Privacy Policy
Effective date: August 31, 2026. This policy is written to comply with the Saudi Personal Data Protection Law (the “PDPL”) and its Implementing Regulations.
1. Who we are
MSL (Master Sport League) is a Riyadh-based multi-sport league app. For the purposes of the PDPL, MSL is the Controller of the personal data described in this policy — the party that decides what data is collected and why. This page is that policy, made available to you before we collect any of your personal data, as required by PDPL Article 12.
2. Definitions
- Personal Data: any data that could identify you, directly or indirectly (name, contact details, photos, and similar).
- Processing: any operation performed on personal data — collecting, storing, using, sharing, or destroying it.
- Controller: the party that decides what data is collected and why — MSL, for the data described here.
- Processor: a party that processes data on the Controller’s behalf — our three service providers, listed in “Who we share your data with” below.
- Sensitive Data: a narrower category under PDPL Article 1 covering racial/ethnic origin, religious or political belief, criminal records, biometric or genetic data, Health Data, and data indicating unknown parentage. MSL does not intentionally collect Sensitive Data.
- Data Subject: you — the individual the personal data is about.
3. What data we collect, and why
The table below lists every category of personal data MSL collects, whether it is mandatory or optional to provide, and why it’s needed. Fields marked mandatory are required to create and maintain your account — without them we cannot register you or run the league (PDPL Article 13¶5).
Account & identity data
- Name, username, email, password, phone number, date of birth (mandatory): used to create your account, log you in, verify your identity, confirm you meet our age requirement, and let other members recognize and reach you for session coordination.
- Gender (mandatory): shown on your profile so other members — particularly female members — have transparency about who they’ll be joining a session with before they sign up. Gender is not “Sensitive Data” under PDPL Article 1’s definition (which covers things like racial/ethnic origin, religious belief, health, and biometric data), so it does not require the extra safeguards that category carries.
- Which sports interest you, your fitness level, how you heard about us, your reason for joining (mandatory at registration): used by admins to review your application and match you to the right sessions.
- Profile photo, X/TikTok/Instagram handles (optional): let other members recognize you and find you off-platform, if you choose to share them.
Payment-display data (optional)
MSL never processes or moves money — session costs are split among attendees and settled directly between members (bank transfer, STC Pay, or Barq), outside the app. If you choose to add a bank name, IBAN, account number, or enable STC Pay/Barq, those details are shown only to other confirmed attendees of a session you owe money to or are owed money by — never published publicly. Bank details are encrypted at rest.
Activity & participation data
Generated automatically as you use MSL: session sign-ups and attendance, scores, peer ratings from other attendees, badges you’ve earned, and internal bookkeeping we use to keep the peer-rating system fair. This is the core of what MSL does — tracking play, ranking, and reliability.
Social & communication data
Direct messages, follows, and blocks between members; in-app notifications; and per-session group chat. Session chat is ephemeral by design — it is permanently deleted the moment a session ends, not retained as history.
Content involving other members
Reports you file against another member (or that are filed against you) for conduct concerns, general feedback you submit to admins, and any images you upload (avatar, payment-proof receipts).
Technical & security data
A session cookie that keeps you logged in (expires after 30 days); one-time tokens for email verification and password resets (only a hash is stored, never the raw token); a flag that identifies disposable email addresses at registration; and admin action logs kept for accountability. Your IP address is read only transiently, to rate-limit repeated login/registration attempts — it is held in memory for that purpose only and is never written to our database or logged.
4. Legal basis for processing
We process your personal data on the basis of your consent (PDPL Article 5), given when you register and accept this policy. You may withdraw that consent at any time — see “Your rights” below for how. Because running the league inherently requires processing your membership data, consent to this policy is a condition of registering (PDPL Article 7 permits this where the processing is directly necessary for the service itself).
5. How we collect, process, and store your data
We collect data directly from you — at registration, in Settings, and through your ordinary use of the app (signing up for sessions, messaging, rating others). Some data is computed automatically rather than entered by you (for example, a flag identifying disposable email addresses). Your data is stored in a managed PostgreSQL database and file storage provided by Supabase, and processed by the application code running MSL. We do not use your data for any purpose beyond running and improving the league — MSL has no analytics or tracking scripts of any kind.
6. Who we share your data with
We do not sell, rent, or trade your personal data to anyone, for any purpose. We share data with three service providers (Processors, under the PDPL), each strictly to deliver a specific part of the service:
- Supabase — our database and file storage provider. This is where your account data and any uploaded images are held.
- Resend — sends transactional email on our behalf (verification links, password resets, session notifications). We never send marketing email through this or any channel — see “Marketing” below.
- Cloudflare (Turnstile) — verifies you’re not a bot when you register, receiving only a widget-generated token, not your personal data.
Cross-border transfer notice (PDPL Article 29): our Supabase database is hosted in Tokyo, Japan. This means your personal data is transferred outside the Kingdom of Saudi Arabia for processing. We limit this transfer to what is necessary to operate the service, and we do not disclose your data to any other party outside the Kingdom.
Other than the three processors above, other MSL members, and administrators reviewing applications or moderating reports, we do not disclose your personal data to anyone.
7. How long we keep your data
- Account & profile data: retained for as long as your account remains active.
- Session chat messages: deleted immediately when the session ends — not retained as history.
- Email verification and password reset tokens: expire automatically 24 hours after being issued, and can only be used once.
- Session cookie: expires 30 days after login.
- Admin audit log entries: retained indefinitely, as non-identifying accountability records that don’t depend on your account still existing.
If you delete your account (see “Your rights” below), identifying data is anonymized and access is blocked immediately. Some non-identifying historical records may remain where they are shared with other members — for example, a session you organized stays on the record so other attendees’ history and the leaderboard remain intact — consistent with PDPL Article 18’s allowance to retain data that no longer identifies you.
8. Your rights, and how to exercise them
Under PDPL Article 4, you have the right to:
- Be informed of the legal basis and purpose of collecting your data — this policy.
- Access the personal data we hold about you.
- Request your data in a readable, clear format (data portability).
- Request correction, completion, or updating of your data — most fields can be edited directly from Settings; contact an admin for anything else.
- Request destruction of your data once it’s no longer needed, and withdraw your consent to this policy at any time.
How to exercise your right to erasure: from Settings → Account, you can permanently delete your account yourself, at any time, with no admin review required. This replaces every identifying field on your account (name, email, username, phone, date of birth, bank details, social handles, avatar) with a placeholder and immediately blocks the account from being used again — genuinely erasing your personal data, not just deactivating the account. Your historical session/score records may be retained in de-identified form where they are shared with other members (for example, a session you organized stays on the record so other attendees’ history and the leaderboard remain intact), consistent with PDPL Article 18’s allowance to retain data that no longer identifies you. Self-service deletion is paused only if there is an open conduct report against you, until an admin has reviewed it.
9. Marketing communications
We do not send marketing or promotional communications of any kind, by email or otherwise. Every email you receive from MSL is transactional — tied to an account action you took or a session you signed up for. If this ever changes, we will ask for your separate, explicit consent first, as required by PDPL Articles 25 and 26.
10. Minors
MSL is only available to individuals 18 years of age or older. Registration is blocked for anyone who does not meet this requirement, and we do not knowingly collect personal data from anyone under 18.
11. Cookies
We use two cookies: a session cookie that keeps you logged in, and a locale cookie that remembers your language preference. Neither is used for tracking or advertising.
12. Security
Passwords are hashed, never stored in plain text. Bank details are encrypted at rest. Session cookies are signed and marked secure/HTTP-only. We take reasonable organizational and technical measures to protect your data, consistent with PDPL Article 19.
13. Data breach notification
If we become aware of a breach, damage, or unauthorized access affecting your personal data, we will notify the Saudi Data & Artificial Intelligence Authority (SDAIA) as required by PDPL Article 20, and notify you directly without undue delay where the breach is likely to cause damage to your data or affect your rights and interests.
14. Changes to this policy
If we materially change how we collect, use, or share your data, we’ll update this page and may ask you to review and re-accept it. The effective date at the top of this page always reflects the version currently in force.
15. Complaints
If you believe we have processed your data in violation of the PDPL, you may submit a complaint to the Saudi Data & Artificial Intelligence Authority (SDAIA), the Competent Authority under the PDPL, in addition to raising it with us directly.
16. Contact us
For any question about this policy or your data, reach out to an MSL admin through the app.