Legal
Privacy Policy
This policy describes how personal data is processed in the RefSupport app and on this support website. RefSupport does not operate its own app backend server and contains no advertising, no user tracking, and no analytics or crash-reporting services.
1. Controller
Oliver Frankholz
Fedelhören 38
28203 Bremen
Germany
Email: ref_support@icloud.com
2. Data processed by RefSupport
Profile data and expense claims
If you fill in “My Data”, the app processes your first and last name, street, house number, postal code, city, selected role and, optionally, your IBAN. This information is stored locally in the app settings on your device and is used to create travel expense claims. Expense data for a match also includes kilometres, cost and fee items, and the selected role.
Matches, observations and delegate data
The following data in particular can be stored for a match: date and times, team names, colours, logos, score, match number, competition, venue and address, names and photos of referees and names of timekeepers and scorekeepers, roster data with numbers, names and roles, match events, penalties, team time-outs, checklists, free-text entries, handwritten drawings, ratings, video and match-time markers, analysis scenes, and a Sportlounge link or game ID. Free text, drawings and imported files may contain further personal or particularly sensitive content entered by you; RefSupport does not analyse or categorise this content for advertising or profiling purposes.
Your documents and imported data
Files you import into the document library are copied locally together with their display name, file type and modification date. Competition, match, team, venue and officials data retrieved from the supported schedule services is stored in a local import cache. Imported team logos and referee photos can become part of a saved match.
Camera, photos, PDF and text recognition
To scan a paper match report, RefSupport requests camera access. Alternatively, you can provide a specific photo or PDF file via Apple’s system picker. Text recognition is performed on the device using Apple’s Vision framework. The scanned, photo or PDF pages are processed in memory for recognition and are not stored in the match as a source document; only the roster data derived from them, which you can review, is stored.
Device settings and credentials
The app also stores your personal delegate checklist questions and the video volume and mute setting locally. If you use the optional Sportlounge feature, access tokens are stored in the Apple Keychain. Only if “Stay signed in” is enabled are your Sportlounge email address, password and club ID additionally stored there, bound to the device. When you sign out, RefSupport deletes this Sportlounge data from the Keychain.
3. Local storage, iCloud and backups
Matches are stored as JSON files in the app’s documents area; your own documents are stored in the Application Support area. Profile data and individual settings are stored in UserDefaults, Sportlounge credentials in the Keychain, and retrieved schedule data in the cache.
If an iCloud account is available, matches and your own documents are synchronised automatically via Apple’s CloudKit in the user’s private database in the container iCloud.com.oliverfrankholz.HandballTimer. This includes personal content contained in matches or your own documents. The profile from “My Data” and the Sportlounge Keychain entries are not synchronised by this CloudKit feature.
Before the local set of matches is reduced, RefSupport creates a local backup and keeps at most five such backups. A deleted match may therefore temporarily remain in these rotating local backups. In CloudKit, technical deletion markers remain for deleted matches and documents so that other devices do not upload deleted content again. Matches older than 90 days are merely archived and are not deleted automatically.
4. Network connections and recipients
With every internet connection, the respective service technically receives necessary data such as IP address, time, requested address and device/HTTP metadata. RefSupport only establishes connections for the features described below:
- Apple iCloud/CloudKit: synchronisation of matches and your own documents in the private iCloud database.
- Apple App Store/StoreKit: loading the subscription products, purchase, checking the subscription status and restoring purchases. RefSupport receives the product ID, the verified entitlement status and, where applicable, expiry, revocation and upgrade information, but no credit card or full payment data.
- Apple Maps and routing service: geocoding of the entered start and venue address and calculation of the driving distance. The current device location is not requested.
www.handball.net: retrieval of competitions, schedules, teams, venues, officials and the logo/photo files referenced in the responses.embed-api.eui.connect.sportradar.com: retrieval of schedule data for the supported HBL competitions.hbf-cms.deinsportplatz.de: retrieval of schedule, venue and officials data for the supported HBF competitions.api.sportlounge.com: optional sign-in with email address and password, club selection, token issuance, and retrieval of an entered game ID, match details, events and video URLs.campus.sportlounge.comis recognised as a permitted link and referenced in required request headers, but is not called by the app as a separate data endpoint.- Dynamic media hosts: logos and referee photos are loaded from the HTTPS addresses supplied by the respective schedule data source. Sportlounge videos are streamed from the HTTPS video address supplied by Sportlounge. The specific hosts are not hard-coded in the app and may be changed by the provider.
Apple provides the iCloud/CloudKit infrastructure as a processor or technical service provider in relation to the app provider. Where Apple processes Apple Account, security, App Store, payment and subscription data for its own purposes and under its own terms, Apple acts as an independent controller. The same applies to the independent processing by the operators of the optionally accessed sports data and video services. Further information is available in Apple’s Privacy Policy.
Depending on the location and infrastructure of the respective service, data may be processed outside the EU/EEA. Such transfers are subject to the safeguards published by the respective provider, in particular an adequacy decision or appropriate contractual safeguards where required.
5. Device permissions
- Camera: only after you grant permission, to scan a paper match report.
- Photos and files: only the images or files you select in Apple’s picker are processed; the app does not request general access to the entire photo library.
- Location: no access to the current device location.
- Microphone, contacts and calendar: no access. Video audio is only played back, never recorded.
6. Exports and sharing
At your request, RefSupport creates temporary PDF files for match reports, analyses and expense claims, text summaries or .refsupportgame files. These may contain personal content from the match or your profile. They are only passed on via the system share sheet to the service or recipient you choose. Temporary files are subsequently subject to the operating system’s storage management; the recipient’s privacy terms apply at the recipient.
7. Third-party SDKs, tracking and automated decisions
The app does not include any third-party SDKs. There is no ad tracking, no analytics, no crash reporting of its own, and no automated decision-making or profiling.
8. Legal bases
- Art. 6(1)(b) GDPR for providing the app features you request, local storage, synchronisation, exports, purchases and support communication;
- Art. 6(1)(a) GDPR where processing depends on a freely given device permission or other consent; consent can be withdrawn with effect for the future;
- Art. 6(1)(f) GDPR for the secure and functional operation of this website and the prevention of abuse; the legitimate interest is the secure provision of support information;
- Art. 6(1)(c) GDPR where data is required to comply with statutory retention or documentation obligations.
9. Retention and deletion
- Profile data, settings, matches and your own documents remain stored until you change or delete them or until the app data is removed. Automatic archiving after 90 days is not deletion.
- Local match backups are limited to at most five versions and are overwritten as new backups are created. They also disappear together with the app data.
- Import caches are limited to a total of 20 MiB; older, least recently used entries are removed when this budget is exceeded. Depending on the type, refresh intervals of 30 minutes to 30 days apply, which do not by themselves trigger immediate deletion.
- If “Stay signed in” is enabled, Sportlounge credentials remain stored until you sign out or the Keychain entry is otherwise deleted.
- Content stored in iCloud remains stored until it is deleted in the app or via the management of your own iCloud account. Technical deletion markers have no automatic expiry.
- Support emails are deleted once the request has been fully dealt with and no statutory retention or documentation obligations prevent deletion.
10. This website and GitHub Pages
This website is static; it sets no cookies itself, loads no external fonts or media and contains no trackers. When you visit it, the hosting provider GitHub processes technically necessary connection and log data, in particular the IP address and request information, in order to deliver and secure the site. GitHub may act as a processor and, for its own security and operational purposes, as an independent controller. Details can be found in the GitHub Privacy Statement.
11. Contact by email
If you write to the support address, your email address, the content of your message and the time are processed in order to answer your request (Art. 6(1)(b) or (f) GDPR). The mailbox is hosted with Apple iCloud Mail; Apple processes the messages as the email provider.
12. Your rights
Subject to the statutory requirements, you have the right of access, rectification, erasure, restriction of processing, data portability and objection. Where processing is based on consent, you can withdraw it at any time with effect for the future. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the place of your habitual residence, your place of work or the place of the alleged infringement.
You can change or delete much of the data directly in the app. For any other request, contact ref_support@icloud.com. For data that Apple or an external sports service processes as an independent controller, you can additionally assert your rights directly with them.
Right to object: Where processing is based on Art. 6(1)(f) GDPR, you can object to it at any time on grounds relating to your particular situation (Art. 21 GDPR).
The supervisory authority responsible for the provider is the State Commissioner for Data Protection and Freedom of Information of the Free Hanseatic City of Bremen (Die Landesbeauftragte für Datenschutz und Informationsfreiheit der Freien Hansestadt Bremen).
13. Whether providing data is required
Providing personal data is neither a statutory nor a contractual requirement. Without certain details, however, individual features are unavailable, for example the expense claim without profile data or Sportlounge videos without signing in.