Privacy Policy
Last updated: July 18, 2026
Controller and contact
This privacy policy applies to the 3D Score Buddy website, admin backend, hosted API, and the mobile app, insofar as personal data is processed or external services are used.
Jürgen Weiß
Ligusterstr. 7
90530 Wendelstein
Germany
Email: [email protected]
Controller for the website, app accounts, infrastructure, security, and direct customer communication. Operator-managed participant data in hosted workflows is generally processed on behalf of the relevant club or course operator.
Scope of services
3D Score Buddy includes a public website, an operator backend for clubs and courses, a mobile app for iPhone and Android, and a shared API for Cloud-Connect, backup/restore, and public result pages.
Pure offline scoring can run locally on the device. The privacy-relevant parts are mainly Cloud-Connect, public live links, account login, backup/restore, map features, and technical protection or monitoring services.
Role split between 3D Score Buddy and operators
3D Score Buddy is the controller for its own website, operator account registration, infrastructure protection, and technical error handling.
When clubs or course operators upload participant lists, assign groups, or publish public result links, those operators usually decide the purpose and content of that data. 3D Score Buddy provides the hosted technical platform for this workflow.
- Questions about club-managed participant data may be directed to the relevant operator and to us.
- Operator-facing processor, subprocessor, and retention documentation must stay aligned with this policy.
- The contractual basis for data processing is set out in our Data Processing Agreement (DPA), available in the admin area at /admin/dpa.
Account, login, and admin access
Access to the internal operator area is available only through OAuth with Google or Apple. There is no local password login on our site.
We process account data such as name, email address, identity-provider subject ID, permissions for the relevant operator account, and required session and security data.
- Necessary cookies are used for login, callbacks, CSRF, PKCE, and session state.
- Profile images may be cached for technical purposes.
- Without this data the protected operator area cannot be provided.
Cloud-Connect and score sync
When Cloud-Connect is used, scoring data from the writing device of a group is transferred to the server. Depending on the event configuration this can include full participant names, bow classes, group assignments, device ID, app version, score data, and timestamps.
For technical incident analysis, the app also sends, where available, the operating-system and firmware version, Android API level, and device manufacturer and model when Cloud-Connect is used. This information is associated with the relevant event session and device ID.
Optionally, when a score is entered, the app stores an event-related technical snapshot: input gesture and correction status, app lifecycle, proximity-sensor status including measured distance, device angle, ambient light (lux), and, on Android, display-interactive, keyguard, and device-lock status. No sensor history is created; the information is used to analyze unintended input and improve protection mechanisms.
During technical score synchronization the IP address of the writing device is also processed via the sync logs and stored in the database.
Inside the operator backend, clubs and course operators can see the full participant and result data that belongs to their own provider account.
- In practice one physically present group member often records scores for the whole group.
- Offline-only events stay on the device until a cloud function or backup/restore is used.
- Technical synchronization data is processed separately from manual administrative changes.
Device Share
The Device Share feature allows a single event with selected participants and score data to be temporarily transferred to another device. A short-lived JSON document is stored on the server that automatically expires after a few minutes and is cleaned up regularly.
GPS data, app settings, and archer directory data are not transferred during Device Share.
- The transfer is limited to a few minutes.
- No location data or personal app settings are shared.
Public results, live links, and name display
Tournament results can be made available through public live or result links. On the event day, participant names are shown in full on public views.
After the event day, later parts of participant names are abbreviated in public views, for example from "Jürgen Weiß" to "Jürgen W.". Public course or practice views are anonymized by default.
- Operators and authorized admin users continue to see full names in their own backend.
- Public result pages are used for live communication and event result publication.
- For removal requests, historical result data may need anonymization rather than physical full deletion in order to preserve score integrity.
Maps, location, and device permissions
Public course and tournament search uses a local GeoIP lookup for a rough starting point and can optionally use browser geolocation to show nearby items. The browser location is not stored by the web app as a persistent user profile attribute.
In the mobile app, camera, location, notification, and live-activity or foreground-service permissions may be used for optional features such as QR scanning, local GPS tracking, target coordinates, maps, or sync status. Local GPS tracks and target positions are stored on the device.
- Map rendering uses OpenStreetMap tiles.
- Geocoding and reverse geocoding use Nominatim/OpenStreetMap.
- Location permission for the mobile full-screen map or local GPS features is optional.
- Local device location is not used for advertising profiles.
Purposes, legal bases, and third-country transfers
We process personal data to provide the website and app, operate Cloud-Connect, public result pages, backup/restore, operator accounts, support, IT security, and abuse prevention.
Where applicable, processing is carried out in particular for contract performance or pre-contractual steps, on the basis of legitimate interests in a secure and functioning service, on the basis of your consent for optional features such as location or camera access, and to comply with legal obligations.
When external services are used, data may also be transferred to recipients in third countries, in particular the United States. Where required, we rely on adequacy decisions or appropriate safeguards such as standard contractual clauses for such transfers.
Backups, monitoring, payments, cookies, and rights
Cloud backup and restore can store app settings, event and score data, and directory entries from the app. The intended directory scope is name, bow class, club, notes, and event references. Cloud backups are retained for a maximum of 2 years and automatically deleted thereafter.
Cloudflare is used as a proxy and protection layer for public endpoints and the website. Sentry is used for technical error and performance monitoring (data retention: 30 days). Browser session replay is currently disabled. We do not intentionally run advertising or marketing trackers at this time.
Google and Apple are used both for OAuth logins and for in-app purchases or purchase restoration. We do not receive full payment card data.
Data is kept only as long as needed for service operation, support, abuse prevention, and result integrity.
- Where legally applicable, you may have rights of access, correction, deletion or anonymization, restriction, objection, and data portability.
- Where processing is based on your consent (e.g., optional location or camera access), you may withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
- Automated decision-making including profiling within the meaning of Art. 22 GDPR does not take place.
- You can contact us at the address above for privacy-related requests.
- Where the GDPR applies, you also have the right to lodge a complaint with the competent supervisory authority. For us, this is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany, [email protected].