Skip to main content Skip to content
GoalGridAI

Rules & privacy

Privacy policy

What the website stores, how account information is used and how to make a privacy request.

Updated

7 sections
On this pageView contents

Controller and contact

Data controller
Nicolai Tonder
Country
Czech Republic
Contact
support@goalgridai.com · Contact form

Use either contact method for questions about your personal data or to exercise your rights.

Account and saved activity

Creating an account involves an email address, a password hash, verification information and account timestamps. Sign-in uses session credentials and a remembered-device recovery key. The readable password is not stored as the account password.

Saved teams, leagues, selections, matches and preferences can be associated with your account to synchronise your devices. Removal records help prevent an old copy of favorites from restoring something you deleted. Public football results are separate from your private favorite list.

Contact messages and automated support

The contact form processes your topic, message, email address and optional page link. Email is optional for problem reports and required for other topics so the operator can reply. Never send passwords, payment details or recovery links.

Your message is saved on the website server and forwarded through a Telegram bot to the operator’s private chat. This includes the email address and page link you provide, the receipt reference and submission time. It is not posted to a public channel. Telegram processes the forwarded information through its service; see Telegram’s privacy policy.

Page-link query strings and fragments are removed automatically. Your message is not used to subscribe you to marketing. Technical request information may be used to limit abuse. See the storage and retention section for how records are handled.

Emails sent to support@goalgridai.com are received through Resend. The message body, sender and recipient information, subject, delivery headers and attachment metadata are stored on the website server. A text preview is forwarded to the operator’s private Telegram chat. Attachments are not automatically opened or sent to AI.

When automated support is enabled, a limited text excerpt is sent to OpenAI to classify the request, select a relevant published FAQ answer and prepare a short summary for the operator. Recognisable email addresses, API keys and link query parameters are removed from this excerpt where detected; other personal information included in your message may still be processed. Passwords, account records and the operator’s credentials are not provided as context.

Automatic email replies are sent through Resend and labelled as automated. Account changes, privacy requests, uncertain cases and follow-up replies are handled by the operator. AI does not change accounts or decide privacy requests. The website retains the selected answer, processing status and delivery reference with the support request. OpenAI response storage is disabled in the API request; provider security and retention policies can still apply. See OpenAI data controls.

Why the data is processed

  • Account access and synchronisation: email, password hash, verification and session credentials, saved items and preferences are processed to provide the account service you request — performance of a contract or steps at your request, Article 6(1)(b) GDPR. Without the necessary account information we cannot create or secure your account; public pages remain available.
  • Account-related support: messages needed to deliver or restore your requested account service are processed under Article 6(1)(b). General questions, suggestions and bug reports, their routing to the operator, and AI-assisted classification and FAQ replies rely on Article 6(1)(f): the legitimate interest in answering incoming requests and maintaining a usable service. We limit the AI excerpt and keep account changes and privacy decisions with the operator.
  • Security and abuse prevention: technical request data, rate-limit records and incident evidence rely on Article 6(1)(f): protecting users, accounts and the availability of the website. This purpose does not permit unrelated marketing or unlimited retention.
  • Privacy requests: necessary request and verification information is processed under Article 6(1)(c) to meet obligations under Articles 12–22 GDPR. Any evidence retained for a specific legal claim is limited to that claim under Article 6(1)(f); a statutory retention duty applies only where the relevant law actually requires it.
  • Optional analytics: Umami usage measurement relies on consent, Article 6(1)(a). It starts only after you allow it and can be stopped through analytics preferences or Settings. Refusal does not prevent use of the website.
  • Optional browser notifications: the subscription and delivery of requested notifications rely on consent, Article 6(1)(a). Withdraw it through notification settings or your browser’s site permissions.

You may object to processing based on legitimate interests. Withdrawing consent does not affect the lawfulness of processing before withdrawal. Support messages are not used to sign you up for marketing, and AI support does not make decisions with legal or similarly significant effects about you.

Services involved in delivery

Telegram is used to deliver contact-form messages to the operator’s private chat. Copies exist on the website server and in that chat; a request concerning your contact message should identify its receipt reference so both copies can be located.

The hosting infrastructure processes requests, stored records and technical logs. Resend receives support emails and delivers account, transactional and support emails. OpenAI processes limited support-message excerpts when automated support is enabled, as described above. If you enable push notifications, delivery also involves your browser’s push service. The website can request external fonts and image resources, which exposes ordinary connection information to the resource host.

API-Football supplies sports data; that is distinct from storing your account favorites. Service providers and their processing locations should be considered for the specific feature used. An international transfer, where applicable, requires an appropriate lawful arrangement.

Only after analytics consent, usage statistics are collected through Umami on stats.goalgridai.com, including limited page and interaction information. The analytics section explains how to allow, refuse and withdraw measurement.

Storage and retention

Retention follows the periods and case-closing criteria below. Closing a browser tab or receiving an automatic reply does not itself delete a support case. Case closure and removal across copies are handled by the operator; there is no automatic deletion timer for the whole support conversation.

  • Account and saved items: kept while the account service is maintained. When a verified account-erasure request is completed, the account and associated saved activity are removed from active records, except information needed for a specifically identified unresolved claim or legal obligation. Session credentials expire or are revoked separately; browser storage durations are described in Cookies.
  • Support messages and AI results: kept until the questions and requested actions in the conversation have been addressed and any associated bug or complaint is resolved. At closure, the operator reviews whether the message body, sender details, raw email, AI excerpt, selected reply and delivery records are still needed for a concrete follow-up or dispute. If not, those personal-data records are removed. A reusable bug description or FAQ may be retained only after identifying details are removed. An automatic acknowledgement alone is not case closure.
  • Copies of a support case: the same closure review covers the website’s feedback records and incoming-email archive, the operator’s private Telegram chat, and available received/sent email records in Resend. Deleting one copy does not delete the others. Copies that must be removed through a provider request are included in that process; providers’ separate security records remain subject to their own applicable retention rules.
  • Server and security logs: the web-server log configuration rotates logs daily and retains 14 rotated files in addition to the current file. Rotation depends on the scheduled rotation task and whether a file has content. Evidence extracted for a particular incident is retained until that investigation and any resulting claim are resolved, then reviewed for deletion. It is not retained indefinitely for unspecified possible incidents.
  • Analytics: identifiable or pseudonymous visit/event records are retained only while needed to investigate a specific usage problem or compare the current calendar year with the preceding calendar year. Once that assessment is complete, retain aggregate findings rather than visitor-level records. Withdrawal stops new collection; requests concerning existing records are handled separately because a visit may not be reliably linked to a named requester.
  • Backups and recovery copies: deletion from active records is followed by a review of recovery copies containing those records. A copy is kept only while it is necessary to restore the specific deployment or incident it protects; once a replacement recovery point makes it unnecessary, it is removed. During that window it is restricted to recovery use. If restored, completed erasure requests must be reapplied before the data is used again. This is an operator-managed review, not a promise that every provider backup disappears immediately.
  • Unresolved legal matters: where a specific claim or legal duty prevents deletion, only the information necessary for that matter is retained. The reason and the event ending retention are recorded for the case; normal deletion resumes once the matter and any applicable legal retention period end.

For a retention or erasure request, write to support@goalgridai.com and include the support reference or account email so relevant copies can be located. Do not send passwords. Clearing local site data does not remove server, Telegram, provider or backup copies.

Your requests and choices

You can request access, correction or erasure, and where applicable restriction, portability or object to processing. You can withdraw consent for processing based on consent. These rights have legal conditions; deleting a browser copy is not the same as completing an erasure request.

Write from your account email and describe the request. Do not send a password. Identity may need to be verified before account data is disclosed or removed. You may also complain to the competent data-protection authority; in the Czech Republic, see ÚOOÚ.

Account privacy settings include local export and device-data controls. For questions, use Contact.

GoalGrid AI / Rules & privacyBack to top