Social Football

Privacy Policy

Last updated: May 2026

Who we are

Social Football is a platform for organising and managing recreational football leagues. It is operated by Leo Edwards and Matt King.

Contact: leo@leoedwards.dev

What data we collect

When you use Social Football we collect:

  • Account data — your name and email address, provided when you register
  • Player data — ability ratings, game history, statistics, and any avatar image you upload
  • Usage data — which pages you visit and when, for security and debugging purposes
  • Login codes — temporary 6-digit codes sent to your email to verify your identity; these expire after 10 minutes and are not stored in plaintext

If your league admin links your user account to a player profile, your game records and stats will be associated with your account.

Why we collect it and our lawful basis

Purpose Lawful basis
Running your account and providing the service Contract
Sending login codes Contract
Maintaining security and preventing abuse Legitimate interests
Sending you relevant service updates Legitimate interests
Promoting relevant local services to you Consent

We do not use your data for automated decision-making or profiling.

Cookies

We use session cookies to keep you logged in. We do not use advertising or tracking cookies. No cookie consent banner is required.

Who we share data with

We do not sell your data. We do not share your personal data with third parties for their own marketing purposes.

We may use third-party services to operate the platform (e.g. email delivery, payment processing). These act as data processors under our instruction and are contractually bound to handle your data appropriately.

In future, we may promote relevant local services (such as nearby gyms or football coaching) to you directly. We will always do this ourselves — we will never hand your data to a partner. You can opt out of these communications at any time by emailing us.

How long we keep your data

We keep your data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it by law (e.g. financial records).

Player stats and game records that do not identify you personally (e.g. anonymous historical records) may be retained for the integrity of league history.

Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your data (right to erasure)
  • Restrict how we process your data
  • Object to processing based on legitimate interests
  • Portability — receive your data in a portable format

To exercise any of these rights, email leo@leoedwards.dev. We will respond within one month.

You also have the right to complain to the Information Commissioner's Office (ICO) if you are unhappy with how we handle your data.

ICO registration

We are in the process of registering with the ICO as required under UK data protection law. This notice will be updated with our registration number once complete.

Changes to this policy

If we make material changes to this policy, we will notify you by email at least 30 days before the changes take effect. You may delete your account if you do not agree with the updated policy.

Read our Terms of Use →