This explains what Matchpoint collects when you book a court, join open play, or run a club on our console — and what we do with it. We do not sell your personal information, and we do not run advertising or third-party tracking in our apps.
This summary is here for speed, not for lawyering — the numbered sections below are the actual policy.
Your email, name, skill level, the courts you book, and the receipt for what you paid. Nothing is collected to build an advertising profile.
Card and GCash payments are handled on PayMongo's hosted checkout. We keep the amount, the method, and the reference — never your card number.
Front-desk staff at that club see your name, skill level, and payment status for their own courts. Other clubs do not.
Matchpoint (“Matchpoint”, “we”, “us”) operates the Matchpoint player app, the court booking site at booking.matchpointlinks.app, the club console used by club staff, and this website.
For the purposes of the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations, we act as the Personal Information Controller for the personal data described in this policy.
You can reach us about anything in this policy at hello@matchpointlinks.app.
This policy applies to personal data we process through:
It does not cover a club's own separate systems, or third-party services you reach from our apps — those are governed by their own privacy policies.
When you create an account we collect your email address. If you sign in with Apple or Google, we receive your email address (or Apple's private relay address) and, where you allow it, your name — we do not receive your password.
Card, GCash, and QR Ph payments are processed by PayMongo on their own hosted checkout. Your card number, expiry, and CVV are entered on PayMongo's page and are never sent to or stored on our servers.
What we store is the record of the transaction: the amount, the currency, the payment method type (for example “GCash” or “card”), the convenience fee applied, the status, and PayMongo's reference for it — so we can show you a receipt and settle with the club.
These are all optional, requested only when you use the feature, and can be revoked in your device settings at any time:
To keep you signed in, our apps store an authentication session on your device. Our infrastructure providers also generate ordinary server and security logs — including IP address, timestamp, and the request made — which we use to operate the service, debug faults, and prevent abuse.
Our apps ship with no third-party analytics, advertising, or attribution SDKs. We do not collect advertising identifiers (IDFA / GAID), we do not build behavioural advertising profiles, and this marketing site sets no tracking cookies and loads no third-party scripts or fonts.
We also do not collect your contacts, your calendar, your microphone or camera input in the player app, your precise background location, or your health and fitness data. We do not sell personal information, and we do not share it for cross-context behavioural advertising.
We do not use your personal data for automated decision-making that produces legal effects on you.
Under RA 10173 we process personal data on these criteria:
Where we rely on consent, you can withdraw it at any time — by changing the relevant device permission or setting, or by contacting us. Withdrawing consent does not affect processing already carried out.
Booking a court necessarily tells the club that you booked it. When you book at a club or join one of its open-play sessions, that club's owner and authorised staff can see:
A club sees only its own bookings and members. It cannot see your activity at other clubs, and it never sees your card details. Clubs are expected to use this information only to run their courts and to comply with RA 10173 in their own right.
Our providers operate data centres outside the Philippines, so your personal data is stored and processed abroad. When personal data is transferred outside the Philippines, we remain accountable for it under RA 10173 and rely on contractual commitments with each provider requiring a comparable level of protection.
Under RA 10173 you have the right to:
You can edit your name, photo, and skill level yourself in the app at any time. For access, portability, erasure, or anything else, email hello@matchpointlinks.app from the address on your account. We will verify your identity and respond within 15 days, and will tell you if we need longer or if an exemption applies.
Ask us at hello@matchpointlinks.app and we will delete your account and profile. Bookings already paid for stay in the club's financial records, and transaction records we are legally required to keep are retained as described above.
We use organisational and technical measures appropriate to the risk, including encryption in transit (HTTPS) and at rest, row-level access rules in our database so one account cannot read another's data, passwordless sign-in so there is no password of yours for us to leak, scoped access for club staff limited to their own club, and payment handling delegated to a PCI-DSS compliant processor.
No system is perfectly secure. If a breach occurs that is likely to give rise to a real risk of serious harm, we will notify the National Privacy Commission and the affected users as required by RA 10173.
Our apps are not directed at children under 13, and we do not knowingly collect their personal data. A parent or legal guardian must create and manage the account for a minor and may book on their behalf. If you believe a child has given us personal data, contact us and we will delete it.
We will update this policy as the product changes. The effective date at the top always reflects the current version. If a change materially affects how we handle your personal data, we will give notice in the app or by email before it takes effect. Continuing to use Matchpoint after a change takes effect means you accept the updated policy.
Questions, requests, and privacy complaints all go to the same place, and reach a person.
Email us and we will respond within 15 days. Put “Privacy” in the subject line so it gets routed correctly.
If you are not satisfied with our response, you may lodge a complaint with the National Privacy Commission of the Philippines.