Privacy Policy
Last updated September 2, 2026 · Version 2026-09-02
1. Who we are
Stadion Arena ("we", "us", "our") operates the Stadion Arena platform (the mobile app and website) that lets players discover venues, book sports slots, form teams, join challenges and tournaments, and lets venue owners manage those bookings.
This Privacy Policy explains what personal data we collect, why, how we use and share it, and the choices and rights you have.
2. Information we collect
Account information: your first, middle and last name, username, email address, phone number (your primary phone is your unique login identifier) and password (stored only as a secure hash).
Profile information: gender, preferred position, favourite sport, chosen avatar, and your country and governorate/region.
Activity information: the venues, slots and courts you book; your tickets and check-ins; the teams you join or lead; match invites, challenges and tournament participation.
Location information: your device location — precise location when you grant it, otherwise approximate — used only while you are using the app, to show nearby venues on the map and to sort nearby open matches and challenges by distance. We use it to answer that request and do not store a history of where you have been. Location is optional — the app works without it, and you can turn it off at any time in your device settings.
Content you create: team names and logos you upload, and reports you submit about other players (for example a no-show or unsporting behaviour).
Safety and conduct reports: when you report a player or a venue, we collect what you tell us — including any description of an incident and anything you attach, such as messages, screenshots or photographs — and we link it to your account and to the account or venue you are reporting. Please include only what is needed to explain the problem, and avoid sending us the personal details of other people, or sensitive information that does not need to be shared.
Device and technical information: a push-notification token so we can send you alerts, plus standard technical data such as IP address, app version and basic log data needed to run and secure the service.
Crash and error diagnostics: if the app or our servers hit a fault, we receive an automatic report describing it — the error and the point in our code it came from, together with technical details of the device it happened on, such as device model, operating system version and app version. These reports are not linked to your account.
Verification information: when you verify your phone number, we may send a confirmation message via WhatsApp or SMS. We store only a hashed version of any verification data and delete it promptly after confirmation or expiry.
3. How we use your information
To create and manage your account and authenticate you (including login by phone number).
To provide the core service: bookings, tickets, teams, challenges, tournaments and match organisation.
To share the minimum necessary booking and ticket details with the venue owner (and their authorised staff) so your booking can be honoured and checked in.
To show relevant venues near you when you enable location.
To send you service notifications (booking updates, invites, team news) via push, and to operate, secure, debug and improve the platform.
To contact you about your account — phone or email verification, password resets, and important service or policy updates.
To keep the community safe — we review reports (such as no-shows or rude behaviour) and may keep records of them to enforce these policies.
4. Legal bases for processing
We process your data to perform our contract with you (to provide the service you request), on the basis of your consent (for example for location and push notifications, which you can withdraw at any time), to comply with legal obligations, and for our legitimate interests in operating and securing the platform.
Some information is treated as sensitive — for example details of an injury or a medical incident, or an allegation that someone has committed a crime. We ask you not to send us sensitive information unless it is genuinely needed. Where you do include it in a safety report, we process it to look into that report, to protect users and to comply with the law, and we handle it with the additional care the law requires for data of that kind.
We are based in Jordan and we process personal data in line with the Jordanian Personal Data Protection Law No. 24 of 2023 and other applicable law. Where the law of the country you live in gives you stronger protection, we honour it.
5. How we share information
With venue owners and their staff: the booking, ticket and check-in details needed to fulfil a booking you make at their venue.
With other users: your public profile (such as username, avatar and the teams you are in) is visible to players you interact with; you can hide yourself from the Explore Players directory in your settings.
When you join an open match or challenge, or take part in a tournament, your participation in it — such as your username and avatar in that lineup or bracket — is visible to the other players involved, and an open match is visible to players browsing that time slot. A booking you make privately for yourself (for example booking a whole court) is not shown to other players.
With tournament organisers: if you are a team captain and your team enters a tournament, the organiser running that tournament can see the phone number and email address on your account, so they can reach you about fixtures and scheduling. An organiser sees this only for the tournaments they manage, and it is not shown to other players.
With service providers who process data on our behalf under contract: Google Firebase (push-notification delivery), our cloud hosting and infrastructure provider (to run and secure the service), and a messaging provider used to send phone-verification codes by WhatsApp or SMS, and Sentry, which receives the crash and error diagnostics described below. When you open the in-app map, the map imagery is served by OpenStreetMap, whose servers receive the map area you are viewing; the app also loads its typefaces from Google Fonts, whose servers receive your device IP address when it does.
For legal reasons: where required by law, or to protect the rights, safety and property of our users or the public.
We do not sell your personal data.
6. Analytics, crash reporting and advertising
We do not show ads and we do not use third-party advertising or cross-app tracking networks.
We use Sentry, a third-party crash-reporting service, to receive an automatic diagnostic report when the app or our servers hit a fault. We use these reports only to find and fix faults and to keep the service stable — never to build a profile of you, and never for advertising.
These reports are configured not to identify you: we do not attach your account, and cookies, authorisation headers, the contents of requests and the query string of web addresses are removed before a report leaves our systems. We use no analytics SDK that profiles you or tracks you across apps; beyond crash diagnostics we rely on basic server logs to run, secure and troubleshoot the service. If we add analytics in future, we will update this policy and our Google Play Data safety disclosure before doing so.
7. Cookies (website)
Our website uses only strictly necessary cookies — for example to keep you signed in and to protect against cross-site request forgery. We do not use advertising or cross-site tracking cookies.
The mobile app does not use cookies; it stores a secure login token on your device to keep you signed in.
8. Data retention
We keep your personal data for as long as your account is active and as needed to provide the service. When you delete your account it is hidden immediately and permanently anonymised after a short grace period (during which logging back in cancels the deletion). We may retain limited records where required for legal, security or accounting purposes.
9. Your rights and choices
You can access and update most profile information in the app or on the website at any time.
You can download a copy of your data using "Export my data".
You can delete your account, which starts the anonymisation process described above.
You can control location and push permissions from your device settings, and hide your profile from the Explore directory.
You can also ask us to correct inaccurate data, to restrict or object to a particular use, to withdraw a consent you have given, and to receive your data in a portable form. Contact us to exercise any of these. We reply within the period the law allows, and we may need to confirm who you are first.
If you are not satisfied with how we have handled your data, you may complain to the competent data-protection authority in Jordan, or to the authority where you live. Telling us first usually resolves it faster, but you are not required to.
10. How to delete your account
In the app: open Profile, choose "Delete account", and confirm with your password.
Without the app: email [email protected] from the address on your account, or use the "Contact / Support" screen, and ask us to delete it. We confirm who you are before acting on the request.
Either way, the account is hidden immediately and permanently anonymised after a short grace period, during which logging back in cancels the deletion. Your profile details, bookings, teams, tickets and notifications are removed or anonymised. We keep only the limited records described under "Data retention" — for example, accounting entries a venue is legally required to hold.
Once the grace period ends this cannot be undone. If you want a copy of your data, use "Export my data" before you delete.
11. Safety and conduct reports
A report about behaviour often contains more than a description. It may include messages, screenshots, photographs, names and contact details, details of an injury or medical incident, and allegations that someone has committed a crime. Send us only what is needed to explain what happened. We treat this material as confidential and, where it is sensitive, with the additional protection the law requires.
Reports about behaviour are handled by a small number of authorised staff. We use them to decide whether to warn, restrict, suspend or block an account, and to spot repeat patterns across reports.
A report is not anonymous to us, but we do not routinely disclose your identity to the person you reported. We may have to identify you where it is necessary to act fairly, where the report concerns that person directly, or where the law requires it.
We keep reports, and a record of any action taken, for as long as needed to keep the community safe — including after an account is deleted or blocked, so that a block cannot be evaded by re-registering. These records are kept to the minimum needed for that purpose.
Where we are legally required or lawfully permitted to do so, we may preserve and disclose records to the police or another competent authority, and we may share the details of an incident with the venue where it happened so it can act on its own premises. Reporting to us is not a report to the authorities: if a crime may have been committed, contact the police directly.
12. Children's privacy
The platform is not directed to children under 13, and we do not knowingly collect data from them. If you believe a child has provided us personal data, contact us and we will delete it. Where local law sets a higher age of digital consent, that higher age applies.
A user under 18 may use the platform only with the consent of a parent or legal guardian, who must also consent to our processing of the personal data of that child. A guardian may contact us at any time to see, correct or delete that data, or to withdraw consent and close the account.
13. Security
We use reasonable technical and organisational measures to protect your data, including hashed passwords and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
If a personal-data breach occurs that is likely to affect you, we will notify the competent authority within the period the law requires and, where the law requires it, tell you as well — describing what happened and what you can do about it.
14. International transfers
Your data may be processed in countries other than your own — for example by our hosting, push-notification and messaging providers.
Where data leaves Jordan, we transfer it only where the law permits: to a recipient bound by contract to protect it to the standard described in this policy, where the receiving country offers an adequate level of protection, where you have consented, or where any approval required by law has been obtained.
15. Changes to this policy
We may update this policy. When we make a material change we will bump its version and ask you to review and accept the updated policy the next time you use the app or website. The "last updated" date below always reflects the current version.
16. Contact us
Questions about this policy or your data? Contact us at [email protected] or through the in-app "Contact / Support" screen.