Skip to content
aftermatch

Privacy policy

aftermatch is built around a sensitive moment: everyone secretly picks the best and the worst player of the match, and the team counts the ballots together at the clubhouse. This page says exactly what we record, who sees it, how long it stays, and what you can ask for. It also says what we do not guarantee - the part most privacy policies leave out.

Last updated: 25 août 2026.

These pages cover three addresses: aftermatch.be, the site you are reading; app.aftermatch.be, the app your team uses; club.aftermatch.be, the club space.

Who decides what

Two separate responsibilities, and they must stay apart. For everything to do with the sport - the squad, the matches, the goals, the cards, the ballots and the reasons - your club is the controller and Oak Eye is only its processor: we carry out, we do not decide. As long as no club has claimed its space, that role is held in practice by the staff who created the team. For the rest - your account, your session, audience measurement, handling claim requests, service emails and billing - Oak Eye is the controller and answers directly for what it does.

You came in through a link, or you were signed up

If you joined your team through its invitation link, you gave your first name, last name, email and password yourself, and you can add a nickname, a shirt number and a phone number. All of it is editable from your profile.

If the staff added you to the squad without any action from you, your record exists with your first and last name, and possibly your email and shirt number. That data comes from your staff, not from us. You can be voted for from the next match on, but you cannot sign in until your account has been activated: it is your staff who passes on the team invitation. You can ask to leave the squad at any time, at privacy@aftermatch.be.

What we record

Your account

First name, last name, email, hashed password, and whatever you add yourself: nickname, shirt number, phone, language, two personal colours. The email is used to sign in, to reset a password and to receive invitations: it is visible only to the members of your teams and, if you are team staff, to your club's space.

Your photo

Nobody can upload your photo on your behalf: the only route that writes a portrait takes the person from your session, never from a player id. Your staff cannot put a face on a teammate's record. The file you send is never stored as received: it is decoded in memory, re-encoded to WebP at 512 pixels, and whatever it carried - GPS position and device, if they were there - goes with the re-encoding. We keep the date of the upload and the IP address it came from, because that is what lets us say a photo was placed by its subject and not by someone else. You remove it whenever you like: the file is erased from disk, not merely hidden. On the club-house screen, the one a club plugs into the bar's TV, your photo only appears if you allow it in your profile: it is off by default, and the screen shows your shirt number instead. Your full name does appear - a club-house board names its players, that is what it is for.

Matches and the match sheet

Date, opponent, home or away, score, and the match sheet: one goal per line with its phase of play - open play, penalty corner, stroke -, the scorer, the assist if there is one, and the green, yellow and red cards with the player concerned. Those lines feed the season rankings. They are readable only by the team's members, and by the club space if the staff has opened match encoding to it.

Your ballot

One ballot per match and per person: the best player and why, the worst player and why, up to 500 characters each. You can change it as long as the staff has not closed the votes; after that it is fixed. The link between a ballot and its author exists in the database - it is what guarantees one ballot per person and lets you come back to yours - but no response from the app ever returns it, to anyone: not to your staff, not to your club's administrator, and not to us from our own console.

Secret, not anonymous

We write secret, never anonymous, and the difference is not cosmetic. Anonymous would mean nobody can tie a ballot back to its author; that is untrue, the link is stored. Secret means the app exposes it nowhere: it never returns a ballot's author, the reading order at the count is drawn at the moment you confirm - whoever voted first is not read first - and you are removed from your own picker, you cannot vote for yourself.

What secrecy cannot do

In a group of twelve, a writing style is recognisable, an absentee can be worked out, a turn of phrase gives you away. No software can prevent that, and we will not pretend otherwise: secrecy protects against a display, not against a deduction made at the clubhouse. Know it before you write a reason, and the staff running the count should say it out loud.

If you were named worst player

This is the question nobody asks and the one that matters most. Being named, and the reason that comes with it, is readable by your team's members in the match retrospective, for as long as the team uses aftermatch. One thing is certain, though: it does not leave the team, nor the room where it was read out. The card shared on social media can only carry the best player - the app accepts no name as a parameter, so nobody can build a worst-player card - and your portrait only appears on it if you are the one sharing your own card. When the club has a screen at the bar, during the count it shows the names and the votes as they climb, yours included: same room, same people who already hear it. The reason never reaches the screen - it stays on the staff's phone, who reads it aloud. To have a reason taken down, write to privacy@aftermatch.be: we read it, we remove what is plainly degrading, and you get an answer even when the answer is no.

What the service records on its own

Your session keeps your IP address and your browser for 30 days: that is what recognises you from screen to screen and saves you retyping your password. Sign-in attempts are capped per minute and per address, so a bot cannot work through passwords. Administration actions - ours as well as a club's - are logged with their author, their target and the IP address, never with the content of a ballot.

The emails we send you

Password resets, invitations to join a team, call-backs when a club is claimed. Every send leaves a line in a log - recipient, subject, delivery status - used to answer 'I never got it' and to spot a dead address. That log is purged daily: past six months, the line is gone. No tracking pixel: opens and clicks are not recorded.

Vote reminders

If you turn them on, your browser creates a subscription with its vendor's relay - Google for Chrome and Android, Apple for Safari and iPhone, Mozilla for Firefox - and gives us its address and two keys. That address is what we call to push you a reminder, so it travels through those relays, part of whose infrastructure sits outside the European Union. The reminder says a match is waiting for your ballot, and nothing else: no player name, no content. It stops as soon as you have voted or the votes are closed, and we keep a record of reminders already sent so we do not repeat them. You switch it all off in your phone's settings, without asking us.

If you claim your club's space

The request records the role you hold, your phone number, your message, the date and the IP address it was filed from, and two declarations: that your committee has mandated you, and that you accept your request being announced to the members. We then verify through an official club channel we noted ourselves before your request - never a number you give us. The person we call back sees your first name, the initial of your surname and the role you claim; never your email, never your phone. The checks, their outcome and the reason for the decision stay on file, including for a refusal: that is what lets us account for it if anyone contests.

Audience measurement

We measure traffic with Oakeye Analytics, a tool we host ourselves, with no cookie and no identifier that follows you. Your IP address and your browser are received, but only in passing: they are used to work out a country, a device type and a visit identifier hashed for that day, then thrown away - they are never stored. The hashing salt is destroyed after 48 hours, which makes the calculation impossible to redo: we cannot recognise you from one day to the next, even if we wanted to. Writing 'we do not collect your IP address' would be false; that is why we put it this way.

On what legal basis

Treatment by treatment, never in one lump. Your account, your teams, your matches, your ballots and service emails: performance of the contract between you, your club and us. Security - sessions, sign-in rate limiting, the administration log - and identifier-free audience measurement: our legitimate interest in running a service whose accounts do not get stolen, weighed against what it costs you, which is little. Reviewing a club claim: our legitimate interest in not handing a club's member list to someone with no mandate. Billing and its accounting: a legal obligation. Push reminders: they only go out if you allowed them in your browser, and that permission is withdrawn in the same place.

Who else sees your data

Your team's members see what the team produces - squad, matches, match sheets, rankings, and reasons once the match has been counted. Your club's space sees its teams, their counters, its partners and its colours, plus the identity and email of team staff only: never a player's email, never a ballot, never a squad list. One exception, and it is deliberate: the club-house screen names the players it shows, in front of the people in the room - and the club sees that too, since it is the one plugging the screen in and setting it up. What it shows of you is decided inside your team and in your profile, never by the committee. Beyond that, four providers: OVH SAS for hosting, Mailjet for sending emails, the push relays of Google, Apple and Mozilla if you turn reminders on, and Oakeye Analytics for traffic. Mollie will join the day a club pays online; that is not the case today. We sell nothing to anyone, and there is no ad network: the partners shown in the app are the ones your club entered itself, and nothing about you is passed to them.

Transfers outside the European Union

One, and it is unavoidable: the push reminder travels through the browser's relay, so through Google, Apple or Mozilla, part of whose infrastructure sits in the United States. What travels is your subscription address and the text of the reminder - that a match is waiting for your ballot, nothing more. If that bothers you, do not turn reminders on: everything else in the app works without them.

How long

The email log: six months, purged automatically every day. A session: 30 days, after which it opens nothing. Your photo: until you replace or remove it. Your account, your matches, your ballots and their reasons: as long as your team uses aftermatch. Let us be blunt - no automatic purge runs on ballots today, and that is a gap, not a choice. A retention period will be set, implemented and published here. Until then, a request to privacy@aftermatch.be is handled by hand.

Your rights

Access what we hold about you, have it corrected, have it erased, ask for a copy, object to a processing based on our legitimate interest, ask for it to be restricted while we decide. This holds even if you have no account: a player whose record was created by the staff has exactly the same rights as someone who signed up themselves.

How to exercise them

By email, to privacy@aftermatch.be. There is no 'export my data' or 'delete my account' button in the app yet: the request lands in a mailbox and a human handles it. We answer within a month. Give your name, your club and your team - without that we cannot find you without digging, and digging is the opposite of what you are asking for.

Erasure has a limit, and it needs saying

If your name appears in a ballot already counted or in a goal, erasing it would break other people's history: a season ranking would change retroactively, a match would lose its scorer. In that case we do not erase, we anonymise - your name is replaced, the rest still stands. We tell you before we do it, and we tell you what remains. Cards already generated are the exception, and it is only fair to say so plainly: they are images that have left our servers, often already shared elsewhere. We cannot recall them. What we can do is make sure no new card carries your name.

What stays on your phone

The app is built to hold up without a network, so it keeps things locally. A ballot you confirm out of coverage sits in clear text on your phone until it goes out. The server's latest answers - rankings, squads with names, reasons - stay cached so the screen still opens without a network. Today, signing out clears neither: that is a known gap, and it matters if you lend your phone. Until it is fixed, uninstall the app or clear the site data from your browser - the cookies and local storage page explains how.

Minors

aftermatch asks for your date of birth at first login, and it is required - new accounts and existing ones alike. Without it the app does not open: it is what tells us which regime an account falls under, and guessing would mean treating a child as an adult. It serves that and nothing else: it is displayed nowhere, and nobody in your team sees it. From 13, you sign up and play on your own. Photo and full name appear on shareable content - a match card, the club-house screen - only if the player and one of their parents have both allowed it, each on their own side. Without both, it is a silhouette and « Tom L. ». One withdrawal is enough to close it again, and it applies to what is generated afterwards: what has already circulated cannot be recalled. Under 13, the guardian's space does not exist yet. Until it does, a profile under 13 cannot obtain any of those consents: it stays pseudonymised everywhere, without exception. If you run a youth team, write to contact@aftermatch.be: we would rather talk about it beforehand than discover the problem afterwards.

How it is kept

Passwords are never stored in the clear. Every read goes through a membership check written into the query itself: we do not ask 'is this person allowed?' after loading the data, we only load what they are allowed - which is what stops anyone seeing another club's team by changing an id in the URL, and it is covered by automated tests. Our own admin console forbids itself from displaying the content of a ballot. Uploaded files are re-encoded before being written, and SVG is refused: it is not an image, it is a document that can carry script.

If you are not satisfied

Write to us first, at privacy@aftermatch.be: most misunderstandings are settled in one exchange. If our answer does not satisfy you, you can lodge a complaint with the Belgian Data Protection Authority, rue de la Presse 35, 1000 Brussels, contact@apd-gba.be. That is your right, and we will not hold it against you.

For clubs: the data processing agreement

A club acting as controller must have a written contract with its processor. Ours exists, dated and versioned; it is not published as a free download, because a two-party contract is not a shop window. Ask for it at contact@aftermatch.be: it goes out with the answer.

If this page changes

We date it at the top. A change affecting what we collect, who sees it or how long it stays is announced in the app before it applies - not after.

Contact

A question about these pages, a report, a request about your data: contact@aftermatch.be. You get an answer, and we tell you what we do with it.

This page is written in plain language, without empty formulas. If a sentence is unclear, write to contact@aftermatch.be - that is on us.

Privacy policy | aftermatch