Privacy
Last updated 18 September 2026
Play runs leagues, tournaments and social events for racket sports. This page explains what we store about people, who can see it, how long we keep it, and how to reach us. It describes what the service actually does; when the service changes, this page changes with it.
The short version
- A play or a group is public to anyone holding its link. Names of players and teams on it can be read by anyone with that link, and by search engines if someone publishes it.
- We never ask for, and the system deliberately cannot store, a way of contacting a player: no email, phone number or handle belongs on a player's entry in a play.
- We do not use advertising, analytics or tracking services. There is no tracking cookie on this site.
- Your account details — your email address above all — are private to you and are never shown on a play.
- Data is held in Google Cloud in the European Union.
Who we are
Play is published by Racket ID CSM AB (organisation number 559200-8097), Garvaregatan 6A, 602 21 Norrköping, Sweden, which is the controller of the personal data described under "Your account" below. Write to us at geral@racket.id about anything on this page, including a request to see or delete your data.
Your account
You can sign in with an email address and password, or with Google. Sign-in is handled by Google Firebase Authentication, which holds your email address, your password in hashed form if you set one, the name and profile picture your Google account provides if you sign in that way, and the times you signed in.
Alongside that we keep a profile for you containing your name, your email address, a link to your profile picture, optionally your gender and ranking if you enter them, and images you have uploaded. Only you can read this record. Nobody can list our users or their email addresses.
Being findable by name
So that an organiser can seat you in a competition as yourself rather than as a typed-in name, we also keep a small public entry for you: your name, your gender and ranking if you gave them, and your user id. Any signed-in user of Play can find this entry by searching for your name. It never contains your email address or your picture. If you do not want to be findable this way, write to us.
Plays, groups, and what is public
A play is one league, tournament or session; a group is several of them shown together. Everything stored in a play is readable by anyone who has its link — the link is the permission, and there is no sign-in on the way in. That includes the names of players and teams, the fixtures, the results and the standings.
A player's entry can hold only a name, and optionally a gender and a ranking. The system refuses anything that looks like a way to reach a person. Team entries are freer in shape, so organisers should keep contact details out of them too.
If you have been entered into a play and want your name removed or replaced, ask the organiser who runs it, since they control what it contains. If you cannot reach them, write to us and we will help.
When an organiser enters other people
Most people in a play were entered by an organiser — a club, a league or an event host — who is using Play under their own account or through their own software. For the names and results they enter, that organiser decides what is collected and why: they are the controller, and we handle it on their behalf. It is their responsibility to have a proper basis for entering people, to tell them their names will appear on a public page, and to take particular care with players who are children.
For your own account, as described above, we are the controller.
Organisations and API keys
An organisation using Play has a record holding its name and its members — for each member, their user id, and the email address and display name shown to their colleagues. API keys are stored only as an irreversible hash: a key is shown once, when it is created, and we cannot recover it afterwards.
Assistants and connectors
You can connect an assistant, such as Claude or another MCP client, to act in Play as you. When you approve such a connection we store which client was approved and that you approved it, so your instructions to it are carried out under your own access and nobody else's. You can ask us to revoke a connection at any time. What the assistant then reads or writes is what you could read or write yourself.
What else we keep
| What | Why | How long |
|---|---|---|
| Activity trail: who changed which play, when, and the content of the change | So an organiser can see what happened to their competition, and so we can investigate problems | 90 days, then deleted automatically |
| Usage meter: counts of work done, recorded against an organisation and a user id | Billing and limits | Kept while the account is open |
| Deleted plays and groups | A safety net if something is deleted by mistake | 90 days, then purged permanently |
| Records of people claiming an entry as themselves | So an organiser can see who claimed which entry, and undo it | Kept while the play exists |
| Server logs held by Google Cloud, containing identifiers rather than content | Security and diagnosing faults | Google Cloud's standard retention |
A deleted play disappears from every reading immediately. Restoring one from the safety net within those 90 days is a manual job we may be able to do if you ask, not something we promise.
Who else sees the data
We use Google (Firebase and Google Cloud) to run the service: authentication, databases, file storage and hosting. Google processes the data on our instructions.
An organisation can ask us to send updates about its own plays to an address it controls, so its website or software can show live results. Only what is already public on the play's page is sent. Nothing is sent anywhere else.
We do not sell personal data, and we do not use advertising or analytics services. We may disclose data if the law requires it, or to protect the service and its users.
Where the data is held
Everything runs in Google Cloud's European regions: our servers, our databases and our file storage are all in europe-west1, in Belgium. Google may process data elsewhere for support and security purposes under its own safeguards.
Cookies and browser storage
We use browser storage to keep you signed in. That is the only purpose. There are no advertising or analytics cookies on this site.
Your rights
If you are in the EU or the UK you have the right to see the data we hold about you, to have it corrected, to have it deleted, to object to how we use it, and to receive a copy of it. Write to geral@racket.id and we will answer within a month. If you believe we have handled your data wrongly, you can complain to your national data protection authority; ours in Sweden is the Integritetsskyddsmyndigheten (IMY).
One limit worth knowing: where an organiser entered your name into their competition, they decide what happens to it, so we will normally pass your request to them and help them act on it.
Children
Play has no age restriction of its own, because junior competitions are ordinary sport. Accounts are meant for adults; a junior player normally appears as a name entered by their club, which is responsible for having a proper basis for that and for keeping it to the minimum. Write to us if you are a parent or guardian and want a child's name removed.
Changes
When we change how the service handles personal data we update this page and change the date at the top. If a change matters to you we will say so in the product rather than leave it here to be found.