Privacy Policy
Last updated: September 11, 2026. Your privacy is fundamental to our architecture. We do not sell your personal data or track your browsing activity across other websites.
1. Information We Collect
We collect only the minimal data required to deliver real-time sports alerts and maintain service reliability:
A. Web Push Notification Credentials
When you click "Enable Alerts" or subscribe to notifications for a match, your browser requests permission to receive push alerts. If granted, your browser generates a standardized Web Push subscription token, including:
- An endpoint URL provided by your operating system or browser push service (e.g. Apple Push Notification Service for iOS/macOS Safari, Firebase Cloud Messaging for Chrome/Android).
- Cryptographic public keys (
p256dhandauth) used to encrypt push payloads end-to-end between our server and your device. - The specific game IDs and alert preferences you chose to track (e.g. Halftime Start, 2-Minute Warning, Score Updates).
This token contains no personally identifiable information (such as your name, email, or telephone number).
B. Local Device Storage (HTML5 LocalStorage)
To ensure your settings persist across visits without requiring an account login, we save your preferences locally on your device using browser localStorage:
- Favorite Teams: Pinned teams displayed in your dashboard and ticker.
- Sound Settings: Referee whistle audio preference and master volume.
- Muted Match IDs: Games you have elected not to receive alarms for.
- Recent Simulation Data: Cached testing data if you use the Simulation Lab.
This data stays exclusively on your machine and is never sold, transmitted to data brokers, or shared with advertising networks.
C. Server Diagnostics & Security Logs
Like virtually all web servers, our hosting infrastructure automatically logs basic HTTP connection metadata, including your IP address, browser user-agent, requested URL, and response status codes. These logs are used strictly for security threat detection, DDoS mitigation, rate limiting, and technical troubleshooting.
2. What We Do NOT Collect
- No Personal Identification: We do not ask for or collect names, postal addresses, phone numbers, or social media accounts.
- No Payment Information: Halftime Tracker is completely free to use. We do not collect credit cards or financial data.
- No Precise Geolocation: We do not track or request access to your device's GPS coordinates.
- No Cross-Site Tracking: We do not employ third-party advertising tracking cookies or canvas fingerprinting.
3. How We Use Collected Data
Data processed by Halftime Tracker is utilized solely for:
- Transmitting push alerts for the matches you have actively selected.
- Pruning expired match alerts and dropping outdated notifications.
- Preventing server abuse, automated bot attacks, and denial of service.
- Maintaining system uptime and optimizing application loading speeds.
4. Infrastructure & Third-Party Services
We work with trusted cloud and platform infrastructure providers:
- Hosting & Server Compute (Railway): Our production backend and in-memory Redis alert cache run on Railway's secure cloud infrastructure.
- Browser Push Gateways: When we dispatch a notification, encrypted data travels through your browser manufacturer's official push server (Apple APNs for Apple devices, Google FCM for Android and Chrome).
- Sports Data Feeds: Live match scores and game statuses are retrieved from public sports information APIs.
5. Your Rights & Data Deletion
You maintain complete control over your notifications and local data at all times:
- Revoking Push Notifications: You can turn off alerts at any time by clicking the "Mute" toggle on any game card, or by adjusting your browser permissions (Site Settings > Notifications > Block).
- Clearing Device Storage: Clearing your browser cookies and site data for this domain immediately and permanently deletes all stored favorite teams, sound preferences, and local cached match data.
- Server-Side Subscription Expiration: When your device unsubscribes or a push endpoint returns an invalid/expired status code (HTTP 404 or 410 Gone), our background worker automatically removes that endpoint from our database.
6. Contact Us
If you have questions, feedback, or concerns regarding this Privacy Policy or our data protection practices, please contact us at: