Privacy Policy
Last updated: December 5, 2025
This Privacy Policy explains how Flag Stats ("Flag Stats", "we", "our", or "us") collects, uses, and protects personal information when you use the Flag Stats mobile application (the "App"), available worldwide through the Apple App Store.
By creating an account or using the App, you agree to the practices described in this Privacy Policy, in accordance with applicable data protection laws, including the EU/EEA General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA").
1. Data Controller
For the purposes of data protection laws such as the GDPR, the data controller responsible for the processing of personal data described in this Privacy Policy is:
Flag Stats
Legal seat: Italy
Email: info@flagstatsapp.com
If you are located in the EU/EEA or in a country with similar data protection laws, Flag Stats is the controller of your personal data processed through the App.
2. Data we collect
We collect and process only the data necessary to provide and improve the App:
Account information: your email address, used to create and manage your user account and to communicate with you about the App (for example, account-related notifications, password reset).
Inâapp purchase information: purchase status and identifiers associated with App Store transactions (such as product identifiers and receipts) needed to unlock or restore paid features. We do not collect or store full payment card details; payments are processed by Apple. Apple may process personal and payment data according to its own privacy policy.
Usage and technical data: information about how you use the App, device type, operating system version, language, and app version, used for analytics, troubleshooting, and improvement of our services (where required, collected in aggregated or pseudonymized form).
We do not intentionally collect sensitive categories of data (such as health, biometric, or precise geolocation data) or information about children under the age where parental consent is required.
3. Purposes and legal bases (including GDPR)
We use your personal data for the following purposes:
To provide and operate the App: creating and maintaining your account, enabling core functionality, syncing your content, and processing inâapp purchases.
Legal basis (GDPR): performance of a contract (Article 6(1)(b)).
To communicate with you: service messages, account security notices, and responses to your requests.
Legal basis: performance of a contract and/or legitimate interest (Article 6(1)(b), 6(1)(f)).
To improve and secure the App: analytics, debugging, and protecting against fraud, abuse, and misuse.
Legal basis: legitimate interest in operating, improving, and securing our services (Article 6(1)(f)).
To comply with legal obligations: accounting, tax, and regulatory requirements.
Legal basis: compliance with a legal obligation (Article 6(1)(c)).
Where local law requires consent for specific types of processing (for example, certain analytics or marketing), we will request your consent and rely on it as the legal basis for that processing.
4. Inâapp purchases and payments
Inâapp purchases are processed by Apple using your Apple ID and the App Store infrastructure.
Apple is responsible for collecting and processing your payment details and certain transaction data under its own terms and privacy notice.
Flag Stats receives limited information needed to verify and deliver your purchase (such as product identifiers, transaction receipts, and purchase status) and does not store full payment card information.
You should review Apple's privacy policy for more details on how Apple processes payment and account data.
5. Use of Supabase (data processor)
Flag Stats uses Supabase as a cloud backend platform to host the App's database, authentication, and related infrastructure services.
Supabase processes personal data (such as your email and accountârelated information) exclusively on our behalf and according to our instructions, as described in a Data Processing Agreement (DPA) between Flag Stats and Supabase.
Where available, data is hosted in an EU region to support compliance with GDPR data residency and international transfer requirements.
Supabase may in turn use subâprocessors (for example, cloud providers) as detailed in its own privacy and security documentation; these subâprocessors are bound by appropriate contractual safeguards.
You can learn more about how Supabase handles data by consulting its publicly available privacy and legal documentation.
6. Data sharing and international transfers
We do not sell your personal information. We only share data in these situations:
Service providers: trusted thirdâparty providers (for example, cloud hosting or analytics) that help us operate and improve the App, bound by contractual obligations to protect your data and use it only on our instructions.
Apple Inc.: as necessary for inâapp purchases and App Store distribution, under Apple's own terms and privacy policy.
Legal reasons: if we are required to do so by law, regulation, or valid legal process, or to protect our rights, users, or the public.
Because the App is available worldwide, data may be processed in countries other than your own. Where required, we implement appropriate safeguards for crossâborder transfers, such as standard contractual clauses or reliance on adequacy decisions recognized by the European Commission.
7. Data retention
We retain your email address and accountârelated data for as long as your account remains active and as necessary to provide the App and fulfill the purposes described above.
If you want to delete your account, you can request deletion at any time by contacting us at info@flagstatsapp.com. Once your request is verified, we will delete or anonymize your personal data within a reasonable period, unless we are required to keep certain information longer to comply with legal or accounting obligations.
8. Security
We use appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, alteration, or destruction, taking into account the nature of the data and the risks involved. No system can be completely secure, but we work to continuously improve our safeguards.
9. Your rights under GDPR (EU/EEA and similar laws)
If you are located in the European Union, European Economic Area, or in a country with comparable data protection laws, you have the following rights regarding your personal data, subject to legal conditions and limitations:
Right of access (obtain a copy of your personal data).
Right to rectification (correct inaccurate data).
Right to erasure ("right to be forgotten").
Right to restriction of processing.
Right to data portability.
Right to object to certain processing based on legitimate interests.
Where processing is based on consent, the right to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
You can exercise these rights by contacting us using the details in the "Contact us" section below. To request deletion of your Flag Stats account, you can contact us directly at info@flagstatsapp.com. You also have the right to lodge a complaint with your local data protection authority.
10. Rights for California residents (CCPA/CPRA)
If you are a resident of California, you may have specific rights under the CCPA/CPRA in relation to your "personal information," including:
The right to know what categories of personal information we collect, use, and disclose.
The right to access and, where applicable, request deletion of your personal information.
The right to correct inaccurate personal information.
The right to opt out of the "sale" or "sharing" of personal information, where applicable.
Flag Stats does not sell personal information in the sense defined by the CCPA/CPRA. If in the future we engage in activities considered "selling" or "sharing" personal information, we will update this Privacy Policy and provide a clear mechanism for you to opt out.
You will not receive discriminatory treatment for exercising any of your privacy rights.
11. Children's privacy
The App is not directed to children under the age of 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from children in violation of applicable law such as COPPA in the United States.
If you believe that a child has provided us with personal information, please contact us so that we can delete it where required by law.
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the "Last updated" date and, where appropriate, by providing a notice within the App.
13. Contact us
If you have any questions about this Privacy Policy or wish to exercise your privacy rights, you can contact us at:
Flag Stats â Privacy
Email: info@flagstatsapp.com
This Privacy Policy is designed to comply with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act and California Privacy Rights Act (CCPA/CPRA), and other applicable international data protection laws.
Copyright © 2025, Flag Stats. All rights reserved.
đ Crafted by Flag Football player.

