Privacy Policy

Last updated: February 14, 2026

This Privacy Policy explains how TennisDataApp ("Company", "we", "us", "our") collects, uses, stores, shares, and protects your personal data when you visit our website and any related pages, tools, and services (the "Site" and "Services").

This Policy applies to all visitors and users of the Site, whether or not you create an account. It should be read alongside our Terms of Service.

We are committed to protecting your privacy and processing your data in compliance with Regulation (EU) 2016/679 (the "GDPR"), Romanian data-protection legislation, and the ePrivacy Directive as implemented in Romania by Law 506/2004, as amended.

By accessing the Site you acknowledge that you have read and understood this Privacy Policy. Where we rely on consent as a legal basis we will obtain it separately (for example, through our cookie-consent mechanism).

1. Data Controller

The data controller responsible for your personal data is:

TennisDataApp

Email: [email protected]

If you have any questions about this Privacy Policy or our data practices, you may contact us at the email address above.

2. Personal Data We Collect

We collect and process a minimal set of personal data. We do not ask for your name, and we do not store passwords. Authentication is handled entirely via magic link β€” a secure, one-time login link sent to your email.

a) Data You Provide Directly

CategoryDetails
Email addressThe only piece of information you provide at registration. Used for authentication (magic-link login), account identification, billing communications, and service notifications.
CommunicationsAny information you include when you email us, submit a support request, or provide feedback.

b) Data Collected Automatically

CategoryDetails
IP addressCollected and stored to detect and prevent trial abuse (e.g. multiple trial accounts from the same origin). Also incidentally present in server logs.
Device & browser dataOperating system, browser type and version, device type, screen resolution. Collected for analytics, compatibility, and abuse-prevention purposes.
Usage dataPages visited, features used, Credit consumption, timestamps, referring URL, session duration.
Cookie & storage dataSession identifiers, authentication tokens, user preferences (e.g. odds format) β€” see Section 6.
Analytics dataPseudonymized interaction data collected by Google Analytics 4, Statcounter, and Microsoft Clarity β€” see Section 7.

c) Data Received from Stripe

When you start a trial or subscribe, Stripe processes your payment and sends us limited information. We do not receive or store your full card number, expiry date, CVV, cardholder name, or billing address.

DataPurpose
Subscription statusWhether your subscription is active, past due, cancelled, etc.
Payment statusWhether a charge succeeded or failed.
Unique payment-method identifierAn opaque token generated by Stripe that represents your payment method. It cannot be used to derive your card number or any card details. We use it solely to detect whether the same payment method has been used across multiple accounts, to prevent trial abuse.

3. How We Collect Your Data

  • Account registration β€” when you enter your email address to create an account.
  • Magic-link authentication β€” when you log in, we send a one-time link to your email. No password is created, transmitted, or stored.
  • Automated technologies β€” cookies, local storage, and tracking scripts placed when you visit the Site (subject to your consent where required).
  • Stripe β€” when you provide payment details during checkout, Stripe processes the transaction in its own secure environment and shares limited information back to us (see Section 2 c).
  • SMTP2GO β€” we use SMTP2GO as our transactional email provider to deliver magic-link emails, billing receipts, and service notifications. SMTP2GO processes your email address on our behalf.
  • Your communications β€” when you email us or submit feedback.

4. Legal Bases for Processing

Under the GDPR, we process your personal data on the following legal bases:

Legal BasisProcessing Activities
Performance of a contract (Art. 6(1)(b))Account creation & management; magic-link authentication; providing the Services; processing subscriptions & payments via Stripe; managing Credits & usage limits; sending transactional emails via SMTP2GO; communicating about your account or subscription
Legitimate interests (Art. 6(1)(f))Protecting platform security & preventing abuse (e.g. using IP addresses and payment-method identifiers to detect trial abuse, scraping, or fraud); improving & optimizing the Site; analyzing aggregated usage trends; enforcing our Terms of Service
Consent (Art. 6(1)(a))Placing non-essential cookies and similar technologies (analytics, session recording); sending promotional / marketing communications
Legal obligation (Art. 6(1)(c))Tax compliance & financial record-keeping; responding to lawful requests from authorities

Where we rely on legitimate interests we have conducted balancing assessments and concluded that our interests do not override your fundamental rights and freedoms. You may object to processing based on legitimate interests at any time (see Section 13).

5. How We Use Your Data

  • Provide and maintain the Services β€” account management, magic-link authentication, subscription & billing management, Credit tracking, delivering Content.
  • Process payments β€” via Stripe, including trial verification, subscription charges, renewals, and refunds.
  • Deliver transactional emails β€” via SMTP2GO, including magic-link login emails, billing receipts, and service notifications.
  • Prevent abuse β€” using IP addresses and payment-method identifiers to detect and prevent multiple trial accounts, credential sharing, scraping, and fraud.
  • Communicate with you β€” account notifications, responses to inquiries, and (with your consent) promotional messages.
  • Improve the Services β€” analyzing how users interact with the Site to fix bugs, improve the experience, and develop new features.
  • Enforce our Terms β€” detecting and preventing violations of our Terms of Service.
  • Comply with legal obligations β€” tax record-keeping, responding to lawful requests from authorities.

6. Cookies, Local Storage & Similar Technologies

What Are Cookies and Local Storage?

Cookies are small text files placed on your device by your browser. Local storage is a browser mechanism that lets websites store data that persists across sessions. Both allow us to recognise you and remember certain information.

Cookie Consent

In accordance with the ePrivacy Directive (Law 506/2004 in Romania) and the GDPR, we obtain your consent before placing any non-essential cookies or similar technologies. You can manage your preferences at any time via our on-site cookie-consent mechanism. Strictly necessary cookies do not require consent.

i) Strictly Necessary Cookies (no consent required)

Cookie / TechnologyPurposeTypeDuration
Session / auth cookie(s)Maintaining your logged-in session after magic-link authenticationFirst-partySession / up to [X] days

These cookies are essential for the Site to operate. Without them the Services cannot function. They cannot be disabled.

ii) Functional Storage (no consent required)

TechnologyPurposeTypeDuration
Local storage: odds-format preferenceRemembering your selected odds format (decimal, fractional, American) across sessionsBrowser local storage (first-party)Persistent until cleared by you

Stores only your chosen display format β€” no personal data.

iii) Analytics & Performance Cookies (consent required)

Placed only after you provide consent through our cookie-consent mechanism.

ProviderPurposeKey CookiesDuration
Google Analytics 4Site traffic & aggregate user-behaviour analytics_ga, _ga_*Up to 14 months
StatcounterPage-view analytics, traffic sources, visitor pathsis_unique, _statcounterSession / up to 5 years
Microsoft ClaritySession recordings, heatmaps, interaction analytics_clck, _clsk, CLID, MUIDSession to 12 months

Note on Microsoft Clarity:

Clarity records user sessions (clicks, scrolls, mouse movements) and generates heatmaps. Sensitive input fields are masked by default; we have configured Clarity not to capture keystrokes. Sessions are tied to pseudonymous identifiers, not your email. Microsoft may use Clarity data to improve its own products β€” see Microsoft's Privacy Statement.

iv) Payment-Related Cookies (Stripe)

ProviderPurposeTypeDuration
StripeSecure payment processing; fraud detection & preventionThird-party (__stripe_mid, __stripe_sid)Session to 1 year

Stripe sets its own cookies when you interact with the payment form. Some are strictly necessary for payment security. See Stripe's Privacy Policy and Cookie Policy.

Managing Cookies

You can manage or withdraw cookie consent at any time by:

  • Using our on-site cookie-consent mechanism (accessible via a link in the footer or a "Cookie Settings" button).
  • Adjusting your browser settings to block or delete cookies (blocking strictly necessary cookies may impair functionality).
  • Using browser local-storage controls to clear stored data (this resets your odds-format preference).

Browser-specific guides: Chrome Β· Firefox Β· Safari Β· Edge

7. Analytics & Session-Recording Tools

Google Analytics 4 (GA4)

We use GA4 to collect pseudonymized data about how visitors use the Site β€” pages visited, session duration, traffic sources, and general interest indicators.

Statcounter

We use Statcounter to collect analytics data including page views, visitor counts, traffic sources, and referral paths. Statcounter may process IP addresses and use cookies to distinguish unique visitors.

Microsoft Clarity

Microsoft Clarity helps us understand how users interact with the Site through:

  • Session recordings β€” replays of clicks, scrolls, taps, and mouse movements.
  • Heatmaps β€” aggregated visualizations of where users click and scroll.
  • Interaction metrics β€” rage clicks, dead clicks, excessive scrolling.

Clarity collects pseudonymous identifiers, device/browser info, pages visited, and interaction patterns. Sensitive input fields are masked by default; we do not capture keystrokes. Microsoft may use Clarity data to improve its own products.

8. Payment Processing (Stripe)

We use Stripe, Inc. (and its affiliates, including Stripe Payments Europe, Ltd. for EEA users) as our payment processor.

When you start a trial or purchase a subscription:

  • Your payment card details are entered directly into Stripe's secure, PCI-DSS-compliant payment form. Your card details never touch our servers. We do not receive, see, process, or store your full card number, CVV, expiry date, cardholder name, or billing address.
  • Stripe shares only the limited data described in Section 2 c with us.
  • Stripe may perform a temporary authorization on your card to verify it (as described in our Terms of Service, Section 7).
  • Stripe processes your data as a data processor on our behalf (for payment processing) and as an independent controller (for its own fraud-prevention and compliance obligations).

More info: Stripe Privacy Policy Β· Stripe Cookie Policy

9. Data Sharing & Third-Party Recipients

We do not sell your personal data. We share it only as described below:

RecipientPurposeGDPR Role
StripePayment processing, subscription management, fraud prevention, tax calculationProcessor / Independent Controller
Google (GA4)Website analyticsProcessor
StatcounterWebsite analyticsProcessor
Microsoft (Clarity)Session recording & heatmapsProcessor / Independent Controller
SMTP2GOTransactional email delivery (magic links, receipts, notifications)Processor
Hosting / infrastructure providersHosting the Site and storing data securelyProcessor
Legal / regulatory authoritiesWhere required by law, court order, or to protect our legal rightsN/A (legal obligation)
Business transfersIn connection with a merger, acquisition, or sale of assets (see ToS, Section 36)Controller (successor)

All third-party processors are bound by data-processing agreements and/or standard contractual clauses where required.

10. International Data Transfers

Some of our third-party providers are based outside the European Economic Area (EEA):

ProviderLocationTransfer Mechanism
Google (GA4)United StatesEU–US Data Privacy Framework (DPF); SCCs as fallback
Microsoft (Clarity)United StatesEU–US Data Privacy Framework (DPF); SCCs as fallback
StripeUS (EU entity: Stripe Payments Europe, Ltd., Ireland)EU–US Data Privacy Framework (DPF); SCCs
SMTP2GONew Zealand (servers may be US/EU)EU adequacy decision for NZ; SCCs where applicable
StatcounterIreland (EEA)No transfer outside EEA required

Where the EU–US Data Privacy Framework applies, we rely on the provider's DPF certification. Where it does not apply or as a supplementary safeguard, we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission.

You may request a copy of the relevant safeguards by contacting us at [email protected].

11. Data Retention

We retain personal data only as long as necessary to fulfil the purposes in this Policy, or as required by law:

Data CategoryRetention Period
Account data (email, payment-method identifier)Duration of your account. After deletion/termination, retained up to 30 days for data-export requests (see ToS, Section 26), then deleted or anonymized.
IP addresses (trial-abuse logs)Retained while needed for abuse detection. Deleted or anonymized no later than 12 months after collection, unless needed for an ongoing investigation or dispute.
Billing & transaction recordsUp to 10 years after the transaction, per Romanian fiscal legislation (Law 82/1991, Romanian Fiscal Code).
Support communicationsUp to 3 years after last communication, or longer for ongoing dispute resolution.
Analytics data (GA4)Up to 14 months (configured by us), then automatically deleted/aggregated by Google.
Analytics data (Statcounter)Subject to Statcounter's retention policies; logs retained for duration of use.
Session recordings (Clarity)Up to 30 days; aggregated heatmap data may persist longer per Microsoft's policies.
Cookie-consent recordsTypically 3 years or until no longer needed for compliance purposes.

After the applicable period, data is deleted, anonymized, or aggregated so it can no longer identify you.

12. Data Security

We implement appropriate technical and organizational measures to protect your personal data:

  • Passwordless authentication β€” we use magic-link login, so no passwords are ever created, transmitted, or stored. This eliminates an entire category of credential-related risk.
  • Encrypted connections β€” HTTPS/TLS across the entire Site.
  • Minimal data collection β€” we collect only what is necessary (email, IP, usage data). Payment card details are handled entirely by Stripe (PCI-DSS certified) and never reach our servers.
  • Access controls β€” limiting who within our organization can access personal data.
  • Regular review of security practices.

No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.

13. Your Rights Under the GDPR

If you are located in the EEA (or where otherwise applicable), you have the following rights:

RightDescription
Access (Art. 15)Request a copy of the personal data we hold about you.
Rectification (Art. 16)Request correction of inaccurate or incomplete data.
Erasure (Art. 17)Request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
Restriction (Art. 18)Request that we restrict processing in certain circumstances.
Data portability (Art. 20)Request your data in a structured, commonly used, machine-readable format.
Objection (Art. 21)Object to processing based on legitimate interests or for direct marketing.
Withdraw consent (Art. 7(3))Withdraw consent at any time without affecting the lawfulness of prior processing.
Automated decisions (Art. 22)We do not make solely automated decisions that produce legal or similarly significant effects on you. Our predictions are informational content, not decisions about you.

How to Exercise Your Rights

Contact us at [email protected]. We will respond within one month (extendable by two months for complex requests). We may verify your identity by sending a confirmation to the email address on your account. There is no fee unless requests are manifestly unfounded or excessive.

Right to Lodge a Complaint

You may lodge a complaint with a supervisory authority. In Romania:

ANSPDCP

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal

www.dataprotection.ro

You may also lodge a complaint with the authority in your country of habitual residence, place of work, or place of alleged infringement.

14. Children's Privacy

The Services are not directed to individuals under 18 years of age (or the applicable legal age in your jurisdiction, as described in our Terms of Service, Section 2). We do not knowingly collect personal data from children.

If we become aware that we have collected data from a child without appropriate consent, we will delete it promptly. If you believe this has occurred, please contact us at [email protected].

15. Links to Third-Party Websites

The Site may contain links to third-party websites (e.g. GambleAware, Gambling Therapy). We are not responsible for their privacy practices or content and encourage you to review their privacy policies.

16. Changes to This Privacy Policy

We may update this Policy from time to time. When we make material changes we will:

  • update the "Last updated" date;
  • notify you by email and/or by a prominent notice on the Site;
  • seek new consent where changes affect processing based on consent.

Continued use of the Services after an update constitutes acknowledgment of the changes (but not consent to new processing that requires separate consent).

17. Contact & Complaints

TennisDataApp

Email: [email protected]

For complaints, see also our Terms of Service β€” Sections 30 and 31 β€” regarding alternative dispute resolution (ANPC/SAL in Romania) and the EU Online Dispute Resolution platform.

This Privacy Policy is effective as of the "Last updated" date above.