Privacy Policy
Version 3.40 · Last updated 6 October 2026
Plain-language summary (not a substitute for the full text below): 8nOut is a map-based app for the One Pocket pool community, worldwide. We store only what the app needs to work. We do not run ads. The 8nOut apps, including the web app, use no third-party analytics; our public website uses Google Analytics to count visits only if you accept it in its cookie banner. We never sell or rent your personal data. Your home-table address stays private and is revealed only to a specific connection you accept, on a grant you can revoke. You can delete your account and everything in it from inside the app, or ask us to by email (a short-lived encrypted backup is the one exception — section 10 explains it).
1. Who we are (the controller)
The "data controller" for your personal data is:
- Espen Falkenhaug, trading as "Digital Commerce Guild" — a sole proprietorship (eenmanszaak / trade name) established in the Netherlands — operator of the service "8nOut".
- Chamber of Commerce (KvK) number: 94972036.
- Contact for all privacy matters: privacy@8nout.com
- Postal address (for letters): Digital Commerce Guild, Postbus 79055, 1070 NC Amsterdam, the Netherlands. This is a correspondence address; our full registered address is held by the Dutch Chamber of Commerce (KvK 94972036) and is available on request to a data subject or to the Autoriteit Persoonsgegevens.
8nOut is operated by a sole proprietor, not a large platform. We are not required to appoint a Data Protection Officer, and we have not appointed one, because our processing does not meet the thresholds in Article 37 GDPR. You can always reach a real person at the contact above.
Because we are established in the Netherlands, your data is handled under the EU General Data Protection Regulation (GDPR) and the Dutch GDPR Implementation Act (Uitvoeringswet AVG, "UAVG"), under the supervision of the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, "AP").
2. Scope
This policy covers the 8nOut iOS app, the 8nOut Android app, the 8nOut web app / PWA (currently 8nout.pages.dev, later 8nout.com), and the public 8nOut website, together "the Service".
It does not cover CueScore, Apple, Google, or any other third-party service you may reach from 8nOut. Those services have their own privacy policies and are independent controllers of the data you give them directly (see section 7).
3. What we collect, why, and our legal basis
We only collect data you give us or that the app needs to function. We collect device GPS location in a small, named set of places, each described below — composing a Shout-out and placing your home table using "use my current location" — and nowhere else in the app. We do not collect advertising identifiers, and the 8nOut apps (iPhone, Android and the web app) collect no analytics. The one exception is statistics about visits to our public website pages, and only if you accept them — see "Website statistics (Google Analytics)" below and section 8.
| Data | What it is | Why we process it | Legal basis (GDPR Art. 6) |
|---|---|---|---|
| Account identifiers | Your account ID (a UUID), the email address from Sign in with Apple (which may be Apple's private-relay address) or Google | To create and secure your account and sign you in | Art. 6(1)(b) — performance of the contract (our Terms of Service) |
| Profile | Display name (set at signup; may later be set from your first and last name — see "First and last name" below), optional home town / country, optional bio, optional avatar photo, optional self-reported Fargo Rating, optional linked CueScore player ID. Your profile link code: a permanent 8-character code that makes up your public profile link (8nout.com/p/…) | To show your profile to other players in the app, and to anyone who opens your public profile link, whether or not they have an 8nOut account, so people can recognise and find you. Anyone who has your link can open it. It only reaches people you share it with, or who are passed it on: we never show your code to other members, and search engines are always told not to list the code link. If you're under 18, or haven't told us your age group, your link opens only for signed-in 8nOut members. If your link has reached someone it shouldn't, contact us at privacy@8nout.com and we'll issue a new one; the old link stops working | Art. 6(1)(b) — contract |
| Public profile name and search engines | Only if you claim a profile name for your link, and only if you've told us you're 18 or over. Your profile name (the part after 8nout.com/p/); a record of each claim or change: the name, which version of the Public Profile Name Terms you accepted, when, and on which app; whether "Let search engines find my profile" is on; and, after you change or remove a name, a hold that stops anyone claiming it for a while, kept only as a scrambled one-way code of the name (a keyed hash), never the name itself and never linked to you | To give you an easy-to-share address for your profile, and, while your switch is on, to let search engines list it. At that address anyone can see: your display name (exactly as it shows in the app, which may be your real first and last name), photo, town / country, bio, Ready to play, win–loss record, self-reported Fargo Rating, your CueScore link and your clubs. Anyone who types the address can open it, even with search engines switched off. While the switch is on, search engines can list the page, and we include the address in a public sitemap with only the date you last claimed, changed or switched on listing, never your activity. Claiming a name switches listing on; you can switch it off at any time. Search engines decide for themselves how they handle their own index: after you switch off or remove the name, listings can take days to weeks to drop, and copies others have made are outside our control. You can remove the name at any time with "Remove my profile name" on your profile: the address stops working at once, and your code link keeps working. We can also remove a name that breaks the rules, and we tell you why. How long we keep each part: section 10 | Art. 6(1)(b) — contract: a service you ask for when you claim a name and accept the Public Profile Name Terms. Checked every time the page is opened: if you're no longer shown as 18 or over, the page stops opening and drops out of search listings and our sitemap |
| Dominant hand and pocket preference | Your optional, self-reported dominant hand (left, right, or ambidextrous) and preferred pocket (left or right). You can set, change, or clear either at any time | Real gameplay facts for One Pocket, not general personalisation. We keep them for your own record, and to show back to you on your profile — never shown to another player by name, and not included on your public profile share link. These two fields may also contribute to a separate, suppressed, non-identifying community-wide statistic — for example, whether players with a particular dominant hand tend to win more often from a particular pocket choice — shown only as a rounded, group-level number that can never be traced back to any one player. Any visibility beyond that suppressed aggregate — for example, showing your own hand or pocket choice to another player individually — remains a separate decision that would need its own update to this policy first. You can set, change, or clear either field at any time, whether or not it has ever contributed to that statistic | Art. 6(1)(b) — contract, for keeping your own record and showing it back to you. Art. 6(1)(f) — legitimate interest, for the suppressed, non-identifying community-wide statistic described alongside |
| Play locations — clubs | The pool clubs you say you frequent. Shown on the map at the club's own address — a pool club is a public business, so there is no private location to obscure. Never your home address | To let players discover each other by club | Art. 6(1)(b) — contract |
| Play locations — home table | Whether you have a home table, its name if you give it one, its precise address/coordinates, and the approximate point we show on the map instead of the address. Also whether you have made it visible to all members | To let you optionally host games. By default, only you and your accepted connections see that you have a home table, as an approximate point, never the address. If you are 18 or older, you can choose to make a home table visible to all members instead (see section 4). The precise address is private either way, and is shared only via a grant you control (see section 5) | Art. 6(1)(b) — contract, for your home table and for showing it to your connections. Art. 6(1)(a) — consent, for showing it to all members: you give it by turning on "Visible to all members", and you can withdraw it at any time by turning that off (see section 4) |
| Contact info | Optional phone number | Shown only to players you have accepted as connections, so you can arrange a game | Art. 6(1)(b) — contract |
| Social graph | Connection requests, personal invite links, and game invitations ("challenges") | To operate the connect-first social features | Art. 6(1)(b) — contract |
| Messages (chat) | The text messages you exchange one-to-one with a connection you have accepted, and the system cards a challenge writes into that chat. Text only — no photos, no attachments | To deliver your messages and show both of you your own conversation, so you can talk and arrange games | Art. 6(1)(b) — contract, for delivering messages and your own chat history; Art. 6(1)(f) — legitimate interest (community safety), for the fixed 60-day retention, for keeping a reported or deleted message reviewable (see section 5), and for a moderator's report-gated read (see "Moderator access") |
| Device location (Shout-out only) | A one-time, reduced-accuracy read of your device's current position — city-level, never street-level — taken only when you tap "use my current location" while composing a Shout-out. On iPhone it is resolved to a city and country on your own device, and only that city/country is ever sent to us. On the website, which has no on-device equivalent, your browser rounds your position to roughly a 1 km grid before it ever leaves your device, and our server resolves that already-rounded position to a city/country and discards it in the same request. We never store the coordinate itself, on either platform — there is no column in our database that could hold one. | So a Shout-out sent from where you are right now can use your actual current city instead of only the city you told us you live in. | Art. 6(1)(f) — legitimate interest (a live "where am I right now, for this one action" signal, in the same family as Presence). We never request more than reduced/coarse accuracy and never in the background — see section 4. |
| Local availability calls — Shout-out and Broadcast | If you send a Shout-out or a Broadcast — a short, one-way call for a game, matched by city rather than by connection — we store its kind, the city/country it targets (either the device location above or your declared home town), the dates you're free, your short note, when you sent it, and when it expires. If another player responds, we store who responded and when. If you pick a respondent, we store who you picked. | To deliver the call to the right players, show you who responded, and connect you with whoever you pick. | Art. 6(1)(b) — contract, for sending, receiving and resolving a call. Art. 6(1)(f) — legitimate interest, for the audience-matching itself where it reaches players you have not connected with, and for the retention/hold rule that applies to it — see sections 5 and 10. |
| Match results | Who won, the score, discipline, date; and, for results imported from CueScore, the opponent's CueScore name and ID (see section 6). Live scoreboard sessions (an optional live, in-match tracker for a race-to-N One Pocket match) additionally capture rack-by-rack detail — who broke each rack, who won it, and the score. That detail is always visible to the two players in the match; whether anyone else can watch it live, and what they see, is a separate opt-in setting described in the next row | To build your win/loss record; the live-scoreboard detail is captured because you or your opponent chose to track the match that way, and is used to compute the match statistics shown to the two of you | Art. 6(1)(b) — contract (for you); Art. 6(1)(f) — legitimate interest (for non-member opponent data — see section 6; and, for the counterparty's own side of a live-scoreboard record, the same legitimate-interest basis that already covers a Match result row generally) |
| Live match watching (optional, off by default) | If you turn on "Let my connections discover and watch my live matches" in Settings, one of your own accepted connections may find your live scoreboard session while it is still in progress and watch it update in real time, the way your opponent already can. This works independently for each player: a given watcher sees your identity and live score only if (a) you turned this setting on, and (b) that specific watcher holds an accepted connection with you — a connection with your opponent never extends to you, and a connection with you never extends to your opponent. If either condition is not met, that player is shown to the watcher only as "Opponent," never by name and never worked out indirectly. A watcher's access ends the instant the match stops being in progress — there is no grace period, and it is re-checked on every read, so revoking the connection or turning the setting back off closes access immediately, mid-match. We also keep a record of which of your connections watched which of your matches, but never as a named list shown to anyone, including you or your opponent — a watcher may see only a bare, unnamed count of how many people are watching that match right now | To let a member who chooses to be watchable share the same live, in-match viewing experience with their own existing connections — a bounded, opt-in, one-match-at-a-time spectator amenity, never a public or map-wide one | Art. 6(1)(f) — legitimate interest, for both sides: the disclosing player's own bounded, revocable, opt-in choice, and the watch record itself (see section 10 for how long it is kept) |
| Live match scoring by an invited scorer (optional, off by default) | If you and your opponent both turn on "Allow a scorer" in Settings, either of you can invite one specific person who does not have an 8nOut account to keep score for that match, including declaring who won. You do this by sharing a link or QR code; before you can generate it, we show you plainly what you're agreeing to — that this person will be able to finish the match on their own. Your opponent has to separately agree too, with their own genuine yes/no choice, so nothing is shared until both of you have said yes. The person you invite sees both your real names before they accept, and is asked to give us a name so you both know who's scoring (for example, "Priya K. is scoring this match") — we don't create an account for them, and we don't ask them for anything else. The link only works for the first person who uses it. Once accepted, they are the only one who can enter scores until the invite ends. When they declare a winner, it is not official right away — either of you has 2 minutes to object, and if neither of you does, it is confirmed automatically. Either of you can end the invite at any time — before it's accepted, or once it's active — which hands scoring control straight back to you and discards any result that was still waiting to be confirmed | To let two players who want a hands-free scorer at the table — the same role a referee or a friend keeping score on paper already plays — track their match live, without giving that person an 8nOut account or any access beyond this one match | Art. 6(1)(a) — consent: each of you is choosing to share your own name and live match data with one specific person you picked, for this one match only, and you can withdraw that choice at any time. The underlying match record continues to rest on the same Art. 6(1)(b)/(f) bases as the Match results row above |
| Device push token | An Apple (APNs) or web-push token for your device, if you enable notifications | To send you the notifications you asked for (new connection, invitation, etc.) | Art. 6(1)(b) — contract; the operating-system permission prompt is your opt-in |
| Moderation data | Blocks you set, and reports you file (reason, optional detail) | To keep the community safe and to act on abuse | Art. 6(1)(f) — legitimate interest (community safety and lawful, abuse-free operation) |
| Agreement / consent record | Your account ID, which documents you agreed to, the document versions, the timestamp, and the IP address the agreement was sent from | To prove you agreed to the Terms and this Policy, and to prevent abuse of the sign-up | Art. 6(1)(f) — legitimate interest (accountability under Art. 5(2), evidence of agreement, security) — see section 9 for IP specifics |
| Technical logs | Standard security/error logs generated by our hosting providers (may include IP address and request metadata) | To keep the Service secure and working | Art. 6(1)(f) — legitimate interest (security, availability) |
| Presence (activity status) | Whether you are currently active in the app, shown to other signed-in members as a coarse status only — "online" (active in the last few minutes) or "recently active" (active in the last 24 hours). It is worked out from the app noting when it is open on your screen; there is no GPS or device location, and we keep only your most recent activity time — no history. | To let members see who in the community is around and reachable now, so they can arrange an in-person game | Art. 6(1)(f) — legitimate interest (a live "who's around to play?" signal for the community). Presence is on by default; you can switch it off for everyone at any time with "Go invisible" (see section 4). |
| Connection count on your profile | The number of connections you have accepted, worked out from your connections each time your profile is viewed. It is only ever a number: never a list, and it never shows who your connections are. Pending, declined or removed requests are never counted. We keep no separate record of it | So members arranging an in-person game can see whether a profile belongs to an established member of the community | Art. 6(1)(f) — legitimate interest. Who sees it: you, always. Other signed-in members who can open your profile, unless you turn off "Show my connection count" in Settings. It is never on your public profile link and never shown to search engines. It is never shown to others for members under 18, or for members who have not told us their age group. It is shown to others only after we have told you about it in the app. Turning it off is your right to object under Art. 21, and we act on it in full, straight away |
| New-joiner label | A coarse "New" label shown next to your name in Find Players and the Connections screen for the first 14 days after you join — worked out from your account's own creation date, which we already have (see "Account identifiers" above). It never shows your join date or a day count, only the single word "New," and it clears on its own once the 14 days pass; there is no separate record kept for it | To help other members notice and welcome new joiners to the community | Art. 6(1)(f) — legitimate interest (a coarse, community-welcome signal, the same family as Presence above). No new data is collected for this — it is worked out from the account-creation date already processed under the Account identifiers row |
| Age group | Whether you're 16–17 or 18 or older — self-reported once, either at sign-up or in a one-time prompt you can skip if you joined before this feature existed | To set your read-receipts default correctly — on if you're 18 or older, off if you're 16 or 17 or you skip the question (see section 5) — and to keep anything that would show you or your data beyond your own connections switched off unless you've told us you're 18 or older: sending or receiving Shout-outs and Broadcasts that reach players you aren't connected with, making your home table visible to all members, and showing your connection count to other members. Used for nothing else. | Art. 6(1)(f) — legitimate interest (letting us turn read receipts on by default for the community generally, while keeping younger members on a protective off-by-default setting instead of one opt-in-only rule for everyone) |
| Where you usually play | Whether you told us you mainly play at a club, at home, or both — asked once, and skippable, during account setup | To help us decide whether a home-table feature is worth building. Used for nothing else, and never shown to any other player or moderator | Art. 6(1)(f) — legitimate interest (understanding demand for a possible future feature). Skipping the question changes nothing else about your account. |
| Onboarding progress | Which step of account setup you were on the last time you tapped "Finish later" — for example, the name step, the city step, or the club step. We keep only your most recent position, not a history: it is overwritten (never appended) each time you tap "Finish later" again, and is not updated if you later come back and answer more questions without leaving again | To understand where members leave the profile-completion sequence, so we can improve its design. Never shown back to you, to any other player, or to a moderator individually — a moderator can only see a floor-suppressed, population-level count across many members, never a number small enough to point at one person | Art. 6(1)(f) — legitimate interest (improving the onboarding sequence's own design). Tapping "Finish later" is the same equally-weighted exit control every screen in account setup already has; nothing about it changes because of this. |
| City Ladder — your rating, your position, and past seasons | Only if you join a ladder. We work out a rating for you — a single number, starting at 1500 for everyone, that moves up or down with each match you play against another member of the same city ladder — and from it, your position on that city's board. We keep how many ladder matches you have played and the date of your most recent one. When a season closes we save a permanent snapshot of the board: your name, your position and your rating on that day. We do not use your self-reported Fargo Rating for any of this, and there is no photo on the board | To give you the thing you asked for when you joined: an ordered ranking of the players in your city, and a lasting record of how each season finished. Your rating and position are shown to the other members of your own city's ladder — not to the public, not to search engines, and not to signed-in members who have not joined that ladder. They do not appear on your profile | Art. 6(1)(b) — contract, for your membership, your rating, the board, and a season snapshot taken while you are still on the ladder: joining is a request for a service, not consent, and the ranking is the service. Art. 6(1)(f) — legitimate interest, for keeping a past season's snapshot after you leave the ladder (a season board is a record of the whole board, and removing one row would change everyone else's position) — you can object to that at any time, in the app, by choosing to appear as "Former member" (see sections 10 and 11) |
| First and last name | Your first and last name, asked as part of account setup. If you fill in both, this becomes your public display name — shown wherever your name appears to other members (chat, map, connections, challenges, and more), the same as the rest of your profile | To help us prepare for a possible future ratings-lookup feature, and for sorting the player list by name | Art. 6(1)(f) — legitimate interest (preparing a possible future ratings-lookup feature, and enabling name-based sorting of the player list) |
| Feedback you send us | The category you pick (bug / idea / question / other) and the free text you write, when you use the in-app feedback form (Settings, or the Help centre's "Still stuck?" block, on iPhone; your Profile page on the web) | To let us read and act on bugs, ideas and questions members send us. Read only by us — never shown to any other member | Art. 6(1)(f) — legitimate interest (operating a feedback channel and improving the Service) |
| Activity — points, badges and a status tier | A participation score, separate from the City Ladder rating above: points for things like sending a challenge, playing a match (won or lost), linking CueScore, making a connection, joining a group, or sending a Shout-out/Broadcast; a small set of one-time badges for participation milestones (a first challenge, a first win, a busy week, a win streak, playing in more than one city, five or more connections, having a home table, linking CueScore); and a tier name derived purely from your total points. None of this measures how good you are at pool — that is what the City Ladder and your self-reported Fargo Rating are for | To recognise showing up and taking part, not winning. Visible to you, always on your own profile. Whether anyone else can see it is your own choice — a three-way setting (Connections / Everyone / Private, default Connections) you control in Settings → Privacy, the same place as Read receipts and Typing indicators. One badge is different: whether you have a home table is never shown to a stranger through this feature, even if your setting is Everyone, and even if you have made the table itself visible to all members. Who can see a home table is decided only by that table's own setting (see section 4), never by your Activity setting — a viewer who does not hold an accepted connection with you simply sees one fewer badge in the total, not a locked or masked one | Art. 6(1)(b) — contract, for keeping your own points/badges/tier and showing them back to you. Art. 6(1)(f) — legitimate interest, for showing your points/badges/tier to another member only when your own setting allows it — recognising participation across the community is a legitimate purpose, and the default (Connections-only) and the Home Table carve-out are both there to keep that purpose from becoming a wider disclosure than you chose |
| Website statistics (Google Analytics) — only if you accept | Only on our public website pages (the home page, Info, Help, the blog, the Privacy, Terms, Accessibility and Child Safety pages, and our "page not found" page) at 8nout.com — never in the web app, the admin pages, public profile pages, or invite and share links, and never in the iPhone or Android app. If you accept: the pages you view (the address without anything after "?" or "#", and the page title), the page you came from (same rule), when you scroll, click a link to another site or download a file, your approximate location (city, region and country, worked out by Google from your IP address — Google does not store the IP address itself), your device type, browser, operating system, screen size and language, and a random identifier kept in two cookies on your device (_ga and _ga_<ID>). Not linked to your 8nOut account: we never send Google your account, your name or anything from your profile, even if you are signed in | To count visits and see which public pages are used and how people find them, so we can improve the website | Art. 6(1)(a) — your consent, given in the website's cookie banner (the same consent the Dutch Telecommunications Act requires for placing these cookies). You can withdraw it at any time with the "Cookie settings" button at the bottom of each of those pages — see section 8 |
We do not knowingly process special-category data (Article 9 GDPR — e.g. health, ethnicity, religion, political opinion). Please do not put such data in your bio or messages.
4. How location and addresses work
This is the most privacy-sensitive part of 8nOut, so it is enforced in the database itself, not just hidden in the app:
- Pool clubs appear on the public map at the club's own address. A pool club is a public business whose address is already public, so nothing is hidden or shifted — the pin is where the club is. It is never an exact private address. Home tables are different, and are covered next.
- Home tables are for your connections by default. Unless you choose otherwise (next point), a home table is shown only to you and to players you have accepted as connections. They see that you have one, its name, and an approximate point on the map — never the address. Nobody else sees anything, not even a hint that a table exists.
- You can choose to make a home table visible to all members. This is off unless you turn it on, and only members who have told us they are 18 or older can turn it on. When "Visible to all members" is on, every signed-in member can see that you have a home table, its name, and an approximate point on the map, placed at least 500 metres from the real location. In a city, that point leads to a neighbourhood, not a street. In a small town or village, it can narrow things down more than that. It is never shown to anyone who is not signed in, and never to members you have blocked or who have blocked you. Members who are not your connections never see whether you are online or at the table. The exact address is not part of this: it stays private, as described next. You can turn this off at any time, and the table goes back to connections-only straight away. If your age group changes to anything other than 18 or older, the table goes back to connections-only automatically, and stays that way until you turn it on again yourself.
- The exact address of a home table is revealed to a specific player only when you accept a game with them. That reveal is a grant that is recorded and that you can revoke at any time in Settings, where you can also see exactly who currently has access. Grants are also time-limited.
- The precise address and coordinates are held in database columns that are never returned to another player's device except through that grant, and access is enforced by database row-level security — not by the app UI.
- The app never tracks your device's GPS location continuously or in the background — every device-location read below is a single, one-time check, made only when you take the specific action that triggers it. Most of these resolve to an approximate city and are never stored; two are different, and are described as such below.
- Shout-out (auto) — a one-time location read, never stored. If you choose to compose a Shout-out using your current location, the app can ask your device, once, for a reduced-accuracy position — never full/precise accuracy, and never in the background (iOS calls this "When-In-Use"). On iPhone, that position never leaves your device: it is resolved to a city and country on your phone, and only that city/country is sent to us. On the website, which has no on-device equivalent, your browser rounds the position to roughly a 1 km grid before it leaves your device, and we resolve that rounded position to a city/country and discard it in the same request — nothing about your exact position is ever written to a database, a log, or a backup. Denying or skipping this permission never blocks you from using Shout-out — you can always type your city manually instead.
- Map tab recenter (the crosshair button) — a one-time location read that stays on your device. If you tap the crosshair button on the Map tab to centre the map on yourself, the app asks your device, once, for your current position — at whatever accuracy your phone's own location setting for 8nOut already allows; this feature never asks for anything more precise, and never runs in the background. That reading is used only to move the on-screen map to roughly where you are, then is discarded straight away. Unlike Shout-out above, it is never resolved to a city, never sent to us or to any third party, and never stored or logged anywhere, on either platform. No marker is left on the map — recenter only moves the camera. If location access is off, tapping the button explains how to turn it on; it never blocks the rest of the Map tab.
- Home table pin ("use my current location") — a one-time location read that is stored, by design. If you use the "use my current location" button while placing your home table, the app reads your device's exact position once, only when you tap it, and never in the background. Unlike Shout-out above, this position is not resolved to a city and discarded — it becomes the precise address of the home table you are creating, stored exactly like any other home-table address (see "Play locations — home table" above, and the two-tier reveal system described in this section): visible to nobody by default, revealed to a specific connection only when you accept a game with them, through a grant you can revoke at any time. You can always place the pin by hand instead, without using this button.
- Venue-proximity banner — checked automatically, every time you open the app. Unlike every other location use on this list, this one isn't triggered by anything you do: 8nOut checks your device's position once, automatically, each time you open or return to the app, to see whether you're near a pool venue already on our public map. The check happens entirely on your device, matched only against 8nOut's own venue list, and nothing about it — your position, the match result, or which venue — is ever sent to us, logged, or stored anywhere. You can turn this off at any time in Settings ("Detect when I'm near a club").
- Presence — who's active now. When presence is on, other signed-in members can see a coarse activity status beside your public map pin — "online" (active in the last few minutes) or "recently active" (active in the last 24 hours). It is shown only to signed-in members, never to the public, and it is never attached to a precise or home-table address. It adds no location detail of its own — it sits beside a pin that is already on the public map. It tells another member that you were active within that window, not exactly when, and not where. We store only your most recent activity time and keep no history of it.
- "Go invisible" — your control. A single "Go invisible" switch turns your presence — and your "Open to play" badge — off for everyone, including your connections, straight away and for as long as you leave it on. Because presence is based on our legitimate interest (Art. 6(1)(f)) and not on your consent, "Go invisible" is your right to object under Article 21, and we act on it in full. It is not a consent you have to give, and not a consent you are taking back — it is an objection we honour. Blocked and banned players never see your presence either.
5. Connections, contact info and messages
- Other players can only reach you after a mutual-consent connection: someone sends a request (or you accept their invite link) and you accept it.
- Your phone number is shown only to accepted connections.
- Blocking a player makes you mutually invisible and severs any connection. The person you block is not told that you blocked them.
- Your connection count. Other signed-in members who open your profile can see how many connections you have — never who they are, and never on your public profile link. You can hide it any time with "Show my connection count" in Settings. Members under 18, and members who haven't told us their age group, never have it shown to others. See "Connection count on your profile" in section 3.
Chat — how your messages are handled
- Chat is text-only and always gated by an accepted connection — for a one-to-one conversation, and for joining a group. There is no way to message a player you are not mutually connected with, and no attachments of any kind, in either. A challenge you send or receive also appears as a card inside your one-to-one chat with that player.
- Groups. A group is a private, text-only chat with a small, capped circle of members, separate from your one-to-one chats. You join a group through an accepted connection with whoever invited you specifically — or, at creation, with the member who created it — not with every other member already there, so a group can include people you have never personally connected with yourself. Because of that, every group's Members list tells you, for each co-member, whether you specifically hold an accepted connection with them — being in the same group does not connect you to anyone; only an accepted connection request does.
- We do not read your messages. Nothing on our servers scans, matches, scores, or flags the content of a message — not automatically, and not by hand. Before a message is sent, the app on your own device checks it against a fixed list of blocked terms (for example money-play language) and can refuse to send it; that check runs entirely on your device and reports nothing back to us — not the text, and not the fact that something was blocked.
- The same fixed list also checks your display name. If you change an already-set display name, it is checked against the same fixed list of blocked terms before the change is saved — a match rejects the change so you can try something else, and nothing about a blocked attempt is logged, stored, or sent anywhere else.
- The one exception is a report. If a message is reported, a moderator can read the reported message and a small, bounded window of the same conversation around it — in a group, narrowed further to messages from the reported member specifically, sent during your own time as a member — nothing from any other conversation — and every such access is recorded, including exactly which messages were shown. See "Moderator access" below.
- Messages. A message you send in a chat is deleted automatically 60 days after it was sent — from your view and everyone else who could see it, alike. The 60 days run per message, not per conversation, so a chat empties gradually from the oldest end. Leaving or being removed from a group does not change this clock: you keep the ability to read whatever was sent while you were a member until each message's own 60 days is up, but you can never send or receive a new message in that group again. We keep an individual message longer only where we have placed it on hold, and we place a hold only where the message is the subject of an open report, of an investigation we are carrying out, or of a request or order from a competent authority that we are required to answer. A held message is kept only for as long as that reason lasts, and in any event no longer than 12 months from the day the hold was placed, unless an authority's order requires otherwise.
- When you delete a message. "Delete for everyone" removes the message from the chat for everyone who could see it — everyone in that conversation will see that a message was deleted, and none of them can read it again. It does not erase it from our records. We keep the deleted message, unreadable in the app, until its normal 60 days are up — or until a hold is lifted, if it is the subject of a report or a legal request. This is deliberate: it means a message cannot be sent and then made to vanish before the person who received it has a chance to report it — a deleted message can still be reported. After that it is deleted for good. If you need a message erased sooner, email privacy@8nout.com and we will consider it under your right to erasure.
- Messages are kept whether or not they are read. A message you send stays for its 60 days even if someone it was sent to never opens the conversation.
- Anything you type in a chat — including an address — stays in that chat for up to 60 days, even if you later disconnect, leave, or block. In a group, this is visible to every current member for as long as it's retained — including anyone you are not yourself connected with — so a group can put what you type in front of more than one person you haven't personally vetted. Revoking access to your home table does not remove an address you typed yourself.
- If you disconnect from, or block, a one-to-one contact — or leave, or are removed from, a group, no new messages can be sent in that conversation in any direction, but the existing conversation stays readable to everyone who was part of it until its messages age out at 60 days. We keep it that way so that a record several people are part of is never invisible to any one of them, and so abuse cannot be erased by disconnecting or leaving.
- Message notifications never contain the message. A push notification tells you who sent you a message — never what it says.
Read receipts
- What it shows. When read receipts are on for both of you, each of you can see when the other has read your latest message — a small line next to the timestamp. It never shows anything about earlier messages, and it never shows that someone is typing.
- On by default if you're 18 or older; off by default for everyone else. If you're 16 or 17, or you haven't told us your age group, read receipts stay off for you until you turn them on yourself — see below.
- Strictly two-way. Read receipts only work when both of you have them on. Turn yours off and you stop seeing anyone's read time immediately — and everyone stops seeing yours, in the same moment. Because this is based on our legitimate interest (Art. 6(1)(f)) rather than your consent, turning read receipts off is your right to object under Article 21, exactly like "Go invisible" — and we act on it in full.
- Blocking or disconnecting ends read receipts for that person immediately, on top of the usual chat rules in section 5 above.
- The first time. The first time you open Chat after this feature reaches your account, we show you a short screen explaining read receipts, with the toggle live and switchable right there. Leaving it as it is, or turning it off, costs you nothing either way.
- Age group. So we can apply the right default, we ask which age group you're in — 16–17 or 18 or older — once, either at sign-up or in a one-time prompt you can skip. Skipping, or answering "16 or 17," both leave read receipts off for you — the same protected default either way. You can update your age group at any time in Settings if it was wrong or has changed. Besides your read-receipts default, it only decides whether features that reach beyond your own connections — Shout-outs and Broadcasts to players you aren't connected with, a home table visible to all members, and your connection count shown to others — are available to you. It never changes who you can connect with or message.
Shout-out and Broadcast — local availability calls
- The one exception to "connect first." Everywhere else in 8nOut, another player can reach you only after you've both accepted a connection. Shout-out and Broadcast are the one deliberate, narrow exception: a short, structured, one-way call for a game, matched by city, that can reach players you have never connected with. This feature never opens ordinary contact — no chat, no phone number, no precise address — see below for exactly what it does and does not do.
- Strictly one-way. A call is not a conversation. A recipient cannot reply to it — the only response is tapping "I'm in" (or the equivalent), which registers interest; there is nothing to type back into. A connection is created only if the sender then picks that respondent — never automatically, and never by anyone else's action.
- What can reach players you're not connected with, and what never does. A Shout-out sent from your current location, and every Broadcast, can reach players in the matched city you are not connected with — never your phone number, never a precise address, never a chat message. A Shout-out sent from your declared home town reaches your connections only. Broadcast lets you turn its reach to your connections off, on top of its always-on reach to non-connected players in the matched city.
- What a recipient sees. Your name and avatar — already visible to any signed-in member on the map (section 4) — your city, the dates you named, and your short note. Nothing else about you.
- Responding, and being picked. If you respond, the sender sees your name, avatar, and when you responded — the same information a connection request already shows them. If they pick you, that creates a connection between you, exactly like accepting one anywhere else in the app. If they pick someone else, you are told only that the call was resolved — never by whom — and no other respondent, and no bystander who merely saw the call, is ever told who else responded or who was picked. Only the sender ever sees the full list of who responded.
- Turning it off. A single setting turns both Shout-out and Broadcast off for you as a recipient, at any time — you will no longer be matched by either. Because this reach rests on our legitimate interest (Art. 6(1)(f)) rather than your consent, turning it off is your right to object under Article 21, exactly like "Go invisible" and read receipts, and we act on it in full.
- If you're 16 or 17. You're excluded — both sending and receiving — from anything that reaches players outside the sender's connections: a Shout-out sent from someone's current location, and every Broadcast, because both reach players who aren't the sender's connections, and under-18 members are excluded from that audience entirely, even when the sender is one of your own connections. You will never be shown, and cannot send, either of those. The one call still open to you is an ordinary Shout-out sent from a declared home town — you can send one yourself, and receive one sent by a connection — because that variant reaches connections only, the same rule that already applies to chat.
- Limits. You can have at most one active Shout-out and one active Broadcast at a time, with a cooldown and a daily or monthly cap on how often you can send either. This is mainly to keep the feature usable for everyone rather than a privacy control on its own, but worth knowing.
- Report and block cover this too. You can report or block a Shout-out or Broadcast exactly as you can a message. Reporting one places it on hold (section 10) so it survives our normal clean-up while the report is open; a moderator reviewing your report can see the call's kind, sender and note — the same content its own recipients could already see, not a new disclosure route (see "Moderator access" below). If we uphold a report against a call, that member's ability to send Shout-outs or Broadcasts is suspended for a period — separate from, and short of, a full account suspension.
Moderator access
To keep the community safe and act on reports, the operator and a small number of senior moderators can open an internal review view of one member at a time. That view shows:
- the profile information other members can already see — your profile details, photos, club list and win/loss record;
- the reports filed about you, and the reports you filed — in both cases without the other person's identity;
- if you sent a Shout-out or Broadcast that's been reported, the call itself — its kind, city, dates and your note — the same content its own recipients could already see;
- any moderation action already recorded about you (what was done, the reason category, our internal note, when, and which moderator did it), and whether your account is currently suspended;
- the number of connections you have accepted — a number only, never who they are.
The view does not give a moderator your precise home-table address, the names of your connections, or your individual match history. The view tells a moderator only whether you have added a phone contact (yes/no) — never the number itself, which stays visible only to connections you have accepted. Your precise home-table address stays behind the separate, time-limited grant you control and can revoke at any time (see section 4) — accepting a connection does not reveal it, and neither does this view. Your sign-in email address is not shown either — with one narrow exception: if your account was created but never finished signing up, the view tells a moderator the email address used to attempt the sign-up, so incomplete or abandoned accounts can be identified and administered. The moment your account finishes signing up, this exception no longer applies, and your email is not shown to any moderator through this view again.
Your messages are not part of this view either — they are reachable only through a separate, narrower route, and only when a message is reported. When someone reports a specific message, a moderator with a separately granted message-review permission can read the reported message and a bounded window of the same conversation around it: at most 5 messages before and 5 after, and no more than 24 hours either side of the reported message. Nothing outside that conversation can be read, there is no browsing, no search over messages, and no way to open anyone's messages without an open report naming one. A message that was deleted for everyone appears in that window (marked as deleted) while we still hold it — that is what makes a deleted message still reportable. Every such read is recorded, including exactly which messages were shown, in the same access record described below.
A moderator must give a reason, or link the report they are acting on, before the review view will open — and for messages, only a linked report will do — and every opening is recorded: who opened it, about whom, when, why, and (for messages) which messages were returned. We keep that access record for 18 months and then delete it; it cannot be read from the app by any member. This is what keeps the access accountable and reviewable.
If you submit a venue for review, a moderator holding a separate verification permission can also open a real two-way conversation with you about that specific submission — even if you are not connected. This is narrower than it sounds: the moderator can only reach you about the venue you submitted, never any other member; the conversation is only available while your submission is pending review, plus 14 days afterward; and every message you receive this way carries an on-screen notice telling you a moderator sent it, which submission it concerns, and that Report and Block work exactly as they do anywhere else in the app. This access ends automatically once the 14 days pass, if the venue is removed, or if either account is deleted — whichever happens first. Every opening and every message sent through this route is recorded in the same access record described above.
Legal basis: our legitimate interest in a safe, abuse-free community (Art. 6(1)(f)). You can object to this processing under Article 21 (see section 11); because it exists to protect other members, we may continue where we have compelling legitimate grounds, but we consider every objection on its facts.
Account merges
Occasionally, two accounts on 8nOut turn out to belong to the same real person — most often a duplicate sign-up, for example one made with Apple and one with Google. When we spot this, the operator can combine the two into one surviving account, using an internal tool built for exactly that. This is not something a moderator can do: it is a manual, owner-only action, used only once we've checked the two accounts really are the same person, never automatic and never based on how alike two profiles look.
For almost everything, nothing you already have there is lost. Your profile details, match history, City Ladder standing, Activity points, badges and status tier, and your sent messages, are all combined onto the account that survives. The two exceptions are your City Ladder standing and a home table pin: whichever of the two accounts has played more ladder matches keeps its own standing, and whichever pinned its home table more recently keeps that pin — even if that means the other account's version is the one that's replaced.
The account that doesn't survive is switched off, not deleted. It can no longer be found on the map or challenged to a new match. Existing conversations it's already part of are not affected by the merge — they carry on exactly as before, through the connections that were already accepted.
Your own connections, challenges and conversations with other members are never moved onto a different account by this process. If someone you're connected with later has one of their accounts merged into another, nothing about your side of that connection, challenge or conversation changes — so we don't need to tell you it happened. Both accounts involved in a merge are told directly, every time.
Legal basis: our legitimate interest in accurate, non-duplicated records for the community (Art. 6(1)(f)). You can object under Article 21 (see section 11); we consider every objection on its facts.
Push notifications
Most notifications tell you about something that already happened to you directly — a message, a connection request, a challenge. The one below is different: it's an extra you turn on yourself, and you can turn it off again at any time.
- New members digest (opt-in). If you turn this on, we send you a weekly notification telling you how many new members joined 8nOut in the past week — a number only, never names or locations. It's off until you turn it on, and you can turn it off again at any time. We don't send it if nobody new joined that week.
Legal basis: our legitimate interest (Art. 6(1)(f)) in helping members notice and engage with a growing community — not your consent: turning this on is a product preference, not a consent flow, and turning it off is as simple as flipping the toggle back. You can object to this processing under Article 21 (see section 11).
6. CueScore integration
8nOut can read your public CueScore profile and public CueScore match results (from CueScore's public read API) so you can:
- Link your CueScore profile — we then store your CueScore player ID and use your CueScore name and photo on your 8nOut profile.
- Import a finished match — we read the public match record and store the result (winner, score, discipline, date) against your 8nOut win/loss record.
Two things you should know:
- Opponent data, including non-members. A match has two players. If your opponent is also an 8nOut member, we link the result to their account. If your opponent is not an 8nOut member, we store their CueScore name and ID only so your own record is accurate. We rely on our legitimate interest (Art. 6(1)(f)) in giving you an accurate personal record for this limited, low-risk storage. Imported match rows — including any opponent name — are private to the two players in the match; they are not shown on any public profile or public page. A non-member opponent's name is never published publicly by 8nOut. If you are a non-member opponent and want your name removed from a member's imported record, contact privacy@8nout.com. One ordering is worth knowing about: if you unlink your CueScore profile first and only then delete your account, we no longer hold anything connecting your CueScore ID to your account, so we cannot find the matches where you appear only under that ID — your CueScore name and ID can remain on the other player's private record of a match you played. Deleting your account directly, without unlinking first, removes them. If you have already unlinked, email privacy@8nout.com with your CueScore ID and we will remove them for you.
- CueScore is a separate service. Reading CueScore is subject to CueScore's own terms; 8nOut does not control CueScore and is not responsible for the accuracy of CueScore data. Links to CueScore open in your browser.
Venue data for the public map (from CueScore). Any signed-in member can add a public pool venue to the 8nOut map by pasting a public CueScore venue link, and our moderators can do the same. When this happens, 8nOut reads that venue's public CueScore details — the venue name, address, city, and country — and stores only those facts, together with the venue's CueScore organisation/venue ID as a record of where the entry came from (its provenance). We do not copy CueScore's page, and we do not store the venue's table list, logo file, or any player, owner, or match data from it. Every submission is reviewed by a moderator before it appears on the public map. A moderator-controlled switch can turn all CueScore reads — venue reads and match imports — off at any time.
Publicly aggregated win/loss counts (like a Fargo rating) may be shown on a member's profile. These are numbers, not a list of named opponents.
7. Who receives your data, and in what role
We do not sell, rent, or trade your personal data, and we do not share it for anyone else's marketing.
Two different kinds of company appear below, and the difference decides who is answerable to you for what happens next:
- Our processors handle data on our instructions and for no purpose of their own. They may not use it for anything we have not asked for, we stay responsible for it, and Article 28 GDPR governs what they may do with it.
- Independent controllers decide for themselves what they do with the data they receive. They do not act on our instructions and would not take them from us. Their own privacy policies — not this one — govern that data, which is why we name them here rather than make promises on their behalf. Section 2 says the same thing.
7.1 Processors — they handle data on our behalf
| Who | What they do for 8nOut | What they hold | Where |
|---|---|---|---|
| Supabase | Database, sign-in, file storage and server functions — the whole 8nOut backend | Everything in your account | Database in the EU (Ireland). The Supabase contracting company is outside the EU — see "International transfers" below |
| Cloudflare | Hosts and delivers our website and web app, and runs a quick, automated check that a sign-up is a real person and not a script (Cloudflare Turnstile), during sign-up on both the website and the iPhone app | Request data only — your IP address, your browser type, and the page you asked for; during sign-up, the same kind of request-level signals (your device/environment), needed to generate that check. Not the contents of your account | Global network; a page can be served from outside the EEA — see "International transfers" below |
| Google (Google Analytics) — only if you accept website statistics | Measures visits to our public website pages for us, so we can see which pages are used (section 3, "Website statistics"). Google acts only on our instructions: we have switched off its data-sharing settings, Google signals and every advertising feature, so it may not use this data for its own purposes or for ads | The website statistics only — pages viewed, approximate location, device and browser details, and the random identifier from the _ga cookies. Never your 8nOut account or anything in it. Kept for 14 months (section 10) | Google Ireland Limited is our contracting party; Google may process the data in the United States — see "International transfers" below |
| Resend | Sends the email that carries your one-time sign-in code, on our behalf, when you sign in or sign up by email; and sends us a short internal notification, on our behalf, when you use the in-app feedback form — that notification never contains the text you wrote, only that feedback of a certain category arrived; and, if your account is deleted at your emailed request or removed for a breach of our Terms, sends you one email confirming this or giving the reasons | Your email address, and the content of that one email — the sign-in code itself, generated fresh each time and expiring within minutes. For the feedback notification: the only reference to you in that email is your internal member ID — used only so a moderator can look you up in our own systems if needed; never your name, your email address, or the text you wrote. For a deletion or removal email: only your email address, the dates, and, for a removal, the category of the reason — never an internal note or who reported you | Processes in the United States. Resend's Data Processing Addendum — Standard Contractual Clauses, a UK Addendum, and its own EU–U.S. Data Privacy Framework certification — covers the transfer; see "International transfers" below |
| Geoapify | Looks up the map coordinates of a pool club's address when someone adds a club, on our behalf | Only the address text typed for the club, sent from our server. Never your IP address, your name, your account, or the club's name | EU. Geoapify is an EU company, based in Cyprus, and handles these lookups in the EU, so this data does not leave the EEA |
| Anthropic | Powers the AI coding-agent sessions we use to build and maintain 8nOut | No access to your data. These sessions read and write our source code and project documentation (tickets, migration files, and similar) — never a live copy of the database, and never member data | We have not yet confirmed where Anthropic's processing takes place or what transfer safeguard applies — see "International transfers" below |
7.2 Independent controllers — they receive data and decide their own use of it
| Who | What they receive, and when |
|---|---|
| Apple — Sign in with Apple | Signs you in, and gives us an account identifier and an email address (often an Apple private-relay address) |
| Apple — push notifications (APNs) | Carries a notification to your iPhone when we send you one |
| Apple — App Store and TestFlight | Distributes the app, and holds its own relationship with you as a customer or tester |
| Apple — Apple Maps (MapKit) | Draws the map inside the iOS app |
| Google — Sign in with Google | Signs you in, and gives us an account identifier and an email address |
| Google — Google Play | Distributes the Android app, and holds its own relationship with you as a customer or tester |
| OpenStreetMap Foundation — map tiles (web and Android app) | Draws the map on the website, in the web app and in the Android app. Your browser, or the Android app, fetches the map images directly from OSM's servers, so OSM sees your IP address and which part of the map you are looking at. We are not in the middle of that request |
| GitHub — MapLibre demonstration map (older Android app builds) | Builds of the Android app that don't yet use OpenStreetMap map tiles draw a basic map (borders and place names only) from a free demonstration map server that the MapLibre open-source project runs on GitHub's hosting. The app fetches that map data directly, so GitHub sees your IP address and which part of the map you are looking at. We are not in the middle of that request. Updating to a build that uses OpenStreetMap map tiles stops this |
| OpenStreetMap Foundation — Nominatim (location lookup) | For Shout-out on the website only: if you use a browser (not the iPhone app) to compose a Shout-out from your current location, we send your already-rounded, approximate position to Nominatim once, to resolve which city you're in, and nothing else. On iPhone your position is resolved to a city on your own device, and Nominatim never sees it. Only the rounded position is sent — never your IP address, your name, or your account. Club addresses are looked up by Geoapify (section 7.1), not by Nominatim. If Geoapify's lookup is unavailable for a longer period, we may temporarily send club address lookups to Nominatim instead, under the same rule: only the address text, nothing about you. |
| Google, Mozilla, or Apple — Web Push relay | If you enable notifications on our website or web app, your notification is relayed by whichever company operates push infrastructure for your browser — Google if you use a Chromium-based browser (Chrome, Edge, Brave, Opera, and others), Mozilla if you use Firefox, or Apple if you use Safari with 8nOut installed to your Home Screen. Only one of the three ever receives a given notification — whichever matches your browser. What it receives is the same minimum content already described above for iPhone notifications: who a message or event is from, never its content |
| Search engines (for example Google) | Only if you claim a profile name and leave "Let search engines find my profile" on: the public page at your name's address, as anyone can see it, and the address is listed in our public sitemap |
About Apple push notifications specifically. Apple carries our notifications under the Apple Developer Program agreement rather than as a company we could bind with a data-processing agreement. That is exactly why we keep the contents of a notification to the minimum needed to tell you what happened.
A name we removed, and why it's back. Earlier versions of this section listed Google Firebase Cloud Messaging as a push provider "if used", then removed it because nothing in the product used it. That has changed for a specific, disclosed reason: if you enable notifications on our website using a Chromium-based browser, your notification is now relayed through Google's push infrastructure, exactly as the Web Push relay row above describes — so Google is a genuine recipient again, for real data, this time. We use no advertising or attribution service of any kind, and the 8nOut apps use no analytics service (section 8). The one analytics service we use is Google Analytics on our public website pages, only if you accept it, with Google as our processor (section 7.1) — it is separate from this relay, which carries only the minimal notification content described above and nothing else. Receiving a notification does not give Google, Mozilla, or Apple any broader relationship with 8nOut or with you.
International transfers. Where data goes outside the European Economic Area, this is the position, provider by provider:
- Supabase stores and primarily processes your data in the EU (Ireland). Its contracting company sits outside the EU, and that part of the relationship is covered by the European Commission's Standard Contractual Clauses, which form part of our agreement with them.
- Cloudflare runs a global network, so a request for one of our pages may be handled outside the EEA. What travels is the request data described above — never your account contents. Cloudflare's transfer safeguards are set out in its own published data-protection terms.
- Resend processes and stores data in the United States by default — the "Ireland" region shown when a sending domain is configured controls only where email is routed and sent from, not where it is stored, so this is not EU-region hosting. The transfer is covered by Standard Contractual Clauses and a UK Addendum in Resend's Data Processing Addendum, plus its own certification under the EU–U.S. Data Privacy Framework.
- Geoapify is established in Cyprus, in the EU, and handles club address lookups in the EU, so no transfer outside the EEA takes place.
- Anthropic — we have not yet confirmed where its processing takes place or what specific transfer safeguard applies, and we are not stating one here until we have. As explained above, no member data is exposed through this relationship.
- Google Analytics (only if you accept website statistics): Google may process the statistics data in the United States. The transfer is covered by Google LLC's certification under the EU–U.S. Data Privacy Framework, and by the Standard Contractual Clauses in Google's data processing terms for Google Analytics, which we have accepted.
- Apple, Google, GitHub, Mozilla and the OpenStreetMap Foundation receive data as independent controllers (for Google: in the roles listed in 7.2, not Google Analytics), so any transfer they make is theirs, under their own arrangements and their own privacy policies.
You can ask us about any of this at privacy@8nout.com.
Law enforcement and competent authorities. If a competent authority requires it under a binding legal instrument, we may have to give them data we hold — including the content of messages that are still within their retention period. We do not act on informal requests: we require a valid order or request from an authority competent over us, and we route requests from outside the Netherlands through the proper legal channels. If an authority makes a valid request to preserve data, we will place it on hold — preserving is not disclosing. We will tell you if your data has been disclosed, unless the law or the order forbids us from telling you, in which case we will tell you as soon as we are allowed to. We may also disclose data to establish, exercise, or defend a legal claim.
8. No ads, no cross-site tracking — and statistics on our website
- We do not run adverts, and we will not use third-party ad networks, ad SDKs, or tracking-based advertising.
- The 8nOut apps — iPhone, Android and the web app — contain no third-party analytics or advertising SDKs.
- No cross-app or cross-site tracking; we do not build advertising profiles. The Google Analytics set-up described below does not follow you to other websites: its cookies are set on 8nout.com only, and Google signals and every advertising feature are switched off.
- 8nOut never processes, holds, or transfers money.
Website statistics (Google Analytics) — only if you accept.
- Where. Only on our public website pages: the home page, Info, Help, the blog, the Privacy, Terms, Accessibility and Child Safety pages, and our "page not found" page (recorded only as "/404/", never the address you typed). Never in the web app (
/app/), the admin pages, public profile pages (/p/), or invite and share links, and never in the iPhone or Android app. - Your choice. On your first visit to one of those pages, a banner asks whether you accept statistics cookies, with three equal buttons: Accept, Reject and Choose. Nothing is loaded from Google and no statistics cookie is set until you press Accept. If you reject, nothing is set and the website works exactly the same. There is no other effect of saying no.
- What is measured, and why. See section 3, "Website statistics (Google Analytics)". It is used only to count visits and see which pages are used, so we can improve the website. It is never linked to your 8nOut account, even if you are signed in.
- Who receives it. One third party: Google, as our processor (section 7.1). Google may process the data in the United States (section 7, "International transfers").
- Cookies.
_gaand_ga_<ID>, set on 8nout.com only. They expire at most 12 months after your last measured visit, and are deleted earlier if you withdraw or when your choice expires. - How long we remember your choice. Your choice (accept or reject) and its date are kept on your own device only, for 12 months; we keep no copy on our servers. After 12 months — or sooner if we add a purpose, a third party or a cookie — we ask again.
- Changing your mind. The "Cookie settings" button at the bottom of every page where the banner appears (the pages listed under "Where") lets you change or withdraw your choice at any time; it is as quick as accepting was. When you withdraw, measurement stops immediately and the
_gacookies are deleted from your device. Data already measured is not linked to you and is deleted when its 14-month retention ends (section 10). If you would like it deleted sooner, send us the identifier from your_gacookie at privacy@8nout.com and we will delete that data from Google Analytics.
Storage that needs no consent. The website and web app also keep a few things on your device that are strictly necessary or that you chose yourself: your sign-in session, your theme and language, which notices you have already dismissed, an invite you are in the middle of accepting, an agreement you are in the middle of giving, and your cookie choice itself. They are never used for statistics or shared with Google, and the Dutch Telecommunicatiewet does not require consent for them.
9. The IP address in your agreement record — the specifics
When you agree to the Terms and this Policy at sign-in, we record the agreement (your account ID, the documents and their versions, the timestamp, and the IP address the request came from). We treat an IP address as personal data.
- Why. To be able to demonstrate that you agreed (our accountability obligation under Art. 5(2) and Art. 7 GDPR) and to detect and prevent abuse of the sign-up (e.g. mass fake accounts).
- Legal basis. Our legitimate interest (Art. 6(1)(f)) in holding evidence of your agreement and in keeping the sign-up secure. We have weighed this against your privacy: the data is minimal, is not used to profile or track you, and is not shared for marketing.
- Retention. We keep the full IP address only for a limited period — 12 months — after which we either delete it or reduce it (for example, dropping the last part of the address) so that only the fact and metadata of your agreement (account ID, document versions, timestamp) remain for as long as your account exists, as proof of agreement.
- Your rights. Because this rests on legitimate interest, you can object (Art. 21). We will stop unless we have compelling legitimate grounds — and note that we may need to retain the record to defend a legal claim.
10. Retention — how long we keep things
- Account, profile, locations, connections, challenges, match results, contact info, device tokens: kept while your account exists.
- Your profile link code: kept while your account exists. We replace it only if you ask us to, or after a safety report; the old link then stops working for good.
- Your profile name: kept while you hold it. The record of your current claim is kept while your account exists. The record of a name you've changed or removed is deleted when that name's 6-month hold ends. If we remove a name for breaking the rules, its record is kept only as long as the moderation record for that decision (24 months). Everything is deleted with your account.
- Holds on past profile names: after you change or remove a name, it's held for 6 months; after an account is deleted, 12 months; a name we removed for breaking the rules is held permanently. A hold is only a scrambled one-way code of the name (a keyed hash) and the date it ends. It never contains the name itself and is never linked to you or your account. Expired holds are deleted daily.
- Live scoreboard sessions: a session that is never finished (abandoned, or the app closed mid-setup) goes stale and can no longer be opened after 20 minutes if it was never started, or 6 hours with no scoring — it never becomes part of your match record. It is then deleted once 30 days have passed with no activity, though that is not a fixed timer — the clean-up runs the next time either of you opens a scoreboard, so a stale session can sit a little longer before it is actually removed. A finished session is kept as part of the match result it produced, under the same "kept while your account exists" rule as any other match result — with one addition: if you delete your account, a finished session you played is not deleted outright (deleting it would corrupt your opponent's own copy of that match) — it is kept, with your own identity removed from it, the same way a match result already works today (see "When you delete your account" below).
- City Ladder — your membership: kept while you are on the ladder. If you leave, your membership, your rating and your position are deleted straight away, and they are deleted with your account if you delete that. If you later rejoin, or join a different city, you start again from 1500 — a rating only means anything relative to the players it came from, so we do not carry an old one over.
- City Ladder — past season boards: kept permanently, and this is the one thing we most want you to be clear about before you join. When a season closes we save that city's board exactly as it stood — your name, your position and your rating on that day — and we keep it indefinitely. That is deliberate: a season board is a record of how a whole community's season finished, which is how competitive rankings work generally, and removing one player's row would silently change everyone else's position in the record. Two things follow, and both are in your hands:
- Leaving the ladder does not remove you from past season boards, and they keep showing your name. Neither does deleting your 8nOut account — in that case the row stays but your name comes off it (see "When you delete your account" below).
- You can take your name off past boards yourself, at any time, without leaving the ladder and without deleting your account. Switch on "Show me as ‘Former member’ in past seasons" — either on the leave screen or on its own, at any time afterwards, including long after you have left. Your past positions and ratings stay on the board; just not your name. This is also how you exercise your right to object (section 11) to us keeping a named row after you have left the ladder. The row itself is never deleted, for the reason above.
- Activity — points, badges and tier: kept while your account exists, and erased together with the rest of your profile in the single deletion when you delete your account. Unlike a match result or a City Ladder season board, this is not a shared record — your points and badges belong to you alone, so there is nothing kept back for anyone else's sake. One thing worth knowing: if you (or the other player) later delete a match you played, using the "delete this match" control on your own match list, the points and any badge that match already earned you stay earned — the same "once given, never taken back" rule your badges already follow everywhere else. That is deliberate: your Activity progress reflects what you did at the time, and one match being removed from your own list later should not silently reduce it, whether you or the other player deleted it.
- Messages (chat): deleted automatically 60 days after each message was sent — see section 5 for the full rule, including the hold regime (an individual message under an open report, an investigation, or an authority's preservation or production request is kept until that reason ends, and at most 12 months from the hold unless an order requires otherwise) and what "delete for everyone" does and does not erase.
- A match you delete yourself. From your own match list, you can permanently delete an individual match you played, at any time. Because a match record is shared, deleting it removes it from both players' copies at once, straight away — and the other player gets an in-app notice that a shared match was removed, so they are never simply left finding it gone; we tell them that it happened, not why. Two kinds of match cannot be deleted this way, so that other members' own records stay accurate: one that has already counted toward a City Ladder rating, and one that came from a live scoreboard session. One nuance worth knowing if the match came from CueScore (section 6): deleting it removes only our copy of that match — if either player later re-imports the same match from CueScore, it can reappear, because 8nOut never touches CueScore's own record of it. A match logged inside 8nOut directly, from a challenge, has no other copy anywhere, so deleting it is final.
- Local availability calls (Shout-out and Broadcast): a call disappears from view once it expires — 24 hours after sending for a Shout-out, and for a Broadcast, the day after your last available date or 14 days after sending, whichever comes first. We keep the expired call and its responses for up to a further 60 days before deleting them for good — the same 60-day/hold pattern as chat messages (section 5): longer only where it is on hold because it is the subject of an open report, an investigation, or a competent authority's request, and even then no longer than 12 months from the hold unless an order requires otherwise. Withdrawing a call yourself does not shorten this — it stops new responses, but the record is cleaned up on the same clock. If you delete your account, a call you sent, or responded to, is not deleted outright — like a shared match result, it stays on its ordinary clock (above) with your name and account link removed, unless it is on hold at that moment, in which case your identity stays on it exactly as it was for as long as the hold lasts — see below for the full rule, including what happens once the hold is lifted. The one-time device location read that may have produced a call's city is never stored at all, so there is nothing there for this clock to apply to.
- When you delete your account (Settings → Delete account), we erase your profile, locations, connections, invitations, messages, photos, contact info, device tokens, and match rows from our live database, in a single deletion, straight away. The one exception for messages: an individual message under hold (see section 5) is kept, cut down to the message itself and a pseudonymous sender reference, until the hold ends — so that deleting an account cannot erase the evidence in an open report or a legal preservation request. Your other messages are deleted with the account; the other person's own messages in your conversations are theirs and stay on their own 60-day clock. A live scoreboard session you never finished is deleted outright, like the rest of your account. A finished one is handled exactly like a match result: kept as your opponent's shared record of the game, with your own name and account link removed from it. Your City Ladder membership, rating and position are deleted with the account; your rows on past season boards are handled the same way as a match result — the row stays, so that nobody else's recorded position changes, but your name and account link come off it and it shows as "Former member". Your Shout-out/Broadcast setting (on or off, and any send suspension) is erased with the rest of your profile. A call you sent, or a call you responded to, is handled like a match result: it is not deleted, but your name and account link are removed from it straight away, so it stays on its ordinary clock (above), no longer linked to any live profile. The one exception: if the call is at that moment on hold (see section 5) — because it is the subject of an open report, an investigation, or a competent authority's request — your identity stays on it exactly as it was, unchanged, for as long as the hold lasts. Nothing happens automatically the moment the hold is lifted, and your identity is never stripped from the call on its own — instead, once the call is both no longer on hold and past its own retention window above, the whole record is deleted for good, identity included, the same eventual outcome a held message reaches. One further, time-limited exception is described under Backups below.
- Presence (activity status): we keep only your most recent activity time, never a history, and it is erased together with your account in the single deletion.
- Age group and your read-receipts setting: kept while your account exists, and erased together with the rest of your profile in the single deletion when you delete your account. There's no automatic re-check — a "16 or 17" answer simply stays in the more protective state if you don't update it, and you can update it yourself in Settings at any time.
- Reports you filed about other players are kept after you delete your account, but with your identity detached (we remove the link to you), so that a bad actor cannot erase the reports against other people by deleting their own account. The report itself carries no personal data about you as the reporter. Every report is deleted on a fixed schedule: 24 months after we act on it, 12 months after we dismiss it, or 12 months after you file it if it is never decided — unless the report is still cited as evidence in an active moderator enforcement record, in which case it is kept until that record itself is deleted.
- Feedback you sent us is kept after you delete your account, but with your identity detached the same way — the category and text you wrote stay, so we can keep acting on a bug report or idea, but the link to you as the person who sent it is removed. Every feedback submission is deleted from our database 12 months after you send it.
- Live match watching: if you watch a connection's live match (see section 3), a record of that — which match, and when you started and last watched it — is kept for up to 48 hours after the match stops being in progress, or deleted immediately if you delete your account, whichever is sooner. It is never shown to anyone, including the two players, as a named list — only a bare, unnamed count is ever shown, and only to a watcher.
- Live match scoring by an invited scorer: the invite record — including the name the person you invited gave us when they accepted — is kept exactly as long as the match session it belongs to is (see "Live scoreboard sessions" above): deleted along with an abandoned, never-finished session once that reaches 30 days of inactivity, or kept as part of a finished match's permanent history the same as everything else about that match. It is never shown to anyone except the two players who were in that match.
- A record of a moderator enforcement action (that an account was suspended or removed, the category of reason, the date, and the account's sign-in identifier) is kept for 24 months and then deleted, including after the account itself is deleted, so that we can operate moderation accountably and prevent a removed account from immediately returning. Your sign-in identifier is your email address or, if we don't have one (for example, some Sign in with Apple accounts), the name of your sign-in provider and the account ID that provider gave us. This record is kept to the minimum needed and is not used to profile you.
- A record that we deleted your account at your request. If you ask us by email to delete your account, we keep a record that we did (your sign-in identifier and the date) for 24 months, to show we handled your request. It is not a moderation record and is never treated as one.
- An email we still have to send you about a deletion or removal is held for up to 7 days, then deleted whether or not it was sent. It is deleted as soon as it has been sent. Resend, who sends it on our behalf, keeps its copy for 30 days.
- A record of a moderator opening a member's review view or a reported message's review window (who opened it, about whom, when, the stated reason or linked report, and — for messages — which messages were returned) is kept for 18 months and then deleted — see "Moderator access" above.
- A record of any disclosure to a competent authority (what was required, under which instrument, what was disclosed, and whether you were told) is kept for 5 years, as our accountability record of having handled the order lawfully. It contains no message content beyond identifying which messages were disclosed.
- Agreement / IP record: see section 9.
- Provider security logs: kept for the short period set by each provider.
- The sign-in code email you receive (via Resend): Resend, who sends this email on our behalf, keeps a copy of it — including the code itself — for 30 days, then deletes it automatically. The code only ever works once and stops working within minutes of being issued, so this 30-day copy is a delivery record, not a live credential; we do not ourselves keep a separate copy of the email's content.
- Website statistics (Google Analytics), only if you accepted: Google keeps the measured data for 14 months from when it was collected, then deletes it; a later visit does not extend that period. Totals in Google's standard reports (for example "visits per page per month") contain no identifier and may be kept longer. The
_gacookies on your device and your cookie choice: see section 8. - Backups. So that member data can be recovered after a technical failure, we take a regular backup copy of the database. It is encrypted before it leaves the operator's computer, and it is held only by us — one copy on the operator's own equipment and one copy in the operator's own cloud storage, where the storage provider holds no key and cannot read it. Backups are deleted automatically after at most 30 days. They exist for one purpose only — restoring the Service after an incident. We do not read them, search them, or use them to answer questions about any member.
This has one consequence we want to be plain about: when you delete your account, your data is erased from the live Service immediately, but a copy can still exist inside an encrypted backup until that backup expires — at most 30 days. During that time the backup is sealed and unused. If we ever do have to restore from a backup, we re-apply every deletion that happened after that backup was taken before the restored data goes back into service, so an account you deleted does not come back.
11. Your rights
Under the GDPR and UAVG you have the right to:
- Access your data and get a copy;
- Rectify inaccurate data (much of it you can edit directly in the app — for a match or live-scoreboard result that looks wrong, the player who recorded it can correct it directly, or you can message them in-app to ask for a correction. Your ladder rating is corrected the same way: it is worked out from your match results, so correcting the result corrects the rating — we reverse exactly what the original result applied and re-apply the corrected one, rather than counting it twice);
- Erase your data ("right to be forgotten") — you can do this yourself at any time via Settings → Delete account. You can also email privacy@8nout.com from the email address linked to your account: we'll ask you to confirm by replying from that address, then delete the account and confirm once it's done. If your account has no email address linked to it (for example, some Sign in with Apple accounts), we can't confirm by email that the account is yours, so please use Settings → Delete account after signing in. If you can no longer sign in, tell us what you can about the account and we'll see whether it lets us identify it;
- Restrict or object to certain processing (see section 9 for legitimate-interest processing). For past City Ladder season boards there is a direct control rather than an email: switch on "Show me as ‘Former member’ in past seasons" and your name comes off every past board immediately — see section 10;
- Data portability for the data you provided, where applicable;
- Withdraw consent at any time for anything that is based on consent (note: most 8nOut processing is based on our contract with you, not consent — see the table in section 3). Website statistics are based on consent: withdraw with the "Cookie settings" button at the bottom of every website page where the cookie banner appears (section 8);
- Not be subject to automated decision-making with legal or similarly significant effects — we do not do this.
To exercise any right, email privacy@8nout.com. We will respond within one month (extendable by two further months for complex requests, and we will tell you if we need that). We do not charge for this unless a request is manifestly unfounded or excessive.
Complaints. If you think we have mishandled your data you can complain to the Dutch Data Protection Authority:
Autoriteit Persoonsgegevens, Postbus 93374, 2509 AJ Den Haag, the Netherlands — autoriteitpersoonsgegevens.nl
You may also complain to the supervisory authority in your own EU country of residence.
12. Children
8nOut is not intended for children under 16. The Service helps adults arrange in-person games, sometimes at private home addresses, so we set a minimum age of 16. If we learn that someone under 16 has created an account, we will delete it. If you believe a child is using 8nOut, contact privacy@8nout.com.
Our public website can be read by anyone. If you are under 16, please choose Reject in its cookie banner (section 8).
(Netherlands: the UAVG sets 16 as the age of valid consent for information society services. 8nOut adopts 16 as its minimum age regardless of the legal basis used.)
13. Security
Access to sensitive data (precise home addresses, contact info) is enforced at the database layer by row-level security and by server-side functions, so it cannot be bypassed from a client app. Data is hosted in the EU and encrypted at rest at the storage layer. We also keep an encrypted backup of the database so that member data can be restored after a technical failure. Backups are encrypted before they leave the operator's computer, are held only by us, are never used for anything but restoring the Service, and are deleted automatically after at most 30 days (see section 10). No system is perfectly secure, but we design 8nOut so that private data is private by default.
14. Changes to this policy
If we change this policy in a way that materially affects you, we will update the version number and the date, and — because agreement is recorded and versioned — we will ask you to review and agree again the next time you open the app or web app. Minor clarifications may be made without re-consent, but the date will always reflect the latest version.
15. Contact
privacy@8nout.com — Espen Falkenhaug, trading as Digital Commerce Guild, operator of 8nOut, established in the Netherlands (KvK 94972036). Letters: Digital Commerce Guild, Postbus 79055, 1070 NC Amsterdam, the Netherlands (see section 1).