Privacy Policy
Last updated 29/08/2026
Cricket Buddy ("we", "us") is operated by James Considine. This policy explains what personal information we collect through cricketbuddy.app and the club sites hosted under it (e.g. cricketbuddy.app/your-club), why we collect it, and what we do with it.
What we collect
We collect information in a few different ways:
- Account details you give us directly — name, email address, mobile number, and a password (or you sign in via a one-time emailed link instead).
- Club data a club's admins enter or upload to run their club through the product — squad and roster details (including player names and photos), fixtures, results, sponsor contact details, club branding, and member lists.
- Scorecards and match photos a club uploads (including phone photos or screenshots) so we can read player figures off them and generate cards, reports and statistics automatically.
- Usage information generated automatically — sign-in timestamps, and which features a club uses — so we can keep the product working and improve it.
- Payment information, if a club subscribes to a paid plan — handled directly by our payment processor, Stripe; we don't receive or store full card numbers ourselves.
- Working With Children Check (or equivalent) card photos, for clubs that use this feature — a coach or volunteer photographs the front and back of their current card so we can read and record its expiry date.
Junior and young players
Many of our clubs run junior or youth grades. Where a club uploads a squad photo, scorecard, or match report that includes a player under 18, that club is responsible for having the appropriate consent (e.g. from a parent or guardian, per the club's own policies) before uploading it — we act on the club's instructions as to what it puts into the product, in the same way we would for any other content a club adds.
Working With Children Checks
Some clubs use Cricket Buddy to track Working With Children Checks (or the equivalent police/background check in your state) for coaches, volunteers and committee members. A club admin can send an eligible person a private link to photograph the front and back of their current card. We use Anthropic's Claude API to read the expiry date and reference number off those photos, the same way we read scorecards.
The photos themselves are only kept for 14 days after upload — long enough to confirm the details — then automatically deleted. After that, only the verified expiry date and reference number are retained, so the club can track who's due for renewal. A club admin can also delete the photos or the whole record early, or enter the details manually without uploading a photo at all.
If a check lapses and isn't renewed for 12 months, the record is archived rather than actively tracked, so a club retains a record of who held a valid check and when, without indefinitely holding sensitive personal data.
How we use it
We use personal information to:
- Run the product — create accounts, apply club branding, and generate match-day and results cards.
- Read scorecards and produce match reports and statistics — scorecard images and match text are sent to Anthropic's Claude API to extract figures (scores, wickets, milestones) and draft written reports. This only happens for scorecards a club actually uploads, and only to produce the output the club asked for.
- Send transactional emails — sign-in links, password resets, and (where a club connects its own Mailchimp account) match report newsletters the club chooses to send to its own list.
- Process subscription payments, via Stripe, for clubs on a paid plan.
- Respond to support requests and fix problems.
- Keep the product secure — including detecting misuse and enforcing our Terms.
We do not sell personal information, and we don't use club or player data to train AI models.
Who we share it with
We share personal information only with the service providers that help us run the product:
- Supabase — hosts our database, file storage and authentication.
- Anthropic — processes scorecard images/text, and Working With Children Check photos where a club uses that feature, to read figures, draft reports, and extract check expiry dates.
- Stripe — processes subscription payments for paid clubs.
- Mailchimp — only if a club connects its own Mailchimp account under Setup → Integrations, to send that club's own newsletters.
- Our hosting provider, to run the application itself.
Within a club, member and player information (names, photos, contact details entered by the club) is visible to that club's own admins and members as part of normal club operation — that's the purpose of the product. We don't share one club's data with another club.
We may also disclose information if required by law, or to protect the rights, safety or property of our users or the public.
Where your data is stored
Data is stored with our infrastructure providers (Supabase and our hosting provider), which may hold data outside your own country. Some processing (scorecard reading, report drafting) is performed by Anthropic, which may also process data outside your country. By using the product, you consent to this transfer.
How long we keep it
We keep account and club data for as long as the account or club is active, plus a reasonable period afterwards for backups and legal/accounting purposes. A club admin can delete individual records (players, sponsors, cards, scorecards) at any time from within the product; deleted files are removed from storage. To close an account or club entirely, contact us at jamesconsidine20@gmail.com.
Cookies and sessions
We use a small number of strictly necessary cookies to keep you signed in and to remember which club you're working in. We don't use advertising or third-party tracking cookies.
Security
We take reasonable technical and organisational steps to protect personal information, including access controls that keep each club's data separate from every other club's, encrypted storage and connections, and optional two-factor authentication you can turn on for your own account under My account. No system is completely secure, and we can't guarantee absolute security.
Your rights
You can access, correct, or ask us to delete personal information we hold about you, and you can update most of it yourself under My account. If you're in a jurisdiction that gives you additional rights over your personal information (for example under the Australian Privacy Act 1988, or the EU/UK GDPR), you can exercise those rights by contacting us at jamesconsidine20@gmail.com. If you're not satisfied with our response, you can complain to your local privacy regulator (in Australia, the Office of the Australian Information Commissioner).
Changes to this policy
We may update this policy from time to time. The "Last updated" date above always reflects the most recent change, and every version is kept on record.
Contact us
Questions about this policy or your data: jamesconsidine20@gmail.com.
See also our Terms of Service.