RackUp Privacy Policy

Effective date: 2 October 2026 · Applies to the RackUp apps for Android and iPhone (com.rackup.app)

Στα Ελληνικά

What changed on 2 October 2026. Version 2.2.0 of the apps brings these changes. The player card our server has kept since 1 October 2026 now shows in the apps: other players with an account can open yours, with your name, category, city, usual hall, photo and the games you play, and players can find each other by name. Being findable is on by default, and you can turn it off in Settings with Show me in player search. The usual hall on your card can be changed or removed there too, under Your home venue. You can send a player a direct challenge that only the two of you can see. The two players of a confirmed match can send each other quick messages chosen from a fixed list, with no typing, and we delete them after 14 days. The iPhone app can now set and remove a profile photo, and, if you allow it, use your approximate location to show the halls and games in your city first. As on Android, your position never leaves your phone. Deleting your account now also deletes your direct challenges and quick messages, sent and received.

Earlier on 2 October 2026, before version 2.2.0. Mostly corrections: the apps did not change. The version dated 1 October 2026 got several things wrong about the apps as they are, version 2.1.0. It said we log twelve analytics events and attach no venue to any of them: we log 23, and two of them carry the id of a billiard hall. It said no part of the app is readable without signing in. That is true of everything personal in our database, but anyone who has the link to your profile photo can open the photo without signing in, and for reading, our security rules check for a sign-in, not for an account. It also left things out: your looking-for-a-game post, the players you follow, the city, usual hall, games and app version on your profile record, and what a notification token is stored with. All of these are now described, and the list of what deletion removes now includes your follows, other players' follows of you and your looking-for-a-game post. One thing is new: since 1 October 2026 our server keeps a player card for each player, ahead of version 2.2.0 of the apps, which is the first to show it. It is described below, and deleting your account deletes it.

What changed on 1 October 2026. The iPhone app now has push notifications too, from version 2.1.0. If you allow them, it stores a Firebase Cloud Messaging token for your iPhone under your account, as the Android app already did, so we can tell you about join requests, match updates, reminders and alerts from halls you starred. It asks once, after you sign in and finish the welcome tour, and you can switch them off in Settings or in your iPhone's settings. Nothing else about what we store has changed.

What changed on 29 September 2026. Deleting your account now also deletes the notifications in other players' activity feeds that name you, such as the one telling a host you asked to join their match. Until this change they stayed in the other player's feed after you left. So that they can be found, each such notification now also stores the user id of the player it names. Nothing else about what we store or delete has changed.

The version dated 4 September 2026 replaced the policy dated 7 July 2026. The old one covered only the Android app and said the app collected no analytics. That was wrong. Both apps include Firebase Analytics and Firebase Crashlytics, and the policy says so, along with everything else the apps actually store. Nothing about the app changed on 4 September 2026: the policy was corrected to match the app.

RackUp is an app for billiards players in Greece who want to find an opponent for a real game at a real venue. You post when and where you want to play, and another player takes the table. This page explains, in plain language, what data the app handles, who can see it, and what your rights are.

Who is responsible for your data

RackUp, Ioannina, Greece, is the data controller for the personal data described on this page. You can reach us at rackupbilliard@gmail.com about anything on this page, including any request about your rights.

What we collect, and why

Your account

To sign in you use an email address and a password, or Google (Android), or Sign in with Apple (iPhone). Passwords are handled and stored by Google Firebase Authentication and we never see them. If you sign in with Apple and choose to hide your address, we store the Apple private relay address exactly as Apple gives it to us.

Your profile record holds your display name, your email address, the skill category you choose for yourself (Pro down to E), your city, your usual hall and the games you play if you gave them, a link to your profile photo if you have one, your notification preferences, whether you appear in player search, your language, which version of the app you last used and on which platform, and a pointer to your most recent venue check-in. Only you can read your own profile record. We use it to run your account, to show your name and category on the matches you post or join, and to build your player card, described below. The app version also tells us how many players have updated.

Your profile photo

You can set a profile photo on Android and, from version 2.2.0, on iPhone. You pick it with your phone's own photo picker, which gives the app only the photo you choose and no access to the rest of your library. The app scales it on your phone to at most 512 pixels on its longest side, saves it as a JPEG and uploads it to Firebase Cloud Storage as avatars/<your user id>.jpg. A link to it goes on your profile and your player card. Any signed in player can view it, because it is shown next to your matches and on your player card. Removing the photo in the app deletes the file, from either app, and so does deleting your account. If a player's photo is offensive, you can report them from their player card.

Your player card and player search

Each player with an account has a player card, which our server has kept since 1 October 2026 and which other players with an account can open from version 2.2.0 of the apps. It is a separate record, playerCards/<your user id>, which only our server writes, copying from your profile: your display name, your skill category, your city, your usual hall, the link to your profile photo, the games you play, whether you appear in player search, and a yes or no for whether your app is new enough to receive direct challenges. That yes or no is worked out from the app version on your profile; the version itself is not copied. For search, the card also holds the beginnings of each word of your name, in Greek and in Greeklish, without accents. Your card never holds your email address, your language, your notification settings, your push tokens or your app version.

The card screen also shows a player's wins and losses this month, their win rate, reliability figure and verified badge, and the viewer's own record against them. The viewer's phone works these out from match records that every signed in player could already read; none of them is stored on the card.

Player search is only for players with an account. It finds a player when what you type matches the start of any word of their name, in Greek or Greeklish, ignoring accents. You type at least 2 letters and see at most 20 players. Email addresses and cities are not searchable. Before you type, it suggests players you played with recently, taken from your own matches, and regulars at your usual hall. Players you blocked never appear.

Being findable is on by default. To stop it, turn off Show me in player search in Settings. That takes your name out of search and you out of the regulars at your hall. Your card itself stays readable: players you have played with can still open it, for example from their Played with recently list or from a match's quick messages, and you still appear on your matches, challenges and leaderboards.

What you post and write

The app is a noticeboard, so a lot of what it stores is content you create on purpose:

Free text you type into a name, a match note, a challenge note, a cancellation note or the feedback form is checked against a profanity list on your device before it is sent.

Safety: reports and blocks

If you report a player, from a match or from their player card for example, we store your user id, their user id, the match or post in question if there is one, and what you wrote. Reports go into a collection that no app can ever read back. Only we can read them, in the Firebase console, and we do so to act on abuse. If you block a player, we store their user id in a private list of yours. Blocking is invisible to the person blocked. It hides their posts from your feed and keeps them out of your player search, and it hides their quick messages and direct challenges, which also stop notifying you.

Feedback

The feedback form in Settings sends us your user id, the category you pick, your message, the app version and build, and which platform you are on. Like reports, no app can read this back.

Notifications

We store a Firebase Cloud Messaging token for each of your devices, Android or iPhone, along with your language, the platform, the app version and build, and the time it was last updated, so we can send you push notifications about join requests, match updates, direct challenges, quick messages, reminders, saved search alerts, new games from players you follow and, for halls you starred, new games and check-ins there. You control these with the switches in Settings and with your device's notification permission. The iPhone app asks for that permission once, after you sign in and finish the welcome tour, and stores a token only if you allow it; its notifications are delivered through Apple's Push Notification service. Signing out removes the token for that device, and deleting your account removes all of them.

A direct challenge adds an entry to the invited player's activity feed and sends them a push naming the sender, the hall and the time; the answer adds an entry and a push for the sender. A quick message comes only as a push, showing the sender's name and the message in your language, and adds nothing to your activity feed. The pushes for both follow the Match updates switch.

Crash diagnostics (both apps)

Both apps include Firebase Crashlytics. When the app crashes or hits a handled error, Crashlytics sends Google a report containing the crash, your device model, your operating system version and the app version. We use it to find and fix bugs. We never attach your account to a crash report. The app never calls Crashlytics' user id function, so reports carry only Crashlytics' own installation identifier, which we cannot match to a person.

App usage analytics (both apps)

Both apps include Firebase Analytics, and it is on by default. The old version of this policy said the app had no analytics profiles. That was wrong, and correcting it was the main reason for the version dated 4 September 2026.

We log 23 events about how the app is used, the same on both apps. Most of them record only that something happened. Here they all are, with any detail an event carries:

The only ids any event carries are hall ids, on match_posted and venue_checked_in. A hall id names a billiard hall in our directory, not a person. No name, no email, no user id, no match id and no free text is ever attached to an analytics event. Firebase Analytics also collects its own standard measurements, such as app opens and sessions, and it derives approximate geography from a masked IP address.

Analytics is not linked to your account. The app never calls Analytics' user id function, so Analytics keys on its own per installation identifier. One practical consequence, stated honestly: because these records are not tied to your account, we cannot pick out an individual person's analytics records, and there is no in-app switch to turn analytics off. Uninstalling the app stops collection.

Location

Both apps can ask for your approximate location, never your precise one, for one purpose: showing the halls and games near you first. The app asks only after you tap the card at the top of the Venues tab that offers to show the venues closest to you first, and it reads your location only while you are using it. The iPhone app asks from version 2.2.0; the Android app, through its coarse location permission, has asked since its first versions.

Your position is used only on your phone, against venue coordinates the app already has. From the hall nearest to you, the app works out your city. It orders every list of halls and games with your starred halls first, then your city, then everything else, nearest first, and it opens Discover on that city. Your position is never sent to us and never stored anywhere, and neither is the city worked out from it: it only orders what you see on screen and is never written to your profile or to any post. If you say no, nothing else changes: the lists put the city on your profile first instead, and the app works normally. Checking in at a venue is on the honour system and is not verified against your location.

What we do not do

Who can see what

For reading, our security rules check that a request is signed in, not that it comes from an account. Firebase also offers a guest sign-in, which it calls anonymous sign-in. The apps do not offer it, but a session signed in that way would be allowed to read what every signed in player can read, listed above, and nothing that is private to you or visible only to us.

One consequence worth knowing: because match records pair a user id with a display name and are readable by any signed in player, a user id that appears anywhere in the app can be resolved to a display name by another player. A player with an account can also read the player card behind it.

Where your data is stored, and who processes it

RackUp runs entirely on Google Firebase, on Google Cloud infrastructure. Google acts as our service provider and processes this data on our instructions. The services we use are:

Our database, storage and server functions are configured to run in Google's European regions. Crashlytics and Analytics are global Google services, so the diagnostic and usage data they collect may be processed outside the European Economic Area under Google's own data processing terms. Google's documentation for all of this is at firebase.google.com/support/privacy.

Data is encrypted in transit. Access from the apps is controlled by Firebase security rules that enforce exactly the visibility described in the section above.

Our lawful basis (GDPR Article 6)

How long we keep it

Deleting your account

In the app: Profile → Settings → Delete account → Yes, delete everything. If it has been a while since you signed in, Firebase will ask you to sign out and sign back in first. If you signed in with Apple, the app also asks Apple to revoke RackUp's access to your Apple Account.

Without the app: email rackupbilliard@gmail.com from your registered address with the subject "Account deletion request" and we will do it for you.

What deletion removes

Your sign-in account is deleted immediately. That automatically starts a server-side job which removes:

The job normally finishes within moments. If a step fails, a scheduled task retries the remaining steps every six hours until they are done.

What survives deletion, and why

We would rather be exact here than reassuring, so please read this part.

We do not claim that deleting your account erases every trace of you everywhere. The list above is what remains.

Your rights (GDPR)

If you are in the EU or the EEA you have the following rights over your personal data, and we will honour them all:

To exercise any of these, email rackupbilliard@gmail.com from the address on your account. We reply within one month, as the GDPR requires. There is no charge.

If you are unhappy with how we have handled your data, you can complain to the Hellenic Data Protection Authority at dpa.gr, or to the supervisory authority in the EU country where you live.

Children

RackUp is not directed at children. The app arranges meetings between adults at billiard halls, and we do not knowingly collect data from children under 16. There is no age verification in the app. If you believe a child has created an account, email us and we will remove it.

Security

All traffic between the apps and Firebase is encrypted. What each account may read and write is enforced by Firebase security rules on the server, not by the app, so a modified app cannot reach data it is not entitled to. The Android app additionally verifies itself with Firebase App Check. We are a small team and we do not pretend to be immune to every risk, but if a breach affects your personal data we will notify the Hellenic Data Protection Authority and, where the law requires it, you.

Changes to this policy

If this policy changes, the new version is published at this address with a new effective date, and we say at the top what changed. This version, dated 2 October 2026, describes version 2.2.0 of the apps and replaces an earlier version of the same day that held only the corrections described at the top. Both supersede the version dated 1 October 2026, which superseded the version dated 29 September 2026. That one superseded the version dated 4 September 2026, which superseded the version dated 7 July 2026 in full.

Σύνοψη στα Ελληνικά

Το RackUp αποθηκεύει: όνομα, email, κατηγορία παίκτη, πόλη, αίθουσα όπου παίζεις συνήθως, τι παίζεις, προαιρετική φωτογραφία προφίλ και όσα δημοσιεύεις ή στέλνεις μέσα στην εφαρμογή, δηλαδή ματς, προσωπικές προκλήσεις, σημειώσεις, σκορ, ακυρώσεις, δηλώσεις ότι ψάχνεις παιχνίδι, ποιους ακολουθείς, γρήγορα μηνύματα, βαθμολογίες αντιπάλων, check-in σε αίθουσες, αναφορές και σχόλια. Όλα βρίσκονται στο Google Firebase (Authentication, Firestore, Cloud Storage, Cloud Functions στην Ευρώπη).

Το email σου είναι ιδιωτικό. Το όνομα, η κατηγορία και η φωτογραφία σου εμφανίζονται στα ματς που δημοσιεύεις ή στα οποία συμμετέχεις, όταν δηλώνεις ότι ψάχνεις παιχνίδι, και στην κάρτα παίκτη σου, μαζί με την πόλη σου, την αίθουσα όπου παίζεις συνήθως και τι παίζεις. Την κάρτα σου τη βλέπουν όσοι έχουν λογαριασμό, και μπορούν να σε βρουν με το όνομά σου, εκτός αν κλείσεις το «Να με βρίσκουν στην αναζήτηση» στις Ρυθμίσεις. Την αίθουσα όπου παίζεις συνήθως την αλλάζεις ή τη βγάζεις από τις Ρυθμίσεις, στο «Η λέσχη σου». Όλα αυτά τα βλέπουν μόνο όσοι έχουν συνδεθεί στην εφαρμογή, με μία εξαίρεση: όποιος έχει τον σύνδεσμο της φωτογραφίας σου μπορεί να την ανοίξει και χωρίς σύνδεση.

Μια προσωπική πρόκληση τη βλέπετε μόνο εσείς οι δύο, μαζί με τη σημείωσή της. Αν γίνει δεκτή, δημιουργείται κανονικό ματς, που το βλέπουν όλοι οι παίκτες, αλλά η σημείωση δεν περνάει σε αυτό: μένει στην πρόκληση και σβήνεται μαζί της. Όταν κλείσει ένα ματς, οι δύο παίκτες του μπορούν να ανταλλάσσουν μόνο έτοιμα γρήγορα μηνύματα, χωρίς πληκτρολόγηση. Τα βλέπετε μόνο εσείς οι δύο και σβήνονται μετά από 14 ημέρες.

Και οι δύο εφαρμογές περιλαμβάνουν Firebase Crashlytics (αναφορές σφαλμάτων) και Firebase Analytics (23 συμβάντα χρήσης, όπως η δημοσίευση αγώνα ή το check-in σε αίθουσα). Αυτά τα δύο συμβάντα καταγράφουν και ποια αίθουσα αφορούν. Κανένα συμβάν δεν περιέχει όνομα, email ή κείμενο που έγραψες, και κανένα από τα δύο εργαλεία δεν συνδέεται με τον λογαριασμό σου: η εφαρμογή δεν στέλνει ποτέ το αναγνωριστικό χρήστη σε αυτές τις υπηρεσίες.

Δεν υπάρχουν διαφημίσεις, ούτε διαφημιστικά αναγνωριστικά, ούτε παρακολούθηση σε εφαρμογές άλλων εταιρειών. Δεν πουλάμε δεδομένα. Από την έκδοση 2.1.0 υπάρχουν ειδοποιήσεις push και στο iPhone: αν τις επιτρέψεις, κρατάμε στον λογαριασμό σου ένα αναγνωριστικό ειδοποιήσεων για τη συσκευή, μόνο για να σου τις στέλνουμε, και μπορείς να τις κλείσεις από τις Ρυθμίσεις της εφαρμογής ή του iPhone. Και στις δύο εφαρμογές (στο iPhone από την έκδοση 2.2.0), αν το επιτρέψεις, η κατά προσέγγιση τοποθεσία σου χρησιμεύει μόνο για να βλέπεις πρώτα τις αίθουσες και τα ματς της πόλης σου, και η θέση σου δεν φεύγει ποτέ από τη συσκευή.

Διαγραφή λογαριασμού: μέσα από την εφαρμογή (Προφίλ → Ρυθμίσεις → Διαγραφή λογαριασμού) ή με email στο rackupbilliard@gmail.com. Μαζί με τον λογαριασμό σου διαγράφονται η κάρτα παίκτη σου, οι προσωπικές προκλήσεις και τα γρήγορα μηνύματα που έστειλες ή έλαβες, και οι ειδοποιήσεις στη ροή δραστηριότητας άλλων παικτών που αναφέρουν το όνομά σου. Διάβασε παραπάνω τι ακριβώς διαγράφεται και τι παραμένει.

Έχεις δικαίωμα πρόσβασης, διόρθωσης, διαγραφής, φορητότητας, εναντίωσης και περιορισμού, καθώς και δικαίωμα καταγγελίας στην Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (dpa.gr).

RackUp · Ioannina, Greece · rackupbilliard@gmail.com
Support · Home