Effective date: September 14, 2026
Contact: privacy@armlog.ca
This privacy policy describes how ArmLog (the “App”) collects, uses, and shares information. The App is published and operated by Mathieu Rancourt (“we”, “us”). It is provided to youth baseball and softball leagues (each, a “League”) and their volunteer coaches and administrators, for the purpose of tracking pitch counts and mandatory-rest eligibility for youth players.
Each League controls its own records. We operate the App’s infrastructure; a League’s administrators decide who may use the App for that League and what player and team records are maintained inside it. In data-protection terms, each League is the controller of its players’ records and we act as a processor on that League’s behalf. Privacy questions about the App generally can be directed to the contact above. Questions about a specific player’s record are best directed to an administrator of the League that maintains it, but you may also contact us and we will work with that League to address them.
The App is intended for adult coaches and league administrators (age 13+). The App is not designed for use by children, and minors do not create accounts or sign in. Coaches enter information about youth players for the purpose of league record-keeping and pitch-eligibility tracking.
This information is entered by approved coaches and admins for the purpose of tracking pitch counts and mandatory rest periods. Within a League, player records are visible to that League’s approved coaches and admins, so that a player’s pitch counts can be aggregated correctly across every team they play for.
If a League chooses to subscribe, its administrator provides billing details directly to Stripe, our payment processor. See “Payments” below.
We do not use third-party analytics, advertising SDKs, or tracking technologies. We do not track you across other apps or websites. We do not sell or share your personal information with third parties for marketing purposes.
Account credentials are stored in Firebase
Authentication (Google LLC). Player, team, pitch-event, and
profile records are stored in Google Cloud Firestore,
in Google’s northamerica-northeast1 (Montréal, Canada)
region. Firebase Authentication is operated globally by Google and may
store credential and sign-in metadata on servers in the United States.
Google’s privacy practices are described at https://firebase.google.com/support/privacy.
Each League’s records live in a separate database. We do not store multiple Leagues’ players in shared tables distinguished by a label. Every League gets its own physically separate Firestore database, and the security rules for each one name that League specifically. This means one League’s coaches cannot reach another League’s player records even in the event of a rule error, rather than relying on every query remembering to filter correctly.
Sign-in accounts are shared across the service — one account belongs to exactly one League at a time — while the League data those accounts reach is separated as described above.
Subscriptions are processed by Stripe, Inc. When a League administrator subscribes, they enter their payment details directly with Stripe. We never receive or store card numbers. We store only a Stripe customer and subscription identifier and the resulting subscription status for the League.
Stripe receives the billing details the administrator gives it — name, email, and payment method — and the League identifier the subscription is attached to. Stripe does not receive any player data. Stripe’s privacy policy is at https://stripe.com/privacy.
We do not sell or rent your personal information.
Your information is shared only as follows: - Within your League. Player records, team rosters, and pitch event history are visible to that League’s approved coaches and admins so that pitch counts can be aggregated across teams. Coach names and the identity of who logged a pitch event may be visible to other coaches and admins in that League. Nothing is shared between Leagues. - With our service providers. Google (Firebase) hosts the App’s authentication and database infrastructure; Stripe processes subscriptions. Each acts on our behalf and receives only what is described above. - As required by law. We may disclose information if required to do so by law or valid legal process.
Depending on where you live, you may have additional rights under laws such as PIPEDA (Canada), Québec’s Law 25, the GDPR (EU/UK), or the CCPA/CPRA (California), including the right to access, correct, or delete personal information we hold about you, to withdraw your consent, and to lodge a complaint with a supervisory authority (in Canada, the Office of the Privacy Commissioner of Canada). You can exercise these rights by contacting us at the email above.
The App is not directed to children under 13, and children do not create accounts in the App. Player records (which may relate to minors) are entered by adult coaches and admins solely for a League’s record-keeping needs — pitch counts and mandatory rest periods. Each League directs which player records it maintains.
If you are a parent or guardian of a player and you would like your child’s information removed from the App, please contact an administrator of your League. You may also email us at privacy@armlog.ca and we will coordinate with the League to remove the record.
We keep a League’s data until someone asks us to delete it. We do not automatically purge a League’s records after a period of inactivity or after a subscription ends.
This is deliberate. Subscriptions are annual and the sport is seasonal, so a League that lapses in the autumn and returns in the spring is an ordinary case — automatically deleting its roster in between would destroy records its administrators expect to find waiting for them.
The corresponding obligation is that deletion must actually work when it is asked for. There are three ways to ask, and all three are real: 1. Delete your own account, from inside the App. 2. Delete your whole League, from inside the App, as an administrator. This removes that League’s database in its entirety. 3. Email us at privacy@armlog.ca. We will delete what you ask us to delete and confirm when it is done, within 30 days.
Account information is retained until the account is deleted. Backups, if any, are overwritten on a rolling basis, so deleted data may persist in a backup for a short period after deletion before being overwritten.
We use Firebase Authentication and Firestore security rules to restrict access to each League’s data to that League’s approved coaches and administrators, and we give each League its own separate database as described above. Connections between the App and our servers are encrypted in transit using TLS. No internet service can be guaranteed 100% secure, but we work to protect your information using industry-standard practices.
We may update this policy from time to time. Material changes will be reflected by updating the “Effective date” above. Continued use of the App after a change indicates acceptance of the updated policy.
Questions or requests about this policy can be sent to privacy@armlog.ca.