Player Privacy Notice
1. Who We Are
Volt is operated by VOLTLK (PVT) LTD, a company incorporated under the laws of Sri Lanka (Company Registration No. PV 00370874).
Our registered address is on file with the Registrar of Companies and is available on request.
Privacy Contact: Email: privacy@volt.lk
This Notice explains how we collect, use, store, share, and protect your personal information when you use the Volt mobile application as a player.
If you also manage a venue through the Volt Admin web portal, the separate Venue Operator Privacy Notice describes how we handle your data in that role.
2. Legal Basis for Processing
We process your personal information in compliance with the Personal Data Protection Act No. 9 of 2022 (PDPA) of Sri Lanka and, where applicable, the General Data Protection Regulation (GDPR).
We process personal data on one or more of the following bases:
- Contractual necessity: to provide the booking service you requested
- Legitimate interests: to operate and improve the platform, prevent fraud, and ensure security
- Consent: for optional features such as marketing communications (where we ask for this separately)
- Legal obligation: where required by Sri Lankan law
Where we rely on consent, you can withdraw it at any time. See Section 8.
3. Information We Collect
3.1 Information You Provide Directly
| Data | Why |
|---|---|
| Email address | Account creation, authentication, transactional email |
| Full name | Account identification |
| Password (hashed) | Authentication, we never store plaintext passwords |
| Gamertag (username) | Public-facing player identity within the platform |
| Profile photo | Optional avatar displayed in the community section |
| Bio | Optional public profile text |
| Preferred sports | Personalisation and venue matching |
| General location | Venue discovery (city/region level, no GPS tracking) |
| Map interactions | Rendering the venue map. The map is served by Google Maps, so the area you view is processed by Google. See Section 5.3 |
| Bank transfer slip images | Payment verification for manual bank transfer bookings |
3.2 Information Generated by Your Use of the Platform
| Data | Why |
|---|---|
| Booking history | Displaying your reservations and enabling cancellations |
| Payment records | Booking confirmation and financial reconciliation |
| Notifications | Booking confirmations, updates, and community events |
| Team memberships | Community and squad features |
| Player connections | In-app friend/connection network |
| Challenge and game invite records | Community gaming features |
| Device push notification token | Sending push notifications to your device |
| Activity logs | Leaderboard and achievement features |
3.3 Information from Third-Party Sign-In
If you sign in using Google, we receive from Google the email address and display name associated with your Google account. We do not receive or store your Google password. Your use of Google Sign-In is also governed by Google's Privacy Policy.
3.4 Automatically Collected Technical Information
- Device information: operating system, device model, app version
- Usage events: screens visited, buttons tapped, features used (collected via PostHog analytics, see Section 6)
- Error and crash reports: collected via Sentry to help us diagnose and fix bugs (see Section 6)
- IP address: used for security, fraud prevention, and infrastructure purposes; not linked to your profile
4. How We Use Your Information
4.1 Providing the Booking Service
- Creating and managing your account
- Displaying available venues, courts, and time slots
- Confirming, updating, and cancelling bookings
- Processing payment slip uploads for manual bank transfer payments
- Sending booking confirmation and status update notifications
4.2 Community Features
- Enabling the player connection network (friend requests)
- Powering the in-app leaderboard and achievement system
- Facilitating challenges and game invites between players
- Supporting squad/team management
4.3 Platform Operations
- Diagnosing crashes and technical errors (Sentry)
- Understanding how features are used to improve the product (PostHog analytics)
- Preventing fraud and unauthorized access
- Communicating service updates and critical notices
4.4 Legal and Safety
- Complying with legal obligations under Sri Lankan law
- Enforcing these policies and our Terms & Conditions
- Responding to lawful requests from government authorities
We do not use your personal data to:
- Build advertising profiles for third-party advertising networks
- Sell your data to any third party
- Make automated decisions that have legal or similarly significant effects on you without human review
5. Information We Share
We do not sell your personal data. We share it only in the following circumstances:
5.1 With Venue Operators
When you make a booking, the venue operator (the admin account managing that venue) can see:
- Your name
- Your booking details (court, date, time, sport)
- Payment status and any uploaded payment slip
This is necessary for them to manage their venue and confirm your reservation.
The venue operator is an independent controller of that data. Under the Venue Operator Terms they must use it only to service your booking, must not use it for unsolicited marketing, and must not share it with unauthorised third parties. If you have a concern about how a venue has used your data, contact us at privacy@volt.lk and we will assist.
5.2 With Other Players (Community Features)
Your gamertag, profile photo, bio, preferred sports, and booking stats may be visible to other players through:
- The in-app leaderboard
- Player search
- Connection requests you accept
- Teams/squads you join
You control your gamertag and profile content. You can update or delete this information at any time in your profile settings.
5.3 With Service Providers (Data Processors)
We engage the following third-party processors who act on our instructions and are bound by data processing agreements:
| Provider | Purpose | Country | Privacy Policy |
|---|---|---|---|
| Supabase Inc. | Database, authentication, and real-time infrastructure | United States | supabase.com/privacy |
| Cloudflare, Inc. | File and image storage (R2) via global CDN | United States | cloudflare.com/privacypolicy |
| PostHog, Inc. | Product analytics (opaque user IDs only, no email sent) | United States | posthog.com/privacy |
| Sentry (Functional Software, Inc.) | Crash and error monitoring (opaque user IDs only, no email sent) | United States | sentry.io/privacy |
| Expo (Expo, Inc.) | Mobile app build and push notification delivery | United States | expo.dev/privacy |
| Resend, Inc. | Transactional email delivery | United States | resend.com/legal/privacy-policy |
| Google LLC | Google Sign-In (OAuth 2.0) | United States | policies.google.com/privacy |
| Google LLC | Google Maps: renders the venue map on the Explore and Bookings screens | United States | policies.google.com/privacy |
Cross-border transfers: Several of these providers are located in the United States. When personal data is transferred to these providers, we rely on standard contractual clauses and/or the providers' data processing agreements as the lawful transfer mechanism under the PDPA. We only send the minimum data necessary to each provider. Notably, we send only opaque user IDs (not email addresses or names) to PostHog and Sentry.
5.4 Legal Requirements
We may disclose personal data if required by a court order, law enforcement request, or other lawful legal process in Sri Lanka or another jurisdiction where we operate.
5.5 Business Transfers
If Volt or its assets are acquired, personal data held by us may be transferred to the acquiring entity, subject to the same privacy protections described in this notice.
6. Analytics and Error Monitoring
PostHog Analytics
We use PostHog to understand how the platform is used in aggregate. We have configured PostHog with:
- Autocapture disabled: we do not automatically capture DOM text or element content
- Identified-only profiles: we only create a profile when you are logged in, using your opaque user ID
- No email or name sent: we identify you by an internal UUID only
- Tracked events include actions like: app open, venue viewed, booking confirmed, feature used
Sentry Error Monitoring
We use Sentry to capture crash reports and application errors. We have configured Sentry to:
- Associate errors with your internal user ID (not your email or name)
- Capture device OS, app version, and the action that triggered the error
- Not capture form field content or any data you have typed
Both PostHog and Sentry operate under data processing agreements with us and process data on our behalf only.
7. Data Retention
| Data Category | Retention Period |
|---|---|
| Account data (name, email, gamertag, avatar) | Until account deletion, then deleted within 30 days |
| Booking records | 7 years from the date of booking (for financial record-keeping under Sri Lankan law) |
| Payment records and payment slip images | 7 years from the transaction date |
| Push notification tokens | Deleted upon sign-out or token refresh |
| Consent records | 7 years from withdrawal or account deletion, as proof of the lawful basis relied on |
| Analytics event data (PostHog) | 30 days |
| Error logs (Sentry) | 90 days |
| Automated database backups | 30 days, encrypted |
When you delete your account, we delete all personally identifiable profile data within 30 days. Booking and payment records may be retained for the legally required period in anonymised or pseudonymised form.
8. Your Rights
Under the Personal Data Protection Act No. 9 of 2022 of Sri Lanka, you have the following rights:
| Right | What it means |
|---|---|
| Right of access | You can request a copy of the personal data we hold about you |
| Right to rectification | You can correct inaccurate or incomplete personal data |
| Right to erasure | You can request deletion of your data (subject to legal retention obligations) |
| Right to restrict processing | You can ask us to limit how we use your data in certain circumstances |
| Right to data portability | You can request your data in a structured, machine-readable format |
| Right to object | You can object to processing based on our legitimate interests |
| Right to withdraw consent | Where processing is based on consent, you can withdraw it at any time |
8.1 Withdrawing Consent In-App
You can review and withdraw the consents you have given from Profile → Privacy & Consent in the app:
- Marketing communications: withdraw at any time. We stop sending marketing email; your account and bookings are unaffected.
- Terms & Conditions / Privacy Notice: these are the basis on which we can operate your account at all. Withdrawing them means we can no longer provide the service, so doing so starts closure of your account. We will tell you this clearly before you confirm.
Withdrawal takes effect immediately and does not affect the lawfulness of processing carried out before you withdrew. We keep a record of consents given and withdrawn (see Section 7) as evidence of the basis we relied on.
8.2 Deleting Your Account
The fastest way to delete your account and associated data is the Delete Account option in the Volt app (Profile → Delete Account). This triggers immediate account deactivation and scheduled data deletion.
8.3 Exercising Other Rights
Email us at privacy@volt.lk. We will respond within 30 days of receiving your request. In complex cases, we may extend this by an additional 30 days with prior notice.
Complaints: If you believe we have not handled your data appropriately, you have the right to lodge a complaint with the Data Protection Authority of Sri Lanka once it is operational under the PDPA, or seek remedies through the courts.
9. Security
- Encryption in transit: all data is transmitted over HTTPS/TLS
- Encryption at rest: database and file storage are encrypted at rest
- Row-Level Security (RLS): database access is enforced at the database layer; a venue admin cannot access another organisation's data
- Authentication: passwords are hashed using bcrypt; we support Google SSO with PKCE flow
- Least-privilege access: the mobile app uses the Supabase anonymous key with RLS; the service role key is never exposed to clients
- Backup encryption: automated database backups are encrypted with AES-256 before being stored
- No payment card data: we do not process or store credit card data; payments are manual (cash/bank transfer)
Despite these measures, no system is completely secure. If you believe your account has been compromised, please contact us immediately at privacy@volt.lk.
Reporting a breach to you
If a security incident affects your personal data and is likely to put you at risk, we will notify you and the Data Protection Authority of Sri Lanka without undue delay, and within 72 hours of becoming aware of it where that is required. Our notice will say what happened, what data was involved, what we are doing about it, and what you should do.
10. Children's Privacy
Volt is not directed at children under the age of 18. We do not knowingly collect personal data from anyone under 18. If you are a parent or guardian and believe your child has created an account without your consent, please contact us at privacy@volt.lk and we will delete the account promptly.
11. Changes to This Notice
We may update this Notice from time to time. When we make material changes, we will:
- Update the Version and Last Updated fields at the top of this document
- Notify active users via in-app notification and/or email at least 14 days before the change takes effect
- Ask you to accept the new version when you next open the app, where renewed consent is legally required
Continued use of the platform after the effective date constitutes acceptance of the updated notice.
12. Contact Us
For any privacy-related questions, requests, or complaints:
VOLTLK (PVT) LTD Company No. PV 00370874 · Sri Lanka
Email: privacy@volt.lk
Business hours: Monday–Friday, 9:00 AM – 5:30 PM (SLST, UTC+5:30)