Privacy Policy
This policy explains what personal information Pickleball Live API uses, why we use it and the choices available to you. We keep the service small and collect only what we reasonably need to provide, secure and improve it.
1. Who is responsible
Pickleball Live API is the controller of the personal information described in this policy. “Pickleball Live API”, “we”, “us” or “our” means the person or business identified as the seller at checkout and on your invoice.
You can contact us through the email address on our support page. Please use that address for privacy questions or requests as well as ordinary support.
2. Information we collect
We may collect:
- Account information: your name, email address, password hash, email-verification status and account preferences. We do not store your password in readable form.
- Authentication and security information: session identifiers, IP address, browser or device information, password-reset records and security events.
- Customer and API information: account name, plan, API-key prefix and hash, key status, usage totals, request identifiers, endpoints or WebSocket topics used, and timestamps. We show an API key secret once when it is created; we store a protected hash rather than the secret itself.
- Billing information: billing name and address, tax details, subscription and invoice status, payment method type, and limited card details such as brand and last four digits. Stripe processes payments. We do not receive or store full card numbers or card security codes.
- Communications: messages you send to support, billing or sales, including any diagnostic information you choose to provide.
- Operational information: server, error, security and audit logs needed to run and protect the service.
- Sports-participant information: names, teams, competition details and match results supplied by our data provider or obtained from published sports sources. We use this information only as part of the sports-data service, to maintain accurate records and to respond to correction requests.
We collect information directly from you, automatically when you use the website or API, from payment and infrastructure providers, and from our sports-data sources.
Please do not send us sensitive personal information or include personal information in API request data unless it is genuinely necessary.
3. How and why we use information
We use personal information only where we have a lawful reason:
- To provide the service and manage our agreement with you: creating and authenticating accounts, issuing API access, measuring plan usage, processing subscriptions, providing support and sending service messages. The lawful basis is performance of a contract or taking steps at your request before entering one.
- To operate and protect the service: monitoring reliability, diagnosing faults, preventing fraud and abuse, enforcing quotas, protecting API keys and investigating security incidents. The lawful basis is our legitimate interest in running a safe and dependable service.
- To administer and improve the product: understanding aggregate use, planning capacity, keeping business records and improving documentation and features. The lawful basis is our legitimate interest in operating and improving the service. We use aggregated or de-identified information where practical.
- To provide sports data: recording and distributing factual information about professional or public sporting events and correcting errors. The lawful basis is our legitimate interest in providing an accurate sports-data service and our customers' interest in receiving it.
- To meet legal duties: maintaining tax and accounting records, responding to valid legal requests and making required regulatory reports. The lawful basis is compliance with a legal obligation.
- For optional marketing or non-essential cookies: only where you have made a choice that gives us a valid basis, such as consent. You can withdraw consent at any time.
We do not sell personal information. We do not use account or support information for third-party targeted advertising.
We do not make decisions about people based solely on automated processing where those decisions have legal or similarly significant effects. Automated quota and security controls may temporarily limit API access, but you can contact support if you think a control was applied incorrectly.
You must provide an email address and authentication details to create an account. Billing details are required only if you buy a paid plan. If you do not provide required account or billing information, we cannot create the account or supply the paid service.
4. When we share information
We share only what is reasonably needed with:
- service providers that host the service, deliver email, process payments, store backups, provide security or help us monitor reliability;
- professional advisers where necessary to obtain accounting, security or legal advice;
- courts, regulators, law enforcement or other authorities where disclosure is legally required or reasonably necessary to protect rights, safety or the service; and
- a buyer or successor if the service or its assets are transferred, subject to appropriate confidentiality and data-protection safeguards.
Our current providers and their purposes are listed on the Subprocessors page. Providers may process information in other countries. Where data-protection law requires it, we use an adequacy decision, approved contractual terms or another valid transfer safeguard. You may contact us for information about the safeguard relevant to your data.
5. How long we keep information
We keep information only for as long as it is reasonably needed for the purposes above:
- account, authentication and API records are normally kept while the account is active;
- after an account is closed or a valid deletion request is completed, we delete or de-identify information that is no longer needed, subject to the exceptions below;
- invoices, payment records and related transaction evidence are kept for the period required by tax, accounting and fraud-prevention rules, commonly up to six years after the relevant transaction or accounting period;
- support, security and operational logs are kept for a limited period based on the sensitivity of the record and the time reasonably needed to diagnose problems, prevent abuse and establish legal claims; and
- records connected with a dispute, security incident, unpaid balance or legal duty may be kept until that matter and any applicable claim period have ended.
Deleted information may remain in restricted backups until those backups are overwritten through the normal backup cycle. We do not restore deleted information from a backup except where needed for disaster recovery, and we remove or isolate it again when practical.
Sports results and participant records may be retained as part of the historical sports record. If such information is inaccurate, contact us and identify the event and correction requested.
6. Security
We use reasonable technical and organisational safeguards appropriate to a small online service. These include access controls, one-way hashing for passwords and API secrets, encryption in transit, secret redaction from application logs, backups and restricted production access. No online service can promise absolute security.
Keep your password and API key confidential. If you believe an account or key has been compromised, rotate or revoke the key and contact support promptly.
7. Cookies
We use cookies or similar storage that are necessary for sign-in, security and basic operation. If we introduce non-essential analytics or advertising technology, we will update our Cookie Policy and request consent where required.
8. Your rights
Depending on where you live and why we use the information, you may have the right to:
- ask for a copy of your personal information;
- correct inaccurate or incomplete information;
- ask us to delete information;
- restrict or object to certain uses;
- receive information you provided in a portable format; and
- withdraw consent, where consent is the lawful basis.
These rights are not absolute. For example, we may keep records required by law or information needed to establish or defend a legal claim. We may ask for enough information to verify your identity before acting on a request. We normally respond within one month where UK data-protection law applies, although the law permits more time for a complex request.
You have the right to object to processing based on our legitimate interests. Tell us what you object to and why, and we will assess your request.
Please send requests to the address on our support page. We would appreciate the chance to resolve a concern first, but you may complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint or to your local data-protection authority.
9. Children
The service is intended for developers, businesses and professional users. It is not directed to children, and we do not knowingly collect account information from anyone under 18. Contact us if you believe a child has created an account.
10. Changes to this policy
We may update this policy as the service or law changes. We will post the new version here and change the effective date. If a change materially affects how we use existing account information, we will also give reasonable notice through the service or by email.
Effective: 20 July 2026
Version: 1.0