Privacy Policy
Last updated 19 September 2026
In short. Your academy decides what goes in Nadina App about you and your child; we hold it for them. We never see a card number, never sell anything to anyone, and a child's medical notes are visible only to their own coaches, their academy's admins and their own guardian.
1. Who is responsible for what
There are two different relationships in this policy, and they matter:
- Your academy is the controller of everything about its players, families, staff, sessions and dues. It decides what to collect and why. We are its processor: we hold and process that data on its instructions, under these commitments. If you are a parent or a player, your first port of call for a correction or a deletion is your academy.
- We are the controller for this marketing website, for enquiries sent to us, and for the account of the academy itself (its admin's name, email and billing).
The operator is Pixels, [REGISTERED ADDRESS]. Data protection contact: Hussein.shaalan77@gmail.com.
2. What we hold
If you visit this website
Nothing beyond what our host records to serve the page (IP address, browser, page requested, time), and whatever you type into the enquiry form and send us — your name, academy, email, phone and message. This site sets no cookies and runs no analytics or advertising trackers.
If you are an academy or a member of staff
Name, email, password (stored only as a bcrypt hash — we cannot read it), role and staff capabilities, the academy's name, branding, scheduling rules and fee plans, your subscription and billing history, and a log of administrative actions.
If you are a family
| Category | What it includes | Why it is there |
|---|---|---|
| Player identity | Name, date of birth, gender, photograph, jersey number, position, height and weight | To know who is on the roster and in which age band |
| Contact | Guardian name and phone, email, phone, emergency contact name and number | So the academy can reach someone when it matters |
| Health | Allergies, medical conditions, medications, doctor's name and number, insurance, free-text medical notes | So the people supervising a child know what they must know. Provided by the academy or the guardian. |
| Participation | Team and squad, attendance, RSVPs, training and match schedule, game statistics, badges | To run the sessions and show a player their season |
| Money | Dues raised, amount, status, method, provider reference, receipts, donations and sponsorships | To show a family what they owe and an academy who has paid |
| Communication | Posts, comments, reactions, suggestions, notifications sent to you | The team feed and the notices your academy sends |
| Technical | Push notification token for each device, sign-in tokens, error logs | To deliver notifications and keep you signed in safely |
3. Why we are allowed to hold it
- To perform a contract — running the academy's membership, and our subscription with the academy.
- Legitimate interests — keeping the service secure, preventing abuse, and supporting our customers.
- Consent — where the academy relies on a guardian's consent, in particular for health information and photographs of children. Consent can be withdrawn through the academy at any time.
- Legal obligation — invoices and tax records.
4. Children
Nadina App is built for clubs whose members are children, so this deserves its own section.
- A child does not sign up. An academy adds a player, or a guardian requests one and an admin approves it.
- Accounts belong to guardians. Where an academy gives an older player their own login, it is that academy's decision and responsibility.
- Medical notes and emergency contacts are visible only to that child's coaches, the academy's admins, and the child's own guardian. They are never shown on a public screen.
- People who sponsor a player see initials only and no photograph — they never see contact or medical details.
- A parent sees their own children. Opening another family's child returns nothing.
5. Payments
We never see a card number. Checkout is hosted by the payment provider; the card details are entered on the provider's page and never reach our servers or our database. What we store is the amount, the status, the method and the provider's reference, so an academy can reconcile and a family can see a receipt.
Each academy's own gateway credentials are encrypted at rest with AES-256-GCM before they are stored, separately per academy.
6. Who else touches the data
We do not sell personal data, we do not rent it, and we do not use it to train machine-learning models. We share it only with the suppliers who make the service work:
| Who | What for | What they get |
|---|---|---|
| Railway | Application hosting and the PostgreSQL database | All service data, encrypted in transit and at rest |
| Google (Firebase Cloud Messaging) | Push notifications to phones | Device token, notification title and body |
| Resend | Transactional email — verification codes, invitations, receipts | Email address and message content |
| Whish Money, Areeba | Card and wallet payments, under each academy's own merchant agreement | Payment amount, reference and whatever the provider's checkout collects directly |
| Cloudflare / our website host | Serving this public website | Standard web server logs |
We will also disclose data where the law compels it, and to protect someone's safety or our rights. If the business is ever sold, data moves with it and we will say so beforehand.
7. Where it is stored
The database and application run on Railway's infrastructure, and some suppliers above operate outside Lebanon. Where data is transferred internationally, we rely on the supplier's standard contractual protections.
8. How long we keep it
- While the academy is a customer. Player records are archived rather than deleted when someone leaves, so the payment history behind them stays intact and auditable.
- 30 days after an academy's account ends, for export — then deleted or irreversibly anonymised.
- Invoices and tax records for as long as Lebanese law requires, typically ten years.
- Enquiries from this website for up to two years.
9. How it is protected
- One academy cannot read another's data. Every record carries its academy, and isolation is enforced three times over: in the sign-in token, in a tenant-scoped database client, and again by row-level security inside PostgreSQL.
- Passwords are stored as bcrypt hashes; we cannot recover them, only reset them.
- Payment gateway credentials are encrypted per academy with AES-256-GCM.
- All traffic is over HTTPS.
- Sessions end themselves after a short period of inactivity and must be signed in again.
- Staff capabilities are checked on the server for every request, not just hidden in the app.
No system is perfectly safe. If a breach ever affects your data, we will tell the affected academy without undue delay and explain what happened and what we are doing about it.
10. Your rights
You can ask to see the data held about you, to correct it, to delete it, to get a copy in a portable format, or to object to a particular use. For anything about a player or a family, ask your academy — it decides, and we act on its instruction. For anything we control ourselves, write to Hussein.shaalan77@gmail.com and we will answer within 30 days.
11. Cookies, storage and notifications
This website sets no cookies. The apps and the management website store your sign-in token and a few preferences (dark mode, the last academy you opened) on your own device, so you are not signed out between visits. Clearing your browser or app storage removes them.
Push notifications are opt-in on your device and can be turned off per category in the app's notification settings, or entirely in your phone's settings.
12. Changes
If we change this policy materially we will tell academies by email or in the app before it takes effect. The date at the top is always the version in force.
13. Contact
Email Hussein.shaalan77@gmail.com · WhatsApp +961 3 707 751 · Beirut, Lebanon.