Privacy Policy
Last updated: April 24, 2026
1. What We Collect
When you use MatchPoint, we collect:
- Phone number for account authentication (SMS OTP) and optional match reminders
- USTA NorCal credentials (encrypted at rest) to sync your team roster and availability
- Team and player data scraped from publicly available pages on TennisRecord.com and USTA NorCal (leagues.ustanorcal.com), including player names, ratings, and match results
- Lineup decisions you save or lock within the app
2. How We Use Your Data
- Generate optimized lineup recommendations for your USTA league matches
- Send match reminders and scrape status alerts via SMS or email
- Compute player ratings, head-to-head records, and partner chemistry stats
- Predict opponent lineups based on publicly available match data
3. Third-Party Services
We use the following services to operate MatchPoint:
- Supabase for authentication and database storage
- Upstash Redis for cached team data
- Twilio for SMS notifications
- Resend for email alerts
- Vercel for hosting
We scrape publicly available data from TennisRecord.com and USTA NorCal. We are not affiliated with either organization.
4. Data Sharing
We do not sell, rent, or share your personal data with third parties for marketing purposes. Data is only shared with the service providers listed above as necessary to operate the app.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing to subcontractors in support of our services (such as Twilio for SMS delivery and Supabase for authentication) is permitted. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
5. Data Retention and Deletion
Your data is retained as long as your account is active. You may request deletion of your account and all associated data at any time by contacting us. USTA credentials are encrypted at rest and can be removed independently of your account.
6. Security
USTA credentials are encrypted using AES-256-GCM before storage. All data is transmitted over HTTPS. Access to production systems is restricted to authorized administrators.
7. SMS and Email Communications
Verification codes (transactional). When you sign in, we text a one-time passcode to verify your phone number. These messages are part of phone-based authentication and are sent only when you request a code.
Match notifications (optional). This is a distinct, unchecked-by-default opt-in presented during account setup or later from the app. The disclosure shown at opt-in is: “Text me match reminders, availability requests and team updates. Automated & recurring texts from MatchPoint; frequency varies. Message & data rates may apply. Reply STOP to opt out, HELP for help. Consent not required to use MatchPoint.”
Reply STOP to any message to unsubscribe from notification SMS at any time. Reply HELP to any message for help, or contact us at the email below. Verification codes may continue after you opt out of notifications, since they are required to sign in by phone. For the full messaging program disclosure, see our Terms of Service.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing to subcontractors in support of our services (such as Twilio for SMS delivery and Supabase for authentication) is permitted. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
8. Contact
For privacy questions or data deletion requests, contact: matchpoint-admins@googlegroups.com