address, coordinates, and contact channels (phone/WhatsApp/Instagram), and partner-application data (business name, contact details, license type) — provided voluntarily by the partner.
f) Device & notification data: notification token (Expo Push Token), operating-system type, and device name — to deliver notifications.
g) Location data: when you request "nearby venues" we ask for location permission to calculate distance only. We do not store your location — it is used momentarily and then discarded.
h) Health and fitness data (optional): when you choose to connect Apple Health through HealthKit on iOS or Health Connect on Android, and after granting the relevant system permissions, Squadra receives read-only access to the scopes you select: exercise sessions and duration, distance, active energy/total calories burned, heart rate and averages, resting heart rate, heart-rate variability (HRV), sleep duration, and exercise routes. An exercise route may contain precise location coordinates and is read only after the separate route authorization where the operating system requires it.
We use this data solely to import your activities and show your private performance and recovery insights. It is read and processed temporarily on your device during the current app session; it is not uploaded to Squadra servers, stored in your account, shared or sold, or used for advertising, profiling, or decisions that affect you. Connecting is optional, and declining or revoking access does not affect bookings, matches, or other App functions.
i) Technical data & usage analytics: basic operational and diagnostic logs for security and stability, plus anonymous usage events (page or screen views, tool usage, payment-link steps) that we collect in our own systems to improve the service — tied to a random identifier that does not reveal who you are, not to your name or email, and never shared with any advertiser.
j) Advertising measurement data — only in app builds where measurement is enabled: if you came to Squadra through a paid advertising campaign, we use a specialist measurement partner (AppsFlyer) to determine which campaign led to the install. For this purpose we collect:
- Your device's advertising identifier — on iOS (IDFA) this is never read unless you give explicit permission via Apple's "App Tracking Transparency" prompt; on Android, the Google Advertising ID, which you can delete in your device settings.
- An internal device identifier generated by the measurement partner, your IP address, and your device model and operating system.
- The app install event, a "registration completed" event (we send only the sign-up method, e.g. "email"), and a "purchase" event (we send only the booking amount and the currency, SAR).
These events are passed from the measurement partner to the ad network the campaign came from — TikTok today, and X (Twitter) if enabled later — for one purpose: measuring the effect of the ad. We never send any advertising partner your name, email, phone number, location, or account content. If you decline tracking, measurement is limited to aggregated reports that do not identify you, provided by Apple (SKAdNetwork) or Google.
5. How We Collect Data
- Directly from you when you register, build your profile, book, and interact.
- Automatically from your device (notification token, technical data).
- From sign-in providers (Google/Apple) when you choose to sign in through them.
- From Apple Health or Health Connect only when you initiate the connection and grant the specific read permissions.
- From partners when they list their venues and activities.
6. Purposes & Legal Basis
| Purpose | Legal basis |
|---|---|
| Account creation, authentication, and core services | Performance of a contract |
| Bookings, payments, and their management | Performance of a contract / Legal obligation (invoicing) |
| Operational notifications (reminders, friend requests, booking confirmations) | Performance of a contract / Legitimate interest |
| Phone matching and friend-discovery features | Your consent (optional) |
| Importing health and fitness data and displaying your private performance and recovery insights | Your explicit consent and the specific system permissions (optional) |
| Security improvement and fraud prevention | Legitimate interest / Legal obligation |
| Marketing messages (if any) | Your consent (withdrawable at any time) |
| Advertising campaign measurement (attribution) | Your consent on iOS via the App Tracking Transparency prompt / Legitimate interest in aggregated measurement — you can opt out at any time (see Section 15) |
7. Children's Data & Guardian Consent
The App serves audiences that may include minors (particularly via academies). Therefore:
- The minimum age to create a self-service account is 13. Those under 13 may not self-register.
- Those under 18 require guardian consent and supervision to use the App and to enroll in activities/academies.
- We take reasonable steps to verify the validity of guardianship at academy enrollment, and we do not process a minor's data in a way that harms their interests.
- The guardian may view the minor's activity and exercise their rights on their behalf; these rights revert to the minor upon reaching legal capacity.
- We do not direct marketing to children and do not build profiles of them.
If you become aware that a child under 13 has created an account without permission, contact us to delete it.
8. Disclosure & Data Sharing
We do not sell, rent, or trade your data for monetary consideration. We may share it, only as necessary, with:
- Venue owners/academies: booking details required to fulfil the booking.
- Technical sub-processors (see Section 9).
- Our advertising measurement partner and ad networks (see Section 9): only the measurement data described in Section 4(j) — nothing more, and solely to measure campaign performance.
- Regulatory/judicial authorities upon a lawful request.
- In a merger or business transfer, while committing to protect your data.
Within social features (friends/clubs/rosters) we expose only public fields (name, username, photo) and never reveal your phone number.
We do not share Apple Health or Health Connect data with any party or transmit it to our servers.
9. Sub-processors (Service Providers)
We use trusted providers to operate the App, including:
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication, and file storage |
| Sign-in, and maps/geocoding for addresses | |
| Apple | Sign in with Apple (on iOS) |
| Apple Health / HealthKit | Optional source of health and fitness data the user chooses to read on an iOS device |
| Google Health Connect | Optional source of health and fitness data the user chooses to read on an Android device |
| Expo | App build infrastructure and notification service |
| SMS provider | Delivering phone verification codes (OTP) |
| Payment provider | Payment processing (when enabled) |
| AppsFlyer | Advertising campaign measurement and install attribution (when enabled) |
| TikTok | Receiving conversion events to measure TikTok ad campaigns (when enabled) |
| X (Twitter) | Receiving conversion events to measure X ad campaigns (when enabled) |
10. Cross-Border Transfers
Some data may be stored or processed on our providers' servers outside the Kingdom. In that case we rely on an appropriate legal safeguard (transfer to a jurisdiction with an adequate level of protection, or SDAIA-approved contractual clauses), and we limit transfers to the minimum necessary. [Hosting region and transfer mechanism to be specified on adoption]
11. Retention & Destruction
We retain your data only for as long as necessary:
- Account & profile: for the life of the account, then deleted or anonymized upon a deletion request (and purged from backups within ≤30 days).
- Bookings, invoices, and payment records: up to 6 years to comply with tax and accounting regulations.
- Support communications: up to 24 months.
- Notification tokens / device data: until de-registration or account deletion.
- Technical logs: up to 90 days.
- Apple Health and Health Connect data: not retained on our servers; processing remains temporary on the device during the current app session.
- Advertising measurement data: retained by the measurement partner in line with the retention periods in its agreement; we do not store your device advertising identifier in our own systems.
- Shared content (clubs/groups/ratings): anonymized rather than deleted to preserve others' records.
12. Account Deletion
You can delete your account from within the App (Settings), or via our public account-deletion page: https://squadrasa.net/account-deletion. Upon deletion we remove or anonymize your personal data, except what we are legally required to retain (such as invoices).
Deleting your Squadra account does not delete the original records in Apple Health or Health Connect because Squadra neither owns nor writes those records. You can manage or revoke Squadra's access in your device's Apple Health or Health Connect settings.
13. Your Rights & How to Exercise Them
Under the law, you have the right to: be informed, access your data, rectify, erase, restrict processing, port, withdraw consent, and object. To exercise any right, email us at info@squadrasa.net and we will respond within the statutory period. You can also adjust your privacy settings in the App (visibility, phone matching, photo visibility), disconnect the health source in the App, or revoke its permissions in your device settings at any time.
14. Data Security
We apply reasonable technical and organizational measures (encryption in transit, access controls, row-level security) to protect your data from unauthorized access or disclosure. No system is 100% secure, but we strive for the best possible protection.
15. Cookies, Tracking Technologies & Advertising Measurement
In the App: we use basic local storage to operate the App (saving your session, preferences, and language). In builds where advertising measurement is enabled, we use your device advertising identifier for the purpose described in Section 4(j) — we do not use it to show you ads inside the App, to build an interest profile about you, or to track you across other apps.
How to turn off advertising measurement — at any time:
- On iOS: choose "Ask App Not to Track" when Apple's prompt appears, or later via: Settings → Privacy & Security → Tracking → turn off "Squadra".
- On Android: Settings → Privacy → Ads → "Delete advertising ID".
- Or email us at info@squadrasa.net and we will stop this processing for your device.
Turning off advertising measurement disables nothing in Squadra — booking, team splitting, clubs, and notifications all work exactly the same.
On the web (squadrasa.net): we use our own first-party analytics to measure site usage: a random anonymous browser identifier is stored in your device's local storage, and events are sent only to our own servers — never shared with any advertiser, never linked to your name or email, and never used to target ads at you. You can clear it by clearing site data in your browser.
Ad measurement tools on the web — only with your consent: to learn which ad brought visitors to our site, we may load measurement tools from our advertising platforms: the X pixel, the Meta pixel (Facebook/Instagram), the TikTok pixel, and the Snapchat pixel. None of these tools ever loads before you consent via a notice with equally prominent accept and decline options — if you decline, nothing loads and nothing about the site changes for you. If you consent, a tool reads the address of the page you visit, the referrer, and your IP address, and may set a cookie from its platform — it never receives your name, your bookings, or your payment details, and it never runs on payment pages or join links. Withdrawing consent is as easy as giving it: use the "Change ad-measurement choice" button on this page, or clear the site data in your browser, and the notice will appear again. Platform privacy policies: X (https://x.com/privacy) · Meta (https://www.facebook.com/privacy/policy) · TikTok (https://www.tiktok.com/legal/privacy-policy) · Snapchat (https://values.snap.com/privacy/privacy-policy)
Server-side conversion measurement (no pixel): when a payment or registration completes, we may report the conversion event to the ad platform that referred you directly from our servers to measure campaign effectiveness, hashing (one-way encrypting) any contact identifier (such as email or phone) before it is sent — your data is never sent in readable form, and your card details are never sent at all. This measurement does not run on payment pages in your browser and does not read your browsing, and you can object to it at any time by writing to info@squadrasa.net.
16. Data Breach Notification
In the event of a breach affecting your data, we commit to notifying the Saudi Data & AI Authority (SDAIA) within 72 hours of becoming aware of it, and to notifying affected individuals without undue delay where there is a serious risk to their rights.
17. Changes to This Policy
We may update this policy and will publish the updated version with a new effective date, notifying you of material changes via the App or email. Your continued use after an update constitutes acceptance.
18. Contact & Complaints
For any privacy enquiry or complaint, email us at info@squadrasa.net. You also have the right to lodge a complaint with the Saudi Data & AI Authority (SDAIA) if your complaint is not resolved.
Squadra — Riyadh, Al-Yarmouk District, Malwi Street · info@squadrasa.net