Legal

Privacy Policy

This policy describes how personal data is processed in the RefSupport app and on this support website. RefSupport does not operate its own app backend server and contains no advertising, no user tracking, and no analytics or crash-reporting services.

Last updated: 8 October 2026. This English version is a convenience translation; the German version prevails.

1. Controller

Oliver Frankholz
Fedelhören 38
28203 Bremen
Germany

Email: ref_support@icloud.com

2. Data processed by RefSupport

Profile data and expense claims

If you fill in “My Data”, the app processes your first and last name, street, house number, postal code, city, selected role and, optionally, your IBAN. This information is stored locally in the app settings on your device and is used to create travel expense claims. Expense data for a match also includes kilometres, cost and fee items, and the selected role.

Matches, observations and delegate data

The following data in particular can be stored for a match: date and times, team names, colours, logos, score, match number, competition, venue and address, names and photos of referees and names of timekeepers and scorekeepers, roster data with numbers, names and roles, match events, penalties, team time-outs, checklists, free-text entries, handwritten drawings, ratings, video and match-time markers, analysis scenes, and a Sportlounge link or game ID. Free text, drawings and imported files may contain further personal or particularly sensitive content entered by you; RefSupport does not analyse or categorise this content for advertising or profiling purposes.

Your documents and imported data

Files you import into the document library are copied locally together with their display name, file type and modification date. Competition, match, team, venue and officials data retrieved from the supported schedule services is stored in a local import cache. Imported team logos and referee photos can become part of a saved match.

Camera, photos, PDF and text recognition

To scan a paper match report, RefSupport requests camera access. Alternatively, you can provide a specific photo or PDF file via Apple’s system picker. Text recognition is performed on the device using Apple’s Vision framework. The scanned, photo or PDF pages are processed in memory for recognition and are not stored in the match as a source document; only the roster data derived from them, which you can review, is stored.

Device settings and credentials

The app also stores your personal delegate checklist questions and the video volume and mute setting locally. If you use the optional Sportlounge feature, access tokens are stored in the Apple Keychain. Only if “Stay signed in” is enabled are your Sportlounge email address, password and club ID additionally stored there, bound to the device. When you sign out, RefSupport deletes this Sportlounge data from the Keychain.

3. Local storage, iCloud and backups

Matches are stored as JSON files in the app’s documents area; your own documents are stored in the Application Support area. Profile data and individual settings are stored in UserDefaults, Sportlounge credentials in the Keychain, and retrieved schedule data in the cache.

If an iCloud account is available, matches and your own documents are synchronised automatically via Apple’s CloudKit in the user’s private database in the container iCloud.com.oliverfrankholz.HandballTimer. This includes personal content contained in matches or your own documents. The profile from “My Data” and the Sportlounge Keychain entries are not synchronised by this CloudKit feature.

Before the local set of matches is reduced, RefSupport creates a local backup and keeps at most five such backups. A deleted match may therefore temporarily remain in these rotating local backups. In CloudKit, technical deletion markers remain for deleted matches and documents so that other devices do not upload deleted content again. Matches older than 90 days are merely archived and are not deleted automatically.

4. Network connections and recipients

With every internet connection, the respective service technically receives necessary data such as IP address, time, requested address and device/HTTP metadata. RefSupport only establishes connections for the features described below:

Apple provides the iCloud/CloudKit infrastructure as a processor or technical service provider in relation to the app provider. Where Apple processes Apple Account, security, App Store, payment and subscription data for its own purposes and under its own terms, Apple acts as an independent controller. The same applies to the independent processing by the operators of the optionally accessed sports data and video services. Further information is available in Apple’s Privacy Policy.

Depending on the location and infrastructure of the respective service, data may be processed outside the EU/EEA. Such transfers are subject to the safeguards published by the respective provider, in particular an adequacy decision or appropriate contractual safeguards where required.

5. Device permissions

6. Exports and sharing

At your request, RefSupport creates temporary PDF files for match reports, analyses and expense claims, text summaries or .refsupportgame files. These may contain personal content from the match or your profile. They are only passed on via the system share sheet to the service or recipient you choose. Temporary files are subsequently subject to the operating system’s storage management; the recipient’s privacy terms apply at the recipient.

7. Third-party SDKs, tracking and automated decisions

The app does not include any third-party SDKs. There is no ad tracking, no analytics, no crash reporting of its own, and no automated decision-making or profiling.

8. Legal bases

9. Retention and deletion

10. This website and GitHub Pages

This website is static; it sets no cookies itself, loads no external fonts or media and contains no trackers. When you visit it, the hosting provider GitHub processes technically necessary connection and log data, in particular the IP address and request information, in order to deliver and secure the site. GitHub may act as a processor and, for its own security and operational purposes, as an independent controller. Details can be found in the GitHub Privacy Statement.

11. Contact by email

If you write to the support address, your email address, the content of your message and the time are processed in order to answer your request (Art. 6(1)(b) or (f) GDPR). The mailbox is hosted with Apple iCloud Mail; Apple processes the messages as the email provider.

12. Your rights

Subject to the statutory requirements, you have the right of access, rectification, erasure, restriction of processing, data portability and objection. Where processing is based on consent, you can withdraw it at any time with effect for the future. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the place of your habitual residence, your place of work or the place of the alleged infringement.

You can change or delete much of the data directly in the app. For any other request, contact ref_support@icloud.com. For data that Apple or an external sports service processes as an independent controller, you can additionally assert your rights directly with them.

Right to object: Where processing is based on Art. 6(1)(f) GDPR, you can object to it at any time on grounds relating to your particular situation (Art. 21 GDPR).

The supervisory authority responsible for the provider is the State Commissioner for Data Protection and Freedom of Information of the Free Hanseatic City of Bremen (Die Landesbeauftragte für Datenschutz und Informationsfreiheit der Freien Hansestadt Bremen).

13. Whether providing data is required

Providing personal data is neither a statutory nor a contractual requirement. Without certain details, however, individual features are unavailable, for example the expense claim without profile data or Sportlounge videos without signing in.