Privacy Policy Boxing Timer Elite

“Float like a butterfly, sting like a bee.” โ€” Muhammad Ali

Effective: 21 May 2026 Updated: 21 May 2026 Version: 2.0

Important update. This Privacy Policy replaces in full all prior versions, including any earlier policy that referred to the application as “Boxing Timer Pro” or stated that the app does not collect data or display third-party advertisements. Those statements are no longer accurate. This document describes the current data processing practices of Boxing Timer Elite as of the effective date above.

Short summary (this is not a substitute for reading the full policy):

1. Who we are (Data Controller)

The data controller responsible for processing personal data in connection with Boxing Timer Elite is:

1.1 Data Protection Officer (DPO)

We have not designated a Data Protection Officer under Article 37 of the EU GDPR. Our processing activities do not meet the thresholds that require mandatory DPO appointment: we are not a public authority, our core activities do not consist of large-scale systematic monitoring of data subjects, and we do not engage in large-scale processing of special categories of data. You may direct any privacy-related question to the contact address above.

1.2 EU/EEA representative

The data controller is established in Ireland, within the European Economic Area. No additional representative under Article 27 of the EU GDPR is required.

1.3 UK representative

If and when we are required to appoint a UK representative under Article 27 of the UK GDPR (because we offer services to UK residents from outside the United Kingdom), the contact details of that representative will be published in this section. Until then, UK residents may contact us directly at the address above.

2. Scope of this policy

This policy applies to:

It does not apply to third-party websites or services linked from the app. Their own privacy policies govern those services.

3. Categories of personal data we process

3.1 Data collected automatically when you use the app

3.2 Data you provide when you sign in with Google

If you choose to sign in with your Google account (optional), Firebase Authentication processes the following information from Google:

You can continue to use the app anonymously without providing any of this information. Sign-in is only required if you want your training data to be backed up to the cloud and to appear in the global ranking.

3.3 Training and gameplay data you create

The following data is generated by your use of the app and, if you are signed in, stored in Cloud Firestore:

3.4 Data collected by App Check and reCAPTCHA Enterprise

To prevent abuse, fraudulent score submissions and credential stuffing against our backend, we use Google App Check together with reCAPTCHA Enterprise. These services analyse signals such as IP address, browser or device fingerprint, mouse and touch behaviour, and timing patterns. Google processes this data as our processor; you can read Google's reCAPTCHA terms at policies.google.com/privacy.

3.5 Data we do not collect

We do not collect any of the following: precise GPS location, contact lists, photos or files from your device storage, microphone or camera input, biometric data, or any “special category” data under Article 9 GDPR.

4. Purposes and legal bases

We process each category of data for one or more of the following purposes, under the corresponding legal basis of Article 6(1) of the EU GDPR and UK GDPR.

Purpose Data categories Legal basis
Operate the timer, save your settings and stats on your device Preferences, local stats Performance of a contract โ€” Art. 6(1)(b)
Synchronise your data across devices when you sign in UID, Google account info, training data Performance of a contract โ€” Art. 6(1)(b)
Display the global weekly ranking with your fighter name Fighter name, weekly score Legitimate interest in providing gamification features โ€” Art. 6(1)(f). You can object at any time by signing out or deleting your account.
Serve non-personalised advertisements Approximate region, app context Legitimate interest in funding a free app โ€” Art. 6(1)(f)
Serve personalised advertisements Advertising ID, in-app behaviour, approximate region Consent โ€” Art. 6(1)(a). Collected through the in-app consent screen (Google UMP, IAB TCF v2.2). You can withdraw consent at any time in the in-app Privacy settings.
Prevent fraud, abuse and credential attacks IP, App Check tokens, reCAPTCHA signals Legitimate interest in protecting the service โ€” Art. 6(1)(f)
Comply with legal obligations (e.g. respond to lawful requests) As required Legal obligation โ€” Art. 6(1)(c)
Diagnose crashes and improve reliability Device info, app version, crash signals Legitimate interest in service quality โ€” Art. 6(1)(f)

Legitimate interest balancing. Where we rely on legitimate interests, we have conducted a balancing test to confirm that our interests are not overridden by your rights and freedoms. You can request a copy of this assessment in summary form by contacting us.

5. Third-party processors

We use the following service providers as data processors under Article 28 of the EU/UK GDPR. Each is bound by a Data Processing Agreement that includes the Standard Contractual Clauses where relevant.

ProcessorServicePrivacy policy
Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) Firebase Authentication, Cloud Firestore, Cloud Functions, App Check, Firebase Cloud Messaging policies.google.com/privacy and firebase.google.com/support/privacy
Google Ireland Limited Google AdMob (advertising) support.google.com/admob/answer/6128543
Google LLC / Google Ireland Limited reCAPTCHA Enterprise (fraud prevention) policies.google.com/privacy
Netlify, Inc. (44 Montgomery Street, Suite 300, San Francisco, CA 94104, USA) Web hosting of the PWA and static assets netlify.com/privacy

We do not sell personal data and we do not share it with third parties for their own marketing purposes.

6. International data transfers

The processors listed in section 5 may transfer personal data outside the European Economic Area and the United Kingdom, in particular to the United States and other countries where Google and Netlify operate infrastructure.

To protect your data during these transfers we rely on:

You can obtain a copy of the safeguards in place by contacting us.

7. Cookies, local storage and identifiers

7.1 Web (PWA) cookies and local storage

NamePurposeCategoryRetention
langStores your language preferenceStrictly necessaryUntil cleared
theme and related preferencesStores your visual themeStrictly necessaryUntil cleared
Firebase Auth tokens (IndexedDB / localStorage)Keep you signed inFunctional โ€” required if you sign inUntil you sign out
Service Worker cacheOffline functionalityStrictly necessaryUpdated on each release
App Check / reCAPTCHA cookiesFraud preventionStrictly necessary (security)Session
AdMob / Google ad cookiesAdvertisingConsent-basedAs declared in the Google CMP

Strictly necessary and security cookies do not require consent under PECR (UK) or the ePrivacy Directive (EU). All advertising and analytics-related identifiers are subject to your consent, collected through the consent screen on first launch.

7.2 Mobile identifiers

On Android, the app may access the Google Advertising ID for advertising purposes only after you grant consent. You can reset this ID at any time via Settings โ†’ Google โ†’ Ads, or opt out of personalised advertising entirely.

8. Retention periods

DataRetention
Anonymous account data (UID, stats) without sign-inUntil you uninstall the app or clear local storage
Signed-in account data in FirestoreUntil you delete your account from Settings โ†’ Delete Account
Weekly ranking entry13 weeks rolling window, then automatically expired
App Check tokensUp to 1 hour, then refreshed
AdMob impressions and request logsPer Google's retention schedule
Backups of FirestoreUp to 30 days after deletion request, then permanently erased
Privacy-related correspondence with usUp to 3 years after the matter is closed, for legal defence purposes

9. Your rights under EU GDPR and UK GDPR

You have the following rights in relation to your personal data:

10. How to exercise your rights

  1. Erasure: Open the app and use Settings โ†’ Delete Account. This deletes your Firestore document, weekly ranking entry and locally cached data.
  2. Withdrawing advertising consent: Open Settings โ†’ Privacy โ†’ Ad Preferences and disable personalised ads, or revoke consent through the Google CMP screen.
  3. All other rights: Send an email to boxingtimerelite@gmail.com from the email address associated with your account, describing your request.

We will respond within one month of receiving your request, as required by Article 12(3) GDPR. We may extend this period by up to two further months for complex or numerous requests, and we will inform you of any extension and the reasons within the first month. We may ask for reasonable evidence of identity before responding.

There is no fee for exercising your rights. We may charge a reasonable administrative fee, or refuse the request, only if it is manifestly unfounded or excessive.

11. Children's privacy

Boxing Timer Elite is not directed at children under 13 years of age in the United Kingdom or under the digital age of consent applicable in your EU member state (between 13 and 16, depending on the country; in Ireland the digital age of consent is 16). We do not knowingly collect personal data from children below those thresholds.

If you believe a child has provided us with personal data, please contact us at boxingtimerelite@gmail.com and we will delete the information without undue delay.

In line with AdMob policies we set tagForUnderAgeOfConsent and tagForChildDirectedTreatment appropriately and use a content rating of “PG” for served ads.

12. Automated decision-making and profiling

We do not make decisions producing legal effects, or similarly significant effects on you, solely on the basis of automated processing within the meaning of Article 22 GDPR.

Some limited profiling occurs as part of advertising: if you consent to personalised ads, Google AdMob may infer interest categories from in-app signals and approximate region in order to show more relevant advertisements. You can refuse or withdraw this consent at any time without losing access to the app.

13. Security measures

We implement appropriate technical and organisational measures to protect your data, including:

No system is perfectly secure. If we become aware of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours as required by Article 33 GDPR and, where required by Article 34, inform affected users directly.

14. Changes to this policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top of this document indicates when the most recent changes were made.

For material changes โ€” for example, new categories of data, new processors, new purposes, or any change that expands processing โ€” we will give you at least 30 days' notice before the change takes effect, through an in-app notice or by another reasonable means. Continued use of the app after the change takes effect constitutes acceptance of the revised policy, except where the change requires renewed consent under applicable law (in which case we will obtain that consent before applying the change).

15. Supervisory authorities

15.1 Ireland (controller's residence and lead authority)

The data controller is established in Ireland, and our lead processor (Google) is also established in Ireland. Accordingly, your primary supervisory authority for matters relating to this processing is the Irish Data Protection Commission. EU/EEA residents may also lodge a complaint with the supervisory authority of their own country of residence.

Data Protection Commission (Ireland)
21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
Website: www.dataprotection.ie
Phone: +353 (0)761 104 800

15.2 United Kingdom

UK residents may lodge a complaint with:

Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom
Website: ico.org.uk
Helpline: 0303 123 1113

16. Contact

For any question, request or complaint relating to this Privacy Policy or your personal data, please contact:

๐Ÿ“ง Email: boxingtimerelite@gmail.com
๐Ÿ“ฎ Post: South Beacon, Sandyford, Dublin 18, D18 RR2H, Ireland
๐ŸŒ Web: boxing-timer-elite-official.netlify.app

Please include “Privacy request” in the subject line so we can route your message quickly.