Privacy Policy
Effective date: 12 August 2026 Last updated: 4 October 2026
Squad Tactics for REMATCH™ ("the app") is a private, invite-only tool for coaches of REMATCH teams. It is operated by Tunnel Vision Gaming LLC, an Ohio limited liability company ("we", "us"), and you can reach us at info@tunnelvisiongaming.com.
This policy explains what the app stores, why, and who else can see it. It forms part of the Terms of Service.
Who is responsible for what. We are responsible for the data about your own account (§1, §1b). For the data a coach enters about their players (§2), the coach decides what is recorded and why, and is responsible for it - its "controller" under laws that use the term. We store and process that data on the coach's behalf, to run the app.
In short
- Access is invite-only. Coaches need an invite code to create an account; players join through their captain's sign-up link.
- Paying for a plan happens on Stripe's own pages. We never see or store your card; we hold Stripe's ids for you and your plan, the plan's status and dates, and never the card.
- We store what you type in: your teams, players, formations, lineups, notes, and the lines you leave in a club's captains' chat.
- The app runs no analytics, advertising or cross-site tracking. The only cookies are the ones the app needs to work.
- We do not sell personal data or share it for advertising. The email we send is listed in §1, with the switches that turn it off.
- You can delete everything yourself, whoever you are, without emailing anybody. See Your Data, or §6 and §7 below.
- Share links go to anyone holding both the link and your team's captain PIN. That is their purpose, and it is the main way data leaves the app.
- Most of the personal data here is about other people, your players. §2 matters most.
1. Data about you, the coach
When you sign in with Discord, Discord tells us the first five of these. The rest we record ourselves as you use the app, and the last row comes from Stripe if you take a paid plan:
| Data | Why |
|---|---|
| Discord display name | Shown in the app header and as the author of instructions on shared plans |
| Discord avatar URL | Same |
| Email address | Identifies your account, and is where we send a weekly summary of your clubs' captains' chats |
| Discord user ID | Identifies your account, and is what your access is recorded against |
| OAuth tokens issued by Discord | Kept by the authentication library to maintain the connection |
| When you accepted these terms, and which version | So we know whether to ask again after a material change |
| When you last signed in, and roughly when you were last here | So we can tell an account in use from one that is not, which matters when the beta plan ends |
| Which plan you are on and its status, when your trial and billing period end, and when your plan ends if you have canceled | So the app knows what your clubs may hold and your account page can say where you stand |
| How many minutes of live pointers the clubs you own use each month, and until when your own use on a board is already counted, kept for a day after | So a plan's monthly pointer hours can be counted, and nobody is counted twice. Never where anybody pointed |
| Stripe's ids for you and your subscription | So we can show your plan and open Stripe's billing page for you. Never your card: you type it on Stripe's page and Stripe keeps it |
The first time you sign in, we ask you to accept these terms and this policy before you can go any further, and to choose whether you want email from us. We record the date and which version you saw. If either document changes in a way that matters, we ask again rather than assuming the old answer still stands.
We request only Discord's default sign-in scopes. We cannot read your messages, servers, or friends, and we never post as you.
We send a weekly summary of your clubs' captains' chats. It can be turned off for one club from its menu, or for everything on your account page, and every message carries a reminder of where those switches are. Turning it off stops all of it; there is no separate marketing list you would still be on. The one exception is the single reminder the terms promise before the beta plan ends, which goes to every beta account whatever those switches say.
Messages you leave in a club's captains' chat are stored with your name against them and shown to every captain of that club, including anyone invited after you wrote them. A line can be answered, and a captain can tag another with an @: we record that you were tagged, and whether you have seen it, so the bell in the app can count it. Once a week, if your email is on and you have not muted the club, we email you a summary of its chat's last seven days: who posted, the start of each post, how many replies it had, and whether you were tagged. A week in which only you wrote sends nothing. You can rewrite a line you wrote, and we record that it was edited; we do not keep what it said before. Reacting to a line records which line, which reaction, and that it was you, and shows your name on the reaction to every captain of that club. You can delete any line you wrote, the club's owner can delete any line on their club, and deleting your account deletes every line you left on any club at once, along with every reaction you gave and the record of every tag you received.
The chat keeps one week. A line leaves the chat seven days after it was written, and is deleted within about a day of that, along with its reactions and the record of anyone it tagged. A post stays past that only while somebody has replied to it in the last seven days; once nobody has, it goes the same way, with its replies.
Live pointers on a tactics board. A tactics board has a Go live button, off until you press it. While it is on, the other captains of that club who have also pressed it see where your pointer is on the pitch and which marker you are dragging, for as long as you are there. Where you point is not stored: the positions pass through Ably (§5) and exist only while somebody is watching, so there is no record afterwards of where anybody pointed. What we do keep is how long: the minutes used each month across the clubs an owner holds, counted against that owner's plan (the table above). Turning live updates off, closing the board, or leaving the tab ends it.
We do not run analytics, so we do not build a profile of your device, location or browsing. Our hosting and live-pointer providers do see IP addresses as part of serving the app (§5).
1c. Why we use it
Where the law asks for a reason (a "legal basis"), these are ours:
- To provide the app you signed up for (performing our contract with you): your account, sign-in, teams, chat, scheduler, share links and plan.
- Because you agreed (consent): the weekly chat summary email. You can withdraw it at any time with the switches in §1.
- For our legitimate interests: keeping the app secure, preventing abuse and trial misuse, telling beta accounts before the beta ends, and enforcing our terms. We weigh these against your rights, and they never include advertising.
- To meet legal obligations: payment and tax records, and lawful requests from authorities.
1a. Opposing captains who booked fixtures
Until October 2026, an opposing captain could book a fixture with a club here through an invite link. That feature has been removed.
Booked fixtures became plain entries in the club's game log, without the other captain's details. The old records, including any handle, Discord name or email address a visiting captain gave us, have been deleted from our database. Our email provider keeps its own delivery log, which is theirs — see §5.
1b. Players who sign in
A captain can share a sign-up link with their team. A player who opens it and signs in with Discord gets an account of their own, and Discord tells us the same things it tells us about a coach (§1). We also record:
- which roster name they claimed, on which team, and when
- the hours they enter for that name (§2)
- the sign-in and terms dates in §1
Who sees what. The team's captains and co-captains see the player's Discord name and avatar beside the roster name they claimed, and their hours. Teammates signing up see only that a name is taken, never by whom. Nobody else on the team sees the player's email address.
A player account cannot create teams and is never charged. It can download and delete its data like any other account (§6, §7).
2. Data you enter about other people
This is the most important section. The app is built for you to record information about your players, who are not users of the app and have not agreed to anything with us.
For each player you may store: a gamertag, gaming platform, jersey number, preferred positions, links to their Rematch Tracker and u.gg profiles, playstyle tags, the skill ratings and work rate you give them, who they play best with or clash with, and free-text notes and instructions you write about them.
Ratings, work rates and player links are never shown on a share link. Only you and your co-captains see them.
The terms ask coaches to identify players by their in-game handle rather than their real name. We cannot enforce that, since no rule tells the two apart, so what is actually stored depends on what your coach typed.
Two consequences:
- You decide what goes in. We do not verify it, and we would rather you did not put anything in a note you would be uncomfortable with that player reading. Assume they may see it, since many of these fields are shown on shared plans by design.
- You are responsible for that data. Under the Terms of Service you confirm you have a proper basis for recording information about your players, and you handle their requests about it. We will help you find, export, or delete it.
Profile links are stored as text only. The app never contacts Rematch Tracker or u.gg, and nothing is fetched from them. Their site icons are served from our own servers, so simply viewing your roster does not tell those sites anything.
When a player fills in their own hours. A captain shares the team's sign-up link. A player opens it, signs in with Discord, picks their roster name, and saves:
- the hours that player is usually free each week
- weeks that differ, or that they are away
- the time zone they entered those hours in
The sign-up page shows roster names only to somebody signed in. A player sees their own hours and nobody else's. The captain and co-captains see everyone's hours together, to find times the team can play, and can enter or change any player's hours themselves, for players who never sign up.
Until October 2026 players entered hours through a link that opened with the team PIN instead of a sign-in. Those links no longer open anything; the hours entered through them stay with each roster name.
Hours are kept until that player is removed from the roster or the team is deleted. One-off weeks are deleted within about a day of being over. A player can clear their hours on their own page, or delete their account, which deletes them too (§6).
3. Share links (the part that leaves the app)
Creating a share link publishes a read-only page at /share/<token> that anyone with both the link and your team's captain PIN can open without signing in. It shows:
- the plan's name, which carries the opponent's club name and the match date
- both game plan sections, Defense and Attack, with their lineups, formations, and the team's name, tag, competition, region and preferred style
- each player's display name, playstyle tags, and the instructions written for their position in each phase
- any team notes you marked as shown on the plan
- your Discord display name and avatar, as the author of those instructions
Two things gate it. The token is 16 bytes of cryptographically random data, so the URL is not practically guessable. The captain PIN is a 4-to-8 digit code you set per team; without it, the page shows only a PIN prompt and reveals nothing about the plan. Not the team name, not the opponent.
Be realistic about what a short PIN buys. It stops a forwarded link from being a working link, which is its job. It is not account-grade security: a determined attacker who has your token could try to guess a 4-digit PIN, and our rate limiting is best-effort. Treat a shared plan as something that could still leak, and do not put anything in it you would not accept becoming public.
We store the PIN only as a salted scrypt hash. Once it is saved, nobody can read it back, including us and including you. Changing the PIN immediately locks out everyone who had already entered the old one.
A new share link stops working 90 days after it is created or last extended. While it still works, a captain can extend or revoke it from the plan's page. Links created before share links had an expiry keep working until they are revoked. Any link also stops working when its plan or team is deleted, or when you remove your team's PIN, which takes every one of that team's plans offline. Revoking is immediate.
4. Cookies
Every cookie the app sets is below, and none of them is used for tracking.
Signing in
- the authentication cookie, set by the authentication library, holding your signed-in session
- while you sign in with an invite code, a pass saying the code was accepted; and while you accept a co-captain invitation, which invitation it is. Each lasts 30 minutes and is read once, by sign-in. The same goes for which team's sign-up link a player is signing up through.
Shared plans
- an unlock cookie set on a share page after the right captain PIN is entered, so a player does not retype it on every reload. It holds no personal data, only a signed value tied to that one link. It is scoped to that one plan's URL, and expires after 12 hours.
Display preferences
- whether a club's pages are painted in its kit colors, set only when you use that switch in the account menu
- which clubs' captains' chat you have folded away, set only when you fold one. It holds those clubs' ids and nothing else.
The two display preferences stay on that browser for a year, are read only by the app, and change nothing but how its pages look.
There are no analytics, advertising, or tracking cookies, so there is no consent banner to click.
5. Who else processes your data
| Provider | Role | What they see |
|---|---|---|
| Vercel | Hosting | Serves the app; standard server logs including IP addresses |
| Neon | Database | Stores everything described above |
| Discord | Sign-in | Knows you authorized this app; sees a request when a browser loads your avatar |
| Resend | The address of anyone we email, and the subject and body of each message, including the chat lines quoted in a weekly summary | |
| Ably | Live pointers on a tactics board, and only while live updates are on | Your IP address, a code that stands for you on that one board, which board you have open, where your pointer is on the pitch, and which marker you are dragging. Never your name, your email, or anything drawn on the board. Ably holds each message for two minutes so a captain whose connection drops can catch up, and keeps nothing after that |
| Stripe | Payment, if you take a paid plan | Your email and name, the card you type on Stripe's own page, and every invoice. We never see the card. Stripe keeps its payment records under its own retention rules, including after you delete your account here, and we match a later account with the same email to that record so a trial cannot be started twice |
These providers process data on our behalf under their terms and data processing agreements. This is the list we use today; if it changes, we update this page.
When we may disclose data. We do not sell personal data or give it to anyone for their own marketing. We may disclose it only:
- when you direct it - for example, by creating a share link (§3);
- when the law requires it, such as a valid subpoena or court order, or to protect the rights, property or safety of our users, the public or us, and to investigate fraud or abuse;
- as part of a merger, acquisition, financing, sale of assets or similar transaction, or in a bankruptcy. Whoever receives the data must honor this policy for data collected under it.
Where data is stored. The app and its database run in the United States, and our providers may process data in other countries. Where data about people in the European Economic Area, the United Kingdom or Switzerland leaves those places, we rely on the safeguards our providers offer for such transfers, such as standard contractual clauses.
Resend keeps a log of what it sent and to whom. That log is theirs and it outlives what the message was about, so deleting a chat line here does not recall a summary that already quoted it. Open tracking and click tracking are switched off, so no message carries a tracking pixel and no link in one is rewritten to count clicks.
Avatars are loaded directly from Discord's CDN, so a person viewing a shared plan makes a request to Discord. We send that request without a referrer, so Discord is not told which plan was being viewed.
6. Keeping and deleting data
We keep data for as long as your account exists, because the app is a working record you come back to between matches. Two things run out on their own: a club's captains' chat keeps one week, as described above, and a share link stops working after 90 days unless a captain extends it (§3).
What you can delete yourself, from inside the app:
- individual players, playstyle tags, formations, lineups, share links, and any line you left in a club's chat
- a whole team, which also removes its players, lineups, instructions, share links, scouting sheets, and its chat
Deletions take effect immediately and are not recoverable. Backups held by our hosting providers may retain copies for a short period afterwards.
Deleting your entire account is self-serve. Your account page has a button that erases your account and everything under it: every team, player, formation, lineup, set piece, game plan, scouting sheet, share link and game, plus every line you left in any club's chat and the sign-in tokens Discord issued. There is no grace period and no way back.
If you have a paid plan, deleting your account cancels it at once, with no refund for the rest of the period.
Players. Releasing a roster name, or a captain unlinking it, removes the link between the account and the name. The hours stay with the name, which is the captain's record. Deleting a player's account deletes the claim and the hours on every name it claimed; the names themselves stay on their teams.
Three things outlive it, and none is used for anything here:
- our email provider keeps its own delivery log — see §5
- Stripe keeps the payment records it is required to keep — see §5
- our hosting providers keep short-lived backups, which roll off by themselves
We may also keep the minimum needed where the law requires it, or to resolve a dispute, enforce our terms or prevent fraud or abuse - for example, a record that an account was removed for breaking the terms.
7. Your rights
Depending on where you live, you may have rights to access, correct, export, delete, or restrict the use of your personal data, and to complain to a data protection authority.
We offer all of these to everybody, wherever you live. Working out who is covered by which law would mean tracking where you are, which is a worse trade than simply giving everyone the same rights.
In practice, and without emailing anyone:
- Access and export: your account page has a Download my data button that gives you one JSON file with everything held about you and everything you have entered. Rosters and lineups also export as CSV.
- Correction: edit it in the app.
- Deletion: see §6. A player who signed in can remove their hours on their own page, release their name, or delete their account (§2, §6).
- Objection and withdrawing consent: turn off email with the switches in §1, or email us.
For anything the buttons do not cover, email us. We answer within 30 days, may ask you to confirm the account is yours first, and may decline where the law allows or requires - for example, to protect someone else's data. You will not be treated differently for using these rights.
Your Data walks through all three, for coaches, for players who signed in, and for players whose coach entered them.
For data a coach entered about you as a player, ask your coach first. They entered it, they control it, and they can edit or delete any of it in seconds. If you contact us directly, we will pass the request to your coach, and if they do not act within a reasonable time we may remove the data ourselves.
U.S. state privacy laws. We do not sell or share personal information as those laws define it, and do not use it for targeted advertising. Residents of states with privacy laws can use the rights above. Because we do not track you across sites, Global Privacy Control and Do Not Track signals have nothing further to switch off.
8. Security
- A new account needs an invite code, a co-captain invitation, or a team's sign-up link. Each is checked before the account is created, so someone who has none leaves no record behind at all. Wrong codes are rate limited, though that limit is best-effort.
- The app is built so that every query is scoped to the signed-in owner inside the query itself. Another coach's data returns "not found" rather than "forbidden", so the app never confirms that someone else's team exists.
- Traffic is HTTPS-only and the app sends HSTS,
X-Frame-Options,X-Content-Type-Options, and a referrer policy. - Links you paste are restricted to
httpandhttpsbefore they are ever rendered as clickable.
No system is perfectly secure, and we cannot guarantee the security of your data. If a breach affects your personal data, we will tell you and the authorities as the law requires. If you find a vulnerability, please email us rather than disclosing it publicly.
9. Children
The app is not directed at children. You must be at least 16 (or the age of digital consent where you live) to have an account, and 18 to buy a plan. We do not knowingly collect personal data from children under 13. If we learn that an account belongs to someone under the minimum age, we delete it. If you believe a child has given us personal data, email us.
Esports rosters often include minors. If you record data about a player under that age, you are responsible for having their guardian's permission, and we would encourage you to keep such notes to the minimum the team actually needs.
10. Changes
If we change this policy we will update the date at the top. If a change materially affects how your data is used, we will tell you directly and ask you to accept the new version before you continue using the app.
11. Contact
Tunnel Vision Gaming LLC, info@tunnelvisiongaming.com