Download Our Data

Last updated: 24 April 2026

Who we are

Dribble360 (dribble360.com) is a football analytics platform. References to "we", "us", or "our" in this policy refer to the operator of dribble360.com. Contact: support@dribble360.com

What data we collect

  • Email address — collected when you subscribe or create an account. Used to send your login link, subscription receipts, and product updates.
  • Payment data — processed by Stripe. We never see or store your card number. Stripe provides us with a subscriber token, plan name, and billing status only.
  • Session token — a random 64-character hex string stored in the dribble_session cookie after you log in. Valid for 30 days. Used to recognise you as a subscriber on return visits.
  • API key — generated for API subscribers. Stored as a SHA-256 hash; the raw key is shown once at creation and not stored.
  • Usage analytics — we use Google Analytics (GA4) and Microsoft Clarity to understand how visitors use the site. These tools collect anonymised page-view data, session counts, and click heatmaps. No personally identifiable information is passed to these services.
  • Server logs — standard request logs (IP address, URL, timestamp, HTTP status code) are retained for up to 30 days for security and debugging purposes.

How we use your data

  • To authenticate you and maintain your session
  • To fulfil your subscription and provide access to paid features
  • To send transactional emails (login links, receipts, service notices)
  • To improve the platform through aggregated usage analytics
  • To detect and prevent abuse (rate limiting, API key validation)

We do not sell, rent, or share your personal data with third parties for marketing purposes.

Third-party processors

ProcessorPurposeData sharedPrivacy policy
StripePayment processingEmail, billing address, payment methodstripe.com/privacy
ResendTransactional email deliveryEmail address, email contentresend.com/legal/privacy-policy
Neon (Neondatabase)Hosted PostgreSQL databaseEmail, session tokens, subscription dataneon.tech/privacy-policy
Google Analytics (GA4)Anonymised usage analyticsAnonymised page events, no PIIpolicies.google.com/privacy
Microsoft ClaritySession replay & heatmapsAnonymised click and scroll data, no PIIprivacy.microsoft.com
AWS App RunnerApplication hostingAll server-side data transits AWS infrastructureaws.amazon.com/privacy
Google Cloud / BigQueryBigQuery subscriber data productsGCP project IDs for BigQuery subscriberscloud.google.com/terms/cloud-privacy-notice

Cookies

We use one first-party session cookie:

  • dribble_session — set after login; stores your session token; expires in 30 days; necessary for the service to function.

Third-party analytics tools (Google Analytics, Microsoft Clarity) set their own cookies to track anonymised sessions across visits. You can opt out of Google Analytics tracking via the Google Analytics Opt-out Browser Add-on.

Data retention

  • Subscriber records — retained while your subscription is active and for 90 days after cancellation, then deleted.
  • Session tokens — expire automatically after 30 days; expired tokens are purged during routine maintenance.
  • API keys — deleted within 24 hours of subscription cancellation.
  • Server logs — retained for 30 days, then deleted.
  • Analytics data — retained according to the respective processor's policy (GA4 default: 14 months; Clarity: 13 months).

Your rights (GDPR & UK GDPR)

If you are in the European Economic Area or the United Kingdom, you have the following rights regarding your personal data:

  • Access — request a copy of the data we hold about you.
  • Rectification — request correction of inaccurate data.
  • Erasure — request deletion of your data ("right to be forgotten").
  • Restriction — request that we limit processing of your data.
  • Portability — receive your data in a machine-readable format.
  • Objection — object to processing based on legitimate interests.
  • Withdraw consent — where processing is based on consent, withdraw it at any time.

To exercise any of these rights, email support@dribble360.com with "Data Request" in the subject line. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority (e.g. the UK ICO at ico.org.uk).

Legal basis for processing (GDPR)

  • Contract performance — processing your email and payment data to fulfil your subscription.
  • Legitimate interests — server logging for security; usage analytics to improve the platform.
  • Consent — analytics cookies set by Google Analytics and Microsoft Clarity (you can opt out at any time).

International transfers

Your data may be processed in the United States and other countries where our processors operate. Stripe, Resend, AWS, and Google Cloud maintain Standard Contractual Clauses (SCCs) and other safeguards approved by the European Commission for international data transfers.

Children

Dribble360 is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us at support@dribble360.com.

Changes to this policy

We may update this policy from time to time. Material changes will be communicated by updating the "Last updated" date above and, where appropriate, by email to subscribers. Continued use of the platform after changes constitutes acceptance of the updated policy.

Contact

For any privacy-related questions or requests: support@dribble360.com

Made With 💜 For The Game

Dribble Inc. • 44 Tehama St. • San Francisco, CA

94105

Privacy Policy