Privacy
Plain-language summary. Last updated September 2026.
Rivals is built for your crew, not for advertisers. Your matches, ratings and standings belong to your crew and stay inside it. Here is exactly what that means.
What we store
- Your account: the email and password you sign in with (passwords are hashed, never stored in the clear), and your display name and optional avatar. If you sign in with Google or Apple we store the account identifier they give us instead of a password, plus the email address they pass on.
- Your play: the crews you belong to, the matches you log, scores, ratings, RSVPs and the belts and records that follow from them.
- Notifications: a device token if you turn on push notifications, so we can tell you a session is starting or a result needs confirming.
What we do not do
- We do not sell your data.
- We do not run ads, and nothing we collect is used to target advertising or shared with an ad network.
- We do not track you across other companies' apps or websites.
- This website loads no ad tech, no social pixels and no third-party fonts — the type, the styles and the images all come off our own server. It does count page visits with Google Analytics; that one exception is spelled out below rather than buried.
- There is no public profile and no global feed. Your standings are visible to your crew, and only your crew.
What this website measures
Every page on getrivals.app loads Google Analytics 4. We would rather tell you plainly than let you find it in your browser's network tab, so here is the whole of it.
- What it records: which page you opened and when, roughly where you are (country or city, worked out from your IP address), and the basics of what you are reading on — browser, operating system, screen size — plus the link or search that sent you here.
- The one event we add: when a tool on this site actually computes something, the page sends Google Analytics an event named
tool_resultcarrying one field,tool, whose value is the tool's slug —padel-elo-calculator,court-cost-splitter, and so on. That is the whole payload — the slug and nothing else. It tells us which tools get used rather than merely opened. What you type into a tool is not part of that event. One thing is worth saying plainly, though: the positioning tool’s Copy board link puts the whole board into the web address so it can be pasted into a group chat. Open a link like that and the address you arrived on is the page address Analytics records, board and all. That is how a shareable link works, and it is the reason we say it here rather than let you find it. - Why: so we can see which pages actually bring crews to Rivals and which ones lose them. That is the entire purpose. Nobody here is building a profile of you, and none of it is joined up with your Rivals account.
- Who: Google, acting as our processor. It uses your IP address to work out that approximate location and then drops it — Analytics does not log or store full IP addresses, and no IP address ever reaches us.
- What it is not for: no ads, no ad network, no remarketing lists. Nothing from it is sold or handed on to anyone.
It sets a cookie so a returning visit can be told from a new one. Block it — browser tracking protection, a content blocker, whatever you use — and the site behaves exactly the same; nothing here depends on it. Apart from Analytics, the site still asks nothing of anyone else.
The app is not the website
The Analytics tag above is the whole of the website's measurement. The app carries rather more, and it would be dishonest to leave that unsaid: to keep it from crashing and to see which parts of it actually get used, the app ships a few Google and RevenueCat components. Here is the whole list.
- Firebase Crashlytics — when the app crashes or misbehaves it sends a diagnostic report: the stack trace, your device model, OS version, app version, and an app-generated identifier for the install. We use it to find and fix the crash, nothing else.
- Firebase Analytics — counts of which screens are opened and which features are used, tied to that same app-install identifier rather than your name. It tells us that the season ceremony gets watched and where people give up mid-flow. We do not use it to build a profile of you, and we do not export it to advertisers.
- Firebase Cloud Messaging — the pipe your push notifications travel down. It needs the device token described above.
- RevenueCat — handles Crew Pro purchases and tells our server whether a crew is entitled to it. It receives your Rivals user ID, the purchase and renewal state Apple or Google reports, and the Firebase app-instance ID, so a purchase can be matched to the install that made it. It never sees your card: Apple and Google take the payment and we never receive your payment details.
The app-instance ID is a random identifier Firebase generates for an installation of the app. It is not your device's advertising ID, it is not shared for advertising, and reinstalling the app produces a new one.
In app-store terms, the data linked to your account is your contact info (email), identifiers (your user ID, the app-instance ID, a push token, and the Google or Apple account identifier if you use social sign-in), purchases (whether Crew Pro is active), and the user content you enter — crew and player names, matches, scores and everything the app builds from them. Crash logs and usage analytics are collected too, tied to the install rather than to your identity.
Who processes data for us
To run the app we rely on a small number of providers, each of which receives only what it needs to do its job:
- Hosting — the servers and database that hold your account and your crew's matches.
- Google — Analytics for this website, and Firebase for the app's crash reporting, usage analytics and push delivery, all as described above.
- RevenueCat — subscription state for Crew Pro.
- Apple and Google — the app stores that take the payment and tell RevenueCat whether a subscription is live.
Each of them is bound to handle the data on our instructions, and processing may happen outside your country — Google and RevenueCat are United States companies with infrastructure in several regions.
How long we keep it
Your account data lives for as long as your account does. Delete the account and it goes with it — see below. Crash reports and in-app analytics are retained by Firebase on its own rolling schedule (a matter of months, not forever) and are not tied to your name; website visit data is held by Google Analytics on a rolling retention window of the same order, and cannot be traced back to your account at all; purchase records are kept as long as the law requires us to keep records of a sale.
Deleting your account
You can delete your account from the app (Settings → Account) or from the web at getrivals.app/delete-account — you do not need the app installed to do it. Crews only you own are destroyed with the account; in crews you share, your personal details are removed and your past results are anonymised so the history and ratings stay consistent for everyone else who played those matches. The page explains all of it before you press anything.
Children
Rivals is intended for players old enough to hold an account under their local rules. It is not directed at young children.
Changes
If this policy changes in a way that matters, we will update this page and the date above.
Contact
Questions about your data? Reach us at hello@musthaveappscorp.com — one address, read by the people who build the app.