Template copy. This page describes how Rally handles the data it processes to operate the app. Review with your legal counsel and align it with each marketplace's data-use policy before launch.

Data Terms

Last updated: July 29, 2026

These Data Terms explain what data Rally accesses, why we access it, and the limits we place on how it is used. They supplement our Privacy Policy and Terms of Service. Where a distribution marketplace or platform (for example an app store or an OAuth provider) imposes stricter data-use requirements, those requirements also apply.

1. Limited use — functionality only

Rally accesses and processes data solely to provide and improve the features you use. Specifically, the data Rally handles is:

  • used only to provide or improve user-facing functionality within the app;
  • not sold, rented, or licensed to third parties, and not transferred except to provide the service, comply with law, or as part of a merger the user is notified of;
  • not used for serving advertising, including retargeting, personalized, or interest-based advertising;
  • not read by humans unless we have your consent for specific data, it is necessary for security (such as investigating abuse), it is required by law, or the data has been aggregated and anonymized.

2. What data we access and why

We only request the data needed to make a feature work. Each category below maps to a specific purpose:

  • Account details (email, name, avatar) — to create and secure your account and identify you to accepted connections.
  • Sports profile & per-sport attributes — to match you with players in a comparable skill range.
  • City / region (not precise location by default) — to surface nearby players, events, and facilities.
  • Events, connections & participation history — to run event discovery, mutual-consent connections, and your session history.
  • Feedback & ratings — to maintain community trust and safety.
  • Technical logs (IP, user agent) — for security, abuse prevention, and reliability.

3. Third-party services (sub-processors)

We use a small number of vetted service providers to operate Rally — for example hosting, database, and authentication infrastructure. These providers process data only on our instructions to deliver the service and are bound by confidentiality and data-protection obligations. They are not permitted to use your data for their own purposes.

4. API & developer access

If you access Rally data through our API or an integration, the same limited-use commitment applies to you: data obtained through the API may be used only to provide functionality to the user it belongs to, must not be sold or used for advertising, and must be handled under a privacy policy at least as protective as this one. Scopes are granted on a least-privilege basis and users can revoke access at any time. See the Developers page for details.

5. Security

We protect data in transit and at rest using industry-standard encryption, restrict internal access on a need-to-know basis, and maintain logging and monitoring to detect misuse. No system is perfectly secure, but we work to hold data to a standard appropriate to its sensitivity.

6. Retention & deletion

We retain data only as long as it is needed to provide the service. You can export or delete your data from your profile settings, and deleted accounts are removed within 30 days, except where retention is required for legal, safety, or fraud-prevention reasons.

7. Changes

If we materially change how we use data, we will update this page and, where appropriate, notify you in the app. Continued use after an update means you accept the revised terms.

8. Contact

Questions about how we handle data? Email hello@rally.app.