Privacy Policy
Version 2026-08
Who we are
Mateo Toniolo, registered at Urquiza 2316, Santa Fe (3000), Provincia de Santa Fe, Argentina ("GDA360", "we"), is responsible for the processing described here.
For questions, or to request access, correction or deletion — including requests from a parent or guardian about a child in their care — write to mateojustotoniolo@gmail.com.
Two different roles, and why it matters
GDA360 is a platform that sports organizations hire to run their tournaments. We handle data in two distinct capacities:
- As controller, for the data of people who create an account: your name, your email and the technical details of your session.
- As processor on the organization's behalf, for athlete data. The club decides what it collects, why, and for how long; we host it on their instructions.
If you are a parent or guardian and want to know what a club holds about your child, the organization is your first point of contact. Write to us anyway and we will help route the request.
What data we handle
If you have an account: first and last name, email, preferred language, a hash of your password (never the password itself), the IP address and browser of each session, and the tournaments, teams and players you mark as favorites. Sessions expire after 14 days.
Athletes, entered by the organization: name, date of birth, jersey number and position; physical and sporting data; a photograph; nationality, school and biography; health data where the club uses that module (blood type, allergies, conditions, medication, insurance, physical clearance, injuries and an emergency contact); training data; and competition data such as goals, cards, line-ups and call-ups.
Parents and guardians: where a record belongs to a child under 13, the system requires a guardian record with consent — who gave it, when, by what method, and against which version of this policy.
Children
- A person under 13 cannot hold their own GDA360 account.
- A record for a child under 13 is not considered valid without a guardian record carrying consent.
- A player's photograph is never published to a content delivery network: it is stored inside our database and served only to viewers who pass the server's access check. A public URL would bypass that check.
- Health data, evaluations and coaching notes are never shown on public screens.
What the public can see
Viewing a tournament requires an account: a visitor without a session sees no tournament data.
Someone with an account who is not a member of the organization sees the scoreboard, standings, schedule and published squad lists, but not medical files, coaching notes, evaluations, entries or call-ups.
Who we share data with
We do not sell personal data, we do not use it for advertising, and we do not track you across other companies’ apps or websites.
We rely on infrastructure providers in the United States: Vercel hosts the application and receives all traffic (IP address, browser, cookies and the contents of your requests); Neon hosts the database and therefore everything described here; Pusher delivers live scores and receives identifiers and scorelines only — no names or personal details travel over that channel, though because your browser connects to it directly, Pusher records your IP address.
We may also disclose data where a competent authority lawfully requires it.
Cookies
We use strictly necessary cookies only: the session cookie, which keeps you signed in and expires after 14 days, and a language preference. We use no advertising or analytics cookies.
Your rights
You can ask us to access your data, correct it, delete it, object to certain processing, or provide a portable copy. Write to mateojustotoniolo@gmail.com and we will respond within 30 days.
You can delete your account yourself from the Account tab. Deletion is immediate and permanent: your name, email, password, favorites and memberships are erased. Results and squad lists you recorded stay with the tournament — they are the competition’s record and the other teams’, not your account’s — but they stop carrying your name.
If you are the only registered guardian of a child under 13, deletion is blocked until another adult takes over or the club archives the record: we cannot leave a child without an adult standing behind the lawful basis for processing their data. The record that consent was given is kept even after a guardian leaves, without identifying them.
Parents and guardians may request access to, correction of, or deletion of their child's data, and may withdraw consent previously given.
Security
Each organization's data is isolated at the database level by row-level security policies, and the application connects using a role without administrative privileges so that isolation cannot be bypassed by accident. Passwords are stored hashed. Traffic is encrypted in transit and private photographs are never published to a CDN.
No system is perfect: we cannot guarantee absolute security.
Changes
If we change this policy we will publish the new version with its date. Consents given by guardians are recorded against the version in force at the time, so it is always possible to establish which text was agreed to.