Privacy Policy
This page is available in English only.
Last updated: 9th September 2026
Padel Ultimate is a padel scorekeeping app for Garmin watches, with an optional web app for your stats. This policy explains, in plain language, what we collect, why, and the control you have. We tried to keep it short and honest.
The short version: we record only the match you play, never your watch's history. Health data is stored only with your explicit consent: per-match summaries and, so you can see how your heart responded to key moments, your heart rate at the end of each point during a match: never a continuous stream, never anything outside your match. We never sell your data or use ad trackers. You can export or delete everything at any time.
Who we are
The data controller is Gentle Pine Labs, the independent developer operating Padel Ultimate ("we"). Contact us at support@padelultimate.net for any privacy question or request.
What we collect and why
| Data | Why we collect it | Legal basis (GDPR) |
|---|---|---|
| Match data: scores, point-by-point log, set results, timestamps, and activity totals for the match (steps, distance, calories) | To record your match and show your stats | Contract (once you have an account) / legitimate interest |
| Heart-rate summaries: average and max per match, time in your heart-rate zones | To show match effort | Your explicit consent (health data) |
| Per-point heart rate: your heart rate at the moment each point ends, during a match | To show how your heart responded across the match (per point / game / set) | Your explicit consent (health data) |
| Heart-rate zones: zone boundaries read from your Garmin fitness profile | To compute accurate "time in zones" | Your explicit consent |
| Match location (optional): one map coordinate captured at the start of a match, only while the watch's "Send location" setting is on (off by default) | To draw your personal court map (the places you play) | Your consent (the on-watch toggle) |
| Court names: the names you give the places you play | To label your court map and your stats by place | Legitimate interest (you choose what to record) |
| People you record: names you type for your partners and opponents (your private people book and per-match lineups) | To label who you played with and against and show per-person stats; these names are visible only to you | Legitimate interest (you choose what to record) |
| Match notes, ratings and goals: free-text notes, your self-ratings after a match, and goals you set | To keep your own record alongside each match and track your progress | Contract |
| Account data: email address, your display name and an optional profile picture | To sign you in, link your matches and show your profile | Contract |
| Settings and preferences: language, court side, email preferences, watch settings and similar choices you make | To make the app behave the way you set it | Contract |
| Push registrations: a device or browser push token, stored when you enable notifications | To deliver the notifications you asked for, via Google or Apple push infrastructure | Your consent (you enable notifications) |
| Waitlist email: an address entered on the waitlist form or on the sign-in page without an invitation | To let you know when access opens (invited players hear first) | Legitimate interest / your request |
| Delivery suppression list: an email address in a normalized form, the reason we stopped mailing it (it bounced, or it was reported as spam) and when that happened. This applies to waitlist-only addresses as well, which never had an account. We keep the entry until the address is confirmed deliverable again, or until you ask us to remove it at support@padelultimate.net: the whole point of the record is to outlive the waitlist entry or the account it came from, because otherwise the next mail would go to the same broken or unwilling address again. | To never send mail to an address that bounced or asked us to stop, and to keep our mail deliverable for everyone else | Legitimate interest |
| Device data: your Garmin device id, watch model, app and firmware versions / a pairing token / sync attempt counts and timestamps | To sync your watch, pair it to your account, and see how well syncing works | Contract / legitimate interest |
| Payment data: handled entirely by our payment provider; we never see card details | To process a premium subscription | Contract |
| Technical logs: the requested address, the time it took, and a masked IP address (the last part is removed, so it points at a network, not at you); kept 14 days | Security, abuse prevention and keeping the service fast | Legitimate interest |
We ask for your consent for heart-rate data the first time a feature uses it, and you can withdraw it at any time (see Your rights).
What we do NOT collect
- No pre-app history. We record only from the moment you open the app / start a match. We never read data that was on your watch before that.
- No continuous or background heart-rate stream. With your consent we store per-match summaries and your heart rate at the moments points end: a bounded set of readings inside your match, never a continuous recording and never anything outside it.
- No selling, no ad trackers, no third-party analytics with your personal data.
- No location by default: GPS is used only if you turn it on. With the optional "Send location" setting we store a single coordinate from the start of each match (for your court map), never a movement track.
Watch permissions and why we ask for them
Garmin shows you these permissions when you install the app. Here is exactly what each one is for. Some are for features we are still building. We say so honestly, and we do not collect anything through them until that feature ships.
| Permission | What it's for |
|---|---|
| Fit / FitContributor | Record your match as a normal Garmin activity (so it appears in Garmin Connect) with our extra fields |
| Communications | Send your finished match to our server, sign you in, and ask our server at each app start whether online features are available yet. That availability check carries only the app's version number and the watch's display language (so any notice we send back can be shown in it); like any web request, our server sees an IP address (see Technical logs above), and nothing else is sent or stored. This is the only way your data leaves the watch |
| Positioning | Optional GPS for the activity and, with "Send location" on, one coordinate at match start for your court map (both off unless you enable them) |
| Background | Upload a finished match in the background, so you don't have to keep the app open |
| UserProfile | Read your configured heart-rate zones, for accurate "time in zones" |
| Sensor / SensorLogging | Upcoming feature (stroke detection). Not collecting data yet |
| Notifications | Upcoming feature (on-watch reminders/alerts). Not collecting data yet |
Who we share data with
We use a small number of trusted providers ("processors") who act on our instructions:
- Hosting: our servers run on Hetzner in the EU (Germany/Finland).
- Email: Resend sends our email: account verification, password reset, recap and waitlist mail.
- Payments: our payment provider (a Merchant of Record) processes payments as the seller of record; they handle your payment data under their own policy.
- Map tiles: the court map's background images load from OpenStreetMap directly in your browser. Nothing goes to them from our servers; like opening any map website, your browser's request reveals your IP address and the viewed map area to OpenStreetMap.
- Error tracking: Sentry receives a report when something in the app breaks, so we can fix it. The reports are stored in the EU (Frankfurt); our account details with Sentry are held in the US. Before a report leaves us we strip out anything identifying: no email addresses, no tokens or cookies, no health data, and never the contents of a request. What remains is the error itself and where in the code it happened.
We do not sell your data or share it for advertising.
Cookies
We use a single strictly-necessary session cookie to keep you signed in. No tracking, advertising or analytics cookies.
Analytics
We use our own self-hosted, cookieless analytics that records only aggregate, non-identifying usage (page views and product events) – no third parties, no cross-site tracking, no personal data. It runs on our own server in the EU, and the counting script is served from this site rather than from anyone else's, so nothing about your visit is sent anywhere outside our own infrastructure.
We keep this aggregate data for 24 months, then delete it automatically.
You can turn it off for this browser at any time. The switch stores your choice in this browser, for this site only, so it does not follow you to another device or browser.
Garmin's role
Data you submit through the app is sent to us (Padel Ultimate), not to Garmin. Garmin only transports it from your watch to your phone to our server, and Garmin has no responsibility or liability for it. Garmin's own handling of your device data is covered by Garmin's privacy policy.
International transfers
Your data is hosted in the EU. Where a provider (e.g. email or payments) is outside the European Economic Area, that transfer is protected by appropriate safeguards such as the EU Standard Contractual Clauses.
How long we keep your data
- Match and account data: for as long as you keep your account. Delete your account and it is permanently erased; residual copies may persist in encrypted backups for up to 30 days.
- Anonymous matches (uploaded before you create an account): kept for 180 days, then deleted - sized so a watch that syncs before its owner can create an account still has those matches waiting at sign-up. If such a match carries heart-rate data, that data is held unused for 60 days only: your consent choice when you connect your watch keeps it or deletes it, nothing is shown or used before you decide, and it is removed automatically if you have not connected within those 60 days (the match itself, without heart-rate data, waits out the rest of the 180 days).
- Unconnected watch registrations (a watch that synced but was never connected to an account): the device identifier and its access credential are deleted 60 days after the watch was last seen, once no matches remain. The watch simply re-registers if it ever syncs again.
- Waitlist emails: until you ask to be removed - every waitlist email includes an unsubscribe link, and deleting an account removes its waitlist entry too.
- Rejected sync payloads: 14 days. When your watch sends us a match our server cannot accept, we park a copy of exactly what it sent, so the fault can be found and the match recovered instead of being lost silently; only a bounded number of these copies exists at a time. Such a copy holds no more than the match itself would have held, under the same consent rules - so it can carry your per-point heart rate and the court location if you consented to them, and carries neither if you did not. It is deleted after 14 days, and sooner when your account and its watch registrations are deleted.
- Technical logs: 14 days, then rotated out automatically.
- Analytics: 24 months, then deleted automatically (see Analytics).
Your rights
Under the GDPR you can, at any time:
- Access and export your data (one-click JSON export in the web app).
- Delete everything (account deletion permanently erases your data).
- Correct inaccurate data, object to processing, and withdraw consent for health data.
What withdrawing heart-rate consent does: it stops us collecting any further heart-rate data, from that moment on. Heart-rate we already stored stays with the matches it belongs to - withdrawing consent does not delete it by itself. To remove it, delete those matches (they go to Trash for 30 days, then are erased permanently), delete your account, or ask us and we will do it for you.
Use the tools in the web app, or email support@padelultimate.net. We respond within 30 days. You also have the right to complain to your local data protection authority.
Children
Padel Ultimate is not directed at children under 16, and we do not knowingly collect their data.
Changes to this policy
If we change how we handle your data, we will update this page and its "Last updated" date. Significant changes will be communicated in the app or by email.
Contact
Questions or requests: support@padelultimate.net.