Privacy Policy — Squadra (سكوادرا)

Last updated / Effective date: July 29, 2026 · Version: 1.4

1. Introduction & Scope

Squadra ("we", "us", or "the App") respects your privacy. This policy explains how we collect, use, and protect your personal data when you use the Squadra app — a platform for organizing matches, splitting teams, booking venues, managing clubs and groups, player cards, and academies.

This policy applies to all users: players, venue owners/partners, academy participants and their guardians, and visitors. It is governed by the Personal Data Protection Law (PDPL) of the Kingdom of Saudi Arabia and its implementing regulations issued by the Saudi Data & AI Authority (SDAIA).

By using the App, you acknowledge that you have read this policy.

2. Controller Identity & Contact

To exercise your rights or for any privacy enquiry, contact us at the email above.

3. Definitions

4. Data We Collect

We collect only what is necessary to operate the App:

a) Account & identity data: name (first/last/display), username, email, phone number, and password (hashed/encrypted by our authentication provider). When you sign in via Google or Apple, we receive your name and email from the sign-in provider.

b) Sports profile data: city, position, preferred foot, goalkeeping ability, height and weight (optional), profile photo, your private notes, and your player card and its stats.

c) Social data: friend requests and connections, club and group memberships, and contact numbers — only if you enable "phone matching" (an optional feature to match your contacts, performed locally; we do not reveal your number without your consent).

d) Activity & booking data: trainings, matches and attendance, bookings (dates, times, status, amount, notes), ratings and reviews.

e) Partner/venue data: venue name, address, coordinates, and contact channels (phone/WhatsApp/Instagram), and partner-application data (business name, contact details, license type) — provided voluntarily by the partner.

f) Device & notification data: notification token (Expo Push Token), operating-system type, and device name — to deliver notifications.

g) Location data: when you request "nearby venues" we ask for location permission to calculate distance only. We do not store your location — it is used momentarily and then discarded.

h) Health and fitness data (optional): when you choose to connect Apple Health through HealthKit on iOS or Health Connect on Android, and after granting the relevant system permissions, Squadra receives read-only access to the scopes you select: exercise sessions and duration, distance, active energy/total calories burned, heart rate and averages, resting heart rate, heart-rate variability (HRV), sleep duration, and exercise routes. An exercise route may contain precise location coordinates and is read only after the separate route authorization where the operating system requires it.

We use this data solely to import your activities and show your private performance and recovery insights. It is read and processed temporarily on your device during the current app session; it is not uploaded to Squadra servers, stored in your account, shared or sold, or used for advertising, profiling, or decisions that affect you. Connecting is optional, and declining or revoking access does not affect bookings, matches, or other App functions.

i) Technical data & usage analytics: basic operational and diagnostic logs for security and stability, plus anonymous usage events (page or screen views, tool usage, payment-link steps) that we collect in our own systems to improve the service — tied to a random identifier that does not reveal who you are, not to your name or email, and never shared with any advertiser.

j) Advertising measurement data — only in app builds where measurement is enabled: if you came to Squadra through a paid advertising campaign, we use a specialist measurement partner (AppsFlyer) to determine which campaign led to the install. For this purpose we collect:

These events are passed from the measurement partner to the ad network the campaign came from — TikTok today, and X (Twitter) if enabled later — for one purpose: measuring the effect of the ad. We never send any advertising partner your name, email, phone number, location, or account content. If you decline tracking, measurement is limited to aggregated reports that do not identify you, provided by Apple (SKAdNetwork) or Google.

5. How We Collect Data

6. Purposes & Legal Basis

PurposeLegal basis
Account creation, authentication, and core servicesPerformance of a contract
Bookings, payments, and their managementPerformance of a contract / Legal obligation (invoicing)
Operational notifications (reminders, friend requests, booking confirmations)Performance of a contract / Legitimate interest
Phone matching and friend-discovery featuresYour consent (optional)
Importing health and fitness data and displaying your private performance and recovery insightsYour explicit consent and the specific system permissions (optional)
Security improvement and fraud preventionLegitimate interest / Legal obligation
Marketing messages (if any)Your consent (withdrawable at any time)
Advertising campaign measurement (attribution)Your consent on iOS via the App Tracking Transparency prompt / Legitimate interest in aggregated measurement — you can opt out at any time (see Section 15)

7. Children's Data & Guardian Consent

The App serves audiences that may include minors (particularly via academies). Therefore:

If you become aware that a child under 13 has created an account without permission, contact us to delete it.

8. Disclosure & Data Sharing

We do not sell, rent, or trade your data for monetary consideration. We may share it, only as necessary, with:

Within social features (friends/clubs/rosters) we expose only public fields (name, username, photo) and never reveal your phone number.

We do not share Apple Health or Health Connect data with any party or transmit it to our servers.

9. Sub-processors (Service Providers)

We use trusted providers to operate the App, including:

ProviderPurpose
SupabaseDatabase, authentication, and file storage
GoogleSign-in, and maps/geocoding for addresses
AppleSign in with Apple (on iOS)
Apple Health / HealthKitOptional source of health and fitness data the user chooses to read on an iOS device
Google Health ConnectOptional source of health and fitness data the user chooses to read on an Android device
ExpoApp build infrastructure and notification service
SMS providerDelivering phone verification codes (OTP)
Payment providerPayment processing (when enabled)
AppsFlyerAdvertising campaign measurement and install attribution (when enabled)
TikTokReceiving conversion events to measure TikTok ad campaigns (when enabled)
X (Twitter)Receiving conversion events to measure X ad campaigns (when enabled)

10. Cross-Border Transfers

Some data may be stored or processed on our providers' servers outside the Kingdom. In that case we rely on an appropriate legal safeguard (transfer to a jurisdiction with an adequate level of protection, or SDAIA-approved contractual clauses), and we limit transfers to the minimum necessary. [Hosting region and transfer mechanism to be specified on adoption]

11. Retention & Destruction

We retain your data only for as long as necessary:

12. Account Deletion

You can delete your account from within the App (Settings), or via our public account-deletion page: https://squadrasa.net/account-deletion. Upon deletion we remove or anonymize your personal data, except what we are legally required to retain (such as invoices).

Deleting your Squadra account does not delete the original records in Apple Health or Health Connect because Squadra neither owns nor writes those records. You can manage or revoke Squadra's access in your device's Apple Health or Health Connect settings.

13. Your Rights & How to Exercise Them

Under the law, you have the right to: be informed, access your data, rectify, erase, restrict processing, port, withdraw consent, and object. To exercise any right, email us at info@squadrasa.net and we will respond within the statutory period. You can also adjust your privacy settings in the App (visibility, phone matching, photo visibility), disconnect the health source in the App, or revoke its permissions in your device settings at any time.

14. Data Security

We apply reasonable technical and organizational measures (encryption in transit, access controls, row-level security) to protect your data from unauthorized access or disclosure. No system is 100% secure, but we strive for the best possible protection.

15. Cookies, Tracking Technologies & Advertising Measurement

In the App: we use basic local storage to operate the App (saving your session, preferences, and language). In builds where advertising measurement is enabled, we use your device advertising identifier for the purpose described in Section 4(j) — we do not use it to show you ads inside the App, to build an interest profile about you, or to track you across other apps.

How to turn off advertising measurement — at any time:

Turning off advertising measurement disables nothing in Squadra — booking, team splitting, clubs, and notifications all work exactly the same.

On the web (squadrasa.net): we use our own first-party analytics to measure site usage: a random anonymous browser identifier is stored in your device's local storage, and events are sent only to our own servers — never shared with any advertiser, never linked to your name or email, and never used to target ads at you. You can clear it by clearing site data in your browser.

Ad measurement tools on the web — only with your consent: to learn which ad brought visitors to our site, we may load measurement tools from our advertising platforms: the X pixel, the Meta pixel (Facebook/Instagram), the TikTok pixel, and the Snapchat pixel. None of these tools ever loads before you consent via a notice with equally prominent accept and decline options — if you decline, nothing loads and nothing about the site changes for you. If you consent, a tool reads the address of the page you visit, the referrer, and your IP address, and may set a cookie from its platform — it never receives your name, your bookings, or your payment details, and it never runs on payment pages or join links. Withdrawing consent is as easy as giving it: use the "Change ad-measurement choice" button on this page, or clear the site data in your browser, and the notice will appear again. Platform privacy policies: X (https://x.com/privacy) · Meta (https://www.facebook.com/privacy/policy) · TikTok (https://www.tiktok.com/legal/privacy-policy) · Snapchat (https://values.snap.com/privacy/privacy-policy)

Server-side conversion measurement (no pixel): when a payment or registration completes, we may report the conversion event to the ad platform that referred you directly from our servers to measure campaign effectiveness, hashing (one-way encrypting) any contact identifier (such as email or phone) before it is sent — your data is never sent in readable form, and your card details are never sent at all. This measurement does not run on payment pages in your browser and does not read your browsing, and you can object to it at any time by writing to info@squadrasa.net.

16. Data Breach Notification

In the event of a breach affecting your data, we commit to notifying the Saudi Data & AI Authority (SDAIA) within 72 hours of becoming aware of it, and to notifying affected individuals without undue delay where there is a serious risk to their rights.

17. Changes to This Policy

We may update this policy and will publish the updated version with a new effective date, notifying you of material changes via the App or email. Your continued use after an update constitutes acceptance.

18. Contact & Complaints

For any privacy enquiry or complaint, email us at info@squadrasa.net. You also have the right to lodge a complaint with the Saudi Data & AI Authority (SDAIA) if your complaint is not resolved.

Squadra — Riyadh, Al-Yarmouk District, Malwi Street · info@squadrasa.net