Hockey Trackr Team is a hockey stat-tracking app for coaches, team managers and parents. It is built and run by an independent developer, Matt Lipscomb, in Quebec, Canada. This policy explains what the app records, who can see it, where it goes, and how to get rid of it.
The short version. The app is free. It keeps your teams and games on your device, and a copy on a server so they survive a lost phone and so the rest of your team can follow along. The people you invite to a team can see that team's roster, games and statistics — that is the point of it. Nothing is sold, and nothing is handed to advertising networks. You can delete everything from inside the app.
What the app records
| Data | Where it comes from |
|---|---|
| Team and game data — team and season names, player names and jersey numbers, opponents, arenas, dates, live stats, goals, penalties and your own notes | Typed in by you |
| Team logos — images you upload, or logos generated by the app's AI feature | Chosen or generated by you |
| A display name — usually a first name, so your team can tell who is keeping score | Typed in by you when you join a team |
| Account details — your email address and an account identifier | Google sign-in, or the email address you register with, only if you choose to create an account |
| Usage events — that a game was started, a report generated, an invitation accepted, and which shared link brought someone in | Recorded by the app as you use it |
| AI usage count — how many AI images have been generated for a team, against its allowance | Recorded when you use the AI logo feature |
The app does not ask for your location, contacts, calendar, microphone or camera roll beyond the image you pick for a logo. It does not collect advertising identifiers, and it contains no third-party advertising or tracking software.
Using the app without an account
You can open the app, build a team and track a whole game without signing up for anything. If you arrive by scanning a teammate's QR code, the app may create an anonymous account for you automatically so that your membership and your device's data have somewhere to live. An anonymous account has no email address attached and identifies you to us only by a random identifier and whatever display name you typed.
The trade-off is that it is tied to that browser. Clearing your browser data removes it, and there is no way for anyone — including us — to give it back to you, because there is nothing to prove it was yours. The app will offer to attach a Google account or an email address so it can be recovered. Doing so is optional.
Where it is stored
Everything is written to your device first, so the app works with no signal at a rink. A copy is stored in a database and file store operated by Supabase, so that it survives a lost phone and so that a team's members see the same games. Access rules on the server restrict every row to the account that owns it and to the members of the team it belongs to. The site itself is served by Cloudflare, which keeps short-lived request logs (including IP addresses) as part of running the service.
Sharing with your team
A team is a shared thing, and the app is built around that. What it means in practice:
- Members of a team can see that team's roster, its games, its live scores and its season statistics, including AI-written reports about them. Everyone you invite gets the same view.
- Anyone holding an invitation link or QR code can join the team and get that view. The app has no way to know who they are. Links get forwarded in group chats; treat one as public the moment you send it. A team owner can regenerate the link at any time, which stops the old one working.
- Anyone holding a link to a single game can watch that game and see its summary afterwards, without joining the team and without an account.
- The person keeping score for a game is shown to everyone watching it, by the display name they chose.
There is no approval step and no membership request queue — that is a deliberate choice to make sharing take one scan in a cold arena. It means control is exercised after the fact: a team owner can see the member list, remove people, and regenerate the invitation link. If who can see a roster of children's names matters to you, share the link narrowly and check the member list.
Reports you export or share out of the app — to a messaging app, email or social media — leave this app entirely and are governed by wherever you sent them.
The AI features
Generating a logo, a scouting report, a game recap or a season report sends the relevant information to Google's Gemini API through the app's own server, and sends back what the model produces. What gets sent is the material the report is about: team and opponent names, the game or season statistics, and — where you have recorded them — the names of players who scored, assisted or took a penalty.
These requests run on a paid Google API account, and Google's terms for paid services apply to them: Google does not use the prompts or the responses to improve its products or train its models, and does not put them in front of human reviewers for that purpose. Google logs them for a limited period to detect abuse and to meet legal requirements.
Even so, treat AI reports as sending that information to a third party, because that is what they do. If you would rather not, simply don't use the AI buttons; every other part of the app works without them, and no data is sent to Google unless you press one.
AI output can be wrong or inappropriate. Every AI result in the app has a Report this AI content link, and reports are used to tighten what the app asks for and filters out.
Children's information
This app is for adults — coaches, managers and parents — and is not directed at children. But the data it holds is often about children: youth players' names and jersey numbers, and now visible to everyone on the team rather than to one person.
- Record only what you need. First names or jersey numbers work perfectly well; full names are never required by the app.
- If you are recording other people's children, make sure that is consistent with your club's or association's rules on player information and parental consent. Adding a child to a roster that a whole team can see is a decision for whoever is responsible for that child.
- Under Quebec law, personal information about a minor under 14 generally requires the consent of a person with parental authority. If you are a coach or manager entering players, you are the one in a position to obtain it.
Advertising and sponsors
There are no advertising networks in this app, and there will not be — the app's own security policy blocks third-party scripts from running on the page at all. Nothing about you is used to target anything, no advertising identifier is collected, and no profile is built.
The app is free to run for you because a sponsor or partner may pay for it. That can mean a sponsor's name, logo or message appearing in the app, and a link to their site. It is the same message for everyone who sees it. A sponsor receives no personal information, and cannot see who viewed or tapped anything beyond a plain count.
Usage measurement
Understanding how the app is actually used is what makes it possible to improve it — and it is measured with the app's own database rather than by embedding somebody else's tracker. Events recorded look like a game was started, a season report was generated, an invitation link was scanned — an action, a timestamp, and the account or team it belongs to. Player names, rosters, scores, notes and the contents of reports are not part of them.
The public marketing pages use Cloudflare Web Analytics, which counts page views without cookies and without building a profile of visitors across sites.
Who else sees it
Your data is not sold or rented, and it is not shared for advertising. Beyond the people on your own team, it is shared only with the services needed to run the app:
- Supabase — the database and file storage behind your account, and sign-in if you use an email address and password.
- Google — sign-in if you use it, and the Gemini API for the AI features.
- Cloudflare — hosting and delivery of the app itself.
Data may also be disclosed if the law requires it. That has never happened, and this sentence will be removed if the app ever stops being able to say so.
If this app is sold
This app is a one-person project, and the realistic futures for it include being bought by, merged into, or licensed to a larger organisation — a hockey brand, a retailer, or a governing body — so that it can keep being developed and supported.
If that happens, the information described in this policy would be transferred to that organisation along with the app itself, because an app whose data stayed behind would not be a working app: your teams and your season would not come with you. The same would apply in a merger, a reorganisation, or a sale of the app's assets, and during the checks a buyer carries out before such a deal.
Three commitments go with that:
- You will be told, in the app and on this page, before a transfer takes effect — not afterwards.
- The acquirer will be required to handle the transferred information under this policy, or one at least as protective, until you are given notice of a change and a chance to delete your data instead.
- Deleting your account before a transfer means there is nothing to transfer. The deletion route in the next section stays available throughout.
Information is not sold to data brokers, advertisers or list buyers under this section or any other. A transfer of the whole app to an operator who will run it is a different thing from selling data about you, and only the first is contemplated here.
Where your data is handled
The app is operated from Quebec, Canada. The services it relies on — Supabase, Google and Cloudflare — are operated by companies based in the United States and store or process data outside Quebec, including in the United States and other countries. Those countries' privacy laws differ from Canadian and Quebec law, and information held there can in principle be reached by their courts and authorities. Each of these providers is bound by contractual data-protection terms, and each is used because it is a standard, audited service rather than an improvised one.
How long it is kept
Your data stays until you remove it. Deleting a team or game removes it from your device and, on the next sync, from the server — and from your teammates' copies. Deleting your account removes the whole account immediately: teams you own, games, logos, display name and AI allowance included. Nothing is retained in a hidden archive.
Two things survive, and they should be said plainly. Usage events are kept in a form that is no longer linked to you. And a game you recorded for a team someone else owns remains part of that team's history, as a scoresheet does — leaving a team does not erase the games that were played.
Your rights
Under Quebec's Law 25 and Canada's federal privacy law you can ask to see the personal information held about you, have it corrected, have it deleted, and receive it in a portable computerised format. You can also withdraw consent, which in practice means deleting your account.
Most of this is faster to do yourself than to ask for: the app has a Backup Data button that exports everything it holds, editing screens for every record, and one-tap account deletion. For anything the app cannot do, write to the address below and expect an answer from a person within 30 days. If you are not satisfied, you may complain to the Commission d'accès à l'information du Québec or to the Office of the Privacy Commissioner of Canada.
Deleting your data
Inside the app: scroll to the Account section on the main screen and choose Delete Account. It takes effect straight away and does not require emailing anyone.
Without the app installed, or if you would rather ask: see the account deletion page.
Deleting your account clears the server copy. The copy on a device you still have is removed by signing out, clearing the app's storage, or uninstalling the app.
Security
Traffic is encrypted in transit. Sign-in is handled by Google, or by Supabase if you register with an email address — either way the app itself never stores your password, and a password you set is held only as a one-way hash that cannot be read back. Server-side access rules restrict every row and every stored file to the account that created it and the team it belongs to. No system is perfect, and this one is run by one person, so the honest position is that it is built carefully rather than certified.
Changes
If this policy changes, the date at the top changes with it. Material changes — anything that widens who can see your information, or a transfer of the app to a new operator — will be announced in the app before they take effect.
Contact
Hockey Trackr Team is developed and operated by Matt Lipscomb, who is also the person responsible for the protection of personal information for the purposes of Quebec's Law 25. Questions, requests, or a privacy problem to report: [email protected] — the same address as the app's support contact, answered by a person rather than a queue.