Court Crew Court Crew
Home About
Sign In
← Back to Home

Privacy Policy

Last updated: August 28, 2026 · Effective: September 11, 2026

Plain English summary: Court Crew collects the minimum data required to provide the service. We do not sell your data. We do not share it with advertisers. The app uses Amplitude for product analytics only if you agree on first launch, and never records your name, email or match details. Crash and error reports are sent to Sentry so faults get fixed; they carry no match details and no credentials. You can delete your account and all your data at any time.

If you scan an assignment slip: the image is sent to Anthropic to read the details off it, and is not kept on our servers. It is stored only if you choose to attach it to your match. See section 3.

1. Who We Are

Court Crew ("we", "us", "our") is a sports referee management application operated by Lovro Predovan, an individual developer based in the European Union. The application is accessible via courtcrew.co and the Court Crew iOS and Android mobile apps.

For the purposes of the General Data Protection Regulation (GDPR) and the UK GDPR, Lovro Predovan is the data controller.

Contact for privacy matters: [email protected]

2. What Data We Collect and Why

We collect only the data necessary to operate the service. The table below describes each category:

CategoryData collectedPurposeLegal basis (GDPR)
Account Email address, first name, last name, profile photo (if Google Sign-In) Authentication, display in app Contract performance (Art. 6(1)(b))
Match data Match dates, times, team names, competition names, venues, age categories, remarks Scheduling, career history, statistics Contract performance (Art. 6(1)(b))
Fee data Match fees, travel fees, paid/unpaid status Earnings tracking Contract performance (Art. 6(1)(b))
Crew data Email addresses of crew members you invite, their names if they have an account Crew coordination and invitations Legitimate interest (Art. 6(1)(f))
Photos Photos you voluntarily attach to matches Match archive Consent (Art. 6(1)(a))
Location names Venue names and addresses you enter, Google Places autocomplete selections Match scheduling Contract performance (Art. 6(1)(b))
Scanned documents The assignment slip, email or roster image you choose to scan. Transmitted to Anthropic for reading; held in memory on our servers only for the duration of the request Prefilling a match form so you do not retype it Consent (Art. 6(1)(a))
Scan accuracy Which field you corrected and whether the parser missed it or got it wrong — never the value, never the document Measuring and improving parser accuracy Legitimate interest (Art. 6(1)(f))
Guest device A random device identifier generated by the app, scan count, platform name (iOS/Android), first and last seen timestamps. No name, no email, no advertising identifier Letting you try the app without an account, and enforcing the free scan limit Contract performance (Art. 6(1)(b))
Product analytics (app only, opt-in) A device identifier, your account identifier once you have one, a fixed list of action names, and coarse buckets (match counts, outstanding-amount bands, error categories, app version, country). Pseudonymous, not anonymous. Understanding which features are used Consent (Art. 6(1)(a)) — asked on first launch, withdrawable in Profile
Authentication tokens JWT access and refresh tokens stored on device Session management Contract performance (Art. 6(1)(b))

2.1 Data We Do NOT Collect

  • We do not collect payment card details or banking information
  • We do not collect GPS location or device location data
  • We do not collect contacts from your phone address book
  • We do not collect biometric data
  • We do not use advertising identifiers (IDFA/AAID) or any cross-app tracking
  • We do not retain scanned documents on our servers, and we do not use them to train AI models
  • We do not collect data from children under 13
  • We do not create advertising profiles or sell data to third parties
  • We do not collect health or fitness data

3. Document Scanning

Court Crew can read an assignment slip, roster or email you photograph or upload, and use it to prefill a match form. This section explains exactly what happens to that document, because it is the most sensitive processing we do.

3.1 Where the document goes

When you scan, the file is sent to Anthropic PBC (United States), whose Claude model reads the match details from it and returns them as structured text. This happens only when you actively choose to scan — nothing is scanned in the background, and the app does not read your photo library.

On our servers the file is held in memory for the duration of the request only. We do not write it to our database or to our file storage. Anthropic processes it under their commercial terms, which provide that inputs submitted via their API are not used to train their models. Anthropic privacy policy: anthropic.com/legal/privacy

The scanned image is stored only if you choose to attach it to your match as a photo. In that case it is stored like any other match photo (section 10), and you can delete it at any time.

3.2 Other people named on your slip

Assignment slips often name people who are not Court Crew users — co-officials, delegates, club contacts, sometimes their phone numbers. When you scan such a document you are providing us with other people's personal data, and you should scan only documents you are entitled to process. We minimise what happens to that data: we extract only the match fields we need, we do not build profiles of the people named, and we do not retain the document.

3.3 Accuracy telemetry

When you correct a prefilled field before saving, we record the name of the field and whether the parser missed it or got it wrong — for example "venue, wrong". We do not record what the field said before or after, and we do not keep the document it came from. This tells us the parser struggles with venues without telling us anything about your matches or the people on your slip.

4. Using Court Crew Without an Account

You can try Court Crew before signing up. In guest mode the app generates a random identifier for your installation and we store it alongside your scan count, your platform (iOS or Android), and first/last seen timestamps. This identifier is not derived from your device hardware, is not an advertising identifier, and cannot be used to recognise you in another app or on a website. Its only purposes are to keep your work attached to your session and to enforce the free scan limit.

Matches you create as a guest are held on your device. If you later create an account, they are migrated into it. If you delete the app without signing up, the local data goes with it and the guest device record expires on our side.

If you agreed to analytics, guest activity is recorded too, against a random analytics identifier rather than a name or an email. Should you later create an account, that earlier activity is linked to it — this is how we tell whether guest mode actually helps people get started. We are telling you now, before any of it is collected, because it would not be fair to disclose it afterwards. If you declined analytics, none of this happens and there is nothing to link.

5. Signing In

5.1 Google

If you choose to sign in with Google, we receive from Google: your email address, first name, last name, and profile photo URL. We use these solely to create and maintain your Court Crew account. We do not access your Google contacts, Gmail, Google Drive, or any other Google service beyond what is explicitly listed here.

Google's own privacy policy applies to the Google Sign-In flow: policies.google.com/privacy

5.2 Apple

If you sign in with Apple, we receive a stable identifier for your Apple account and, on first sign-in only, your name and email address. If you choose Apple's Hide My Email option, we receive a private relay address rather than your real one and never learn your actual email — the service works normally either way. Your name is provided by Apple only once, so if you decline it we will not ask Apple again.

Apple's privacy policy: apple.com/legal/privacy

6. Google Calendar Integration

If you use the Google Calendar export feature, we request permission to create calendar events in your Google Calendar. We use this permission exclusively to create match events you explicitly request to export. We do not read, modify, or delete existing calendar events. We do not access your calendar without your action.

You can revoke this permission at any time at myaccount.google.com/permissions.

7. Google Maps / Places

The location picker in the app uses Google Places API to autocomplete venue names. Search queries you type into the location field are transmitted to Google. We store only the final selected venue name and address — not the intermediate search queries. Google's API terms apply: cloud.google.com/maps-platform/terms

8. Analytics

The website uses no analytics at all. No measurement tag is loaded on any page, and no analytics identifier is set. An earlier version of this policy described a Google Analytics setup that was never actually configured; that was inaccurate and has been removed.

The mobile app uses Amplitude for product analytics, and only if you agree to it. We ask once, on first launch. If you decline, the Amplitude SDK is never started and no identifier is written to your device. You can change your mind at any time in Profile → Analytics; switching it off stops all further collection.

What we record is a short, fixed list of actions — a match was created, a scan finished, a fee was marked paid, a screen was opened — together with coarse buckets such as “2–3 matches” or “€201–500 outstanding”. We do this to learn which parts of the app referees actually use, because we cannot see that any other way.

What is never sent: your name, your email address, team or competition names, venues, match notes, exact amounts, photographs, or the contents of any scanned document. The permitted fields are enumerated in the app’s source code and enforced automatically — a value that is not on the list is discarded rather than transmitted.

Amplitude is configured to store data in the European Union. We have disabled collection of your IP address, city, region, mobile carrier and advertising identifiers. We do not use Amplitude for advertising, we do not share this data with advertisers or data brokers, and we do not track you across other apps or websites.

8b. Error Reporting

When something goes wrong — the app crashes, or a request to our server fails — a report is sent to Sentry so the fault can be found and fixed. This is separate from analytics: it records failures, not what you do.

A report contains the error message, the stack trace, which screen or endpoint failed, and your account identifier so repeated faults can be recognised as affecting one person. It does not contain the contents of your requests — no fees, team names, venues or match notes — and authentication tokens are removed before the report leaves the app or server.

Sentry is configured to store data in the European Union. We rely on our legitimate interest in keeping the service working (Art. 6(1)(f)); you can object at any time using the contact details below.

9. Email Communications

We send transactional emails only: account-related notifications (e.g. password reset), and crew invitation emails on your behalf when you invite co-referees. We do not send marketing emails unless you have explicitly opted in. We use Brevo (formerly Sendinblue) to deliver email. Brevo privacy policy: brevo.com/legal/privacypolicy

10. Data Storage and Security

Your data is stored on servers operated by DigitalOcean (data center: Frankfurt, Germany — EU territory). Data in transit is encrypted via TLS (HTTPS). Passwords are hashed using bcrypt before storage and are never stored in plain text.

Profile photos and match photos are stored on DigitalOcean Spaces, in the same EU region as the rest of the infrastructure. An earlier version of this policy named Amazon S3; that was never the storage provider and has been corrected.

We apply reasonable technical and organisational measures to protect your data. No internet transmission is 100% secure and we cannot guarantee absolute security.

11. Data Retention

We retain your data for as long as your account is active. Specific retention periods:

  • Account data: Retained until account deletion
  • Match and fee data: Retained until account deletion
  • Photos: Retained until you delete them or delete your account
  • Chat messages: Retained until account deletion
  • Scanned documents: Not retained. Held in memory for the request only, unless you attach the image to your match, in which case it follows the Photos rule above
  • Scan accuracy records: Each record holds a field name, whether the parser missed or mis-read it, and a reference to the account that reported it. On account deletion the account reference is removed, leaving an anonymous accuracy statistic that we keep indefinitely
  • Guest device records: Retained for as long as the installation is in use. The record holds a random installation identifier and a scan count — pseudonymous rather than anonymous, since it can be linked to an account if you later create one
  • Analytics data (only if you consented): Retained for 24 months, then deleted. On account deletion we also instruct Amplitude to delete the events associated with your account identifier
  • Server logs: Retained for up to 30 days for security and debugging

After account deletion, all personal data is permanently deleted within 30 days. Anonymised aggregate statistics may be retained.

12. Your Rights (GDPR)

If you are in the European Economic Area (EEA) or United Kingdom, you have the following rights:

  • Right of access: Request a copy of all personal data we hold about you
  • Right of rectification: Request correction of inaccurate data
  • Right to erasure ("right to be forgotten"): Request deletion of your account and all associated data
  • Right to data portability: Request your data in a machine-readable format
  • Right to object: Object to processing based on legitimate interest
  • Right to restrict processing: Request that we limit how we use your data
  • Right to withdraw consent: Where processing is based on consent, withdraw it at any time. For analytics this is Profile → Analytics in the app; no email is needed

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

13. Account and Data Deletion

You can delete your account directly within the Court Crew mobile app: go to Profile → Settings → Delete Account. This will permanently delete all your data including matches, fees, photos, crew connections, and chat history. Deletion is irreversible.

Alternatively, email [email protected] with the subject "Delete my account" and we will process the deletion within 5 business days.

14. Children's Privacy

Court Crew is not intended for users under 13 years of age. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal data, contact us immediately and we will delete it.

Users aged 13–17 may use the app with parental consent. In Croatia, where Court Crew is established, the age at which a person can consent on their own behalf is 16. Below that age, consent — including consent to analytics — must be given or authorised by a parent or guardian.

15. Third-Party Services Summary

ServicePurposeData sharedTheir privacy policy
Google Sign-In Authentication Email, name, photo policies.google.com
Apple (Sign in with Apple) Authentication Account identifier; name and email on first sign-in only, or a private relay address apple.com/legal/privacy
Anthropic Reading scanned assignment documents The document you scan. Not retained by us; not used to train models anthropic.com/legal/privacy
Amplitude (EU region) Product analytics — only with your consent Device and account identifiers, action names, coarse buckets. No name, email, match content or amounts amplitude.com/privacy
Sentry (EU region) Error and crash reporting, so faults are found before a referee has to report them Error message and stack trace, the URL that failed, and your account identifier. No request contents, so no fees, teams, venues or notes. Credentials are stripped before sending sentry.io/privacy
Google Maps Platform Venue autocomplete Location search queries cloud.google.com
DigitalOcean Server infrastructure All user data (encrypted, EU) digitalocean.com
DigitalOcean Spaces Photo storage Profile and match photos digitalocean.com
Brevo Transactional email Email address, invitation content brevo.com

16. Cookies

We use a small number of cookies. For the full list and management options, see our Cookie Policy. Essential cookies (authentication session) cannot be disabled without breaking the service. Analytics cookies can be declined via the consent banner.

17. International Transfers

Our infrastructure is located within the EU (DigitalOcean, Frankfurt), including photo storage and, where you have consented to it, analytics — the Amplitude project is configured for the EU region. When data is processed by Google, Apple, Anthropic or Brevo, it may be transferred outside the EEA. These transfers rely on Standard Contractual Clauses (SCCs) and/or adequacy decisions where applicable.

In particular, document scanning involves a transfer to the United States: the file you scan is sent to Anthropic PBC for processing. This is the only feature that routinely sends your content outside the EEA, it happens only when you choose to scan, and the document is not retained. If you would rather no data leave the EEA, do not use the scan feature — every match can be entered manually with no third-country transfer.

18. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes we will notify users via email and/or an in-app notice at least 14 days before the changes take effect. The "Last updated" date at the top reflects the most recent revision. Continued use of the service after the effective date constitutes acceptance of the revised policy.

19. Contact

For any questions, concerns, or requests regarding this Privacy Policy or your personal data:

  • Email: [email protected]
  • Response time: within 5 business days for general inquiries, within 30 days for GDPR requests
Court Crew

Court Crew

The referee app built for referees, not assignors.

Legal

  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Company

  • About
  • Contact

© 2026 Court Crew. All rights reserved.