Privacy Policy
1. Who we are
Play Badminton Now (we, us, our) is a mobile app that helps badminton players in Australia find and host casual sessions. The app is operated by Wei-kai Lin (sole trader) of 39 Palace St, Ashfield, NSW 2131, Australia. You can reach us at weikaiau@gmail.com.
This Privacy Policy explains what personal information we collect, how we use it, and the choices you have. It is written to comply with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
If you are in the European Economic Area or the United Kingdom, please also see the “International users” section below.
2. What we collect
We only collect what we need to run the app. You decide most of what to share.
From you, when you sign up and use the app
- Account identifiers — email address (and a Firebase Authentication user ID assigned to your account). If you sign in with Apple, we receive your Apple-provided email (which may be a private relay address) and the authentication token; we do not receive your Apple ID or password.
- Display name — chosen by you, visible to other players on the sessions you join or host.
- Optional profile content — profile photo, short bio, dominant hand, skill level, racket details, language preference, notification preferences. You can leave any of these blank.
- Payment identifier — if you choose to host, you may save a PayID (email or phone number) so other players can pay you directly. We display this only to players registered on your sessions; we never process or hold money.
- Phone number — optional, only collected if you provide it.
Generated by your use of the app
- Session activity— sessions you host or register for, your waitlist position, payment status (e.g. “pending payment”, “paid”), the time you registered or cancelled.
- Credit score and history — an in-app number we maintain to track reliability (e.g. cancellations within a cutoff window deduct credit). The history is visible to you in the app.
- Friend connections — the user IDs of players you have added as friends. Adding a friend is opt-in for both sides.
- Payment proof uploads — if a host requires it, you may upload a screenshot of a payment transfer. The host can view it to confirm payment.
- Recent joined sessions— the last 20 sessions you joined, used to power your public profile's “this week” list (which you can hide in settings).
Generated automatically
- Diagnostic logs and crash reports — we use Firebase Crashlytics and Cloud Functions logs to debug problems. These contain technical identifiers (e.g. anonymous device identifiers, app version), not the content of your messages or photos.
- Approximate region — derived from your IP at sign-in by Firebase for abuse prevention. We do not collect precise GPS location.
What we DO NOT collect
- Precise GPS location of you or your device.
- Health, biometric, or financial-account data (your PayID is an alias, not a bank account number).
- Contacts, photos, microphone audio, or camera video other than the profile/payment screenshots you explicitly upload.
- Cross-app tracking identifiers, advertising IDs, or any data used for third-party ad targeting.
- Children's data (the app is intended for ages 13+ — see section 9).
3. How we use it
We use your information only to:
- Authenticate you and keep your account secure.
- Show you sessions, run registration and waitlist logic, calculate cancellation deadlines and credit changes.
- Show your display name and profile to other players on shared sessions and on your public profile.
- Send transactional notifications (e.g. “you have been promoted from the waitlist”, “payment confirmed”). You can adjust email notifications in settings.
- Detect and prevent abuse (e.g. spam accounts, repeated no-shows).
- Improve the app (debugging crashes, fixing bugs surfaced in logs).
- Comply with legal obligations.
We do not sell your personal information. We do not use it for advertising, profiling, or any automated decision-making with legal effect.
4. Who we share it with
- Other players— your display name, profile photo, bio, dominant hand, skill level, racket details, and “recent joined sessions” are visible to any signed-in user who lands on your public profile. Your payment proof is visible only to the host of the session you uploaded it for. Other fields (email, phone number, PayID) are visible only as documented above.
- Firebase / Google Cloud— we use Firebase (a Google product) for authentication, the database (Cloud Firestore), file storage (Cloud Storage for Firebase), serverless functions (Cloud Functions), and crash reporting. Data is stored in Google's
australia-southeast1region (Sydney). Google processes this data on our behalf under their terms. See Google Cloud's privacy practices. - Apple— if you sign in with Apple. Apple's privacy policy applies.
- Expo / EAS — used only for the build pipeline, not for runtime app data. See Expo's privacy policy.
- Service providers we directly engage — e.g. email sending if we later add a transactional-email vendor. We will update this policy and, where required, ask for consent before adding any new categories of recipient.
- Law enforcement / regulators — only when we are required by valid legal process (a subpoena, court order, or similar) or to protect the safety of users or the public.
We do not transfer your personal information to anyone else for their own marketing or analytics purposes.
5. How long we keep it
- Active accounts — for as long as you use the app.
- Deleted accounts — when you request account deletion in the app, we mark your account as soft-deleted and schedule a hard delete for 30 days later. Signing back in during that window does not automatically cancel the deletion; contact support before the scheduled hard-delete date if you made the request by mistake.
- After hard delete — we remove your user record from Firebase Authentication and your
users/{uid}document from Firestore. Friend edges referencing you are removed. Historical records that reference your user ID (e.g. a past session you joined) may remain for the host's own record-keeping but no longer link to identifiable data about you. - Logs and backups— diagnostic logs and database backups expire on Google Cloud's default retention schedule (typically 30 to 90 days).
- Legal holds — we may retain specific data longer if required by a legal obligation or to defend against a legal claim.
6. Your choices and rights
You can, at any time:
- Access and reviewthe personal information we hold about you (most of it is visible in the app's Profile section).
- Correct or update your profile in the app.
- Delete your account in the app (Profile → Delete account). Subject to the 30-day grace period in section 5.
- Withdraw consentto optional email notifications in the app's Notifications settings.
- Ask for a copy of your data in a portable format by emailing us at weikaiau@gmail.com. We will respond within 30 days.
- Complain to the Office of the Australian Information Commissioner (OAIC) if you believe we have mishandled your personal information.
7. Security
We rely on Firebase's authentication, encryption-in-transit (HTTPS), and encryption-at-rest. Payment proof images live in private Cloud Storage buckets, gated by Firestore-rule checks so only the relevant host can read them. We do not store passwords ourselves — they are managed by Firebase Authentication.
No system is perfectly secure. If we become aware of a security incident that materially affects you, we will notify you as required by Part IIIC of the Privacy Act 1988 (Notifiable Data Breaches scheme).
8. International users
The app is targeted at users in Australia, but signing in from outside is not blocked.
- If you are in the European Economic Area or the United Kingdom, the legal basis for processing your personal information is (a) the contract between you and us when you create an account; (b) our legitimate interest in running and securing the app; and (c) consent where you provide optional information. You have additional rights under the GDPR / UK GDPR, including the right to data portability and the right to object to processing. Contact us at weikaiau@gmail.com to exercise these rights.
- Cross-border transfer — your data is stored in Google's
australia-southeast1region. If you are outside Australia, your data is transferred to Australia for processing.
9. Children
The app is not directed to children under 13. If you are under 13, please do not create an account. If we learn we have collected personal information from a child under 13 without parental consent, we will delete it.
In Australia, hosts and players under 18 should have a parent or guardian's permission before signing up.
10. Changes to this policy
We may update this policy from time to time. When we do, we will change the “Last updated” date at the top. For material changes (e.g. new categories of data, new third-party recipients), we will notify you in the app or by email before the change takes effect.
11. Contact
For privacy questions or requests, email or write to:
- Email: weikaiau@gmail.com
- Mail: 39 Palace St, Ashfield, NSW 2131, Australia
See also: Terms of Service