1. Introduction
GameTab ("we," "our," or "us") is a sports group management app developed by Nexavyn (ABN: 21 696 400 476), a sole trader business based in Australia. It helps you organise, join, and participate in local sports games and tournaments. This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and what choices you have.
By using GameTab, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the app.
2. Information We Collect
2.1 Account Information
When you register, we collect:
- Full name (first and last name)
- Email address
- Password (stored as a secure hash — never in plain text)
- Username (auto-generated on signup; unique identifier)
2.2 Profile Information (All Optional)
Everything in this section is voluntary — you can use GameTab without providing any of it, and you can add, change, or remove these details at any time:
- Phone number (optional on your profile and optional when submitting a request to join a group — you can leave it blank)
- Suburb/City, State/Region, and Country (manually typed or picked by you — an approximate locality only, so other players know roughly where you are based; we never ask for your street address, and nothing is stored as GPS coordinates)
- Profile photo
- Bio / short description
- Sport interests and skill levels
2.3 Game & Group Activity
When you participate in groups and games, we record:
- Groups you create or join
- Games you register for or create (dates, times, venue name, participant status)
- Your participation status: Confirmed, Waitlisted, or Cancelled
- Game venues (place name, street address, city — text only; no GPS coordinates)
- Tournament participation and scores you submit
2.4 In-App Communications
- Group chat messages within a group
- Game chat messages within a game (including "Notify Team" updates such as running late or can't make it)
- Direct messages between group admins and members
- Message metadata: emoji reactions, @mentions, replies, edits, and pinned status
- Announcements you author (admins) and comments you post on group announcements
- Emoji reactions ("likes") on announcements and read/seen status
- Poll votes
- Feedback and support messages you submit within the app
2.5 Credits, Billing & Transactions
- In-app credit balance per group
- Credit transactions (amounts, dates, type, and notes)
- Credit requests sent or received between group members
- Subscription records for Admin Plan users (plan history, trial dates)
- Billing invoices for Admin Plan users (billing month, amounts, per-group player counts, payment references you submit, payment status)
2.6 Notification & Push Token Data
- Device push notification tokens (to deliver alerts to your device)
- Your notification preferences (per type and per group)
- In-app notification history (type, message, timestamp)
2.7 Device, Session & Security Data
- Device platform (IOS or Android) — used only for targeted push notification delivery
- Authentication session tokens (stored locally on your device and sent with your requests to authenticate them)
- If you enable multi-factor authentication (MFA): one-time email verification codes, delivered to your email address via our email provider (Resend — see Section 5.2), stored as a hash (not plain text) once generated, expiring 10 minutes after being sent and purged from our database within 24 hours, plus a record of which sessions have completed MFA verification
- While you have a chat screen open, a short-lived "presence" record so we can avoid sending you push notifications for a conversation you are already viewing (removed when you leave the screen)
2.8 Information You Provide About Others
- Guest players: group admins can add a guest player to a game by entering the guest's name. If you add a guest, you must have that person's permission. Guest names are visible to game participants and are included in the group's game records and (for Admin Plan billing) player counts.
- Score entries: when logging personal scores you may enter a partner or opponent name as free text.
If your name has been entered by another user and you would like it removed, contact us at [email protected].
2.9 Group Payment Details (Admin-Entered)
Group admins can optionally add payment details (such as a PayID, BSB and account number, or similar) to their group's info page, so members know how to pay membership or session fees directly to the admin. This information is visible only to current members of that group — never to the public or to non-members browsing Explore Groups. GameTab does not process, verify, or store any actual payment made using these details; any such payment happens directly between the member and the admin, exactly as described for G-Credits in Section 2.5.
3. Device Permissions
GameTab requests the following device permissions. Each is requested only when the relevant feature is used, and you can manage or revoke them at any time from your device Settings.
3.1 Camera
- Why: To take a photo when updating your profile picture
- When asked: Only when you tap "Take Photo" in profile settings
- Data handling: Photo is resized on your device and uploaded to our cloud storage (see the image storage note below). No other camera access occurs.
3.2 Photo Library / Media
- Why: To select a photo for your profile picture, a group's cover image, or an announcement image; and to save an image to your library when you explicitly request it (for example, saving a shared game card)
- When asked: Only when you tap "Choose from Gallery" (or save an image)
- IOS Limited Access: We fully support IOS Limited Photo Access. If you grant limited access, only photos you select are visible to the app.
- Data handling: Selected photo is uploaded to our cloud storage. We do not browse or scan your photo library.
3.3 Share Invitations (No Contacts Permission)
- Why: To let you share invite text using any app you choose
- When used: Only when you tap "Share invite via any app"
- Data handling: Recipient and app selection are handled by your device and selected app, not by GameTab
3.4 Calendar
- Why: To add game reminders to your calendar so you never miss a match
- When asked: Only when you choose to add a game to your calendar
- Data handling: Events are written to your device calendar only. No calendar data is sent to our servers.
3.5 Push Notifications
- Why: To alert you about new games, player updates, reminders, group announcements, and messages
- When asked: On first app launch after login
- Data handling: A push token is stored in our database linked to your account, and deleted when you log out. You can customise notification types within the app and mute individual groups.
- Android system permissions: On Android, the app also declares the standard notification-delivery permissions (post notifications, exact alarm scheduling, and restart-after-reboot) used solely so reminders and notifications arrive reliably. They are not used to collect any data.
3.6 Location
Game and group venues are entered as text addresses by you or your group admin — GameTab does not collect or store GPS coordinates.
The Explore tab includes an optional "Use my location" feature. If you tap it, GameTab requests your device's GPS location (foreground only) to identify nearby groups. Your coordinates are passed to Apple (iOS) or Google (Android) geocoding services to convert them to a city and region name — this is handled by your device's operating system, not GameTab's servers. The raw GPS coordinates are not stored in our database. Only the resulting city/region text is used for filtering. The app never requests location silently or in the background.
Third-party geocoding: When you use the "Use my location" feature, your device sends GPS coordinates to Apple Maps (iOS) or Google Maps (Android) to resolve a place name. This is subject to Apple's and Google's respective privacy policies. GameTab does not receive or store those coordinates.
4. How We Use Your Information
| Purpose | Data Used |
|---|---|
| Provide and operate the app | Account info, group/game data, activity |
| Authenticate your identity | Email, password, session tokens |
| Show your profile to group members | Name, photo, sport skills, city/country |
| Send notifications | Push tokens, notification preferences |
| Facilitate game scheduling | Game dates, venue, participant lists |
| Track game participation | Registration status, game history |
| Deliver in-app messaging | Chat messages, reactions, mentions, read status, presence (to avoid duplicate push alerts) |
| Manage in-app credits | Credit balances, transaction history |
| Invoice Admin Plan subscribers | Subscription records, per-group active player counts, payment references |
| Secure your account (optional MFA) | Email verification codes, session verification records |
| Enable friend invitations | Invite message shared via device share sheet (recipient selection handled by your device and chosen app) |
| Allow group admins to contact members | Phone number (from your profile or join request) — shared with group admins only |
| Respond to support requests | Feedback messages, email |
| Compute personal head-to-head tournament stats | Tournament match results and participant data — stats are visible only to you and never shared with other users |
| Improve GameTab and develop new features or services | Account activity and usage patterns — used internally only, never shared with third parties for this purpose (see Section 5.2) |
| Comply with legal obligations | As required by applicable law |
5. How We Share Your Information
5.1 With Other GameTab Users
The following is visible to other members within shared groups:
- Your name, username, and profile photo
- Your city, state, and country, bio, and sport skills — each of these can be hidden using the privacy toggles in Settings (Privacy section); hidden fields are enforced on our servers, not just in the app
- Your game participation status (Confirmed / Waitlisted / No-show)
- Comments you post on announcements, your announcement likes, and your poll votes (vote summaries can include voter names)
- Messages, reactions, @mentions, and edits you post in a group chat (visible to that group), a game chat (visible to that game's players), or a direct message (visible to the other participant)
- Scores and results you submit, leaderboard standing, and tournament participation
The following is visible only to group admins of groups you belong to or have requested to join: your phone number — shared so the admin can contact you about your membership or request.
The following is never visible to any other user: your email address, credit balance, password, and device information. Your personal performance statistics and weekly goals are visible only to you.
5.2 With Service Providers
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase (supabase.com) | Database, authentication, file storage | All user and app data |
| Expo / EAS (expo.dev) | Push notification infrastructure | Device push tokens, notification content |
| Apple APNs | iOS push notification delivery | Push token, notification payload |
| Google FCM | Android push notification delivery | Push token, notification payload |
| Sentry (sentry.io) | Crash reporting and error diagnostics | Device info, app version, anonymised user ID, stack trace |
| Resend (resend.com) | Transactional email delivery for feedback notifications and MFA login codes | Feedback content (type, message, rating) and your name and email address when you submit feedback; your email address, first name, and one-time login code when MFA is enabled and you sign in |
| OpenStreetMap Nominatim | City/suburb autocomplete | Location search text only (no user ID) |
We do not sell, rent, or trade your personal data. We do not share personal data with advertisers or data brokers. We do not use your data for third-party advertising tracking, behavioural profiling, or targeted marketing of any kind.
5.2a Where Your Data Is Processed (Overseas Disclosure)
Your account data, app content, and uploaded images are stored in Australia (our database and file storage run on Supabase infrastructure hosted in the AWS Sydney region, ap-southeast-2).
Some of the service providers listed above process limited data outside Australia, primarily in the United States:
- Sentry (US) — crash diagnostics with an anonymised user identifier
- Expo (US) — push notification routing (device tokens and notification content)
- Resend (US) — transactional email delivery (email address and email content, including MFA one-time login codes when MFA is enabled)
- Apple / Google — push delivery and, if you use "Use my location", on-device geocoding, under their own global infrastructure and policies
We only share with these providers the minimum data needed for their function, as set out in the table above.
5.3 App-Initiated Device Actions
Certain in-app actions open your device's native applications without sending data through GameTab:
- Phone Dialler — when a group admin taps a member's phone number, GameTab opens your device's native dialler with the number pre-filled. No call is initiated, recorded, or routed through GameTab. This action requires no additional device permission.
- Maps — when a user taps a game location, GameTab opens the device's Maps application with a pre-filled address. No location data is sent to or processed by GameTab.
- Share Sheet — when sharing an invite, GameTab generates a text snippet and opens the device share sheet. Recipient and app selection are entirely controlled by you and your device.
5.4 Legal Disclosure
We may disclose your information if required by law, court order, or government authority, or to protect the rights, property, or safety of GameTab, our users, or the public.
6. Data Storage and Security
- Database and file storage are hosted by Supabase (PostgreSQL cloud database)
- All data is transmitted over HTTPS/TLS encrypted connections
- Passwords are hashed using Supabase's secure authentication (bcrypt)
- Database-level access rules (row-level security) restrict every record to the users entitled to see it — for example, group content is only accessible to that group's members
- Optional multi-factor authentication (email verification codes) can be enabled in Settings; when enabled, it is enforced on our servers for every session
- Session tokens are stored locally on your device and auto-refreshed
- Push tokens are deleted immediately when you log out
- Crash reports sent to Sentry use an anonymised user identifier rather than your name or email, and Sentry's default data-scrubbing settings are applied
- Automated database backups are taken daily and managed by our hosting provider (Supabase). Backups exist solely for disaster recovery, are not used for any other purpose, and are automatically overwritten on a short rolling cycle
7. Data Retention
7.1 Account and Profile Data
Your account and profile data (name, email, photo, sport skills, location) is retained for as long as your account is active. When you delete your account, your personal data is removed or de-identified as described in Section 8.4 — most data is deleted immediately, and a small set of records is retained in anonymised form or as a limited audit record where the law requires it.
7.2 Chat Messages
Chat messages are subject to automatic retention limits to manage storage and protect user privacy:
| Chat Type | Displayed In App | Stored In Database |
|---|---|---|
| Game Chat | Last 30 days | 90 days |
| Group Chat | Last 90 days (paginated) | 90 days |
| Direct Messages | Last 90 days | 90 days |
Messages older than 90 days are automatically and permanently deleted from our database each day via a scheduled process. Pinned messages are exempt from automatic deletion — a pinned message is retained until it is unpinned by an admin, at which point it becomes subject to the standard 90-day deletion cycle on the next scheduled run. (Direct messages cannot be pinned and are always purged at 90 days.)
Emoji reactions, reply references, and read receipts associated with deleted messages are also removed as part of the purge process.
7.3 Games, Groups, Announcements, Polls, and Tournaments
Group records themselves are retained until the group admin deletes the group. Content within a group is subject to automatic time limits:
| Data | Retention |
|---|---|
| Games and participation records | 2 years from the game date |
| Announcements | Until 30 days after their expiry date (reactions, comments, and view records are removed with the announcement) |
| Closed polls and their votes | 1 year after closing (open polls are kept until closed) |
| Completed or cancelled tournaments | 3 years (including matches and scores) |
| Personal score entries | 3 years from the session date |
| Resolved join requests and invites | 90 days after resolution |
Leaving or being removed from a group: your access to that group's chats, announcements, polls, member list, resources, and future group activity ends immediately. Your contributions to shared content (such as messages, poll votes, reactions, and comments) remain with that content until its normal retention period ends. Games that have ended and completed or cancelled tournaments you participated in remain available to you as read-only personal history. You must first leave any game that has not ended and withdraw from any unfinished tournament; unresolved G-Credit balances must also be settled or, where the app permits, expressly waived before membership ends.
Group deletion: memberships, join requests, invites, live G-Credit balances, chats, announcements, polls, templates, saved group resources, and the group's live profile are removed. Games that have already ended, their rosters, and completed or cancelled tournaments are preserved for participating members until their normal retention period ends, with the deleted group's name and sport stored as a historical label. Credit transaction history is preserved with the deleted group's name as a historical label and its live group reference removed, as described in 7.4. A group cannot be deleted while it has a game that has not ended, an unfinished tournament, or a non-zero member G-Credit balance. The admin must re-enter their current password and type the exact group name. Associated stored images are queued for secure deletion with automatic retries.
7.4 Credits, Billing, and Financial Records
Credit transaction records, Admin Plan billing invoices, and subscription records are retained for up to 7 years where needed for applicable record-keeping, audit, fraud-prevention, and dispute-resolution purposes. If your account or group is deleted before then, direct account and group references are removed where possible for the remainder of the period. Resolved credit requests are retained for 2 years.
7.5 Notifications, Push Tokens, and Security Data
In-app notification records are retained for 90 days. Push notification tokens are deleted immediately when you log out of the app, and any token not used for 180 days is automatically purged. MFA verification codes are purged within 24 hours. Feedback you submit is retained for up to 2 years.
7.6 Backups
Our database is backed up automatically every day for disaster recovery. When data is deleted from the live database — whether by you, by an admin, or by an automatic retention purge — residual copies may persist in these backups for a short period until the backups are overwritten on their normal rolling cycle. Backups are never used to restore individually deleted content, are not accessible through the app, and are not used for any purpose other than recovering from a system failure.
8. Your Rights and Choices
8.1 Access and Correction
You can view and update your profile at any time within the app (Profile → Edit Profile).
8.2 Notification Preferences
Manage notification types and mute specific groups within the app (Profile → Notification Settings). You can also revoke push notification permission via device Settings.
8.3 Permission Management
- IOS: Settings → Privacy & Security → [Permission] → GameTab
- Android: Settings → Apps → GameTab → Permissions
8.4 Account Deletion
Permanently delete your account from within the app (Profile → Settings → Delete Account). GameTab currently supports one admin per group. Before deleting an admin account, every group that account administers — including an inactive or disabled group — must first be deleted through the normal group-deletion process. Member-only accounts do not need to leave every group manually, but all users must settle outstanding credit balances, resolve non-zero Admin Plan invoices, leave games that have not ended, and withdraw from unfinished tournaments. Account deletion requires typing DELETE and re-entering the current password.
If you can no longer access the app, you can also request account deletion by emailing [email protected] from the email address registered to your account. We will verify the request and complete the deletion within 15 days. A standalone summary of both options is also available at nexavyn.com/gametab/delete-account.
Deleted permanently: database records below are removed in the account transaction. The stored profile-photo prefix is queued in that same transaction for secure Storage deletion; automatic retries handle temporary Storage failures.
- Your profile (name, phone, photo URL, bio, location, sport skills, preferences) and the queued stored profile-photo file
- All group memberships and roles, and pending join requests and invites
- Your reactions on announcements
- Your personal score logs (My Stats). Score entries other players logged that mention you are their records and keep the name recorded at entry.
- All push notification tokens and in-app notifications
- Feedback records linked to your account
- Your authentication credentials (email login, password, sessions, MFA records)
Shared records that remain after the direct account link is removed (shown as "Deleted User" where applicable), so that other members' history and records retained for the purposes above stay intact:
- Game participation records within their normal retention window
- Tournament match history and poll vote counts
- Comments you posted on announcements, shown as "Deleted User"
- Credit transactions, subscription, and billing records — retained with direct account links removed for up to 7 years where needed for the purposes in 7.4
- Chat messages you sent are no longer linked to your account (they display the name recorded at the time of sending) and are purged on the normal 90-day cycle
Limited audit record: to meet legal, fraud-prevention, and compliance obligations, we keep a minimal deletion record (your name, email address, plan, deletion date, and aggregate account statistics — no activity content) for up to 7 years, stored separately from the live app and not visible to any user. Your email address is also blocked from re-registration for 24 hours after deletion.
Backups: residual copies of deleted data may persist in our automated daily backups for a short period until those backups are overwritten on their normal rolling cycle (see Section 7.6). Backups are used only for disaster recovery and are never used to reinstate deleted accounts.
8.5 Data Export / Access Request
To request a copy of your personal data, contact us at [email protected]. We will respond within 15 days.
9. Children's Privacy
GameTab requires users to be at least 16 years old (see our Terms of Service), and the app is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child under 16 has created an account or provided us with personal information (including as a guest player added by an admin), contact us at [email protected] and we will promptly delete it.
10. Analytics and Crash Reporting
GameTab uses Sentry (provided by Functional Software, Inc., sentry.io) to automatically collect crash reports and error diagnostics when the app encounters a problem.
Sentry may collect:
- Device model and operating system version
- App version at the time of the crash
- A stack trace of the error
- An anonymised user identifier (a one-way hash of your Supabase user ID — not your name or email)
This information is used solely to identify and fix issues in the app. It is not used for advertising, behavioural profiling, or any purpose other than app stability. Sentry data is handled under Sentry's privacy policy, available at sentry.io/privacy.
GameTab does not currently use any third-party analytics services beyond crash reporting.
11. Data Breach Notification
In the event of a data breach that is likely to result in serious harm, we will notify affected users and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches (NDB) scheme.
Notifications will be sent to the email address associated with your account and/or posted at nexavyn.com/gametab/privacy.
12. Australian Privacy Act
Nexavyn operates in Australia and complies with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Under Australian privacy law, you have the right to:
- Know what personal information we hold about you
- Access your personal information
- Correct inaccurate, incomplete, or out-of-date information
- Request deletion of your personal information
- Complain about a breach of the APPs
To exercise any of these rights, contact us at [email protected]. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
13. Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of Australia. Any disputes relating to this policy shall be subject to the jurisdiction of Australian courts.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the updated policy at nexavyn.com/gametab/privacy and updating the "Last Updated" date above.
15. Contact Us
For privacy questions, data requests, or to report a concern:
We aim to respond within 15 days.
Typical support response time: 1-2 business days.
You can also use the in-app Feedback form: More → Leave Feedback