Privacy Policy
Last updated: 18 July 2026
Level is a tool for grassroots football coaches to build fair player rotation plans. This policy explains what personal data we process, why, and what rights you have over it. See also our Safeguarding & Children's Data Statement, which covers the specific rules around children's information.
1. Who we are
Level is built and operated by Alasdair Carr ("we", "us"), trading as a sole trader in the UK. For anything in this policy, or to exercise any of the rights below, contact [email protected].
2. Roles & responsibility for squad data
Level is used by coaches, team managers, or club administrators ("Coaches") to record information about the players in their squad, including children. The Coach — and their club or league — decides what information to enter, and is responsible for having a proper basis for holding it (for example, under their club's or league's existing safeguarding and parental consent arrangements).
In data protection terms:
- Squad, player, and match data entered by a Coach: the Coach (and their club) is the data controller; Level acts as a data processor, storing and processing it only to provide the service.
- Coach account data (the email address used to sign in): Level is the data controller.
Because of this split, a parent or guardian asking about a specific child's record will usually get the fastest answer from that child's Coach directly, since the Coach holds the context. We will act on a request sent straight to us too — see "Your rights" below.
3. What we collect
- Coach account: an email address used to sign in. No payment or physical address details are collected.
- Team/squad: a team name and, optionally, a team crest image. Player photographs are never part of this — see Safeguarding.
- Player records: first name (a surname or initial is only added where two players share a first name and the Coach needs to tell them apart), shirt number, skill rating, position preferences, goalkeeper suitability, and match statistics (goals, minutes/slots played). We do not collect date of birth, address, school, medical information, or any other identifying detail.
- Match/tournament records: dates, opponents, scores, and the generated rotation plan.
- Bug reports: if a Coach uses in-app "Report a bug," the description and some technical context (screen name, match ID, browser user agent) is stored, and may be forwarded to a public GitHub issue. Please don't include player names or other personal data in a bug report — treat it as visible to the public.
4. Photos of children — not collected
Level has no feature to upload or store a photograph of a player, and none should ever be added via a team crest, shirt number, or any free-text field. Full detail in our Safeguarding & Children's Data Statement.
5. Why we process this data
To provide the rotation-planning service a Coach has signed up to use, and to operate account sign-in. We don't use squad or Coach data for marketing, profiling, or advertising, and we never sell data.
6. Where data is stored
App data is stored in a Postgres database hosted with Neon in the EU (Dublin, Ireland — EU-West region), and the application runs on Railway. All data stays within the EU — we don't transfer it outside the EU/UK. Connections to the app are encrypted (HTTPS). Each Coach's squad, players, and matches are isolated from every other Coach's account.
7. Who else sees the data
- Neon — database hosting
- Railway — application hosting
- GitHub — only bug report descriptions/context, if a maintainer has enabled forwarding
- A transactional email provider, once magic-link sign-in is live — used only to deliver login links to a Coach's own email address
We don't share data with advertisers, data brokers, or anyone else.
8. How long we keep data
We keep data for as long as a Coach's account is active. A Coach can clear all of their own football data — every player, match and tournament — at any time from Settings → Clear squad & data in the app; this is immediate and can't be undone. If a Coach — or a parent/guardian — asks us to delete an entire account, or a specific player's record, we will also do that promptly, normally within a few days. There's no automatic deletion based on inactivity: if you want something removed, clear it in the app or ask.
9. Your rights
Anyone — a Coach, or a parent/guardian of a child whose details appear in a squad — can ask us to:
- See what data we hold about them or their child
- Correct inaccurate data
- Delete their data
- Ask how their data is used
Contact [email protected]. If you're unhappy with our response, UK residents can complain to the Information Commissioner's Office.
10. Security
Accounts are invite-only, each Coach's data is isolated from others', credentials are stored hashed (never in plain text), and connections are encrypted. To report a suspected security issue, email [email protected].
11. Changes to this policy
We'll update this page if what we collect or how we use it changes, and update the date at the top.