Privacy Notice
How the current CrowdScout beta handles account, community and technical data.
Who operates CrowdScout
CrowdScout is operated by Match Simulator, registered in the Netherlands with the Dutch Chamber of Commerce (KvK) under number 84493763. Privacy and data-rights requests can be sent to [email protected].
Account and identity data
Native accounts store an internal ID, display name, email address, a password hash (never the plaintext password), email-verification and account status, authentication timestamps, and roles or permissions where applicable.
If optional Match Simulator sign-in is configured and you use it, CrowdScout can receive and store a Match Simulator user ID, username, email-verification status, provider account-creation time and CrowdScout authentication time. CrowdScout does not receive the Match Simulator password or login cookie through this flow. Anonymous Scouts receive a durable pseudonymous community identity; that identity and its contributions can outlive the browser session.
Scout evidence
CrowdScout can store the assignments and questions shown; player and metric pairings; model values shown at the time; left, right, equal or skip answers; selected player; league-knowledge levels; response time; revisions; question batches; trust and expertise weights at submission; and the rating version connected to the evidence.
Community evidence may be retained across rating releases for model and rating improvement, integrity, moderation, audit and reproducibility.
Trust, integrity and moderation
To protect community and rating integrity and determine how much evidence should count, CrowdScout calculates or stores signals including trust level and score, control-question agreement, consistency, transitivity, peer alignment, abuse risk, network-cluster risk, coordinated-pattern risk, expertise or knowledge weighting, and moderation outcomes. Moderators can review cases and add notes. This is not advertising profiling, and the current system includes manual moderation rather than claiming a wholly automated adverse account-decision process.
Network and device information
In MariaDB community evidence and authentication-rate-limit records, network data is generally represented by keyed HMAC-derived identifiers. Community evidence can similarly contain an HMAC-derived user-agent identifier. Operational Apache and security logs can contain the raw client IP address and raw user agent. CrowdScout’s access-log format intentionally records the URL path rather than query strings, so verification and reset query tokens are excluded from CrowdScout access logs.
AWS SES sends transactional account verification and password-reset email. CrowdScout does not operate newsletters or marketing email. Migadu supports human-operated support, privacy, copyright and security mailboxes; incoming messages are not automatically ingested into CrowdScout or MariaDB.
Analytics
CrowdScout loads Google Analytics 4 using measurement ID G-SJVP8LH3BQ with Analytics storage denied by default. Before consent, or after rejection, Google receives limited cookieless measurements and consent-state signals. These requests can include the page, timestamp, user agent, referrer, IP address and other ordinary request information, but Analytics cookies are not set or read. If you accept analytics cookies, Google Analytics can additionally assign a pseudonymous client identifier and session state using first-party cookies and provide fuller visit and interaction measurement. CrowdScout does not send your account name or email address to Google Analytics and disables Google signals and advertising-personalisation signals in its tag configuration.
Analytics is used to understand site usage and improve CrowdScout. Optional Analytics storage is based on your consent. You can reject analytics or withdraw consent on the Cookies page; withdrawing changes Analytics storage to denied and attempts to remove the first-party Analytics cookies. Your preference is stored locally in your browser. Limited cookieless measurements continue while storage is denied. Google may process Analytics data outside the European Economic Area under its applicable data-transfer safeguards. Exact controller/processor, retention and transfer settings in the Google Analytics property must be confirmed during final legal review.
Services and external assets
The current architecture uses Hetzner for hosting/origin infrastructure; Cloudflare for DNS, proxy, network security and real-IP handling; AWS S3 for private backups and model/data artifacts; AWS SES for transactional email; Migadu for human-operated mail; Sportmonks for football reference and performance data; Google Analytics for usage measurement under Consent Mode; and GitHub for source and deployment tooling.
Club images can be loaded from Sportmonks-hosted URLs and flags from Flagpedia-hosted URLs. Your browser therefore contacts those hosts and sends ordinary request information such as IP address and user agent. When Analytics is enabled for the deployment, your browser also contacts Google Analytics with storage denied unless you accept Analytics cookies.
Why data is handled
Account and service processing is used to provide the requested service and manage the service relationship where applicable. Security, integrity and abuse-prevention processing is based on Match Simulator’s legitimate interests where applicable. Information may also be handled to meet legal obligations. Non-essential Google Analytics processing is based on consent. Consent is not presented as the basis for all processing. The exact legal-basis wording remains subject to final legal review.
Retention
- Sessions last for the browser session, until logout or earlier destruction.
- Verification links are valid for 24 hours and reset links for one hour. Used and expired token database rows are currently retained; no automatic purge exists.
- Assignments are valid for 30 minutes.
- Authentication/security-attempt cleanup targets approximately seven days.
- Beta Apache, PHP and application logs target 30 days.
- Google Analytics first-party cookies default to two years; the Analytics property’s event and user-data retention setting must be verified before launch.
- Production local database backups target seven days; S3 database backups target 90 days in production and 30 days in staging.
- Community, trust, moderation and audit evidence may be retained long-term where needed for integrity, reproducibility, moderation and historical releases.
- Published rating packages and history are retained as immutable historical product records.
Backups can temporarily preserve personal data after deletion until the applicable backup-retention period expires.
Your rights and deletion
CrowdScout does not currently provide self-service export or deletion. Contact [email protected] to request access, correction, deletion or other applicable data-protection rights. Match Simulator may need to verify your identity. Some non-identifying aggregates, derived rating outputs, legally required records and staff/moderator audit records may need different handling from account-linked personal data.