Last updated 2026-06-17 · Version 1.1 (Beta — not yet independently legally reviewed)
This Privacy Policy explains how the noelle service collects, uses, and shares personal data of users of the noelle mobile application and website (noelle.basketball, the Service).
German residents: a German-language version is available at noelle.basketball/privacy/de. In case of conflict, the German version prevails for users resident in Germany.
The Service is currently operated as a private, non-commercial project by:
Alexander Hurley noelle basketball c/o flexdienst – #21344 Kurt-Schumacher-Straße 76 67663 Kaiserslautern Deutschland
Contact: hello@noelle.basketball (general), privacy@noelle.basketball (privacy matters), delete@noelle.basketball (data-deletion requests).
noelle is not a registered business at this time. We do not charge for the Service, do not run advertising, and do not earn revenue from your use of it. If this ever changes (see §12 Future commercial operation), we will tell you in advance and require separate, explicit opt-in to any paid feature — you will never be billed simply because you continued to use the free Service.
The operator is the data controller within the meaning of Art. 4(7) GDPR / DSGVO and the German Federal Data Protection Act (BDSG).
| Data | Purpose | Legal basis |
|---|---|---|
| Email address | account creation, login, security notifications | Art. 6(1)(b) — contract |
| Username | account identification, leaderboards, profile | Art. 6(1)(b) — contract |
| Password (bcrypt hash, never plain text) | authentication | Art. 6(1)(b) — contract |
| City and country (optional) | location-based filtering, leaderboards | Art. 6(1)(a) — consent |
| Display name, bio, profile photo (optional) | public profile | Art. 6(1)(a) — consent |
| Match results, scores, dispute notes | gameplay, leaderboards, fair play | Art. 6(1)(b) — contract |
| Court ratings and reviews | helping other users discover quality courts | Art. 6(1)(b) — contract |
| Data | Purpose | Legal basis |
|---|---|---|
| ELO rating, sportsmanship score | gameplay mechanics | Art. 6(1)(b) — contract |
| Approximate location (only when you grant device permission) | nearby-court discovery, event scoping | Art. 6(1)(a) — consent |
| Push notification tokens | in-app notifications | Art. 6(1)(a) — consent |
| Login timestamps, IP address | security, abuse detection, rate limiting | Art. 6(1)(f) — legitimate interest |
| Crash reports and basic device info (OS, app version) | reliability, bug fixes | Art. 6(1)(f) — legitimate interest |
If you sign in with Google or Apple, we receive your email address, a provider-issued opaque user ID (sub), and your full name (only the first time you sign in with Apple). We do not receive your Google or Apple password. The OAuth ID is stored only to recognize you on subsequent logins.
When you visit noelle.basketball or any API endpoint, our edge server (Caddy, running on Hetzner) necessarily receives request metadata in order to deliver the response:
This data is processed on the legal basis of Art. 6(1)(f) GDPR (legitimate interest) in operating the Service securely. It is used only to deliver content, detect attacks, and diagnose operational problems. Access logs are not used for marketing or profiling. Application access logs are kept for at most 7 days and then rotated out; security-relevant log entries (auth events) follow the retention rules in §1.2 and §5.
When you write to one of our published contact addresses (hello@, privacy@, delete@, ops@ at noelle.basketball), we process the contents of your message and your email address.
If you submit your email through a signup form on noelle.basketball or inside the app:
The mailing list is operated through our email-service provider (see §3 Sharing with third parties).
We do not sell your personal data. We do not show third-party advertising. We do not use behavioural-tracking SDKs. If any of this changes we will update this policy and notify you at least 30 days in advance.
We share the minimum personal data necessary with the following processors (Auftragsverarbeiter). A Data Processing Agreement (DPA) under Art. 28 GDPR will be / is in place with each:
| Processor | Purpose | Region | Data shared |
|---|---|---|---|
| Hetzner Online GmbH (Germany) | application hosting, database storage, backups | EU (Nuremberg / Falkenstein) | all application data |
| Cloudflare, Inc. (USA) — if/when enabled | DNS, TLS termination, DDoS protection (proxy-only, no caching of user content) | EU edge nodes | request metadata only (IPs, paths) |
| Brevo SAS (France) — primary email provider for newsletter, transactional, and admin broadcasts | newsletter delivery, password-reset emails, service announcements, legal notices | France (EU) | email address, message subject + body |
| Expo / 650 Industries, Inc. (USA) — push notification relay | aggregates outgoing push notifications and forwards them to APNs / FCM for delivery to your device | USA (transient — payloads buffered briefly, not stored long-term) | Expo push token (opaque per-device string) + notification title + body |
| Apple Inc. (USA) — Apple Push Notification service (APNs) | terminal delivery hop for iOS push notifications; also "Sign in with Apple" identity verification | USA | push token + notification payload; OAuth identity data for sign-in |
| Google LLC / Google Ireland Ltd. — Firebase Cloud Messaging (FCM) | terminal delivery hop for Android push notifications; also "Sign in with Google" identity verification | USA / Ireland (EU) | push token + notification payload; OAuth identity data for sign-in |
US-based processors are covered by the EU-U.S. Data Privacy Framework (adequacy decision, July 2023) and by Standard Contractual Clauses (SCCs) where applicable.
A note on the unavoidable terminal hop. Mobile push notifications must terminate at either Apple's APNs (for iPhones / iPads) or Google's FCM (for Android devices). There is no technical path for any app to deliver a notification to an iOS or Android device that bypasses these services — they are operated exclusively by Apple and Google respectively. We use Expo's relay only to batch and route notifications to the correct terminal service; the relay itself does not change the fact that the final delivery hop is operated by a US-headquartered company. If you do not want push notification metadata to traverse Apple or Google infrastructure, you can disable notifications at the operating-system level — we will fall back to email (Brevo, France) and in-app banners (served from our own Hetzner servers) for any important messages, including legal notices and security alerts.
Sensitive content does not traverse the push channel. For the "legal — security incident" classification, we replace the push body with a generic prompt ("Important security update — open the app for details") so that the substance of any breach notification reaches you only via email and in-app banner, never via the US-based push relays.
We do not transfer personal data to any other third party except when required by law, with your explicit consent, or to the operator's legal counsel in the event of a legal dispute concerning the Service.
| Data | Retention period |
|---|---|
| Account profile (email, username, etc.) | until you delete your account |
| Match history, rankings, badges | until account deletion |
| Refresh tokens | 7 days from issue, rotated on each refresh |
| Login timestamps and IP logs | 90 days, then anonymized |
| Crash reports | 180 days |
| Newsletter confirmed addresses | until you unsubscribe or delete your account |
| Newsletter unconfirmed addresses | 30 days, then deleted |
| Push notification tokens | until you disable notifications in the OS, uninstall the app, or delete your account |
| Broadcast delivery records (which user received which message) | 12 months, for audit + bounce diagnosis |
| Backup snapshots | 30 days rolling, then overwritten |
When you delete your account (see §5), we hard-delete your profile and all directly linked records (matches, rankings, badges, push tokens, refresh tokens, event participations, ratings). Authored content that benefits other users (e.g. courts you registered, events you hosted) is preserved in anonymized form — your name is removed and replaced with a generic placeholder.
If the Service ever transitions to commercial operation (§12), payment records will be retained for 10 years as required by German tax law (AO §147). This only applies to records created after you have opted into paid features.
You have the right to:
We will notify affected users and the responsible supervisory authority within 72 hours of becoming aware of a personal-data breach (Art. 33–34 GDPR).
The Service is not directed at children under 16. We do not knowingly collect personal data from children under 16 without parental consent (Art. 8 GDPR). Parents who believe their child has registered may contact privacy@noelle.basketball for account deletion.
The mobile app does not use cookies. The website (noelle.basketball) uses only strictly necessary cookies (session, CSRF) where required. We do not use Google Analytics, Meta Pixel, or any third-party behavioural-tracking SDK. We do not run advertising networks.
The Service is operated from Germany. Users outside the EU/EEA should be aware that data is stored on servers located in Germany / EU member states under EU privacy law, which is generally stricter than equivalent regimes elsewhere. By using the Service you consent to processing in the EU.
If you are a California resident, you have additional rights under the CCPA — contact privacy@noelle.basketball to exercise them. If you are a Brazilian resident, you have additional rights under the LGPD — contact the same address.
The Service allows users (and the operator) to host events, leagues, and tournaments. When you participate in an event:
We will update this Privacy Policy from time to time. Material changes will be announced by an in-app banner the next time you open the app, a push notification (if you have notifications enabled), and an email to your registered address. We will give at least 30 days notice before any material change takes effect.
The Service is currently free and non-commercial. We reserve the right to introduce paid features (e.g. tournament hosting fees, premium analytics) in the future. If we do:
We maintain a presence on Instagram as @noelle.bball for community updates and announcements. Instagram is operated by Meta Platforms Ireland Ltd. (4 Grand Canal Square, Dublin 2, Ireland).
noelle.basketball website itself does not embed Instagram feeds, pixels, share buttons, or any other Meta resource. The only Instagram touchpoint from the website is an outbound link in the footer — your data is transferred to Meta only when you actively click it.You can object to processing for legitimate-interest grounds at any time under Art. 21 GDPR — contact privacy@noelle.basketball.
| For | Address |
|---|---|
| Privacy questions, GDPR rights (access, rectification, restriction, portability, objection) | privacy@noelle.basketball |
| Data-deletion requests | delete@noelle.basketball (include username + registered email address) |
| General | hello@noelle.basketball |
| Postal | see §0 Operator and nature of the Service |
The {OPERATOR_NAME} / {OPERATOR_*} placeholders in §0 are filled in on the production server before this page is reached by visitors. This draft is the operator's source-of-truth statement and does not constitute legal advice. A German IT-Recht / Datenschutz attorney should review before commercial launch.