Privacy Policy

Last updated: 9 September 2026

Goals Against Limited (company number 17272236, registered in England and Wales, registered office 7 Grange Lane, Northampton, NN6 9AP, United Kingdom) is the data controller for the Goals Against app and goalsagainst.com ("the Service"). We are registered with the Information Commissioner's Office, registration reference ZC239717. Questions and requests: support@goalsagainst.com.

1. What we collect, and why we're allowed to

Each item below lists what we collect, what it is for, and the lawful basis under UK GDPR:

  • Email address — account sign-in and essential service emails (contract)
  • Sign-in identifiers (your Google or Apple user id) or a one-way hashed password — operating your account securely (contract)
  • Push notification token — delivering the alerts you signed up for (contract)
  • Your team, rivals, themes, tones, quiet hours and similar preferences — making the Service do what you asked, and, in aggregate and without identifying you, understanding which teams and rivals are popular so we can plan coverage (contract; legitimate interests)
  • Which notifications you pin, favourite or delete — keeping your list as you left it, and, in aggregate and without identifying you, learning which messages people value so we can improve them (contract; legitimate interests)
  • When you share a notification or card — we record that you shared it and when, together with the unique reference printed on the card, so the card works when opened, so we can investigate misuse, and, in aggregate and without identifying you, so we can learn which messages people most enjoy sharing (contract; legitimate interests). We do not see where you shared it or who received it.
  • Subscription state (which tier, active or not) — knowing what you've paid for (contract)
  • Approximate country, from your device's locale or, transiently, your IP address — showing prices in your currency (legitimate interests)
  • Operational records of what we sent you and when, including the unique reference printed on each shareable card — accuracy, support, and investigating misuse (legitimate interests)
  • Waitlist email address, if you joined via the website — telling you the app has launched (consent)

We keep no advertising profiles of you, and the app and website contain no third-party analytics, advertising or tracking software. Any analysis of how the Service is used is done in aggregate on our own records, never identifies you, and is never shared with anyone. No automated decision-making or profiling takes place. We do not sell your data to anyone, ever.

If you signed in with Apple and chose to hide your email, we hold your @privaterelay.appleid.com address, treat it as your email address, and never attempt to de-anonymise it.

2. What we don't collect

  • Payment card details — payments are taken by Apple's App Store or Google Play; we only ever learn that you subscribed, never how you paid.
  • Location data (your device locale is not location tracking).
  • Contacts, photos, microphone or camera — saving a sticker to your photos happens on your device, at your request. (The sticker image itself is generated on our servers from your team and rival choices and held only transiently.)
  • Browsing history, in or outside the app.

Like every online service, our hosting providers record standard, short-lived technical logs (including IP addresses) as traffic passes through; we do not use these to identify or profile you.

3. Who processes your data for us

Processors — they receive personal data, under contract, to run the Service:

  • Expo — push notification delivery
  • Neon — database hosting (London, United Kingdom)
  • Railway — application hosting
  • Resend — service email delivery

Independent controllers — they handle the payment relationship under their own privacy policies when you subscribe through them: Apple (App Store) and Google (Google Play).

Data suppliers — third-party providers send us match data. No personal data is ever shared with them, and we may change or add suppliers at any time without notice.

Authorities — where we reasonably believe conduct involving our content may be criminal or may cause serious harm, or where we are required by law, we may share relevant account details and records with the police, regulators or other competent authorities (legal obligation, or legitimate interests under the crime and legal-proceedings provisions of the Data Protection Act 2018).

4. International transfers

Your account data lives in the United Kingdom — our database is hosted in London. Some processors above operate from the United States; where personal data reaches them, the transfer is protected by the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses in each provider's data-processing agreement. Transfers within the EU/EEA rely on the UK's adequacy regulations.

5. How long we keep it

Account data: for the life of your account, then deleted within 30 days of account deletion, except records we must keep for legal or accounting purposes. Push tokens: deleted with your device record when you log out or your account is deleted. Waitlist emails: used for launch announcements only, then deleted within 90 days of launch. Correspondence you send us (support or privacy requests) is kept for up to 24 months after the matter closes, then deleted. Hosting-platform technical logs expire automatically on short cycles.

6. Deleting your account

You can delete your account inside the app (Settings → Subscription & account → Delete account) — no email required — or by writing to support@goalsagainst.com. Deletion removes your personal data as described in section 5.

7. Your rights

Under UK GDPR you have the right to: access your data; correct it; delete it; receive it in a portable, machine-readable form; restrict our processing; object to processing based on legitimate interests — including an absolute right to object to direct marketing; withdraw consent at any time where consent is the basis; and lodge a complaint with the Information Commissioner's Office (ico.org.uk). Email support@goalsagainst.com and we will respond within one month.

8. Security

All data moves over HTTPS/TLS and is encrypted at rest in our database. Passwords, where used, are stored only as one-way hashes. No system is perfectly secure: if a breach occurs we will notify the ICO within 72 hours where required, and tell affected users without undue delay where the breach is likely to put them at high risk.

9. Cookies

goalsagainst.com sets no analytics, advertising or other non-essential cookies — which is why you don't see a cookie banner.

10. Children

The Service is a paid subscription contracted by adults (18+). Its content is suitable for general audiences, but it is not directed at children and we do not knowingly collect children's data. If you believe a child has created an account, contact us and we will delete it.

11. For US residents

We do not sell or share personal information as defined by the California Consumer Privacy Act and similar state laws. The rights in section 7 are available to you via the same contact.

12. Changes

Material changes will be announced by email or in-app notice before they take effect.

Contact

support@goalsagainst.com