grovr
Features Broadcast Live Scoring Terms Download
Legal — Data & Privacy

Privacy
Policy.

Effective 18 July 2026 · Version 1.0

On this page
  1. Who we are
  2. What we collect
  3. What we don't collect
  4. How we use it
  5. Sharing & third parties
  6. Storage & security
  7. Retention & deletion
  8. Your rights
  9. Children
  10. Changes
  11. Contact

Grovr is a sports club management app. We collect only what's needed to make it work — accounts, match data, photos you upload, and the streams you choose to broadcast. We do not sell your data, we do not track you across the internet, and we do not read your location.

You can delete your account and everything tied to it from inside the app at any time.

01

Who we are

Grovr ("we", "us") is a mobile app for cricket, badminton, tennis, squash, table tennis, pickleball, padel, football, and netball clubs. This policy explains how we handle your personal data when you use the app or the website at grovr.team.

For any privacy question, write to [email protected]. For general support, use [email protected].

02

What we collect

Everything below is entered by you or generated by your use of the app. We don't buy data from third parties or enrich your profile from external sources.

Data we hold
  • Account. Email address and password, handled via Supabase Auth.
  • Profile. Display name, and an optional profile photo.
  • Club & match activity. Fixtures, availability responses, squad selections, ball-by-ball or point-by-point scoring events, player stats, and finance records entered by you or your club admins.
  • Photos. Match photos and poster images you upload, stored in Supabase Storage.
  • Live stream video & audio. When you tap "Go Live", video and audio from your device are sent to your own YouTube channel via YouTube's live-stream ingestion. Grovr never records or retains the stream itself — YouTube does.
  • Push notification tokens. A device token issued by Firebase Cloud Messaging, used only to send you notifications you've enabled.
  • Crash reports. Anonymous stack traces and device metadata via Firebase Crashlytics when the app crashes, so we can fix bugs.
  • Sponsors & streaming partners. Records your club admins enter for on-broadcast sponsor branding (name, logo, sport, arrangement type) in the club_sponsors table.
  • Play-Cricket sync data. If your club has provided its Play-Cricket API token, we fetch fixtures and scorecards from the ECB's Play-Cricket API and store the results against your club.
03

What we don't collect

Never collected
  • Financial or payment information. Grovr 1.0 is free. There are no in-app payments, no card details, no bank details.
  • Location. We do not read, request, or store precise or coarse location. Android requires the ACCESS_FINE_LOCATION permission for Bluetooth Low Energy scanning (used for scoreboard peripherals); Grovr uses the BLE APIs only and never queries your location.
  • Contacts, health, calendar, or SMS. None of these are read by the app.
  • Advertising identifiers or cross-app tracking. We do not use IDFA, GAID, or any advertising SDK. There are no third-party trackers on the website.
04

How we use it

  • Run the core features you signed up for — fixtures, availability, live scoring, squad selection, finance, chat, notifications, and broadcasts.
  • Send push notifications you've opted into (match-day reminders, score updates, sponsor sales in auctions).
  • Diagnose crashes and fix bugs.
  • Respond when you email us for support.
  • Meet legal obligations we owe as a business (e.g. responding to lawful requests).
05

Sharing & third parties

We do not sell, rent, or trade personal data. Data is shared inside your club (admins see member profiles, availability, and match stats for their own club), and with a small set of technical service providers who make the app work:

SupabaseBackend · EU-west
Hosts our Postgres database, authentication, file storage, and Edge Functions. This is where all of Grovr's data lives.
Firebase (Google)Crashlytics · Cloud Messaging
Delivers push notifications and receives anonymous crash reports so we can debug the app.
YouTube Data API (Google)User-initiated OAuth
When you connect your YouTube channel and tap "Go Live", we use YouTube's API to create the broadcast and ingest your video/audio. The stream itself is hosted on YouTube under your account.
Play-Cricket API (ECB)If your club supplies a token
Fetches your club's fixtures and scorecards from the England & Wales Cricket Board's Play-Cricket platform. Only enabled if a club admin provides the token.

We may also disclose data if compelled by law, valid legal process, or to protect the rights or safety of Grovr, our users, or the public.

06

Storage & security

All Grovr data is stored on Supabase infrastructure hosted in the European Union (EU-west region). Transport is protected with TLS end-to-end. Database access is governed by row-level security policies scoped to your account and your club, and privileged operations run through security-definer server functions rather than direct client writes.

No system is perfectly secure. If we ever suffer a personal-data breach that puts your rights at risk, we will notify the relevant authority and affected users as required by law.

07

Retention & deletion

  • Account deletion. Open the app, go to Profile → Delete Account. This triggers the delete_account RPC on our backend and removes your identity from Grovr.
  • Retention. Personal data is kept until you delete your account. Automated database backups are retained for up to 30 days after deletion before being permanently overwritten.
  • Club data. Match records, scorecards, and finance history remain with the club after you leave; your identity is unlinked from those records on account deletion.
  • Streams. Live streams live on YouTube under your account. Deleting your Grovr account does not delete YouTube content — manage that from YouTube directly.
08

Your rights

Depending on where you live, you may have the following rights under GDPR, the UK GDPR, or comparable laws:

  • Access. Ask us for a copy of the personal data we hold about you.
  • Correction. Fix inaccurate data — most profile fields are editable directly in the app.
  • Deletion. Delete your account and personal data from Profile → Delete Account in the app, or by emailing us.
  • Portability. Request a copy of your data in a structured, machine-readable format by writing to [email protected].
  • Objection. Object to specific processing.
  • Withdraw consent. Turn off push notifications, disconnect YouTube, or remove your profile photo at any time.

You also have the right to lodge a complaint with a data protection authority — in the UK, that is the Information Commissioner's Office (ico.org.uk).

09

Children

Grovr is not intended for children under 13. Users under 13 need parental consent to have a Grovr account, and club admins are responsible for ensuring that consent has been obtained for any minor members of their club. If you believe a child under 13 has an account without appropriate consent, contact us at [email protected] and we will remove it.

10

Changes to this policy

When we make material changes to this policy, we'll update the effective date at the top of the page and, where appropriate, notify you through the app. Continued use of Grovr after the new effective date means you accept the updated policy.

11

Contact us

Three inboxes — pick the one that matches your query.

Privacy
[email protected]
Support
[email protected]
Legal
[email protected]
grovr
Privacy Policy Terms of Service Delete Account [email protected] App Store Google Play
© 2026 Grovr · All rights reserved