Privacy policy
Last updated: 10 July 2026 · Applies to the REF! app for iPhone and Apple Watch
The 30-second summary: REF! keeps your matches on your device. We only upload to our servers what is strictly needed for the social features you choose to use (your profile, your friendships and the matches you share with other referees). We do not sell your data, there are no ads and we do not track you for advertising purposes. Your health data only leaves your device if you share a match, and you can delete your account and all your remote data from within the app.
Language: this is a courtesy translation of the Spanish original. In the event of any discrepancy, the Spanish version prevails.
1. Data controller
The controller of your data is Rodrigo Vicente Valmorisco (Spain), developer of REF!.
Contact for any privacy question or to exercise your rights: soporte@therefapp.es
2. What data we process
2.1 Account data
- Sign in with Apple: this is the only way to create a REF! account. We receive the identifier Apple gives us and, if you authorise it, your name and email (or Apple's private relay address if you choose to hide it). REF! never sees or stores your Apple password.
- User identifier (UUID) generated when the account is created.
2.2 Profile data
- The display name and username you choose to show to other users.
- An avatar photo, if you decide to upload one (stored with our storage provider).
- Your preference on whether or not to share your statistics with friends.
2.3 Sport and health data (HealthKit) — with your explicit permission
If you grant Health access, REF! reads during your matches: heart rate, distance covered and active calories. REF! also writes each match as a workout in Apple's Health app, with its route and metrics.
HealthKit commitment: health data is used exclusively to show you your performance inside the app. It is never used for advertising or marketing, never sold and never shared with third parties for those purposes. It only leaves your device if you share a match with your officiating team (see 2.5), and only the metrics derived from that match.
2.4 Precise location — with your permission and only during a match
We use GPS (from the iPhone or the Apple Watch) while you referee to calculate distance covered, detect sprints and draw your heat map of the pitch. Location is only recorded during an active match, never in the background outside one.
2.5 Shared matches and social features
- Friendships: requests sent/received and your friends list.
- Match invitations: who invites whom to referee as a team.
- Shared performances: when you share a match with other referees, the following is uploaded to our servers and shown to the participants in that match: your display name, your officiating role (main referee/assistant), distance, top speed, sprints, average heart rate, calories and the GPS route for that match (for the combined heat maps and the awards).
- Blocks and reports: if you block or report a user, we store the block and, in the case of a report, the reason and the detail you write, so we can moderate the platform.
2.6 Push notifications
We use OneSignal to send you notifications (friend requests, invitations, shared match activity). To do so, your device's notification token and your language are associated with your user identifier. You can turn them off at any time in iOS Settings.
2.7 Data that never leaves your device
Stored locally only (and in your manual backup if you export one): your matches and their history, teams, stadiums, competitions, seasons and your fees and earnings as a referee. REF! does not upload your financial information to any server.
2.8 iCloud
Invitations to shared matches may rely on CloudKit (iCloud), within the app's container and under your Apple account. HealthKit data is never stored in iCloud by REF!.
2.9 What we do NOT do
- We do not show ads or use your data for third-party advertising.
- We do not sell or rent your data.
- We do not track you across third-party apps or websites (no "tracking" in the sense of Apple's ATT framework).
- We do not use third-party analytics tools that profile your usage.
3. What we use your data for and on what legal basis
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Create and maintain your account, sync your profile | Account, profile | Performance of a contract (art. 6.1.b) |
| Show your physical performance in each match | Health, location | Explicit consent (art. 6.1.a and 9.2.a), revocable in Settings |
| Social features: friends, team matches, awards, combined maps | Profile, shared performances | Performance of a contract; sharing is voluntary |
| Send you notifications | Push token, user ID, language | Consent (notification permission) |
| Community moderation and safety | Blocks, reports | Legitimate interest (art. 6.1.f) |
4. Who we share data with (processors)
| Provider | Service | Data |
|---|---|---|
| Supabase | Authentication, database, storage and realtime sync | Account, profile, friendships, invitations, shared performances, blocks and reports. Server region: European Union (eu-west-1, Ireland) |
| OneSignal | Push notification delivery | User ID, push token, language |
| Apple | Sign in with Apple, APNs, iCloud/CloudKit, HealthKit (local) | According to each Apple service and its own policy |
These providers act as processors under their corresponding data protection agreements. If any of them processes data outside the EEA (e.g. OneSignal in the USA), this is covered by the European Commission's Standard Contractual Clauses or other valid international transfer mechanisms.
5. How long we keep your data
- Remote data (profile, friendships, shared performances): for as long as your account is active. Deleted when you delete your account.
- Moderation reports: may be kept for as long as necessary to manage platform safety, in minimised form, even after the reporting account is deleted.
- Local data (matches, earnings, etc.): held on your device and under your control; removed when you uninstall the app or delete them yourself.
- Health data: workouts written to the Health app stay under your control in Health, even if you delete REF!.
6. Account deletion
You can delete your account directly from the app: Profile → Delete account. This erases your remote data (account, profile, avatar, friendships, invitations and shared performances). Local data on the device and workouts in the Health app are untouched: they are yours and it is your call. You can also request deletion by writing to soporte@therefapp.es.
7. Your rights
Under the GDPR and Spain's LOPDGDD, you can exercise your rights of access, rectification, erasure, objection, restriction of processing and portability at any time by writing to soporte@therefapp.es. You can also withdraw Health, location and notification permissions in iOS Settings without affecting the rest of the app.
If you believe we have not handled your rights properly, you can complain to the Spanish Data Protection Agency (aepd.es) or to your local supervisory authority.
8. Minors
REF! is not intended for children under 14. If you are under 14, do not create an account. If we detect an account belonging to someone under that age without their guardians' consent, we will delete it.
9. Security
All communication with our servers is encrypted (TLS). Access to remote data is protected with row level security (RLS) policies, so each user can only reach their own data and the data other users have explicitly shared with them. Passwords are stored with secure hashing managed by the authentication provider.
10. Changes to this policy
If this policy changes substantially, we will tell you inside the app or by email before the change takes effect. The version in force will always be published on this page.
11. Contact
For any privacy question: soporte@therefapp.es