As letras pequenas, em linguagem clara
Privacidade
Atualizado pela última vez a 8 de setembro de 2026
Este documento é mantido apenas em inglês, e é o texto em inglês que se aplica. Traduzi-lo de forma aproximada podia fazê-lo dizer algo falso sobre os seus dados, numa língua que não podemos verificar.
Em resumo
- We collect as little as the site can work with, and this page lists all of it.
- There is no advertising and no tracking cookie. The only cookies we set are the ones that keep you signed in.
- Analytics is four anonymous counts, and it is off until you turn it on. The footer of every page says which it is and changes it in one click.
- You can delete your account and everything in it yourself, from your Passport page, without asking us.
Este resumo não é o documento. Tudo o que vem abaixo é.
Who we are
PlayFootyAnywhere is run by one person from India. There is no company behind it. For anything on this page, including a request about your own data, write to nirajmulani@mailmasker.com and that person will answer.
Being one person is the reason for a lot of what this page says. There is no advertising because there is nothing to sell, the analytics counts four things rather than everything because nobody here has time to read more than that, and the delete control does the deleting itself because a request queue with one person in it is a request queue that waits.
Where the data is, and which law covers it
The database, the file storage and the sign-in system are hosted in the European Union. Nothing here is stored outside it, and none of it is copied anywhere else for us to look at.
The person running the site is in India, which is outside the EU. That does not narrow your rights: this directory is written for people in European cities, so the GDPR applies to it because of who it is for rather than because of where we sit, and the rights set out further down are the ones we work to.
It does change one practical thing. A company inside the EU answers to one national authority; a one-person project outside it does not have one, so if you want to complain about how this was handled, the authority to go to is the one for the country you live in. That is your right directly and you do not have to come to us first.
If you only read the directory
Nothing is stored about you and no cookie is set. You can search cities, open a source and read a public Passport without us keeping a record that you did. That stays true unless you turn analytics on, and it is off until you do.
Our host, Vercel, logs the request the way every web server does — your IP address, the page, your browser. Those logs are theirs, they are used to keep the site up, and we do not build anything on top of them.
If you submit a source or report a listing
Both forms are open to people without an account, so both take an email address and both are rate-limited. Here is exactly what is kept:
- What you typed: the city, the source and how to join it, and any notes. This is the part we may publish, edited, in the directory.
- Your email address, so we can send a receipt and come back to you if the listing needs a detail. On the submission form you choose separately whether we may contact you about anything else.
- A keyed hash of your IP address — not the address itself. It exists so that one person cannot submit two hundred listings, and it cannot be turned back into an address.
Reports work the same way, and the email address on a report is optional. A report is never shown publicly and the person who runs the listing is not told who filed it.
Both forms run a Cloudflare Turnstile check before they will accept anything, which is the one thing on this site that looks at your browser rather than at what you typed.
If you make an account
An account exists to hold a Football Passport. You can have one by email link or by Sign in with Google; either way, your email address is the account.
- Your email address, and — with Google — the name Google returns.
- A handle and display name you choose, a bio and a home city if you fill them in, and an avatar if you upload one. The handle and anything you put in those fields are public if your Passport is public.
- Your Passport: which city you played in, the date, the format, and a note if you wrote one.
- A file you upload as proof of a game, if you upload one. This is the private part — see below.
- Which listings you have confirmed. The count is public; who confirmed is not, and is visible only to you and to a moderator.
Your Passport is public by default and there is a switch on the Passport page to make it private. Private means the page at your handle stops existing for everyone but you, and it leaves the sitemap.
Proof files are the private part
A proof file — a photo, a screenshot of a booking, a PDF — goes into a bucket that is not public. No URL serves it. Even on a public Passport, a proof file is never included: the page shows that a stamp was verified, not what verified it.
When you view your own proof, the site mints a link that expires. Moderators can see a proof file in order to verify a stamp, and that is the only reason anyone else looks at one.
Who else sees it
We run this site on other people's infrastructure, so those companies process data on our behalf. We do not sell anything to anyone, and nobody on this list is paid in data.
| Company | What they do, and what they see |
|---|---|
| Supabase | The database, sign-in, and file storage. Hosted in the EU. Everything the site stores: your account, your Passport, uploaded files, and submitted sources. |
| Vercel | Hosting. Every page and API request passes through them. Request metadata, including your IP address and browser, in their operational logs. |
| Cloudflare | The Turnstile check that keeps the submission and report forms from being used by bots. Your IP address and browser signals, when you use one of those two forms. |
| Resend | Sending the emails this site sends: sign-in links, submission receipts, moderation replies. Your email address and the contents of that email. |
| Google (only if you choose it) | Sign in with Google, if you choose it instead of an email link. Google tells us your email address and name. Google also learns that you signed in here. |
| Sentry | Telling us when the site breaks, so a fault is found by us rather than by you. Hosted in the EU. If a page or request fails: the error message, where in the code it failed, and the address and browser of the request that failed. Not your IP address, cookies, or anything you typed. |
| PostHog (only if you choose it) | Counting four things about how the directory gets used, if you allow it. Hosted in the EU. Only if you allow analytics: that a search happened, that a source page was read, that a join link was followed, or that a Passport stamp was added — with the city and source slugs from the page, which are public. Not your IP address, not what you searched for, and nothing tied to your account. |
Google is on that list only if you use Sign in with Google. Choose the email link instead and Google is never contacted.
How long we keep things
| What | How long |
|---|---|
| Your account, profile and Passport | Until you delete it. Deleting is immediate and it is yours to do. |
| A published listing | Indefinitely — it is the directory. It carries no personal data of yours once it is published, only the source's own public contact details. |
| A submission or a report you sent | Indefinitely, including the email address on it. It is the record of why something in the directory is there, or was removed. Ask us and we will strip the address from it. |
| The keyed hash of an IP address | As long as the submission or report it belongs to. |
| Rate-limit counters | Swept nightly. Nothing older than a day survives. |
| Moderation decisions | Indefinitely. Which moderator acted, on what, and when — the audit trail is the point. |
| An analytics event, if you allowed analytics | 30 days, then PostHog deletes it. It is not tied to your account, so there is nothing in it to look you up by. |
What you can ask for
You can see everything we hold about you, correct it, take it elsewhere, or have it deleted. Two of those do not need us at all:
- Correct it, or take it with you: your Passport page edits everything on it, and exports your Passport as a PDF.
- Delete it: there is a Delete account control on the same page. It removes your profile, every stamp, every proof file, your avatar and the account itself. It is not a request queued for us to action — it happens when you confirm it.
For anything else — a copy of what we hold, an objection, or removing your email address from a submission you sent before you had an account — write to nirajmulani@mailmasker.com. We answer within 30 days and usually much sooner.
One thing deletion does not remove: if you have acted as a moderator, the record of the decisions you made stays, because a moderation log that can be erased by the person who was moderating is not a log. The account is deleted with us and the entries stop naming you.
If we handle this badly, you can complain to the data protection authority for the country you live in — see above for why there is no single one to name.
Age
Accounts are for people aged 16 and over. We do not knowingly keep an account for anyone younger; tell us at nirajmulani@mailmasker.com and it will be removed.
Sixteen because that is the age the GDPR sets for a young person consenting for themselves, unless the country they are in has lowered it. Picking the top of that range means the number is right everywhere this directory is written for, rather than right in some countries and short in others.
Changes to this page
The date at the top is the last time the substance changed. If a change means we start doing something with your data that this page did not describe, we will say so before it starts, not after.