HoopShift Privacy Policy
Last updated: 16 September 2026
HoopShift is a basketball team-management app operated by Dubbelman Technologies AB. This policy covers the app, including its TestFlight beta. For privacy questions or requests, email linus@dubbelman.tech.
Information we use
- Account information: your Apple sign-in identifier and the name and email address Apple shares with us, which may be a private relay address. We do not receive your Apple password.
- Team information: Staff names, email addresses, invitations, roles, and game assignments; player names, jersey numbers, optional profile details, skill ratings, and rotation settings.
- Game information: schedules, opponents, venues and their coordinates, scores, lineups, substitutions, playing time, statistics, and saved game history.
- Scan images: photos or images you choose for roster or schedule scanning, and information extracted from them.
- Technical and support information: account identifiers, IP addresses, request and error logs, scan usage counts, and messages or attachments you send us.
Information about players and invited Staff may be supplied by other Staff, even if those people do not have an account.
Firebase Analytics is disabled. We use Firebase Crashlytics to diagnose failures; it processes installation identifiers, device/software details, and crash reports. Apple also makes TestFlight usage, crash information, and submitted feedback available to developers as described in TestFlight & Privacy.
Why we use it
We use this information to provide accounts, save and sync team records, manage Staff access, run game and rotation tools, process scans, troubleshoot the beta, prevent misuse, and respond to requests.
Where the GDPR applies, our legal grounds are providing the service under our agreement with you, legitimate interests in administering and protecting the service, compliance with legal obligations, and consent where required for optional processing. You may object to processing based on legitimate interests or withdraw consent for future processing.
A club or team determines the purposes of the player records it enters. Where we handle those records on its instructions, we act as its processor. The team must have a lawful basis for using that information and inform players and, where appropriate, parents or guardians. HoopShift is intended for Staff; youth-team records can still contain children's information. Please avoid entering unnecessary sensitive or medical information.
Who receives information
Your team's Staff. Staff with access can receive shared roster and membership information and the game records available to them. Game records can contain ratings and historical details even when a particular app view does not display them.
Google / Firebase. We use Firebase for authentication, cloud storage, backend operations, and the technical services described above. See Firebase privacy information.
OpenAI, when you scan. After you choose Send and scan, selected images go through our backend to the OpenAI API. The whole image is sent, so remove unrelated personal details first. Schedule scans also include your team and competition names, the date, and your device's time zone. We send a hashed account identifier for abuse prevention. Reviewing or discarding results happens after processing; you can instead enter information manually.
Our backend does not keep an image archive. OpenAI does not use API data for model training by default unless the API customer opts in. We disable stored response history, but OpenAI may retain content for abuse monitoring for up to 30 days, with legal and safety exceptions. See OpenAI API data controls.
Apple. Apple provides sign-in, TestFlight, purchase services, and Maps venue searches. Searching for a venue or resolving one from a scanned schedule sends venue search text to Apple Maps. Venue coordinates are not a GPS reading of your device. StoreKit supplies purchase entitlement information; we do not receive payment-card details.
Connected devices. Live game information, including player names, scores, and playing time, can be shared with a paired Apple Watch and connected nearby devices. Nearby discovery can expose your device name and game title before a connection is approved.
We may also disclose information when legally required or necessary to protect the service and people's rights.
Storage and retention
Records are stored locally and in Firebase. Local files and cached records may remain on devices or in device backups. Signing out does not necessarily remove those copies. We use authentication, access rules, and encrypted network connections to protect information.
We retain account and team information while needed to provide the service, and support and security records while needed to resolve requests, investigate problems, or meet legal obligations. Historical games can retain player information after a player is removed from the current roster. Saved scan results become team records. Provider logs and backups may take longer to expire after deletion from active systems.
Providers may process information outside your country, including in the United States. Applicable provider data-processing terms govern that processing. Transfers requiring additional protection must be covered by an appropriate legal safeguard, such as standard contractual clauses. Contact us for information about the safeguards applicable to your data.
Your choices and rights
You can change camera, photo, and local-network permissions in iOS Settings. You can use manual entry instead of scanning and ask your team administrator to correct team records or remove access.
To delete your account, open User → Legal & Support → Delete account and confirm with Apple. Teams where you are the only active Staff member are deleted; shared teams remain. If you are a shared team's only admin, assign another admin or delete that team first. Deletion may continue on the server after you close the app. We remove your account, Staff memberships, associated invitations and scan counters, and clear this device's account files and cloud cache. Minimal deletion records remain to prevent stale devices from restoring deleted data.
Email linus@dubbelman.tech to request access, correction, deletion, restriction, or a portable copy of eligible personal information, or to object to processing. Players and parents or guardians can contact us without an account. We may verify your identity and involve the team responsible for the records. We will explain any information that must be retained and why. We normally respond to GDPR requests within one month.
You may complain to your local data-protection authority, including Sweden's IMY. Deleting an account does not cancel an Apple subscription.
Changes
We will update this page as the beta develops and notify testers of significant changes. Where a change requires consent, we will ask for it.