Privacy Policy
We collect only what we need, protect it carefully, and never sell it. Here's exactly how we handle your data.
1. Overview
UnderDraft ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy describes what personal information we collect, how we use it, who we share it with, and what rights you have regarding your data.
By using the UnderDraft platform, you agree to the collection and use of information as described in this policy. If you do not agree, please discontinue use and contact us to delete your account.
2. Information We Collect
We collect information you provide directly, information generated by your use of the Service, and limited information from third-party providers.
- Account information: name, email address, role (player / captain / organiser / referee).
- Profile information: display name, avatar, sport preferences, league affiliations.
- League & game data: scores, rosters, schedules, game events you record or are recorded in.
- Usage data: pages visited, features used, session duration — collected via PostHog analytics.
- Device data: browser type, operating system, IP address for security logging.
- Communications: messages you send to our support team.
3. How We Use Your Information
We use your information only to operate and improve UnderDraft. Specifically:
- Provide, maintain, and improve the Service and its features.
- Authenticate your identity and enforce role-based access control.
- Send transactional emails (account confirmation, password reset, game reminders).
- Detect and prevent fraud, abuse, and security incidents.
- Analyse aggregate, anonymised usage patterns to guide product development.
- Comply with legal obligations.
5. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete or anonymise your personal data within 30 days, except where retention is required by law.
Aggregated, anonymised data (e.g. statistics about league activity) may be retained indefinitely as it cannot be used to identify you.
6. Security
We implement industry-standard security measures including TLS 1.3 encryption in transit, AES-256 encryption at rest, row-level database security, and regular security reviews. However, no method of transmission over the internet is 100% secure.
For a full overview of our security practices, visit our Security page at underdraft.app/security.
7. International Transfers
Your data is processed in Canada and the United States. Our infrastructure providers (Supabase on AWS, Fly.io) may process data in other jurisdictions. We ensure all providers meet equivalent data protection standards through contractual safeguards.
8. Children's Privacy
UnderDraft is not intended for users under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a minor, please contact us immediately at privacy@underdraft.app and we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-app notification at least 14 days before the changes take effect. The "Effective" date at the top of this page will always reflect the most recent version.
Your rights
Exercising your rights
Access
Request a copy of all personal data we hold about you.
Correction
Ask us to update or correct inaccurate information.
Deletion
Request permanent deletion of your account and personal data.
Portability
Receive a machine-readable export of your data.
Restriction
Ask us to limit processing of your data in certain circumstances.
Objection
Object to processing based on legitimate interests.
To exercise any of these rights, email us at privacy@underdraft.app. We respond within 30 days.
Questions about your data?
Contact our privacy team — we aim to respond within 2 business days.