PADLR by Rebel Lion Labs | Last updated: 2026-07-29
This Privacy Policy explains how Rebel Lion Labs ("we", "us", or "our") collects, uses, and protects your information when you use the PADLR mobile application ("App").
1. Information We Collect
We collect the following categories of personal data:
Account information: Email address and display name (required for account creation), and your unique @handle
Date of birth: Collected once at sign-up to verify that you meet our minimum age of 16. Your date of birth is stored in a private area of your account that only you can read — it is never visible to other users. Where you have enabled it, Apple may additionally share an age range (not a date) with the App as a secondary check; we never receive a date of birth from Apple.
Profile information: Profile photo (optional), preferred playing position, playing style, favourite clubs, and approximate location (optional)
Location data: If you grant location access, we use your device location to show nearby players, clubs and open games. Before any coordinate is stored where other users can see it, we round it to three decimal places (roughly 150 metres), so your precise position is never published.
Match data: Match results, scores, participants, venues, and match history logged by you — or logged by another player who named you in a match
Booking data: Scheduled matches you create or join, including time, venue, and the other participants
Social data: Posts, comments, replies, reactions, follow relationships, and follow requests
Messages: The content of direct and group messages you send in the App, together with your display name and photo as shown to other participants
Reliability data: No-show reports and the votes other participants cast on them, used to maintain a reliability signal on your profile
Dispute records: Match disputes you raise or that are raised against a match you played in, and their outcome
Moderation records: Reports you submit about other users' content, reports submitted about your content, any moderation action applied, and any appeal you lodge
Ratings and rankings: Your calculated skill rating, rating history, confidence value, badges, and leaderboard placement including the local region used to rank you
Device information: Push notification tokens (FCM), device type and OS version for app functionality
Usage data: In-app interactions and feature usage for analytics and improvement
Contact information: Phone contact names and numbers are locally hashed on your device for the "Find Friends" feature. Only irreversible cryptographic hashes are transmitted to our servers — we never see or store your raw contacts.
Crash and performance data: Crash logs, stack traces, device model, and OS version collected by Firebase Crashlytics to diagnose and fix technical issues
2. How We Use Your Information
Calculate your padel skill rating using the Weng-Lin Bayesian algorithm
Enable partner discovery, club discovery, and compatibility matching
Create and manage match bookings and invitations
Rank players on global, national, and local leaderboards
Deliver push notifications for match confirmations, rating updates, bookings, messages, and social interactions
Operate direct and group messaging between players
Display your profile, ratings, and match history to other users
Detect and act on match manipulation, no-shows, and abusive content, and keep the community safe
Handle reports, moderation decisions, and appeals, and produce the transparency reporting we are legally required to publish
Improve the App through anonymised usage analytics
Provide customer support
Comply with legal obligations
3. Legal Basis for Processing (GDPR)
If you are in the European Economic Area, we process your personal data on the following legal bases:
Contract performance: Account creation, match logging, rating calculation, bookings, messaging, and subscription management — necessary to provide the Service you signed up for
Legitimate interest: Analytics, crash reporting, fraud and manipulation detection, no-show handling, community safety, and service improvement — balanced against your rights with minimal data used
Consent: Personalised advertising (AdMob), optional location access, optional contact matching, and marketing communications — you can withdraw consent at any time
Legal obligation: Age verification, retention and submission of content-moderation records under the EU Digital Services Act, responding to lawful requests from authorities, and complying with tax and financial regulations
4. Automated Decision-Making and Profiling
PADLR uses the Weng-Lin Bayesian rating algorithm (OpenSkill) to calculate your skill rating automatically based on match results. This constitutes automated profiling under GDPR Article 22. The system considers match outcomes, score margins, and opponent ratings to produce a skill estimate on a 0–7 scale.
Three further processes in the App operate automatically:
Match confirmation: A match that names other registered players stays pending until a named participant confirms it. If nobody responds, the match is automatically confirmed after a fixed waiting period. A match you post that names no other registered player is confirmed immediately.
No-show handling: Where participants report and vote that a player did not attend, the match may be automatically voided and a reliability signal recorded.
Content moderation: Automated filters may hide content that appears to breach our rules before any human sees it.
You have the right to:
Request a human review of any rating, moderation, or reliability decision that materially affects you
Express your point of view regarding any such decision
Contest a decision by contacting us at rebellionlabsofficial@gmail.com, or — for moderation decisions — by using the in-app appeal described in section 5
Our manipulation detection system may also flag suspicious match patterns automatically. Flagged accounts are reviewed by a person before any account restriction is applied.
5. Content Moderation and Your Rights Under the Digital Services Act
When content is reported or removed, we create and keep a record of the decision. This is required by the EU Digital Services Act (Regulation (EU) 2022/2065) and it involves processing personal data about both the person who reported the content and the person who posted it.
Notice and action (Article 16): Any user can report content. We record the report, the reason given, and the reporter's account.
Statement of reasons (Article 17): If we act on your content, we record and send you the specific rule applied, the reason, whether the decision was automated, and how to appeal.
Appeals: You may appeal any moderation decision affecting your content from within the App. Appeals are decided by a person, never by an algorithm alone. We aim to decide every appeal within 14 days. We offer this voluntarily — as a micro enterprise we are excluded from Articles 20 to 28 of the Digital Services Act by Article 19 of that Regulation.
Moderation statistics: We compile and publish aggregate statistics about moderation activity. These contain no personal data and identify nobody.
We retain moderation records for as long as necessary to handle appeals, meet the obligations above, and defend legal claims. This may be longer than the retention of the content itself. See section 9.
6. Third-Party Services
We use the following third-party services to operate the App:
Firebase / Google (Google LLC, USA): Authentication, cloud database (Firestore), file storage, push notifications (FCM), and analytics. Google Privacy Policy: policies.google.com/privacy
Firebase Crashlytics (Google LLC, USA): Crash reporting and performance diagnostics. Collects crash logs, stack traces, device model, and OS version. Data is processed by Google under their Data Processing Addendum.
Resend (Resend, Inc., USA): Transactional email delivery (account verification, deletion confirmation). Resend processes the recipient email address and message content under their Data Processing Agreement. Resend Privacy Policy: resend.com/legal/privacy-policy
Google AdMob (Google LLC, USA): In-app advertising displayed to free-tier users. Google Privacy Policy applies. You can opt out of personalised ads in your device settings.
Apple Inc.: Sign in with Apple, in-app purchases, push notification delivery, and — where you have enabled it — an optional age range signal used to corroborate our age check.
7. Advertising and Tracking
Free-tier users see ads served by Google AdMob. On iOS, we request your permission via Apple's App Tracking Transparency (ATT) framework before enabling personalised advertising. If you decline, you will still see ads, but they will not be personalised based on your activity across other apps and websites.
Users we know to be under 18 are never shown personalised advertising, regardless of the ATT response.
You can change your tracking preference at any time in your device's Settings > Privacy & Security > Tracking.
8. Data Sharing
We do not sell your personal data. We share data only:
With the third-party service providers listed above, who process data on our behalf
With other users of the App, as described below
When required by law or to protect our legal rights
With your consent for any other purpose
Your display name, @handle, profile photo, ratings, badges, leaderboard placement, and match history are visible to other users of the App as part of the social features. Your date of birth, email address, precise location, and contact hashes are never visible to other users.
Because matches are shared records, another player can log a match that names you. Where a match names a registered player other than the person posting it, that match does not count towards anyone's rating or statistics until it is confirmed. You can remove yourself from a friendly match you did not agree to, and dispute a competitive one.
9. Data Retention and Account Deletion
We retain your data for as long as your account is active. You can request account deletion at any time from within the App under Settings > Account > Delete Account.
Your account enters a 30-day grace period during which you can cancel the deletion
After 30 days, the deletion is carried out
Your Apple ID sign-in token is revoked immediately upon deletion request
What is deleted, and what is anonymised. Some content in PADLR is shared with other people — a match has other players in it, a conversation has other participants, a comment sits under someone else's post. Deleting that content outright would destroy other users' records. So:
Deleted outright: Your profile, email address, date of birth, photos, contact hashes, push tokens, private settings, follow relationships, and your reactions
Anonymised, not deleted: Matches you played in, messages you sent, comments and replies you wrote, and feed entries about you. Your name and photo are replaced with a "Deleted User" placeholder and can no longer be linked back to you.
Retained where the law requires it: Content-moderation records, including statements of reasons and appeal outcomes, are kept to meet our obligations under the Digital Services Act
Specific retention periods:
Account and profile data: Retained while your account is active, plus the 30-day deletion grace period
Match history and ratings: Retained while your account is active; anonymised on deletion as described above
Messages: Retained for the lifetime of the conversation; anonymised on deletion
Crash logs: Retained for 90 days by Firebase Crashlytics
Analytics data: Retained for 14 months by Firebase Analytics, then automatically deleted
Contact hashes: Deleted immediately upon account deletion
Push notification tokens: Revoked and deleted upon account deletion or when you disable notifications
10. Your Rights (GDPR)
If you are located in the European Economic Area, you have the right to:
Access: Request a copy of the personal data we hold about you
Rectification: Correct inaccurate personal data
Erasure: Request deletion of your personal data (see section 9)
Portability: Export your data in JSON format (available in Settings > Export Data)
Object: Object to processing of your data for direct marketing purposes
Restrict: Request restriction of processing in certain circumstances
Withdraw consent: Where we rely on your consent, withdraw it at any time without affecting processing already carried out
You also have the right to lodge a complaint with your local data protection supervisory authority if you believe your rights have been violated.
11. Your Rights (California — CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act and California Privacy Rights Act:
Right to know: Request the categories and specific pieces of personal information we have collected about you in the past 12 months
Right to delete: Request deletion of your personal information
Right to correct: Request correction of inaccurate personal information
Right to opt-out: We do not sell your personal information. We do not share personal information for cross-context behavioural advertising unless you have opted in via the ATT prompt.
Non-discrimination: We will not discriminate against you for exercising any of these rights
To exercise these rights, contact us at rebellionlabsofficial@gmail.com. We will verify your identity and respond within 45 days.
12. Children's Privacy
PADLR requires users to be at least 16 years of age and is not directed to children under 16. We verify age at sign-up. We do not knowingly collect personal information from anyone under 16. If you believe a person under 16 has provided us with personal information, please contact us and we will delete it promptly.
13. Data Storage Location and International Transfers
Your data is stored on Google Firebase servers located in the United States (the nam5 multi-region; primary region us-central). By using the App, you consent to the transfer and storage of your data in the United States.
For users in the European Economic Area, the United Kingdom, and Switzerland, we rely on the following safeguards under GDPR Article 46 / UK GDPR / Swiss FADP:
EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension and Swiss-U.S. DPF: Google LLC is self-certified under the DPF, providing an adequacy mechanism for personal-data transfers from the EU/UK/Switzerland to the United States. See Google's certification on the official DPF list: dataprivacyframework.gov/list (search "Google LLC").
Standard Contractual Clauses (SCCs): Where the DPF does not apply, we rely on the European Commission's 2021 SCCs incorporated into Google's Data Processing Addendum and Resend's Data Processing Agreement.
Supplementary measures: All data in transit is TLS 1.2+ encrypted; data at rest is AES-256 encrypted by Google Cloud.
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. All data is transmitted over HTTPS and stored securely in Google Firebase. Access to our backend is protected by server-side security rules and app attestation, and sensitive fields such as your date of birth are readable only by you.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes through the App or by email. The "Last updated" date at the top of this page reflects the most recent revision.
16. Contact
If you have any questions about this Privacy Policy, please contact us: