Your data
Privacy policy
Effective 6 October 2026.
This policy covers Matchday6 on the web, iOS and Android, and these Matchday6 information and support pages. Other Fanhabit games and business services are outside its scope.
Who is responsible
The controller is Dynamx GmbH, FN 478649x, Münzfeld 3, 4810 Gschwandt, Austria. Contact: oliver@fanhabit.com.
Playing without a login
You do not need a player login, name, email address or phone number to save six picks. We create a random device-linked identifier and store it with its creation time. Saved entries contain that identifier, an entry ID, the gameweek, six fixture/player selections, submission time and entry status. These identifiers are pseudonymous personal data, not proof that we process no personal data.
The recovery identifier is held in iOS or Android SecureStore, or your browser’s localStorage. It acts as an access credential for saved entries. Keep it private. A different device or browser has separate storage; there is no login-based recovery.
Log out clears only the local entry identifier and current picks. It does not delete saved server entries or turn off notifications. Clearing storage or uninstalling can remove your means of recovering data; native secure storage can behave differently by platform.
Optional matchday alerts
Alerts require a separate choice in Settings or the post-entry prompt. Saving picks does not opt you in. We store a separate subscription ID, the push destination, browser encryption keys where applicable, consent and expiry times, and delivery status, retry and receipt records. Notification subscriptions are not linked to your entry identifier in our database.
Native delivery uses Expo’s push service and Apple Push Notification service (APNs) or Google Firebase Cloud Messaging (FCM). Browser delivery uses your browser’s push provider, such as Google, Mozilla, Apple or Microsoft. These services process routing identifiers, message content and technical connection information. Android’s messaging SDK may initialise and process installation information before you choose alerts; this does not subscribe you to Matchday6 alerts.
Turn Settings → Matchday alerts off to delete our subscription and its delivery records. Already accepted messages cannot be recalled. Operating-system settings can also block display. Our opt-out does not itself erase the provider’s installation records; provider retention is separate.
Updates, hosting and technical data
Expo EAS Update checks for compatible native app updates. It receives a separate random installation identifier, platform, runtime/channel and update requests, and can receive launch-failure details and failed-update identifiers. We use this to deliver and maintain working updates.
Cloudflare hosts these public pages and provides the game’s CDN, DNS and security edge. The game API and PostgreSQL database run on our hosted server in the Helsinki network region. Connections expose IP addresses and request metadata to infrastructure providers. Web-server access/error records can include request paths, times, response status, browser information and errors. We do not intentionally log entry credentials or push destinations.
The inspected app has no advertising SDK, advertising-ID use, cross-app advertising tracking, payment collection, contacts, camera, microphone or precise-location feature. Football feed providers supply fixture/player data; our feed importer does not send them player-entry data.
Beta testing
If you join a TestFlight or Google Play test, the store provider processes tester-account, installation, diagnostic and feedback data under its own terms. We can receive the tester information and feedback those tools make available. This is separate from the game’s login-free device identity.
Support and purposes
If you contact us, we process your email address, correspondence and details you choose to provide. Do not send passwords, full device identifiers, push tokens, payment details or unrelated sensitive information in an initial message.
We use entry data to provide and recover the game you request; optional notification consent to send matchday alerts; technical data for our legitimate interests in security, reliability and fixing faults; and support records to respond to you and fulfil applicable legal obligations. You may withdraw notification consent at any time without affecting earlier lawful processing. We do not sell your data.
Retention and deletion
- Saved entries and device identities: there is currently no automatic expiry job. They remain in the database unless removed following a verified request or an operational retention decision. Logging out is not deletion.
- Notification data: consent expires 90 days after its last successful renewal. App visits can renew an active subscription. The notification worker removes expired subscriptions and associated deliveries; it also removes delivery records last updated more than 90 days ago. Cleanup resumes when the worker recovers after an outage.
- Host logs: Nginx is configured for daily rotation with 14 archived rotations. Container logs are size-limited to three 10 MB files per container, so they have no fixed number-of-days lifetime. CDN/provider records follow their separate retention practices.
- Database backups: private host-local database dumps are made daily. The cleanup job removes dump files older than its 14-day threshold when it runs; this is not immediate deletion from every backup. A restore needs to reapply completed deletion requests.
- Support correspondence: no fixed automated mailbox-deletion period is currently established. We review requests and any necessary legal retention individually.
Providers and international processing
Our delivery chain includes Cloudflare, the server-hosting provider, Expo, Apple, Google and the browser push provider relevant to your device. Support email is handled through Google Workspace. Some providers process information globally, including outside the EEA.
Cloudflare publishes a data-processing addendum with transfer provisions. Expo describes its transfer arrangements and Data Privacy Framework participation in its privacy policy. Google describes global processing and messaging identifier retention in its Firebase privacy documentation. Contact us for information about the arrangements applicable to your data. These provider statements do not mean data stays exclusively in Austria or the EU.
Your rights and requests
Depending on applicable law, you can request access, correction, erasure, restriction or portability, and object to processing based on legitimate interests. Use our privacy and deletion-request process. We may need to verify control of the relevant device data. If you have lost the identifier, we may be unable to reliably locate or attribute an entry; we will explain any limitation rather than delete another person’s information.
You can complain to the Austrian Data Protection Authority or your competent local authority. Where GDPR applies, we respond within its applicable time limits and explain any permitted extension or refusal.
Age and eligibility
Matchday6 does not currently collect dates of birth or provide an age-verification or parental-consent flow. If you are a parent or guardian concerned about a child’s use or data, contact us so we can assess the request and take appropriate steps. Store audience declarations and any prize eligibility are separate from simply being able to access the website.
Changes
We will update this page when practices change and show the effective date. Material changes will be explained here or in the app where appropriate.