Privacy Policy
Draft engineering inventory — operator and legal review required before public release.
FieldFinder ("we", "us", "our") operates the website at www.fieldfinder.xyz ("the Service"). This Privacy Policy explains how we collect, use, and protect your personal information. This page describes the current implementation as reviewed in the source repository; it is not a legal compliance determination.
1. Information We Collect
1.1 Account Information
We store account and profile information such as name, email address, profile image, password hash for password accounts, preferences, and account/session records. Google OAuth account records can include provider identifiers and OAuth access, refresh, and ID tokens where the authentication adapter stores them.
1.2 Profile Information
You may optionally provide additional information such as a bio, preferred sports, and skill level. This information is visible to other users on your public profile.
1.3 Location Data
With your permission, the browser may provide approximate location to help show nearby matches and fields. Match, venue, tournament, and community-board records can store locations and latitude/longitude. The retention and visibility of location-derived data require operator review.
1.4 Usage Data
We automatically collect information about how you interact with the Service, including pages visited, application events, matches joined, messages, notifications, reports, blocks, and related operational records. PostHog currently identifies signed-in users by their stable application user ID; the client integration no longer sends email or name as identify properties.
1.5 Payment Information
Payment card details are collected and processed by Stripe. The application stores payment amounts, status, and Stripe checkout/session and payment-intent identifiers; rental requests may also contain applicant contact information and insurance-document links.
1.6 Uploads and device notifications
Profile images, match cover images, permits, proof-of-booking files, and insurance-document links may be stored or referenced. The service also stores web-push subscription endpoints and keys, and may store Expo mobile push tokens, when a user enables notifications.
1.7 City launch waitlist
If you join the city-launch waitlist, we store the email address you submit, the selected language, the form source, a consent-version label, and creation/update timestamps. We use this information for FieldFinder city-launch updates. The waitlist does not store your IP address or user-agent in its application record.
2. How We Use Your Information
We use your information to:
- Create and manage your account
- Display your profile to other users
- Show you relevant matches and fields based on your location
- Send notifications about matches you've joined (email and push notifications, with your consent)
- Send requested city-launch updates to waitlist subscribers
- Process payments for paid matches
- Calculate and display your reliability score based on attendance
- Moderate content and enforce our Terms of Service
- Improve and maintain the Service
3. Third-Party Services
We use the following third-party services that may process your data:
| Service | Purpose | Data Shared |
|---|---|---|
| Google OAuth | Authentication | Name, email, profile picture |
| Stripe | Payment processing | Payment details, transaction info |
| Neon (PostgreSQL) | Database hosting | All stored user data |
| Cloudinary | Media storage | Profile images, match covers, permits, and proof-of-booking uploads |
| Resend | Email delivery | Email address, notification content |
| Vercel | Hosting | Request logs, IP addresses |
| CARTO | Map tile rendering | Map viewport/tile requests and standard request metadata; FieldFinder does not intentionally send precise browser location to CARTO |
| OpenStreetMap Nominatim | Address and place search | The search query and standard request metadata through FieldFinder's same-origin geocoding proxy |
| PostHog | Product analytics | Pseudonymous identifiers, browser storage, pageviews, and configured event data |
| Sentry | Error and performance monitoring | Error context, performance data, and sampled session replay data |
Field records imported from OpenStreetMap are shown with contributor attribution and source links where available. OSM provenance indicates the source of an imported record; it does not verify venue ownership, current availability, amenities, or accuracy. Imported data may be stale and is refreshed according to the project's import policy.
Each third-party service has its own privacy policy. We encourage you to review them.
4. Cookies and Local Storage
We use the following browser storage technologies:
- Session cookies: To maintain your authentication state while signed in.
- Local storage: To save theme preference, PWA state, the dismissal preference for the city-availability announcement, and, when PostHog is configured, analytics persistence.
- Cookies: To maintain authentication, locale and consent preferences, and potentially PostHog persistence when analytics is configured.
PostHog may use cookies and local storage. The operator must review consent, regional notice, and opt-out requirements before public release.
5. Push Notifications
With your explicit consent, we may send push notifications to your device about upcoming matches and other updates. You can manage or revoke push notification permissions at any time through your browser settings or the FieldFinder settings page. Your push subscription endpoint is stored in our database and deleted when you unsubscribe.
6. Data Retention
The current implementation includes account export and deletion flows, but retention periods, deletion coverage, backups, processor deletion, and legal exceptions have not been independently verified. The operator must define and validate retention before public release.
7. Your Rights
You have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Update or correct your profile information through the settings page.
- Deletion: Delete your account and all associated data. Contact us at support@fieldfinder.xyz to request account or waitlist-email deletion, or to opt out of city-launch updates.
- Data portability: Request an export of your data in a machine-readable format.
- Withdraw consent: Opt out of notifications or revoke location permissions at any time.
8. Data Security
The implementation includes the following engineering controls, which require continuing review and do not guarantee security or compliance:
- Encrypted database connections (TLS/SSL)
- Secure authentication via OAuth 2.0
- Content Security Policy and other browser security headers
- Input sanitization and rate limiting on API endpoints
Security and privacy review remains open for OAuth token handling, JWT lifecycle, replay configuration, webhook idempotency, access control, dependency health, and third-party processor settings.
9. Children's Privacy
The intended audience and age-gating obligations require operator/legal review before public operation. Do not rely on this draft as a completed children's privacy notice.
10. International Users
Processor regions, international transfer mechanisms, and regional rights notices require operator/legal review before public operation.
11. Changes to This Policy
This draft must be replaced or approved by the operator before a public release. Any production notice and change-management process must be reviewed for the applicable jurisdictions.
12. Contact Us
For the operated service, contact support@fieldfinder.xyz. The operator must verify that this contact path, rights-request process, and response obligations are staffed before public release.
See also our Terms of Service.