The short version
Your account, team and money records support the app; authorized teammates can see team data. Contact messages go to our support mailbox. The landing page uses Google Analytics automatically without a consent prompt. Data requests are reviewed by email, and leaving a team does not erase its history.
This overview is a guide. The full policy below provides the details.
01
Scope and contact
This Privacy Policy describes how information is handled when you visit the public TurfLedger website, create an account, use a team’s records or contact us. “We” and “us” refer to the operator of TurfLedger. The product is developed by Reverb Solution. For privacy questions and requests, contact mushfiqueyeasir@gmail.com.
The policy covers information you provide, records added by authorized teammates, browser storage and information processed by the providers used to run the service. A player may be included in a team roster without having a TurfLedger account, so this policy also describes records about non-account players.
TurfLedger is a team-management and expense-recording tool, not a payment gateway, bank, wallet or turf booking provider. Payments and bookings take place outside the application. Our Terms & Conditions describe the responsibilities that come with using the service.
02
Information we handle
- Account and profile: your full name, email address, account identifier and authentication/session information. Signup, login, confirmation and password-reset flows use Supabase Auth. Passwords submitted through those flows are handled by Supabase Auth; they are not stored in TurfLedger’s player or financial ledger records.
- Teams and memberships: team names, team identifiers, ownership, member account references and owner, admin or member roles. Membership management uses the email address of the person being added.
- Players: player names, optional phone numbers, active or archived status, team association and an account reference if a player is linked to a member. A player record does not require an account or email address.
- Matches: scheduling information, turf name, participants, status, costs, final shares and related creator and timestamp information. Monetary values are recorded in BDT using poisha; scheduling uses Asia/Dhaka.
- Financial ledger: amounts, match charges, payments received, refunds, adjustments, method labels such as Cash, bKash, Nagad, Bank or Other, notes, timestamps, creator account references, team/player/match references, allocation records and retry identifiers used to prevent duplicate submissions. Balances and reports are derived from these records.
- Contact and support: your name, email, optional team name, message and any information you choose to include in subsequent correspondence.
- Technical and usage information: session cookies, the selected-team cookie, pending-payment browser storage, contact rate-limit identifiers, and website analytics described below. Hosting and other providers may also process request information, including IP addresses, browser/device details and diagnostic logs as part of delivering and protecting the service.
Payment-method labels and ledger amounts describe transactions your team records; they do not give TurfLedger access to your bank or mobile-wallet account. Do not include passwords, PINs, card details, payment credentials, identity documents or unnecessary sensitive information in notes or contact messages.
03
Why we use information
We use information to provide account access and recovery, show the correct team, manage permissions, maintain rosters and match plans, calculate costs and balances, preserve financial history, and generate team reports. We also use information to respond to enquiries, investigate reported errors, limit contact-form abuse, secure the service and meet applicable legal obligations.
Landing-page analytics help understand website visits and improve the public product presentation. They are separate from the team ledger and do not verify external payments or bookings.
Where applicable law requires a legal basis, the basis depends on the purpose and context. It may include providing a service you request, legitimate interests in operating and protecting the service where that basis is available and appropriately balanced, compliance with legal obligations, or consent where required. Agreeing to the terms or reading this policy is not a blanket consent to all processing. The current analytics implementation and its lack of a consent prompt are explained explicitly below.
04
Team access and player data
Your records are associated with a team and are not intended as public website content. Authorized team members can view team records, which may include other players’ details, balances and notes. Owners manage access; owners and admins can manage records; members have read-only access. The service is not a private personal ledger hidden from all other teammates.
Organizers must have appropriate authority and any legally required consent to add people, record their optional phone numbers, link accounts or grant membership. They should tell players what is recorded and who can access it. Share the minimum information needed for team organization and do not put sensitive personal details in broadly visible notes.
If a teammate added your information, contact the team organizer about ordinary roster corrections or access questions. You may also contact TurfLedger directly about personal-information rights or inappropriate use, even if you do not have an account. We may need to identify the relevant team and verify your relationship to the record before acting.
Members may copy or share information they can access outside the application. We cannot guarantee the handling of those independent copies; members remain responsible for using them lawfully. Revoking membership does not retrieve information already copied.
06
Landing-page analytics
The public landing page loads Google Analytics 4 (GA4) automatically when a valid measurement ID is configured. The current website has no analytics consent banner or opt-in interface and does not wait for you to accept analytics before enabling it. Its configuration grants analytics storage by default while denying advertising storage, advertising user data and advertising personalization. This technical configuration is not a statement that legally valid consent has been obtained.
The integration disables Google signals and advertising-personalization signals. Its explicit configuration and page-view event use the public homepage URL and a fixed product title, omit URL query strings and hashes, and send an empty referrer. The explicit event does not include account names, emails, roster details, ledger entries or contact-message content.
Google still receives the network requests needed to load and use its analytics service and may process cookie identifiers, IP-derived approximate location and browser/device information under its own practices. Sanitizing our explicit page-view event is not a guarantee that every request sent by a third-party script contains no identifying information.
Enhanced Measurement and related data-stream settings are configurable outside this code in Google Analytics. If enabled, they can collect additional interactions such as scrolls, outbound clicks or other measurements. The safeguards on our explicit page-view event should not be read as a guarantee about all externally configured measurements.
This integration is mounted on the landing page, not deliberately on authenticated team pages or these legal pages. Analytics cookies can remain in your browser after you leave the landing page. You can use browser cookie controls, tracking protection or an analytics blocker to limit collection, and contact us about your rights. Where applicable law requires prior consent or other controls, those requirements still apply; this policy does not replace them.
07
Contact and abuse prevention
The public contact form asks for your name, email address, optional team name and message. Valid submissions are sent through a configured SMTP email provider to mushfiqueyeasir@gmail.com, a Gmail mailbox. The SMTP provider and Google process the message for delivery and mailbox storage. Your email address is used so support can reply. Direct emails and later replies also remain part of that correspondence.
The form also checks a hidden anti-spam field and uses a Supabase-backed rate limiter. For rate limiting, the normalized email address is transformed with a secret-key HMAC-SHA256 hash; an IP address is similarly hashed when a trusted client IP is available from supported hosting headers. The current IP-header integration is specific to Vercel, so an IP bucket is not always used.
The rate-limit table stores hashed identifiers, scope, usage counts, window start times and expiry times, rather than the raw email or IP as its rate-limit key. The hashes are pseudonymous abuse-prevention identifiers, not a claim of complete anonymization. The original email is still included in contact delivery, and request IP information may be handled separately by hosting or network providers.
Current rate-limit windows are 10 minutes, one hour and one day, depending on scope. Expired rows are cleaned up when a later rate-limit request runs, not by a guaranteed deletion job at the exact expiry time. If no later traffic arrives, an expired row may remain until cleanup occurs. This limited rate-limit retention does not describe how long messages remain in Gmail or with the SMTP provider.
08
Providers and disclosures
The service relies on third parties that process information needed to provide their functions:
- Supabase: authentication, account/session services, database storage for team and ledger records, and contact rate-limit storage.
- Google: GA4 for landing-page analytics and Gmail for the support mailbox.
- The configured SMTP provider: delivery of contact messages; the provider can vary by deployment configuration.
- Hosting and infrastructure providers: serving the website, running server functions and handling operational requests and logs. The actual provider and settings depend on deployment.
Access by people operating or supporting TurfLedger may be needed to address support, security or maintenance issues. Team information is also displayed to authorized members as described above. We may disclose information when required by applicable law or where lawfully necessary to address misuse, protect users or establish, exercise or defend legal claims.
Provider processing, logs, backups, security measures and retention are affected by their contracts, configurations and policies. References to these providers do not mean that all of their separate practices are controlled by TurfLedger. Following an external link also subjects you to that destination’s own practices.
09
International processing
Although TurfLedger is designed around football teams using BDT and Asia/Dhaka scheduling, information is not promised to remain in Bangladesh. Supabase, Google, the SMTP provider and hosting providers may store or process information in other countries, including locations used for infrastructure, support or backups. The locations depend on the deployment and provider settings.
Other countries may have different privacy laws. Where applicable law requires safeguards for an international transfer, those requirements must be addressed through the relevant arrangements and provider terms. Contact us if you need information about the current deployment or transfer arrangements; this policy does not assert a specific hosting region or a transfer certification that has not been established.
10
Retention and deletion
There is no single published fixed retention period for all TurfLedger data. Retention depends on the record’s purpose, ongoing team use, account and ledger relationships, support needs, security investigations, legal obligations and provider settings. Do not assume that signing out, leaving a team or stopping use deletes your information.
Financial transactions are immutable in the normal application workflow: original entries, timestamps and creator references are preserved, and corrections append refund or adjustment records. Archiving a player keeps balances and history; removing membership removes access rather than rewriting past entries. Shared records may continue to be needed by the rest of the team.
For account closure, deletion or information removal, email mushfiqueyeasir@gmail.com. Requests are reviewed manually; there is no promise of immediate or universal deletion and no general self-service deletion workflow is offered by this policy. We will assess identity, scope, team authority, other people’s rights and applicable requirements, and explain any information that must be retained or cannot be removed as requested.
Immutability in the product is not an exemption from applicable privacy law. A personal-data correction or deletion request may require a separate operational process rather than an ordinary ledger edit. Copies in backups, provider systems or a support mailbox can have different retention and removal schedules. Information independently copied by team members is not automatically removed by an account request.
Rate-limit expiry and cleanup are described in Contact and abuse prevention. Browser cookie and session-storage lifetimes are described in Cookies and browser storage; neither sets a general retention period for your team’s records or support correspondence.
11
Security and your choices
The application uses authenticated sessions, team-role permissions, database access controls, input validation and contact abuse controls. Contact email transport is configured to require TLS. These measures reduce risk but cannot guarantee that information will never be lost, misused or accessed without authorization.
Protect your account and email, use a unique password, review team roles, and share only necessary information. Avoid entering confidential details in ledger notes or support messages. Tell us promptly about suspected unauthorized access; do not send your password as part of a report.
You can choose not to provide an optional player phone number or optional contact team name. Necessary account and team information is required for the corresponding features. You can stop using the service, ask an owner to remove team access, use browser controls for storage and analytics, or send a privacy request. Removing access or local storage is not the same as deleting the underlying team ledger.
12
Privacy rights and requests
Depending on the law that applies to you and the processing involved, you may have rights to request access or a copy of personal information, correction, deletion, restriction, portability, or to object to particular processing. Where processing depends on consent, you may be able to withdraw it without affecting the lawfulness of earlier processing. These rights can have exceptions and are not identical in every location.
Send requests to mushfiqueyeasir@gmail.com. Describe what you need and, if relevant, identify the team and the name or email associated with the record. A player without an account may also make a request. Do not send passwords or unnecessary identity documents; we will ask for proportionate verification if needed.
Requests for information or exports are handled manually, rather than through a promised automatic export tool. We may need to clarify your request and verify identity or authority so we do not disclose someone else’s information. We will respond in accordance with applicable legal requirements and explain relevant limitations, including those affecting shared financial history.
You may also have the right to raise a concern with the appropriate privacy regulator or another competent authority under applicable law. Contacting us first can help clarify the issue but does not waive that right.
13
Younger players and changes
TurfLedger is not presented as a service directed specifically at children. Team organizers should take particular care before recording a younger player’s information and obtain any parent, guardian or other authorization required by applicable law. If you believe a child’s information has been added inappropriately, contact the organizer or our privacy email so the record can be reviewed. Account users must have the legal capacity or authorization required in their location, as described in our Terms & Conditions.
This policy was last updated on 5 October 2026. We may revise it when features, providers, data practices or legal requirements change. The updated date will appear on this page; for material changes, we will seek to provide additional notice through the service or available contact details where appropriate and meet any applicable notice requirements. Publishing a revised policy does not by itself obtain consent where consent is required.
Questions about this policy?
Contact TurfLedger at mushfiqueyeasir@gmail.com or use our contact form.
Back to top ↑