PinpointAlpha

Privacy Policy

Effective Date: April 28, 2026 Last Updated: July 23, 2026


1. Introduction

Welcome to Pinpoint ("we," "us," "our"). Pinpoint is a bowling league management platform. We respect your privacy and are committed to protecting the personal information you share with us.

This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights you have over your information. It is designed to comply with the EU/UK General Data Protection Regulation (GDPR), the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA), and other applicable privacy laws. We are also working toward compliance with South Korea's PIPA and Japan's APPI; updates will be reflected here.

By using Pinpoint, you agree to the practices described in this Policy. If you do not agree, please do not use the Service.

2. Who We Are and Our Role

2.1 Data Controller

The data controller responsible for personal information processed under this Policy is:

  • Company: Pinpoint Labs Inc. ("Pinpoint")
  • Trading as: Pinpoint
  • Incorporated in: Ontario, Canada
  • Email: privacy@pinpointbowl.com
  • Postal mail: Available on request — please email us first.
  • Privacy lead: We have not formally appointed a Data Protection Officer because our processing does not require one under GDPR Art. 37. Privacy matters are overseen by an internal privacy lead, contactable at the email above.
  • EU/UK Representative (GDPR Art. 27): Not currently appointed. EU and UK users may direct privacy inquiries to the email above. We are evaluating appointment of a representative.

If you are in the European Economic Area (EEA) or the United Kingdom, you may have additional rights as described in Section 10.

2.2 When Pinpoint Is a Controller vs. a Processor

Pinpoint plays two different roles depending on whose data is being processed and why:

  • Controller. When you create your own Account and use Pinpoint directly, Pinpoint is the controller of the personal information related to your Account, your authentication, your direct interactions with the Service, and the analytics or marketing preferences you set. This Policy describes how we handle that data.
  • Processor. When a Center, League Admin, or organizer ("Customer") uses Pinpoint to manage their league, team, event, or roster — including by adding "Guest" entries for people who do not have their own Pinpoint Account (such as bowlers, dues payers, or registrants) — Pinpoint acts as a processor on the Customer's behalf for that information. The Customer is the controller of that information and decides why and how it is collected and used. In this context:
    • Pinpoint processes the data only on the Customer's documented instructions, under contractual terms (a Data Processing Addendum) that meet GDPR Art. 28 and applicable PIPEDA requirements;
    • If you are a person whose information has been added by a Customer (rather than someone who created their own Account), you should direct privacy requests (access, correction, deletion, etc.) to that Customer first. We will support the Customer in fulfilling such requests, and where required by law we will respond to you directly;
    • The Customer is responsible for having a lawful basis for collecting your information and for telling you how it will be used.

If you are unsure who controls your data, contact us at privacy@pinpointbowl.com and we will help direct your request.

2.3 How We Handle Guest Entries

Because Customers can add Guest entries for people without Pinpoint Accounts, we apply specific limits to how that Guest data is used:

  • We require only the Guest's first and last name to add a Guest entry. Email and other contact details are optional.
  • If a Customer chooses to enter a Guest's email address, the Customer must affirmatively confirm that the Guest has consented to be contacted at that email. We do not automatically add Guests to any mailing list or marketing program.
  • We never use Guest information for marketing purposes. Guest information is used only to support the Customer's league or Event administration.
  • We may use anonymous, aggregate Guest counts (for example, "how many Guests are in the system?") for our internal analytics and service-health metrics. These counts do not identify individual Guests.
  • In the future, we may send a single transactional email to a Guest whose email was provided — for example, "An admin has posted your scoring on Pinpoint. View it online and create an Account to claim your scores." This kind of email is operational, not marketing. If the Guest creates an Account, they will go through the standard onboarding consent flow, including separate opt-in for marketing communications.

We never automatically subscribe a Guest to marketing emails without their direct, affirmative consent obtained through the standard onboarding flow.

3. Information We Collect

We only collect personal information that we genuinely need to provide and improve the Service.

3.1 Information You Provide Directly

  • Account information: name, email address, profile photo (optional), display name, time zone, language preference.
  • Optional contact information: city or region, phone number (used for SMS notifications where you opt in).
  • Bowling profile information: bowling federation or association license number(s) (for example, USBC, CTF, or other governing-body identifiers), bowling average, handicap, and hand dominance (left/right). These fields are optional unless required by an Event you register for.
  • Billing information (for paid Organizer accounts): if you are a League Admin, Tournament Organizer, or Center Admin who pays for the Service, billing details (such as billing name, billing address, and email used for invoicing) and your payment method information are collected and processed by Stripe, our third-party payment processor. Pinpoint does not collect or store full payment card numbers ourselves. We may receive limited information from Stripe (such as the last four digits of a card, card brand, country of issue, and the success/failure of a transaction) to manage your subscription and to comply with our financial record-keeping obligations.
  • League and event data: team rosters, match results, scores, statistics, event registrations, comments, and any other content you submit.
  • Communications: messages you send to us (support requests, feedback).
  • Parent/guardian information (where applicable): see Section 9.

We may add additional features over time (such as photo and video uploads, or device identifiers for push notifications). When we do, we will update this Policy and, where required by law, request your consent before collecting that additional information.

3.2 Information from Authentication Providers

When you sign in using a third-party identity provider, that provider shares limited account information with us as authorized by you. The providers we currently support at launch are:

  • Google
  • Facebook (Meta)
  • Apple
  • Discord

We may add additional identity providers in the future (and will update this Policy when we do). The information we receive typically includes your name, email address, profile picture, and a unique identifier from the provider. We do not receive your password. Each provider has its own privacy policy that governs the data it shares with us.

3.3 Information Collected Automatically

When you use the Service, we automatically collect limited technical information to ensure the Service functions, is secure, and can be improved.

Always collected (Strictly Necessary):

  • IP address, used for security, abuse prevention, geolocation at the country/region level, and as required for the Service to function.
  • Anonymous, cookieless usage signals for service-health monitoring (for example, how many requests succeeded or failed). These are aggregated and do not identify you individually.
  • Error and security logs, including timestamps and error messages.

Collected only with your opt-in consent (Analytics):

If you opt in to analytics through our cookie banner, our analytics provider PostHog (see Section 5.1) collects additional information to help us understand how the Service is used and improve it. This typically includes:

  • Device type, operating system, and browser
  • Screen size and basic device characteristics
  • Pages visited, features used, session duration, click events, and referrer/UTM information
  • A pseudonymous identifier so we can recognize the same browser across sessions
  • IP-derived approximate location (country/region only)

We do not collect precise GPS location, biometric data, hardware fingerprints, or browser-plugin information.

You can withdraw analytics consent at any time through the "Cookie Preferences" link in the website footer or in your Account settings. When you opt out, PostHog stops collecting analytics data about you, but the always-collected baseline above continues for service-health and security purposes.

3.4 Information We Do Not Collect

We do not request or collect special categories of data (such as racial or ethnic origin, political opinions, religious beliefs, health information, biometric data, or sexual orientation). Please do not submit such information through the Service.

4. How We Use Your Information and Legal Bases (GDPR)

Under GDPR, we must have a lawful basis for processing your personal information. We rely on the following bases:

PurposeLawful Basis (GDPR)
Creating and maintaining your accountPerformance of a contract (Art. 6(1)(b))
Providing core league management features (rosters, scoring, scheduling)Performance of a contract (Art. 6(1)(b))
Processing payments for paid Organizer accountsPerformance of a contract (Art. 6(1)(b))
Sending service-related notifications and security alertsPerformance of a contract / Legitimate interests (Art. 6(1)(b), (f))
Preventing fraud, abuse, and securing the ServiceLegitimate interests / Legal obligation (Art. 6(1)(f), (c))
Analytics (only if you opt in)Consent (Art. 6(1)(a))
Marketing communications (only if you opt in)Consent (Art. 6(1)(a))
Anonymous, cookieless usage measurementLegitimate interests (Art. 6(1)(f))
Complying with legal obligationsLegal obligation (Art. 6(1)(c))
Processing children's data with parent consentConsent (Art. 6(1)(a) + Art. 8)

You can withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.

Under PIPEDA, we collect, use, and disclose personal information for purposes that a reasonable person would consider appropriate in the circumstances, and we obtain consent (express or implied, depending on context and sensitivity).

4.1 Marketing Communications

We may send marketing emails about Pinpoint features, new functionality, leagues, events, promotions, and similar topics. Marketing communications are only sent to Users who have given express opt-in consent, in line with the requirements of:

  • Canada's Anti-Spam Legislation (CASL);
  • the EU/UK GDPR and ePrivacy rules;
  • and similar requirements in other jurisdictions.

You can withdraw marketing consent at any time by:

  • clicking the unsubscribe link in any marketing email;
  • changing your preferences in your Account settings; or
  • emailing privacy@pinpointbowl.com.

Withdrawing marketing consent does not affect service-related communications (such as security alerts, billing notices, and changes to these terms), which we will continue to send as long as you have an Account.

4.2 AI and Machine Learning Features

We may introduce AI- or machine-learning-powered features in the future (for example, performance insights, suggested team placements, or score predictions). Before launching any such feature that processes your personal data, we will update this Policy and, where required, obtain your consent or rely on another appropriate legal basis. We will not introduce any feature that makes solely automated decisions producing legal or similarly significant effects on you (within the meaning of GDPR Art. 22) without specific notice and the protections required under applicable law.

5. How We Share Your Information

We do not sell your personal information to third parties. Ever.

We share information only in the limited circumstances described below.

5.1 Subprocessors and Service Providers

We rely on a small number of carefully chosen service providers ("subprocessors") to operate the Service. They process personal data on our behalf, only on our instructions, and under contractual confidentiality and security obligations.

SubprocessorPurposeLocation
ConvexApplication database and backend infrastructure, including storage of Events email content and delivery metadata. Our retention target is up to 12 months: records are marked for deletion after 364 days, while daily bounded cleanup may be delayed and its lag is monitored. Convex's own subprocessors, including PlanetScale for database infrastructure, are listed in Convex's published subprocessor list.United States
CloudflareEdge compute, CDN, DDoS protection, network security, bot mitigation, and object storage. Cloudflare is not the Events outbound email provider.Global edge network; data may be processed in any country where Cloudflare has presence
JetEmail Pty LtdDelivery of Events transactional and organizer-update email, including processing message content, recipient addresses, and delivery events. Pinpoint's corresponding Convex records are marked for deletion after 364 days; bounded cleanup may be delayed.Australia / provider infrastructure locations
RailwayHosting of authentication services, including data exchanged with supported authentication identity providers.United States
PostHogProduct analytics and error tracking only when you opt in through our cookie banner.United States (PostHog Cloud US)
Amazon Web Services (SES)Delivery of legacy marketing emails to users who have opted in. Amazon SES is not the Events outbound email provider.United States
Google Maps PlatformOptional address autocomplete during onboarding. We do not use Maps to track real-time location and do not store device location.United States / global
Stripe (Planned integration)Payment processing for paid organizer accounts when integrated. Pinpoint does not directly store full payment card numbers.United States and other Stripe-operated jurisdictions
Sentry (Planned integration)Error monitoring if enabled in the future.United States

Each subprocessor processes only the data necessary to perform its function. We review their security and privacy practices before engaging them and require them to commit to GDPR-compliant data processing terms. Each of these providers publishes its own Data Processing Addendum or equivalent — links are available on our public subprocessors page (see below).

A current list of subprocessors is maintained at pinpointbowl.com/legal/subprocessors. We will notify users of material changes to this list.

5.2 Other Users of Pinpoint

The Service is collaborative. Information you share within a league, team, or event (e.g., your name, scores, comments) will be visible to other members of that league, team, or event. League administrators may have access to additional information about their league members.

Where the Service includes public-facing displays such as live scoring, leaderboards, center-wide score feeds, tournament pages, standings, brackets, or historical result archives, your Event-related information may be visible beyond a single league. This may include your name or display name, team, scores, standings, match results, awards, and other competition records.

Bowling leagues and tournaments often maintain public historical records, similar to other sports results. Unless the relevant Center, League Admin, or Event administrator removes or restricts the Event record, these public Event records may remain available after the Event ends and after you delete your Account. Account deletion removes or deactivates your Account and private profile/contact details; it does not necessarily remove your name, scores, standings, or other information from historical Event records where that information forms part of the official or public record of the Event.

League and Event administrators may configure privacy settings for their Events and may remove or correct Event records where appropriate. If you have a concern about a public Event record, contact the relevant administrator first. You may also contact us at privacy@pinpointbowl.com, and we will review the request or help direct it to the appropriate administrator. We may remove, anonymize, restrict, or correct public Event information where required by law, where the information is inaccurate, or where we determine that continued publication creates a disproportionate privacy or safety risk.

For children registered by a Parent, the additional protections in Section 9 apply. In particular, upon Parent request, we will anonymize or remove child-identifying information from public Event records where reasonably feasible, unless retention is required by law or needed for a specific safety, integrity, dispute-resolution, or legal purpose.

5.3 Legal Disclosures

We may disclose information if required to do so by law or in response to valid requests by public authorities (e.g., a court order or subpoena), or where we believe in good faith that disclosure is necessary to protect our rights, your safety or the safety of others, or to investigate fraud.

5.4 Business Transfers

If Pinpoint is involved in a merger, acquisition, or sale of all or part of its assets, your information may be transferred. We will notify you and provide options where required by law.

6. International Data Transfers

Because many of our subprocessors (Convex, Railway, PostHog, Amazon SES, Stripe, Google Maps, Sentry, and others) are located in the United States, Cloudflare operates a global edge network, and JetEmail Pty Ltd is based in Australia, your personal information may be transferred internationally.

When we transfer personal data out of the EEA or UK, we rely on appropriate safeguards as required by GDPR, including:

  • The European Commission's Standard Contractual Clauses (SCCs) and the UK's International Data Transfer Addendum, as published by each of our subprocessors;
  • Adequacy decisions, where they apply;
  • Supplementary technical and organizational measures (such as encryption in transit and at rest) where necessary following the Schrems II decision.

Note on PostHog (analytics). PostHog is hosted in the United States (PostHog Cloud US). PostHog's own GDPR guidance recommends that companies using Cloud US either anonymize EU user data or migrate EU users to PostHog Cloud EU. We currently target North America and apply IP and identifier minimization where appropriate. If you are an EU/UK user and concerned about analytics data transfer, you can opt out of analytics through our cookie banner and PostHog will not collect data about you.

For Canadian users, in accordance with PIPEDA, you should be aware that personal information processed by our subprocessors in the United States or other jurisdictions may be subject to the laws of those jurisdictions, including lawful access by foreign authorities. We use contractual measures to ensure a comparable level of protection.

You may request a copy of the safeguards in place by contacting us at privacy@pinpointbowl.com.

7. Data Retention

We keep personal information only as long as necessary for the purposes described in this Policy, or as required by law. Different categories of data are kept for different periods:

Data categoryRetention
Private Account and profile data (email, authentication identifiers, profile settings, optional contact details, private preferences)While your Account is active. If you delete your Account or it is deregistered after inactivity, we delete or anonymize this data except where retention is required by law or needed for security, dispute, billing, or legal reasons.
League and event administration data (rosters, registrations, team assignments, admin notes, non-public Event records)For as long as needed to administer the relevant Event, support the Customer, preserve Event integrity, comply with legal obligations, or resolve disputes. Some records may remain accessible to the relevant Center, League Admin, or Event administrator after your Account is deleted.
Public Event records (names or display names, teams, scores, standings, brackets, match results, awards, tournament pages, league history, and similar sports-result records)May be retained and displayed indefinitely as part of the historical record of the Event, unless removed, restricted, corrected, or anonymized by the relevant administrator, by Pinpoint, or as required by law.
Children's private Account or registration data (registered by a Parent)Only for the duration of the relevant Event, unless a longer period is required to administer the Event, resolve disputes, comply with law, or preserve limited Event records with appropriate parental consent. Removed within a reasonable period after the Event ends or upon Parent withdrawal of consent, whichever is sooner, except where retention is legally required.
Child-identifying public Event records (child's name or display name connected to scores, standings, brackets, awards, or similar Event results)May be displayed only as necessary for Event participation and historical Event records. Upon Parent request, we will anonymize or remove child-identifying information from public Event records where reasonably feasible, unless retention is required by law or needed for a specific safety, integrity, dispute-resolution, or legal purpose.
Technical, security, and log dataUp to 12 months, or longer where reasonably needed to investigate suspected misuse, fraud, or security incidents.
Events email content and delivery metadata (recipient, rendered message, provider identifiers, status, and signed delivery events stored in Convex)Our retention target is up to 12 months: records are marked for deletion after 364 days, while daily bounded cleanup may be delayed and its lag is monitored. JetEmail Pty Ltd processes Events outbound email; Cloudflare and direct Amazon SES delivery are not used for that path.
Analytics data (only if you opted in)Up to 7 years in identifiable form, then anonymized or deleted.
BackupsMay persist for up to 30–90 days after deletion before being overwritten.
Anonymized/aggregated dataMay be retained indefinitely, as it is no longer personal data.
Records required by law (e.g., tax invoices, dispute records)Retained for the period required by applicable law.

Even after these periods, we may retain personal data for longer if it is necessary to fulfil a legal obligation, or to establish, exercise, or defend legal claims. When data is no longer needed, it is deleted or anonymized.

7.1 Account Inactivity

If you do not log in to your Account for 24 consecutive months, we will send you a notice to your registered email address giving you a reasonable opportunity to keep the Account active. If you do not respond within the notice period, we will deregister your Account and delete or anonymize your private Account and profile information, except where retention is required by law or these terms.

Deregistering, deleting, or anonymizing your Account does not necessarily remove public Event records, historical scores, standings, tournament results, or league records that identify you by name or display name. Those records may continue to be retained and displayed as described above.

8. Cookies and Similar Technologies

We use a small number of cookies and similar technologies. They fall into two categories:

8.1 Strictly Necessary (always on)

Required to operate the Service: authentication, session management, security, load balancing, and abuse prevention. These cannot be turned off because the Service would not function without them. We also collect basic, cookieless, anonymous usage data on this basis (e.g., aggregate page views without identifiers) to measure service health.

8.2 Analytics and Marketing (opt-in only)

These cookies and technologies (including PostHog product analytics) are only enabled if you give explicit consent through our cookie banner. You can change your preferences at any time through the "Cookie Preferences" link in the footer of our website or via your Account settings.

The on-screen banner may use bowling-themed wording (instead of the word "cookies") to make it friendlier and more visible — but the underlying mechanism, the categories of data, and your rights are exactly as described in this Policy and apply regardless of the wording used.

We do not use advertising cookies or share data with advertising networks.

9. Guests, Children, and People Without an Account

Pinpoint allows Customers (Centers, League Admins, Tournament Organizers) and Parents to add Guests — people who participate in an Event without creating their own Pinpoint Account. Guests can include adult bowlers (for example, a senior who doesn't want to manage an Account), other family members, or children registered by a Parent.

9.1 Guest Registration (General Rules)

When a Customer or Parent adds a Guest:

  • We require only the Guest's first and last name.
  • All other fields (email, phone, federation/association license number, bowling average) are optional.
  • If an email is provided, the registering person must affirmatively confirm that the Guest has consented to be contacted at that email address. We will not automatically add Guests to any mailing list (see Section 2.3 for full Guest data handling).
  • Event Organizers may, at their own discretion, ask a Guest to present identification matching the registered name on arrival at an Event. That identification check is between the Organizer and the Guest; Pinpoint does not store identification documents.

9.2 Children Specifically

If a Guest is under the digital consent age in their jurisdiction (under 13 in Canada and the U.S., or up to 16 in some EU member states under GDPR Art. 8), additional protections apply:

  • A child cannot register a Pinpoint Account directly.
  • A Parent or legal guardian must add the child as a Guest through their own Pinpoint Account, and must affirmatively confirm at the time of adding that:
    1. They are the child's parent or legal guardian and have the legal authority to provide consent on the child's behalf;
    2. They consent to our collection and use of the child's information solely to register and administer the child's participation in the relevant Event(s);
    3. They are providing only the minimum information necessary.
  • The child does not receive Pinpoint communications, login credentials, or Account access. The Parent acts as the child's representative within the Service.
  • The Parent can review, correct, delete, or request anonymization of the child's information at any time through their Account or by emailing privacy@pinpointbowl.com.
  • The Parent can withdraw consent at any time. On withdrawal, we delete or anonymize the child's personal information within a reasonable period and remove the child from active Events (subject to Event-level rules administered by the relevant League Admin). Where the child's name or display name appears in public Event records, we will anonymize or remove child-identifying information where reasonably feasible, unless retention is required by law or needed for a specific safety, integrity, dispute-resolution, or legal purpose.

9.3 How We Verify Parental Consent

To meet the verifiable parental consent requirements of GDPR Art. 8, PIPEDA's meaningful consent guidance, and (where applicable) the U.S. Children's Online Privacy Protection Act (COPPA), we use the following process:

  1. Parent-only registration. A child cannot register an Account directly. The Parent must first create their own Account using their own valid email and authentication.
  2. Affirmative in-app consent. When a Parent adds a child as a Guest, the Parent must affirmatively confirm (via an explicit checkbox or equivalent action — not pre-ticked) that they are the child's parent or legal guardian and consent to our limited collection and use of the child's information.
  3. Confirmation record. We log the date, time, and method of consent, and we send a confirmation email to the Parent's verified email address summarizing the information collected and how to withdraw consent.
  4. Stronger verification where required. Where applicable law requires a stronger form of verifiable consent (for example, certain COPPA contexts), we may require additional verification steps, such as a credit card transaction (no charge), signed consent form, or government-ID check, before completing registration.
  5. Withdrawal. Parents can withdraw consent at any time through their Account settings or by emailing privacy@pinpointbowl.com.

9.4 Limits on Use of Children's Data

Where we hold information about a child:

  • We use it only for the limited purposes described in this Policy and to administer the child's participation in the Event(s) the Parent has registered them for.
  • We do not send marketing communications to children.
  • We do not publicly display the child's information beyond what is necessary for Event participation or limited historical Event records, and we will anonymize or remove child-identifying information from public Event records upon Parent request where reasonably feasible.
  • We do not allow children to link their participation to any third-party social network from within the Service.
  • We do not share children's personal information with third parties except our subprocessors acting on our behalf (see Section 5.1) or as required by law.

If we learn that a child's data has been submitted without proper parental consent, we will delete it as soon as reasonably possible. Parents who believe their child's data is in the Service without consent should contact us at privacy@pinpointbowl.com.

This approach is designed to comply with GDPR Art. 8, PIPEDA's principles regarding meaningful consent for minors, and (where applicable) COPPA.

10. Your Rights

10.1 If You Are in the EEA, UK, or Switzerland (GDPR / UK GDPR)

You have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data ("right to be forgotten") in certain circumstances. This right is not absolute and may not require removal of historical Event records where continued retention or publication is lawful, necessary to preserve the integrity of competition records, or controlled by a Center, League Admin, or Event administrator.
  • Restrict processing in certain circumstances.
  • Data portability: receive your data in a structured, machine-readable format.
  • Object to processing based on legitimate interests, including profiling.
  • Withdraw consent at any time, where processing is based on consent.
  • Lodge a complaint with your local supervisory authority. A list of EU authorities is at https://edpb.europa.eu/about-edpb/about-edpb/members_en; the UK ICO is at https://ico.org.uk.

We do not engage in solely automated decision-making with legal or similarly significant effects.

10.2 If You Are in Canada (PIPEDA)

You have the right to:

  • Access the personal information we hold about you and request information about how it is being used and to whom it has been disclosed.
  • Correct inaccurate or incomplete information.
  • Withdraw consent for collection, use, or disclosure (subject to legal or contractual limits). Withdrawal may not require removal of historical Event records where retention or publication remains appropriate in the circumstances or where the relevant Customer controls the record.
  • Challenge our compliance with PIPEDA. You can also file a complaint with the Office of the Privacy Commissioner of Canada at https://www.priv.gc.ca.

10.3 How to Exercise Your Rights

Email us at privacy@pinpointbowl.com or use the in-app account settings. We will respond within one month (GDPR) or 30 days (PIPEDA), or otherwise notify you of any extension allowed by law. We may need to verify your identity before fulfilling certain requests.

11. Data Security

We use a combination of technical and organizational measures to protect personal information, including:

  • Encryption of data in transit (TLS) and at rest where supported by our infrastructure providers;
  • Access controls and authentication for our staff;
  • Regular review of our subprocessors' security postures;
  • Secure software development practices.

No system is completely secure, but we work continually to protect your information. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and affected users in accordance with GDPR (within 72 hours where feasible) and other applicable laws.

12. Changes to This Policy

We may update this Policy to reflect changes in our practices or legal requirements. The "Last Updated" date at the top will reflect the most recent revision. For material changes, we will notify you in-app or by email before they take effect. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.

13. Contact Us

For any privacy-related question, request, or complaint:

  • Email: privacy@pinpointbowl.com
  • Mail: Available on request — please email us first.

We aim to respond to all inquiries promptly and in good faith.