Privacy Policy
This is the privacy policy for SocialReferee at socialreferee.com and the
URC Playoff Predictor at urc.socialreferee.com — a small, free fan-built
project. It describes what we collect, why, and how to remove it. Plain language only;
no hidden gotchas.
What we collect
You can use the entire predictor without an account — fixture picks, scoreline edits,
try counts and form toggles all live in your browser's localStorage, never
sent anywhere.
If you choose to sign in with Google, we receive these from Google:
- Your Google subject identifier (a stable opaque ID)
- Your email address
- Your display name
- Your profile picture URL
And we store, on our side:
- The four items above, linked to a randomly-generated user ID
- Your prediction settings as a single JSON record — form overrides, fixture-winner picks, score overrides, try-count overrides — so you can use the site across devices
- Timestamps of when your account was created and last seen
Cookies
While signed in, we set one HTTP-only session cookie (urc_session,
signed, 30-day expiry, scoped to .socialreferee.com) so the site
recognises you across the apex landing and the URC predictor. During the sign-in flow,
short-lived cookies (urc_oauth_state, urc_oauth_return, both
ten-minute lifetimes) are set for CSRF protection and post-login redirect. We also set
a sr_theme cookie (1 year, not HTTP-only) to remember your theme choice.
None of these is used for tracking; none is read by third parties.
What we don't do
- No third-party analytics, ad networks, or tracking pixels.
- No selling, sharing, or trading of your data.
- No payment information (the site is free).
- We don't track your activity outside this site.
Where it's stored
Primary user data (your account record and prediction settings) lives in Cloudflare D1 (a SQLite-backed database) hosted in the EU (Frankfurt region). The site itself is served by Cloudflare Pages, which is global. Cloudflare receives standard request metadata (IP address, timestamp, request path) for delivery and abuse prevention, governed by Cloudflare's privacy policy. OAuth identity flows transit Google's US-region infrastructure; outbound forwarded email transits Cloudflare Email Routing.
Third parties
- Google — for sign-in via OAuth. Subject to Google's privacy policy.
- unitedrugby.com — standings, fixtures, and team logos are fetched at site-build time for the URC predictor. We don't pass user data to URC.
- Cloudflare — hosting, DNS, email forwarding. See the link above.
Retention & deletion
We keep your data until you ask us to delete it. Signing out only clears the session cookie — your stored settings remain so you can sign back in later. To delete your account and settings entirely, email us (see Contact below); deletion is permanent and processed within a few days.
Your rights
You can ask us to provide, correct, or delete your data at any time. If you're in the EU/UK, the GDPR/UK GDPR applies to this processing.
Changes
We may update this policy as the site evolves. The "last updated" date at the top tracks revisions; significant changes will be flagged in-app.
Contact
For privacy questions or data requests, email info@socialreferee.com.