Privacy policy
Effective date: 31 July 2026
App: Pitchmark
Controller: Serhii Moroz, an individual entrepreneur (FOP) registered in Ukraine, operating Pitchmark
Service address: 13 Yuvileyniy Street, Kryvyi Rih, 50048, Ukraine
Contact: pitchmark.app@gmail.com
This Privacy policy explains how Pitchmark collects, uses, stores, shares, deletes, and protects information when you use the Pitchmark app or web app.
1. Who we are
Pitchmark is operated by Serhii Moroz, an individual entrepreneur (FOP) registered in Ukraine. For privacy purposes, Serhii Moroz is the controller of personal information processed through Pitchmark, unless stated otherwise. The fastest way to contact the controller is by email at pitchmark.app@gmail.com. You may also write to the service address listed above.
2. Information we collect
Pitchmark collects information you provide, information created through your use of the app, and limited technical information needed to operate the service.
Account information. When you create an account or sign in, we may process:
- Email address and authentication credentials entered through Clerk's authentication service
- Authentication status and account identifiers
- Sign-in method, including email credentials or third-party social providers
- Email verification and password-reset status
- Session and account-preparation status
Authentication is provided through Clerk, including supported Google and Apple social sign-in. Pitchmark's backend stores your Clerk user identifier and verifies Clerk session tokens, but it does not receive or store your raw password. Clerk and the selected social sign-in provider process authentication information as described in Section 7.
Profile information. Your supporter profile includes a username and may include an optional display name. Your profile is private by default. If you choose to make it public, your username and optional display name are visible to other signed-in supporters.
Matchday and visit information. When you log a matchday or manage visit history, we may process the selected stadium, visit date, competition, home and away teams, final scores, ticket price and currency, optional experience ratings, sync/edit/delete status, and duplicate-detection signatures.
Stadium, team, and catalog submissions. When you add a custom stadium or team, we may process the submitted details, such as name, country, optional city, capacity, initials, colors, verification/review status, and information linking the submission to your account while it is pending review.
Community safety information. To keep Pitchmark safe, we process:
- Users you block, meaning the block relationship between your account and the blocked account
- Reports you submit about another supporter, optionally in connection with a public visit you can view, including the report category, any optional details you add, and the report status
- Moderation outcomes and enforcement records
Wishlist, badges, and preferences. Pitchmark may process wishlisted stadiums, earned badges and milestones, theme/appearance settings, accent color, default currency, distance unit, and app language.
Contact requests. When you submit a support request, we may process your message, request date, resolution status, our resolution or rejection notes, and the account linked to the request.
Do not include passwords, payment-card details, government identifiers, health information, or other unnecessary sensitive personal information in report details or contact requests.
Location information. With your permission, Pitchmark may use your device location to show nearby stadiums, center the map, and calculate distances. Pitchmark does not include your precise device coordinates in requests to its own backend, and it does not track location in the background. The app uses Apple Maps on iOS and Google Maps on Android. Those platform map providers may process location and map interactions under their own privacy policies and terms. You can revoke location access at any time in your device settings.
Device and technical information. Pitchmark processes limited technical information needed to operate, secure, and protect the service, such as device/app environment signatures, authentication and session state, request timestamps and IP addresses, rate-limit and abuse-prevention signals, and error/connectivity/sync status.
Server and security logs. Our network and server systems process request timestamps, IP addresses, requested routes, response status codes, request IDs, and limited client information to operate, secure, and troubleshoot Pitchmark. IP addresses are masked before access logs are stored. Authorization credentials, cookies, search text, and user-agent strings are redacted or excluded from access logs.
Note on service limits. Pitchmark does not collect custom product-interaction analytics and does not currently include commercial third-party tracking or advertising software, crash-reporting packages from ad networks, push notifications, in-app purchases, camera access, photo-picker access, social-sharing intents, file imports, or PDF parsing.
Crash and error diagnostics. If the app encounters a serious error, it may send a first-party report to Pitchmark containing the error message, a redacted stack trace, the app release and build number, the platform, and the report type. We redact common bearer tokens, JWTs, email addresses, URL query strings, and phone numbers before the report is sent. These reports help us diagnose and secure the service.
3. Information stored on your device
Pitchmark stores some information locally using native storage, including your theme, accent color, default currency, distance unit, language, offline stadium/team/competition catalog, pending or failed matchday visits waiting to sync, pending mutation identifiers, local sync and error state, and Clerk authentication and session tokens. Clerk session tokens are stored using operating-system secure storage that encrypts them on the device.
If you delete the app or clear device storage, locally stored data may be permanently removed. When you request account deletion in the app, locally stored account data is cleared when the deletion flow begins, even if remote deletion remains temporarily pending.
4. How we use information
We use your information to:
- Create, maintain, and manage your authenticated account
- Authenticate sign-in and password reset via Clerk, Google, or Apple
- Display your stadium passport stats, stadium lists, and maps
- Save, edit, sync, and permanently delete matchday records
- Maintain your wishlist and award badges
- Operate public supporter profiles and the follow feature
- Enforce blocks and act on reports to keep the community safe, remove objectionable content, and suspend or remove abusive users
- Remember your preferences and language across launches
- Process and display contact requests
- Protect our infrastructure from oversized payloads or rapid, abusive requests
- Troubleshoot sync, database, or connectivity issues
- Execute permanent account deletion
5. Legal bases for processing
Where laws such as the GDPR require a legal basis, we rely on:
- Contract: to provide the features you request, such as account access, matchday logging, history, wishlist, badges, preferences, sync, and contact submissions.
- Legitimate interests: to secure our infrastructure, prevent abuse, review catalog submissions, operate reporting and blocking tools, moderate objectionable content, and respond to support requests.
- Consent: where required for optional device permissions such as location access.
- Legal obligations: where we must retain limited metadata to comply with applicable law.
6. How we share information
We do not sell your personal information. We use third parties to operate parts of Pitchmark, including Clerk for authentication and user management; Hostinger for the production VPS, PostgreSQL database, and disaster-recovery backups; Cloudflare for domain registration and DNS; Apple Maps and Google Maps for native map features; and Apple or Google for app distribution and supported social sign-in.
Some providers process personal information on Pitchmark's behalf and under Pitchmark's instructions, subject to the contractual safeguards applicable to that service. Some providers may also independently determine how they process defined information under their own privacy policies and terms. A provider's role depends on the service and processing activity; not every provider acts only as Pitchmark's processor or is covered by the same data-processing agreement. We may also disclose information where required by law or to protect the safety, rights, and property of Pitchmark or its users, including to act on abuse reports.
7. Authentication providers
Pitchmark uses Clerk for registration, verification, password reset, and session management. If you choose Google or Apple social sign-in, that provider also processes the information required to authenticate you. Clerk generally processes Pitchmark end-user authentication data on Pitchmark's behalf, while Clerk and social sign-in providers may process defined account or service information independently under their own privacy policies and terms.
8. Location permissions
Pitchmark requests location only when you use map or proximity features. You can deny or revoke access at any time. Pitchmark does not send precise device coordinates to its own backend, track your location in the background, or use location for advertising. Apple Maps on iOS and Google Maps on Android may process map interactions and location under their own privacy policies and terms.
9. Public and shared content
Your profile and matchday history are private by default. If you choose to make your profile public, other signed-in supporters may see your username, optional display name, visited stadiums, visit dates, competitions, teams, scores, and ratings. Your ticket prices remain private. Changing your profile back to private hides your matchday history from other supporters. Blocking another supporter removes follow relationships in both directions and hides both supporters from each other in supporter search, follower and following lists, public profiles, and public matchday and visit views. Your blocked-supporters list and existing report history may retain limited references needed to operate those features.
Your wishlist, badge progress, and contact history remain private and scoped to your account.
Custom stadiums and teams you submit are visible only to you while pending review. If approved, they become part of Pitchmark's shared public catalog for all users.
If you delete your account, your private, unverified submissions are deleted. Submissions that have already been approved into the shared catalog may be retained, because removing them would break other users' matchday records. Where we retain such an entry, we remove the link between it and your account so the retained record is no longer associated with your profile.
10. Retention
We retain personal information only as long as necessary to operate your account, support offline sync, resolve support requests, keep community-safety records, or meet legal obligations.
- Account details, wishlists, and badges are kept for the life of your account.
- Pending local changes stay on your device until synced or cleared.
- Active blocks are kept until you unblock the supporter or either account is deleted.
- Pending contact requests are kept until they are resolved or rejected. Resolved and rejected contact requests, including our response or rejection notes, are retained for 14 days after their last status update and then deleted on an automated schedule.
- Pending and reviewing reports are kept until reviewed. Actioned and dismissed reports, including report details and moderation records, are retained for 14 days after review and then deleted on an automated schedule. A report is also deleted if either associated account is deleted before that time.
- Account-deletion coordination records are kept only while deletion is pending and are deleted when deletion successfully completes.
- Approved catalog submissions are retained in the shared catalog but anonymized upon account closure.
- Server access and security logs, backend error logs, and first-party mobile crash reports are access-restricted and retained for up to 14 days. A relevant log extract may be retained longer only when necessary to investigate a specific security incident or comply with a legal obligation.
When data is no longer needed, or when you request deletion, it is deleted from our live production systems or permanently anonymized. Pitchmark's hosting provider creates routine whole-VPS backups weekly and retains the two most recent weekly backups. Deleted information may remain in a backup until it is replaced, for up to approximately 14 days after backup creation. Backups are stored separately from the VPS and used only for disaster recovery, not ordinary operations.
11. Deleting matchday records
You can delete individual matchday records in the History or Match Detail views. Confirmed deletions permanently remove the record from our live production database and it cannot be recovered through the app. As described in Section 10, deleted information may remain temporarily in routine disaster-recovery backups. Security or rate-limiting metadata may briefly record the transaction timestamp for abuse prevention but does not retain the deleted record.
12. Deleting your account
Pitchmark provides a clear Delete account action in the Account section of your Profile. When you confirm, Pitchmark creates a durable deletion request and asks Clerk to delete your authentication account before deleting the corresponding Pitchmark database account. Temporary provider or database failures keep the deletion request pending for automatic retry and are not reported as completed. While deletion is pending, the request contains your Clerk identifier, retry status, attempt count, and a generic failure description. When account deletion completes, we delete:
- Your Pitchmark user account and email pointers
- All logged matchday visits and history
- Your wishlist records
- All earned badges and milestone progress
- Your contact-request history
- Your private, unverified stadium and team submissions
- Your block relationships, reports associated with your account, and related moderation records
As described in Section 9, submissions already approved into the public catalog are retained but permanently unlinked from your identity.
Local demo mode exception. If the app is running in local developer demo mode, it will not perform a remote deletion; it will instruct you to disable the developer flag and restart.
13. Account deletion limitations
When account deletion completes, your personal data is removed from the live production database and cannot be recovered, restored, or transferred through the app, even if you sign up again with the same email. Deleted information may remain in a routine backup until that backup is replaced, for up to approximately 14 days after backup creation. Routine backups are used only for whole-system disaster recovery and are not used to restore individual accounts or matchday records. Limited technical logs or rate-limiting records may capture the deletion timestamp for security purposes.
14. Your privacy rights, including GDPR
Depending on your jurisdiction, you may have the right to access, correct, erase, restrict, or object to processing of your data, to data portability, and to withdraw consent for device features such as location. To exercise these rights, contact pitchmark.app@gmail.com. We normally verify your identity through your authenticated account. If you cannot access your account, contact us from the account email address where possible. We may request information reasonably necessary to verify your identity and authority, but we will never ask for your password. If we cannot verify a request safely, we may be unable to act on it.
15. International transfers
Pitchmark's production backend and PostgreSQL database are hosted on a Hostinger VPS. Other providers, including Clerk, Cloudflare, Apple, and Google, may process information in other countries according to their service configuration and terms. Where cross-border transfer rules apply, we rely on the transfer mechanism applicable to the provider and processing activity, such as an adequacy decision, the EU-US Data Privacy Framework, or standard contractual clauses. Contact pitchmark.app@gmail.com to request more information about applicable safeguards.
16. Security
We apply reasonable technical and organizational safeguards, including authenticated token routing, account-isolated data, rate limiting, payload limits, encrypted transport, and weekly backups. No system is perfectly secure, and you are responsible for keeping your password and device secure.
17. Age requirement
Pitchmark is not intended for anyone under 16 or anyone who has not reached a higher minimum legal age required in their country to use online services. We do not knowingly collect personal information from anyone who does not meet this requirement. If we learn that an account does not meet the age requirement, we will delete it. If you believe an underage person has registered, contact pitchmark.app@gmail.com.
18. No advertising or sale of personal information
Pitchmark does not monetize your information. We do not run behavioral ad targeting, do not use tracking pixels, and do not sell user data to data brokers or ad networks.
19. Changes to this Privacy policy
We may update this policy to keep it accurate. If we make material changes to how we handle personal data, we will update the effective date above and may show a notice in the app. Continued use after an update means you acknowledge the revised policy.
20. Contact
For privacy questions or data-subject requests, contact:
Serhii Moroz, an individual entrepreneur (FOP) registered in Ukraine, operating Pitchmark
13 Yuvileyniy Street, Kryvyi Rih, 50048, Ukraine
Email: pitchmark.app@gmail.com