Skip to main content
MatchFlow

MATCHFLOW PRIVACY POLICY

Published in good faith — not yet professionally reviewed. MatchFlow will revise this policy following professional legal review; material changes are notified per the policy.

Effective date: July 17, 2026 · Controller/Business: MatchFlow (operated by Zack Ballantine) · Contact: zack@zballantine.com

The short version: we collect what a tennis club needs to run — your profile, skill rating, availability, bookings, matches, and messages. We use it to operate the club you belong to, including proposing fair match pairings. We don't sell your information or use it for cross-context behavioral advertising. You can see it, export it, correct it, or delete it from your account settings.

1. Who does what

For most processing, your club decides how member data is used and MatchFlow processes it on the club's behalf (we are the club's "service provider"/"processor") — or your coach, if you train with an independent coach: your coach decides how your data is used within their coaching business, and MatchFlow processes it on their behalf, the same as for a club. For account registration, security, and service improvement, MatchFlow acts as a business/controller. EU/UK members: the DPA between MatchFlow and your club (or independent coach) governs processor duties.

2. What we collect

  • Identity & contact: name, email, phone, club membership status.
  • Booking guests: if you or club staff add a non-member guest to a booking, we collect that guest's name and, optionally, email/phone — used only to run that specific match (roster, capacity, and reaching them if needed). See Section 13a.
  • Player profile: skill rating(s) (e.g., NTRP — self-reported or entered by club staff), a movement/mobility rating entered by you or club staff, age/gender where provided (used for match balance and formats like mixed doubles), format preferences, availability, seasonal presence, and optional home country/state. If you sign up directly through the Service (rather than being registered by club staff), we collect your date of birth at signup — used only to verify you're old enough to hold an adult account; see Section 12 for what happens if you're under 18.
  • Play data: bookings, queue requests, match participation and results, waitlist and recruitment responses, event registrations, and, if you're on an interclub team, your team roster, lineup and match results, and your own availability status for upcoming matches (available/unavailable/maybe) with any optional note you choose to add.
  • Communications: messages you exchange with the club through the Service (SMS and in-app chat), messages you exchange with your club's coaches through the Service, notification preferences, and delivery logs.
  • Notes and flags: club staff may record notes about members (e.g., scheduling preferences, injury mentions); the Service may extract structured indicators from those notes to improve match pairing. If you work with a coach, this also includes your coaching goals, assigned practice homework, and the progress notes your coach records. See Section 4 (inferences) and Section 8 (sensitive information).
  • Payments: handled by Stripe; we receive transaction metadata (amount, status) but never your card number. If you're a junior athlete with a confirmed guardian, you cannot attach a payment method or complete a payment yourself — your guardian completes lesson payments on your behalf, and the payment flows through their account, not yours (Section 12). Independent coaches who subscribe to Coach Pro (a paid tier unlocking additional coaching tools) are billed directly by MatchFlow through the same Stripe processor MatchFlow itself uses; that subscription billing relationship is between the coach and MatchFlow and is separate from — and never mixed with — the payments MatchFlow processes on the coach's behalf for their own students' lessons.
  • Technical: log data, device/browser type, and security events. We use only essential cookies (session/authentication); no advertising cookies. If you install MatchFlow to your device and turn on push notifications, we store a device push token (a subscription identifier issued by your browser, not readable by us as a location or ad identifier) so we can deliver notifications to that device; it's deleted when you turn notifications off or the browser reports the subscription is no longer valid. Push notifications are opt-in — a token exists only after you grant your browser's notification permission.

3. Where it comes from

You; your club's staff; your play activity in the Service; and payment confirmation from Stripe. If your club imports existing records (e.g., from a previous system or its website), the club is responsible for having collected them lawfully.

4. How we use it — including matchmaking inferences

We use personal information to: operate bookings, events, and programs; propose match pairings using skill rating, mobility, age, gender balance for mixed formats, variety of recent partners, preferences, and staff-note indicators; send service communications; process payments via Stripe; provide club analytics and weekly summaries; secure and improve the Service; and comply with law. Inferences: the Service computes internal indicators from your play (for example, pairing-compatibility scores and performance-based skill estimates) to keep matches fair. Where such inferences are stored in your record, they are included in your data export. Automated pairing suggestions are reviewed and approved by club staff and do not produce legal or similarly significant effects; you may decline any proposed match. AI processing: certain features use AI models from Anthropic to classify message intent, draft message text (verified against booking facts before sending), analyze staff notes into structured pairing indicators, and summarize club activity. For clubs using coaching features, an AI "lesson prep" summary may be generated for your coach ahead of a lesson, summarizing your recent coaching notes, messages, and goal progress; it is always shown alongside the underlying notes it summarized. AI inputs are not used by us or, under our agreements, by Anthropic to train foundation models.

5. Legal bases (EU/UK members)

Performance of contract (running your membership and bookings); legitimate interests (service security, improvement, fair matchmaking operated for your club, and your club's oversight of coach communications — operating its coaching programs, member safety and safeguarding, and preventing circumvention of club policies); consent (optional SMS recruitment messages; any future marketing); legal obligation (records, tax). Where the club is controller, the club determines the basis; ask your club for its notice.

Where your club has enabled the coach-messaging consent setting (EU/UK clubs by default), your explicit consent — recorded when you enable coach messaging — is the basis for handling any health-related information you choose to include in those conversations. You can withdraw that consent at any time in your settings; withdrawing turns coach messaging off for your account (Section 14).

6. Sharing

We share personal information only with: subprocessors that host and operate the Service (see the subprocessor list — including Supabase (database), Vercel (hosting), Stripe (payments), Twilio (SMS), Resend (email), Anthropic (AI processing), Sentry (error monitoring), Upstash (rate limiting), Inngest (background jobs), and, if you turn on push notifications, your browser's own push relay (Apple, Google, or Mozilla, depending on your browser/device) — the same infrastructure your browser already uses to deliver push notifications for any installed app or site, not a service MatchFlow chooses); your club (staff see member profiles, ratings, notes they create, and play data needed to run the club; for clubs using coaching features, club owners and administrators can also view coach↔member conversations as described in Section 14); other members, limited to what club play requires (e.g., your name and match schedule on a match card — never your contact details, ratings history, or notes; the one exception is interclub teams: if you're on an interclub team, your own declared availability status and any optional note you add for a specific match are visible to that team's leader — a fellow member, not club staff — so they can plan the lineup; club staff can also see it); your friends, if you've turned on friend activity visibility (Section 14c) — never before you've explicitly opted in, and never with a member under 18 in either direction; and authorities where legally required. We do not sell personal information and do not share it for cross-context behavioral advertising, and we have not done so in the preceding 12 months.

7. Your rights

Depending on your location (California CCPA/CPRA; EU/UK GDPR; and similar laws), you may have rights to know/access, export (portability), correct, delete, and limit certain processing, without discrimination for exercising them.

  • Self-service: account settings include Export my data (machine-readable JSON) and Delete my account; corrections can be made in your profile or by your club.
  • By request: zack@zballantine.com. We verify requests via your account email. Authorized agents may submit requests with proof of authorization. We respond within the legally required period (45 days CCPA, extendable; 30 days GDPR).
  • Exports include the personal information and stored inferences in your record, your coach conversations, your consent records, your booking-availability status, a summary of staff access to your coach conversations (staff role and date), and — if you're on an interclub team — your team membership(s), the interclub matches you participated in, your own declared availability (including any note), and your own match-line results. They exclude other members' information (e.g., the identity of members involved in pairing-preference records, or a doubles partner's identity on an interclub match line — neither their name nor an internal reference to their record), internal staff/system identifiers not meaningful to you (e.g., which internal record made a booking, or is assigned to a conversation), our security logs, and MatchFlow's proprietary algorithms, weights, and business information (protected as trade secrets under applicable law).
  • California members: we do not "sell" or "share" personal information, so there is no opt-out to exercise; you may still submit rights requests above. EU/UK members may also lodge complaints with a supervisory authority. Where your club is the controller, we will route your request to the club or assist it in responding.

8. Sensitive information

We do not seek sensitive personal information. Staff notes may occasionally reference injuries for scheduling safety; where the Service derives an injury-related indicator, it is used solely to avoid unsuitable match assignments and to alert club staff, is not used for any other purpose, and is minimized. We do not collect government IDs, precise geolocation, or biometric data.

Coach conversations may occasionally mention injuries or health conditions because that is how players naturally talk to coaches. We do not ask for this information, do not extract or analyze it from coach conversations, and staff access to those conversations exists to run the club — not to collect health information. Where required (EU/UK clubs), we obtain your explicit consent before you use coach messaging (Section 14).

9. Retention

Account and play data are retained while your membership is active and deleted or de-identified within 90 days of verified account deletion, except records we must keep (e.g., payment records, security logs) and de-identified/aggregate data. Clubs may retain their own exports.

10. Security

Access controls with role-based permissions and club-scoped isolation; encryption in transit; row-level security at the database; rate limiting; audit logging of administrative actions. No system is perfectly secure; we will notify affected clubs/members of breaches as required by law.

11. International transfers

Data is hosted in the United States. For EU/UK members, transfers rely on Standard Contractual Clauses with our subprocessors as described in the DPA.

12. Children

The Service is not directed to children under 13, and we do not knowingly collect their data without appropriate consent. Junior club members under 18 may be registered by their club, offline, with parent/guardian consent obtained by the club.

Junior athletes who self-register directly through the Service — whether joining a club or an independent coach — work differently: signup collects a date of birth, and anyone who comes back under 18 requires a parent/guardian. The junior's account is created inactive — it cannot log in and cannot be messaged — until a guardian confirms. That confirmation is also where we record the junior's required agreements to the Beta Tester Agreement, Terms of Service, and this Privacy Policy, on the junior's behalf. Once confirmed, every message thread between the junior and their coach automatically includes the guardian — the guardian sees every message and can reply, structurally, not just as a setting that can be turned off (see Section 14's independent-coach carve-out). A junior may have more than one confirmed guardian. When the junior turns 18, they're asked to confirm their own agreement to these terms; once they do, every former guardian's access to their coach conversations ends automatically and their account works like any other adult's. Past messages are kept — nothing is deleted — but a former guardian can no longer view or send new ones.

Payments for a junior's lessons follow the same guardian relationship: a junior with a confirmed guardian can never attach a payment method or complete a payment themselves, on any lesson-payment screen — this is enforced structurally, not just hidden in the interface. Their guardian completes the payment instead, from the same guardian view described above, and the payment record (amount, status, and processor transaction data — see Section 2) is tied to the guardian's account as the paying party. This restriction, like the messaging inclusion above, ends automatically at 18.

13. Restringing / pro shop service (walk-in customers)

Clubs offering racket restringing may take in rackets from non-member walk-in customers as well as members. For a walk-in customer we collect only name and phone number — nothing else (no email, no address, no account, no login). This information is used solely to create and track the restring service record (racket, string, tension, price, status, and pickup) so staff can identify whose racket is whose and reach the customer about the job. Walk-in customer records are staff-only — they are never shown to members and never appear in the member-facing string catalog page, which lists only the club's available strings (brand, model, gauge, type, price) and contains no customer or job information. Walk-in records are retained for as long as the club's service records generally are (see Section 9) and are deleted or de-identified on the same schedule. Member restring jobs are linked to the member's existing profile rather than a separate walk-in record, and are handled like the rest of your play data under this policy.

13a. Booking guests

If you invite a non-member guest to a match, or club staff add one for you, we collect that guest's name and, optionally, an email and/or phone number — nothing else. This is a separate data category from the walk-in pro-shop customers in Section 13: a booking guest is tied to a specific match, not a service record. Their name is visible to the other players on that booking (the same way any player's name appears on a shared match card, Section 6) so everyone knows who they're playing; their email and phone are never shown to other members and are visible only to club staff, used solely to run that booking (roster, capacity limits, and reaching the guest if needed). Guest records are retained on the same schedule as the play data of the booking they're tied to (Section 9).

13b. Guest registration for events (book-on-behalf)

If you register a non-member guest for a club event — for example, bringing a guest to a social event your club allows guests at — we collect the same information as a booking guest above: name and, optionally, email and/or phone. No account is created for a guest, ever. A guest's name is visible to the event's staff and organizer, the same way any registrant's name is; their email and phone are visible only to club staff. A guest is never shown in another member's friends list, friend activity, or play-with-history (Section 14c) — those features only ever involve accounts, and a guest has none.

14. Coach conversations and staff oversight

Messaging between you and your club's coaches happens on a club-operated channel — it is not a private direct message. Your club's owners and administrators can view these conversations to support your coaching, coordinate bookings and programs, keep members (including juniors) safe, and ensure club policies are followed. Front-desk staff do not see message content; where useful for scheduling, they see only a booking-availability status (for example, "limited"), which is set by your coach or an administrator and never includes medical detail.

You will always see this stated in the conversation itself — every coach conversation carries a notice that club staff can view it, for both you and the coach.

Every staff view is logged. A summary of staff access to your conversations (role and date) is included when you export your data, along with the messages themselves and your consent records.

EU/UK clubs: you'll be asked to acknowledge and consent before first using coach messaging. If you decline — or later withdraw consent in your settings — coach messaging is simply unavailable for your account, and you can coordinate with your coach at the club instead. Messages sent before a withdrawal are retained under Section 9 and remain subject to the same staff visibility.

If you object to staff oversight of your coach conversations, contact zack@zballantine.com or your club. We (or your club, as controller) will review your objection; because this oversight also serves fraud-prevention and member-safety purposes, it may be maintained even after an objection, and you will receive a response either way. EU/UK members may also lodge a complaint with a supervisory authority.

Independent coaches: if you train with an independent coach rather than a club, there is no additional club staff — your coach is the only party you message with, and this section's staff-oversight provisions do not apply because there is no staff besides your coach to oversee it. The one exception is junior athletes: if you're under 18, your confirmed parent/guardian is an additional party to every conversation with your coach, by design — see Section 12. This is a structural safeguard specific to independent coaches (who have no other staff to provide it), not the club-staff oversight described earlier in this section, and it applies everywhere, not only in the EU/UK.

14a. Trust & safety reports, MatchFlow operator access, and suspension (independent coaches)

Because an independent coach has no club staff to provide oversight (Section 14), MatchFlow itself provides a safety backstop for independent-coach conversations specifically.

Reporting. If you train with an independent coach, you (or your confirmed guardian, if you're a linked junior athlete) can report a specific message, a conversation, or the coach's profile directly from the Service — for a safety concern, harassment, a payment issue, impersonation, or another reason you specify. A report includes the reason you selected, any details you add, and a reference to the conversation or message if you reported one.

MatchFlow operator access. Filing a report gives a small number of MatchFlow operators (not club staff — MatchFlow's own team) access to the reported conversation so we can review it. This access is separate from, and narrower than, the club-staff oversight described in Section 14: operators only see what's needed to review a specific report, and every operator view of a reported conversation is logged (who viewed it and when), the same way club-staff access is logged for club conversations.

Suspension. If review of a report finds a safety or policy concern, MatchFlow may suspend an independent coach's account. Suspension halts that coach's portal access, conversations, payments, and new bookings for that specific coaching business — it does not delete any data, and past conversations remain available to their participants' data exports. If the same person also has a separate, unrelated account (for example, as a member or staff at a different club), that separate account and its own data are not affected by a coaching-business suspension.

Credentials. An independent coach's listed certifications are self-reported by the coach — MatchFlow does not verify them. This is disclosed directly on the coach's profile, next to the listed certifications.

14b. Messaging between members

Members can choose to message each other directly — and, where the club offers it, in a group thread tied to a program, event, or booking — entirely separate from the coach conversations described in Section 14.

What we collect. Direct messages between you and another member, and any group-thread messages sent through the same messaging system; a connection record of who you're connected to and how (for example, that you've played together, or that a connection came from an accepted introduction); your block list (members you've chosen not to hear from); and introduction requests you send or receive, including any note attached.

Opt-in, tiered, off by default. Messaging another member requires you to choose a visibility tier in your settings — message from anyone in the club, only members you've played with, or off. The default is off: no member can message you, and you do not appear in another member's "message" affordance, until you explicitly choose a tier. You can change your tier at any time in your settings, and the change takes effect immediately.

Staff oversight, disclosed. Like coach conversations (Section 14), member-to-member messaging happens on a club-operated channel — it is not a private direct message. Your club's owners and administrators can review these conversations to keep the community safe and to enforce club policies. You will always see this stated in the conversation itself — every member thread carries a notice that club staff can view it, shown to every participant. Every staff view is logged, and a summary of staff access to your member conversations (role and date) is included when you export your data, the same as for coach conversations.

Adults only. Accounts for members under 18 can never participate in member-to-member messaging, in any circumstance — they cannot send or receive messages, appear in another member's "message" affordance, or be the target of an introduction request. Where club life would otherwise involve a junior in member messaging on their household's behalf (for example, a booking huddle), their confirmed guardian participates instead, from the guardian's own account.

Program and event group chats. Where your club runs a group chat tied to a season program or a one-off event, it works differently from the direct messaging described above: no visibility tier or opt-in applies. These are club-program communications, not private messaging between individuals — if you're actively registered for the program or confirmed for the event, you (or your confirmed guardian, on your behalf, per the next paragraph) are in the thread. You can mute a specific thread from your own settings at any time, but you can't opt out of appearing in it while you're an active registrant, the same way you can't opt out of a club email about a program you're enrolled in. The same club-staff oversight described above applies — every group thread carries the same visible notice, and staff views are logged and exportable the same way. Messages in a group thread are visible to your fellow current registrants for that program or event, to the assigned coach or event organizer, and to club staff — never to the whole club.

Guardians stand in for their junior athletes, one seat per family. If a junior athlete is registered for a program or confirmed for an event with a group chat, the junior is never a participant — instead, each of their confirmed, currently-linked guardians gets a seat in the thread, in the guardian's own name, so a junior's messaging exclusion (above) applies in group chats exactly as it does everywhere else. A guardian with more than one child in the same program or event still gets a single seat, covering all of them; the thread makes clear which junior(s) a guardian's seat covers. A guardian who is also an active adult registrant in their own right keeps their own seat and doesn't get a second one. A guardian's seat becomes read-only once none of their linked juniors remain actively registered for that program or event; the thread's history stays visible to them, the same as for any other participant whose active involvement has ended.

Archived threads stay readable. A program thread is marked read-only once the program ends; an event thread is marked read-only roughly 48 hours after the event. In both cases the thread stops accepting new messages, but its history remains visible to everyone who participated, under the same retention schedule (Section 9) as any other message.

Looking-to-play preference. You can optionally set a "looking to play" preference in your settings — your preferred formats (singles, doubles, or either), preferred times, and a short note. Setting it is entirely up to you, and it's included in your data export the same as your other messaging settings. It is shown only to members who pass your messaging visibility tier above — the same audience who can already message you, no one broader. Like member-to-member messaging itself, only adult accounts can set this preference.

Blocks and introduction requests are personal data. Your block list is included in your data export, the same as your messages and connection records. Introduction requests you've sent are included in full, every status, with any note you attached. Introduction requests you've received are included only once accepted — you're only ever notified about an introduction once it's accepted, so a pending or declined request made to you isn't something you already know about, and it's left out of your export; accepted received requests don't include the sender's note.

Retention. Member-messaging data is retained on the same schedule as the rest of your account and play data — see Section 9.

Account deletion. When you delete your account, your own messages are removed and replaced with a neutral placeholder (for example, "[removed — account deleted]") in the threads of any other participants; the thread itself and other participants' own messages are unaffected. Your connection records, block list, and introduction requests are handled as part of account deletion under Section 9.

14c. Friends, activity visibility, and play-with history

Separately from messaging (Section 14b), members can send and accept friend requests, and choose whether to let their friends see when they're playing.

Friend requests require both people to agree. Sending a request creates a pending request; nothing changes until the other person accepts it. You're not shown as someone's friend, and you don't appear in their friend activity, until you've both agreed. You can decline a request you received or cancel one you sent, and either of you can end an existing friendship (unfriending removes it for both of you) at any time.

Friend activity visibility is opt-in and off by default. You control whether friends can see when you're playing through one master toggle plus three separate toggles for court bookings, programs, and events. The master toggle must be on, and the specific toggle for that kind of activity, before any of your activity is shown to a friend — turning the master toggle off hides everything regardless of the individual toggles. Nothing is shared with anyone until you turn this on yourself, and you can turn it off again at any time in your settings.

Play-with history. The Service can show how many times you and another member have played together (direct matches, drop-in "live ball" sessions, programs, and events all count) and, if you're mutual friends, the date you last played together. A bare count — with no name and no date — may be shown even between members who aren't friends, since it doesn't reveal anything beyond what a shared match roster already would; the name and date are shown only between mutual friends.

Adults only, the same as messaging. Accounts for members under 18 cannot send or receive friend requests, cannot appear in another member's friend activity or court-sheet display, and are excluded from play-with history — regardless of any setting, on either side of the pair. This is enforced the same way member-to-member messaging is (Section 14b).

Book-on-behalf. A member can register a friend, or a non-member guest (Section 13b), for an event on their behalf. Registering a friend requires their confirmation before it's final: an unconfirmed invite is held for up to 24 hours or until the event starts, whichever comes first, and then releases automatically if the friend hasn't responded. When confirming, the friend pays by default, unless the person who invited them chooses to cover the cost themselves. A member can grant a friend standing permission to register them without asking each time — this is always per-friend, always something you can revoke in your settings, and never applies to anything with a cost: a paid registration always requires your explicit confirmation, even with standing permission in place.

Account deletion. Deleting your account removes your friendships (both directions), any pending friend requests, and any standing permissions you granted or received. See Section 9.

15. Changes

We will post changes here and notify you of material changes (email or in-app) before they take effect. The effective date above always reflects the current version.