Last updated: 27th August 2026
Playr ("we", "us", "our") helps people find others to play sport with, one-to-one or as part of a team or group. This policy explains what information we collect, why, and what choices you have. Playr is intended for adults aged 18 and over only. This policy covers both the Playr app (at app.playrmatch.net and in the iOS and Android apps) and our marketing website at playrmatch.net.
Playr is operated by PlayrMatch LTD. Our registered office is 124-128 City Road, London EC1V 2NX, United Kingdom. You can contact us about privacy questions at playrmatch@gmail.com.
Some of this is required to use Playr at all - you can't create an account without an email address and date of birth, for example, and you won't be findable by other users or able to send match requests until phone and age verification are complete. Where information is optional, like your bio or a profile photo, we say so below.
Your bio and profile are visible to other users, so please don't include anything there you wouldn't want shared publicly - for example details about your health, sexual orientation, religion, or ethnicity. We don't ask for information like this and don't want you to feel you need to include it. If you choose to share something like this in a free-text field such as your bio, that's your choice, not something we've requested or rely on for any feature.
For age verification, we use a third-party provider, Didit, to estimate your age from your device's camera. If the estimate is close to the 18-year threshold, Didit may additionally ask for an identity document to confirm your age. This imagery is processed by Didit on our behalf; we receive and store only the verification result (passed, failed, or pending) and a session reference - we do not receive or store the images themselves.
Didit retains the underlying photo/document data for a maximum of 30 days under our configuration with them. In most cases it is deleted sooner than that: once your verification reaches a final result (passed or failed), we automatically instruct Didit to delete that session's data immediately, rather than waiting out the full 30 days.
Profile photos, and the extra gallery photos available with permanent Premium, are automatically reviewed by OpenAI's moderation service before becoming visible to other users, to check for content that violates our community standards. The photo URL is sent to OpenAI for this purpose; the moderation result (approved or rejected) is stored against the photo.
Several screens show an interactive map from Mapbox: dropping a pin on an event location, drawing a running or cycling route, and viewing a saved route. Using these sends Mapbox the map area you are viewing and, depending on what you are doing, the coordinates you tap or drag - to draw the map, turn a dropped pin into a place name, snap a drawn route to nearby paths and roads, and find things like cafes and public toilets near a route. Mapbox processes this to provide the mapping service, under its own terms. We do not send it your name or profile. We also keep our own count of how many Mapbox requests the app makes, for billing and capacity monitoring; that count is not tied to individual users.
For outdoor sports, accounts with Premium can see a weather forecast for an event, generated from its location and start time. Looking this up sends the event's coordinates to Mapbox (to turn a dropped pin into a place name, or a searched place name into coordinates) and to the Met Office (to fetch the forecast itself). We cache the forecast against the event rather than looking it up on every view.
Messages in one-to-one and team chats are checked against OpenAI's moderation service in automated sweeps that run on a schedule - not the moment you send a message, and not read by a person unless something is flagged. Both the wider conversation and each individual message are checked.
If a message is flagged, we store a record of it - the message text, who sent it, who received it, and the categories it was flagged under - separately from the chat, so it stays usable for safety review even if the chat or message is later deleted. Depending on the category:
If you keep getting prompts about someone you know and trust, you can choose "Trust this person" to stop being prompted about their messages. We store this as a list of the people you have chosen to trust. It only changes whether you see the prompts - it does not switch off moderation, and the most serious categories are still escalated regardless.
You can give another player a 1-5 star rating after you've actually matched or played with them, once per person. Individual ratings are private - only visible to the person who gave them, never to the person rated or to anyone else - but an average rating and the number of ratings received are shown on the rated person's profile to other users.
We don't use advertising or analytics cookies, and we don't run any third-party analytics or tracking scripts. The app keeps you signed in using your browser or device's local storage, not cookies - this is strictly necessary for the app to work and isn't used to track you across other websites or apps. Our marketing website at playrmatch.net works the same way: it sets no cookies and runs no analytics, tracking scripts, third-party fonts, or embeds.
If you enable notifications, we send pushes for things like new players signing up near you, match requests, and new direct or team messages. On the web these are delivered directly by your browser; on Android they're delivered via Google's Firebase Cloud Messaging, which receives only a device token - not your profile, messages, or any other content - to route the notification to your device. Native push on iOS isn't available yet; when it is, we'll update this policy to reflect Apple's role in delivering it. You can turn notifications on or off at any time from Settings in the app.
Where we rely on your consent - currently, the camera-based age-estimate step and push notifications - you can withdraw it at any time (by contacting us, or, for notifications, from Settings in the app). This won't affect anything we did while consent was in place, but may mean you can no longer use parts of Playr that depend on it.
We may also use aggregated or de-identified data - information that no longer identifies you - to understand how Playr is used and to improve it.
Search and match results are generated automatically from explicit filters - yours and other users' - covering sport, skill level, distance, age range, and gender. This isn't behavioural profiling: we don't build a hidden model of your preferences or infer characteristics about you to decide who to show you. Results are everyone nearby who matches the criteria set, ordered by distance and, for Premium accounts, priority placement.
We use the following third-party services to operate Playr. Each processes only the data necessary for its function:
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, file storage, realtime sync | All account and profile data |
| Vercel | Application hosting | Technical/usage data |
| Didit | Age verification | Camera image / ID document, processed by Didit and deleted on our instruction once verification completes (max 30 days); we retain only the result |
| OpenAI | Automated moderation of profile photos and chat messages | Profile photo URL; message text, checked in scheduled sweeps rather than in real time |
| Twilio | Sending phone verification codes | Phone number |
| Resend | Account and password-reset emails | Email address |
| Google (Sign-In) | Optional sign-in method, as an alternative to email/password | Name, email address, and profile picture, only if you choose to sign in with Google |
| Google (Firebase Cloud Messaging) | Delivering push notifications on Android | Device push token only - not your profile, messages, or other content |
| RevenueCat | Managing Premium subscription purchases, in front of Apple's and Google's app store billing | Purchase and subscription status; no card details, which stay with Apple/Google |
| Mapbox | Interactive maps, event-location geocoding, route path-snapping, nearby-place lookups | Map view area; coordinates of pins and route points you place; place search text |
| Met Office | Weather forecasts for outdoor events (Premium) | Event location coordinates and start time |
We do not sell your personal information. We do not share your data with advertisers.
Other Playr users can see your name, age, area (not precise location), bio, sports, photo (once approved), and rating (if you've received one), plus a "Premium" badge if you currently have active Premium. They cannot see your email, phone number, exact GPS coordinates, or why you have Premium or when it expires.
Some of the providers above (including OpenAI, Didit, Google, RevenueCat, Mapbox, and the Met Office) may process data outside the UK/EEA. Where this happens, we rely on the provider's own data protection safeguards, such as standard contractual clauses.
We keep your account and profile data for as long as your account is active. If you delete your account, your profile, messages, team memberships, and profile-view records are removed, other than data we're required to retain for legal or safety reasons (for example, records relating to blocked users or reported content).
Reports, blocked-user records, and flagged-message records are kept for as long as needed for safety, moderation, and legal purposes, which can mean they outlive the deletion of the account(s) involved.
If your account has (or has had) Premium, we also keep a one-way cryptographic hash of your verified phone number after deletion - never the phone number itself, and not linked to any other data we hold about you. Its only purpose is so that deleting and re-creating an account can't be used to claim a second free trial, and so you don't lose paid Premium, or have to pay for it again, if you ever delete and rejoin under the same number.
Age verification imagery held by Didit is deleted automatically once your verification result is final (typically within moments), and in any case no later than 30 days. We retain only the outcome (passed, failed, or pending) and a session reference indefinitely as part of your account record.
Depending on where you live, you may have the right to:
You can also delete your account from playrmatch.net without signing in, by confirming a one-time code sent to your registered email. That email address is used only to send the code and identify the account to delete.
To exercise any of these, contact us at playrmatch@gmail.com. UK users also have the right to complain to the Information Commissioner's Office (ICO).
Playr is strictly for users aged 18 and over. We do not knowingly collect data from anyone under 18. If age verification indicates a user is under 18, their account will not be permitted to continue onboarding.
We use industry-standard measures to protect your data, including encrypted connections (HTTPS) and database-level access controls that restrict who can read or edit your data. No method of transmission or storage is 100% secure, and we can't guarantee absolute security. If a breach occurs that's likely to put your rights or freedoms at risk, we'll notify affected users and the ICO in line with our legal obligations.
We may update this policy from time to time. We'll update the "Last updated" date above when we do. Material changes will be highlighted in the app.
Questions about this policy or your data? Email us at playrmatch@gmail.com.