Beta version · 12 September 2026

Privacy Policy

1. Data processed

We process your email address, password hash, adult-confirmation flag, account role, authentication sessions and subscription status. When present, we also retain the campaign source and referring domain attached to registration; we do not store the visitor's IP address for marketing attribution. Match analysis activity is not used for advertising profiles. Card details are entered directly into Stripe and are not stored by MatchMetric.

2. Purposes and legal bases

Account and session data are required to provide the service and protect access. Subscription data is required to administer a requested plan. Security logs are processed for legitimate interests in preventing abuse and diagnosing incidents. Any optional marketing will require a separate choice.

3. Processors

Hetzner hosts the application and database. Stripe processes Sandbox payment and subscription events. API-Football supplies match data and does not receive MatchMetric user-account data through this application.

4. Retention

Authentication sessions expire after 30 days or are removed at logout. Account data is retained while the account exists. A user may download a portable copy or delete an eligible account from the dashboard. Active subscriptions must first be cancelled and reach the end of access so billing state remains consistent.

5. Your rights

Authenticated users can download their account data and request permanent local deletion from the dashboard. Applicable law may also provide rights of access, correction, restriction, objection and portability. A formal privacy contact and response procedure will be published before Live Mode.

6. Cookies and tracking

The service uses a strictly necessary, HttpOnly authentication cookie. Temporary browser session storage preserves campaign parameters until registration. There are no advertising trackers, fingerprinting or third-party analytics cookies in the current beta.

7. Security

Passwords are irreversibly derived with PBKDF2-SHA256 and an individual random salt. HTTPS, server-side sessions, restricted network access and daily database backups protect the service. No system can guarantee absolute security.

Back to home