Matchday V1 · Updated 28 July 2026
Privacy Notice
What Matchday stores, what appears publicly, and how deletion and export work.
Phone-first identity
WhatsApp delivers short-lived authentication codes. The application profile stores no raw phone number; it keeps a protected fingerprint and masked verification audit while Better Auth maintains the account identity in its isolated Convex component.
Never share an OTP. Matchday support will not ask for one.
Public and private fields
Public rosters show only a claimed display name and optional avatar, or a neutral guest label. Phone numbers, cash status, emergency contacts, private host notes, and reliability history are never public.
Private invitation secrets stay in URL fragments. The browser removes the raw key and sends only a one-way SHA-256 digest to Convex; durable invitation records keep only a domain-separated keyed verifier of that digest.
Retention and rights
You may export your account data after fresh authentication. A deletion request de-identifies the public profile and removes optional private fields, while financial, attendance, consent, security, and audit records may be retained where required for disputes, safety, fraud prevention, or legal obligations.
Anonymous presence uses a short-lived, edge-signed network pseudonym and expires automatically. Matchday does not store the source address.