Last updated: August 16, 2026
The short version. We collect what's needed to run your events and your account. We don't sell your data, we don't show ads, and we don't run advertising trackers.
No advertising, no ad or analytics trackers, no selling or renting personal information, and no marketing email you didn't ask for.
To operate the Service; to sign you in; to send transactional email (password resets, organizer invitations); to apply plan limits and process subscriptions; to keep the Service secure; and to answer support requests.
Only providers that process data on our behalf:
| Provider | Purpose | What it receives |
|---|---|---|
| Vercel | Hosting | Requests and server logs |
| Neon | Database | Stored application data |
| Resend | Transactional email | Recipient address and message |
| Anthropic | AI assistant, roster import | Your questions and any document you import |
| Optional sign-in | Authentication data only | |
| Stripe | Payments (when enabled) | Billing details — card data goes to Stripe directly, we never see it |
Under Anthropic's commercial terms, content we send to their API is not used to train their models, and is deleted within 30 days — except where their automated safety systems flag it as violating their usage policy, in which case they may keep it longer.
We may also disclose information if legally required, or to protect the Service's or someone's safety.
An active share link, public league page, or TV display makes that event's participant names, scores, and standings visible to anyone with the link. An event's share link is on by default and can be turned off per event at any time — while it is off, the public page shows nothing. Public league pages and TV displays are off until you enable them. All of it is reversible.
The export file is generated and downloaded in your browser. We don't transmit it to DUPR — you upload it yourself.
We keep account and event data while your account is active. When you delete your account we remove your personal data within 30 days, except anything we must retain for legal, tax, or fraud-prevention reasons. Backups age out on their own cycle, within 30 days.
View and correct your name and email on your account page, change or set a password there, and connect or disconnect a sign-in provider. To delete your account, contact PickleFlow support at support@pickleflow.live and we'll process the request.
Wherever you live, you can ask us to access, correct, delete, or export your data at support@pickleflow.live; we respond within 30 days. If you're in the EEA or UK you may also complain to your local data protection authority. We do not sell or share personal information as those terms are defined by the CCPA.
Roster members aren't PickleFlow users and don't have accounts. The organizer who added you controls that record; we store it on the club's behalf. To have it corrected or removed, contact your club organizer, or email us and we'll pass the request on.
PickleFlow isn't intended for children under 13 and we don't knowingly collect their personal information. Organizers must not add under-13 players' email addresses or DUPR IDs to a roster. If we learn we've collected such information, we'll delete it.
Traffic is encrypted with HTTPS, passwords are stored as bcrypt hashes, club data is access-scoped by organizer role, and our database provider encrypts data at rest. No system is perfectly secure, so please use a strong, unique password.
In the United States.
Only a first-party session cookie to keep you signed in, plus a short-lived CSRF cookie during sign-in. No advertising or analytics cookies — so there's no cookie banner to click.
We'll post updates here with a new “Last updated” date, and give in-app or email notice for material changes.