Back to Home

Privacy Policy

How Shotcall collects, uses, and protects your personal information.

Last updated: May 25, 2026

Shotcall ("we", "us", or "our") is operated by Soroosh Sorkhani, an individual based in Toronto, Ontario, Canada. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our service at shotcall.app. By using Shotcall, you consent to the practices described in this policy.

1. Information We Collect

Information you provide directly:

  • Account information: email address, password (hashed), display nickname, and avatar emoji you choose during onboarding.
  • Game data: match score predictions (bets), champion picks, group memberships, and any content you submit through the platform.

Information collected automatically:

  • Usage data: pages visited, features used, and interaction timestamps, collected through Vercel Analytics.
  • Authentication tokens: session tokens stored in your browser to keep you signed in.

Information from third-party sign-in (Google):

  • When you sign in with Google, we receive your email address and Google account ID from Google's OAuth service.
  • We do not receive or store your Google password, contacts, calendar, Gmail, or any other Google data.
  • We only request the minimum scopes needed: your basic profile email to create and identify your account.

2. How We Use Your Information

We use your information only for the following purposes:

  • To create and manage your Shotcall account.
  • To authenticate you and keep you signed in securely.
  • To enable core game features: placing bets, tracking scores, computing points, and displaying leaderboards.
  • To show your nickname and avatar to members of groups you join.
  • To send transactional emails (password reset, account security notices). No marketing emails.
  • To analyze aggregate, anonymized usage to improve the platform.
  • To detect and prevent fraud, abuse, or violations of our Terms of Service.

We do not sell, rent, or trade your personal information to third parties. We do not use your data for advertising profiling.

3. Information Sharing & Disclosure

We share your data only as described below:

  • With other users in your groups: Your nickname and avatar are visible to other members of any group you join. Your bets are hidden until a match kicks off, then visible to your group members.
  • Service providers: We use the following sub-processors to operate the platform:
SupabaseDatabase, authentication, and real-time dataUnited States
VercelHosting, deployment, and analyticsUnited States
Google OAuthOptional sign-in authentication onlyUnited States
  • Legal requirements: We may disclose your information if required by law, court order, or to protect the rights, property, or safety of users or the public.
  • Business transfer: If Shotcall is acquired or merged, your data may be transferred as part of that transaction. You will be notified beforehand.

4. Google Sign-In (OAuth)

Shotcall uses Google OAuth 2.0 to allow you to sign in with your Google account. When you choose this option:

  • You are redirected to Google's sign-in page, which is operated by Google LLC.
  • Google authenticates you and shares only your email address with us.
  • We create or match a Shotcall account using that email address.
  • We store your Google account's unique ID internally to recognize future sign-ins. We never store your Google password.

Revoking Google access: You can disconnect your Google account from Shotcall at any time via your profile settings. You can also revoke access directly from your Google Account permissions page. Revoking access does not delete your Shotcall account or data.

Our use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

5. Data Retention & Deletion

  • We retain your account data for as long as your account is active.
  • You can delete your account at any time from the Profile page. This permanently removes your authentication record and all associated personal data from our systems.
  • Anonymized, aggregated game statistics (e.g., platform-wide totals) may be retained after account deletion.
  • Backups may retain your data for up to 30 days after deletion before being purged.

To delete your account: go to Profile → scroll to bottom → Delete Account. Deletion is permanent and cannot be undone.

6. Security

  • All data is transmitted over HTTPS (TLS encryption).
  • Passwords are never stored in plain text. They are hashed using industry-standard algorithms by Supabase Auth.
  • Database access is controlled via Row-Level Security (RLS) policies, so users can only access data they are authorized to see.
  • We do not store payment information; Shotcall is a free platform with no transactions.
  • While we take reasonable precautions, no system is 100% secure. If you discover a security vulnerability, please contact us at soroosh.sorkhani@gmail.com.

7. Your Privacy Rights (Canada, PIPEDA)

As a resident of Canada, you have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA) and Ontario provincial privacy law:

  • Right to access: Request a copy of the personal information we hold about you.
  • Right to correction: Request correction of inaccurate personal information.
  • Right to withdrawal of consent: You may withdraw consent to our use of your data at any time, subject to legal and contractual restrictions. Withdrawal of consent may prevent us from providing you with the service.
  • Right to deletion: Request deletion of your personal information (subject to legal retention requirements).
  • Right to complain: If you believe your privacy rights have been violated, you may file a complaint with the Office of the Privacy Commissioner of Canada.

To exercise any of these rights, contact us at soroosh.sorkhani@gmail.com. We will respond within 30 days.

8. Cookies & Local Storage

  • We use browser cookies and local storage strictly for authentication sessions (to keep you signed in).
  • We use Vercel Analytics which collects anonymized, aggregate usage data. It does not use third-party advertising cookies or fingerprinting.
  • We do not use Google Analytics, Facebook Pixel, or any behavioral advertising trackers.
  • Blocking cookies will prevent sign-in from working. All other pages are accessible without cookies.

9. Children's Privacy

Shotcall is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us at soroosh.sorkhani@gmail.com and we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. If changes are material, we will notify you via the in-app announcement banner. Continued use of Shotcall after changes are posted constitutes your acceptance of the updated policy.

11. Contact Us

For any privacy-related questions or requests, contact the data controller:

  • Name: Soroosh Sorkhani
  • Location: Toronto, Ontario, Canada
  • Email: soroosh.sorkhani@gmail.com