Version 2.0 — last updated 24 August 2026.
SEV7N is a football match tracker. Much of what it records concerns young players, so we have written this policy to be specific rather than generic: what we hold, why we are allowed to hold it, how long we keep it, exactly who else touches it, and what you can do about it.
This policy covers sev7n.app, my.sev7n.app and our mobile apps. It does not cover websites we link to. The company responsible for your data — the "data controller" — is identified in section 14, and you can reach us any time at privacy@my.sev7n.app.
| What we do | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and run your account, provide the Service | Account, match content, subscription | Performance of a contract — Art. 6(1)(b) |
| Take payment and manage your subscription | Subscription, billing identifiers | Performance of a contract — Art. 6(1)(b) |
| Send service emails (password reset, match invitations, renewal reminders) | Account | Performance of a contract — Art. 6(1)(b) |
| Keep accounting and tax records | Subscription, invoices | Legal obligation — Art. 6(1)(c) |
| Keep the Service secure, prevent abuse, fix faults | Technical, diagnostic | Legitimate interests — Art. 6(1)(f): running a secure and working service |
| Hold information about players entered by an account holder | Match content about third parties | Legitimate interests — Art. 6(1)(f): see section 3 |
| Understand how visitors use our public website | Analytics | Consent — Art. 6(1)(a) |
| Send product or marketing emails | Account | Consent — Art. 6(1)(a), withdrawable at any time |
| Establish, exercise or defend legal claims | As relevant | Legitimate interests — Art. 6(1)(f) |
Where we rely on legitimate interests, we have assessed that interest against your rights and freedoms, and we can provide that assessment on request. You can object to processing based on legitimate interests at any time — see section 9.
We do not sell personal data. We do not use your match content to train machine learning models. We do not use advertising cookies or run behavioural advertising.
SEV7N records the names and performance of players who are often children. That information is the child's personal data. It belongs to no one; the child has rights over it, exercisable by a parent or legal guardian, regardless of who typed it in.
The adult who enters a player's details — a parent, a coach, a club official — decides what to record and who to share it with. We provide the tool and store the result. In practice both of us have responsibilities: the account holder for having the authority to record the information and for telling the family about it, and us for keeping it secure, limited and available for deletion.
If you are a club or team using SEV7N to record players on the club's behalf, you act as a data controller in your own right and we act as your processor for that content. Contact privacy@my.sev7n.app for our data processing agreement under Article 28 GDPR.
Information about injuries, health or medical condition is "special category" data under Article 9 GDPR and needs a much stronger justification than we have. SEV7N is not designed to hold it, and you must not enter it — including in free-text notes. If we find such data, we may remove it and will tell the account holder.
You must be at least 16 to hold a SEV7N account, and 18 to pay for one. We do not knowingly create accounts for children under 16. If you believe a child under 16 holds an account, tell us at privacy@my.sev7n.app and we will remove it.
When an account holder creates a viewer link, anyone holding that link can see that match — including any player names shown in it. The link contains a long random identifier that cannot reasonably be guessed, and it is not indexed by search engines. It can be revoked at any time by the account holder, which stops access immediately, and it expires on its own: team share links after 7 days, game and batch import links after 24 hours. Expired links show nothing and cannot be reused.
A link is only as private as the person who shares it. If you receive a link about a child, please do not repost it publicly.
A parent or guardian who wants a child removed from a shared match can write to privacy@my.sev7n.app.
We use a small number of specialist providers. Each acts on our documented instructions under a data processing agreement, and none of them may use your data for their own purposes.
| Provider | What they do | Data involved | Where processed |
|---|---|---|---|
| Vercel | Website and application hosting | Technical data, traffic logs | EU edge; company US-based |
| Supabase | Database and authentication | Account data, match content | EU region; company US-based |
| Sentry | Error and crash reporting | Diagnostic data, account identifier, IP | European Union region, with enhanced privacy controls enabled |
| Resend | Sending transactional email | Email address, display name | US / EU |
| RevenueCat | Subscription management across stores | Subscription status, app user ID, device data | US |
| Stripe | Card payments on the web | Payment data (they collect it directly) | EU (Stripe Payments Europe, Ireland) |
| Apple, Google | In-app purchase billing | Purchase data — they act as independent controllers under their own privacy policies | Per their policies |
| Google Analytics | Website analytics, consent-gated | Analytics identifiers, IP | Google Ireland Ltd |
We also use a secrets management service to protect our own credentials; it holds no user data.
Beyond these, we disclose data only: to professional advisers under a duty of confidentiality; where required by law or a valid order from a competent authority; to protect someone's vital interests, in particular a child's safety; or to a buyer if the business is sold, in which case we will tell you beforehand.
We keep this list current. Ask us at privacy@my.sev7n.app for the version in force on any date.
We host your account data and match content in the European Union. Some of the providers above are US-based and may access data from outside the EEA for support and maintenance.
Where that happens, the transfer is covered by the European Commission's Standard Contractual Clauses, or by the EU–US Data Privacy Framework where the provider is certified under it, together with additional technical measures such as encryption in transit and at rest. You can request a copy of the safeguards for any specific transfer.
| Data | Retention |
|---|---|
| Account data and match content | While your account is open. After closure, available for export for 30 days, then deleted within 30 further days. |
| Backups | We keep every backup from the last 14 days, plus a first-of-month snapshot for up to 366 days. Anything older is deleted. Data you have erased can therefore persist in a monthly snapshot for up to 366 days before it ages out — see the note below the table. |
| Invoices and accounting records | 7 years, as Belgian accounting law requires. This survives account deletion. |
| Server and security logs | Held by our hosting and database providers for no more than 30 days, then deleted automatically. |
| Error reports | 90 days |
| Support correspondence | 3 years from the last message |
| Analytics data | Up to 14 months |
| Records needed for a legal claim | Until the claim and any appeal period ends |
About backups. When you delete data or close your account, we remove it from our live systems on the timescale above. Backups are a separate copy kept only for disaster recovery: they are never used to serve the Service, are not searched or analysed, and are encrypted at rest. Deleted data ages out of them on the cycle described above rather than being erased on request, because selectively editing a backup would compromise its integrity.
If we ever have to restore from a backup, we re-apply every deletion made since that backup was taken, so data you erased does not come back. We treat data held only in backups as beyond use for every other purpose.
Essential cookies keep you logged in and keep the Service secure. They are always active because the Service cannot work without them, and they need no consent.
Analytics cookies — Google Analytics (_ga, _ga_*) — are set on our public website only after you accept them. Analytics storage is denied by default until you choose. We store your choice in a sev7n_cookie_consent cookie. We do not use advertising cookies, and advertising signals are disabled.
Before you choose, Google Consent Mode may send limited, cookieless measurement signals so we can see overall traffic levels. These set no cookies and enable no analytics storage.
You can change or withdraw your choice at any time from the cookie settings link in the site footer, or by clearing cookies in your browser. Withdrawing is as easy as giving consent, and does not affect the lawfulness of what happened before.
Under the GDPR you have the right to:
Write to privacy@my.sev7n.app. We respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month. Exercising your rights is free; we may charge a reasonable fee only for manifestly unfounded or excessive requests. We may need to verify your identity first.
A parent or guardian may exercise these rights on behalf of a child whose data appears in SEV7N.
Please raise concerns with us first — we would rather fix it. You also have the right to lodge a complaint with a supervisory authority, in the country where you live, where you work, or where the issue arose. Ours is:
Autorité de protection des données / Gegevensbeschermingsautoriteit
Rue de la Presse 35 / Drukpersstraat 35, 1000 Brussels, Belgium
contact@apd-gba.be — autoriteprotectiondonnees.be
We apply measures appropriate to the risk, including: encryption in transit (TLS) and at rest; passwords stored only as salted hashes; row-level access controls so accounts cannot read each other's data; centrally managed secrets; least-privilege access for the small number of people who can reach production; and regular patching of our dependencies.
No online service can be guaranteed completely secure, and we do not claim otherwise. What we do commit to: if a breach occurs that is likely to result in a risk to your rights, we will notify the Belgian Data Protection Authority within 72 hours as Article 33 requires, and we will tell you directly, without undue delay, where the risk to you is high.
If you find a vulnerability, please report it to security@my.sev7n.app. We will not pursue good-faith security research that respects users' privacy and does not degrade the Service.
We will update this policy as the Service changes. For significant changes we will notify you by email or in-app notice before they take effect, and where the change requires your consent we will ask for it. The version number and date at the top always reflect the current text, and previous versions are available on request.
Privacy questions and data rights requests: privacy@my.sev7n.app
Security: security@my.sev7n.app
We answer at these addresses. Our postal address is in section 14 below.
See also our Terms of Service.
The data controller for the processing described in this policy is Next7 SRL, trading as "SEV7N", a private limited liability company incorporated in Belgium.
Our registered office, company number and other identification details are set out in our Legal Notice, which is linked from every page of this site.
For anything concerning your personal data, write to privacy@my.sev7n.app. We have not appointed a Data Protection Officer, as we are not required to; messages to that address reach a person, not a queue.