- Information We Collect
- How We Use Your Information
- Lawful Basis for Processing (GDPR)
- Data Storage & Security
- Data Sharing
- International Data Transfers
- Payments
- Cookies & Local Storage
- Children's Privacy
- Your Rights & Choices
- Additional Rights for European Users
- Data Retention
- Changes to This Policy
- Contact & Complaints
01 Information We Collect
We collect the following information when you use Breakout Scout:
- Account information — your email address and team name, provided when you create an account.
- Scouting data — match records, player markers, kill markers, field layouts, notes, plays, and merged matches that you create within the app.
- Usage data — basic information about how you interact with the app, collected to improve the product.
- Payment information — if you subscribe to Breakout Scout Pro, payment details are processed by Stripe. We do not store your credit card number or payment credentials on our servers.
- Device information — device type and operating system, used to ensure compatibility and diagnose technical issues.
We do not collect your precise location, contacts, camera, or microphone data.
02 How We Use Your Information
We use the information we collect to:
- Create and manage your account
- Store and sync your scouting data across devices
- Process subscription payments and manage your Pro access
- Send transactional emails such as password resets and account notices
- Diagnose bugs and improve the app
- Respond to your support requests
- Comply with legal obligations
We do not use your data for advertising, profiling, or any purpose beyond operating and improving Breakout Scout.
03 Lawful Basis for Processing GDPR
For users in the European Economic Area (EEA), United Kingdom, and Switzerland, we process your personal data under the following lawful bases as required by the GDPR:
- Contract performance (Art. 6(1)(b)) — processing your email address, account data, and scouting data is necessary to provide the Service you signed up for.
- Legitimate interests (Art. 6(1)(f)) — we process basic usage and device data to improve the app, diagnose issues, and maintain security. We have assessed that our legitimate interests are not overridden by your privacy rights.
- Legal obligation (Art. 6(1)(c)) — we may retain certain payment records to comply with applicable tax and financial reporting laws.
- Consent (Art. 6(1)(a)) — where we rely on consent, you may withdraw it at any time without affecting prior lawful processing. Contact matt@breakoutpaintball.com to withdraw consent.
04 Data Storage & Security
Your data is stored securely using Supabase, a hosted PostgreSQL database platform. All data is encrypted at rest and in transit using TLS. Our primary servers are located in the United States.
Field layout images are stored in Supabase Storage with access controls restricting viewing to authorized users only.
We implement reasonable technical and organizational measures to protect your personal data. However, no system is completely secure. If you believe your account has been compromised, contact us immediately at matt@breakoutpaintball.com.
06 International Data Transfers GDPR
Breakout Scout is operated from the United States. If you are located in the EEA, United Kingdom, or Switzerland, your personal data will be transferred to and processed in the United States.
We rely on the following safeguards for these transfers:
- Standard Contractual Clauses (SCCs) — our processors including Supabase and Stripe implement EU Standard Contractual Clauses approved by the European Commission.
- Adequacy decisions — where applicable, we rely on adequacy decisions by the European Commission.
You may request information about our transfer mechanisms by contacting matt@breakoutpaintball.com.
07 Payments
Subscription payments are processed by Stripe, Inc., a PCI DSS-compliant payment processor. Your payment information is transmitted directly to Stripe and is never stored on our servers. Stripe's privacy policy is available at stripe.com/privacy.
If you subscribe through the iOS App Store, payments are processed by Apple Inc. and subject to Apple's privacy policy.
09 Children's Privacy
Breakout Scout is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. If you believe your child under 13 has created an account, contact us at matt@breakoutpaintball.com and we will promptly delete it.
Users between 13 and 18 should review this policy with a parent or guardian before using the app.
10 Your Rights & Choices
All users have the following rights:
- Access — view all your scouting data within the app at any time.
- Export — export matches as JSON files from within the app.
- Correction — edit your team name and account information from app settings.
- Deletion — delete your account from app settings, or by emailing matt@breakoutpaintball.com. All personal data is removed within 30 days.
- Opt out of emails — unsubscribe from non-essential communications at any time.
Contact matt@breakoutpaintball.com to exercise any of these rights. We respond within 30 days.
11 Additional Rights for European Users GDPR
If you are located in the EEA, United Kingdom, or Switzerland, you have the following additional rights under the GDPR:
- Right of access (Art. 15) — obtain confirmation of whether we process your data and receive a copy of it.
- Right to rectification (Art. 16) — have inaccurate personal data corrected without undue delay.
- Right to erasure (Art. 17) — request deletion of your personal data where it is no longer necessary or where you withdraw consent.
- Right to restrict processing (Art. 18) — request that we limit how we use your data in certain circumstances.
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable format. JSON export is available directly in the app.
- Right to object (Art. 21) — object to processing based on legitimate interests. We will stop unless we can demonstrate compelling grounds.
- Automated decision-making (Art. 22) — we do not make automated decisions that produce legal or similarly significant effects on you.
To exercise any GDPR right, contact matt@breakoutpaintball.com. We respond within 30 days at no charge.
12 Data Retention
We retain your personal data for as long as your account is active. Upon account deletion, all personal data and scouting records are permanently deleted within 30 days, except where retention is required by law.
Payment transaction records may be retained for up to 7 years for tax compliance purposes. System backups may retain deleted data for up to 90 days before being fully purged.
13 Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-app notice at least 14 days before they take effect. The effective date at the top reflects the most recent update.
14 Contact & Complaints
For questions, requests, or concerns about this Privacy Policy or your personal data:
matt@breakoutpaintball.com
We respond to privacy inquiries within 5 business days and formal data subject requests within 30 days.
EU and UK residents who are unsatisfied with our response have the right to escalate to their national data protection authority. See Section 11 for details.