Privacy Policy
Last updated: 2 May 2026
This Privacy Policy explains how Josef Lischka ("we", "us") collects, uses, and protects your personal data when you use the WM2026 Tippspiel web app, iOS app, and website (collectively, "the Service").
We process your data in accordance with the EU General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).
1. Data controller
The controller responsible for your personal data is:
Rüdigergasse 23
1050 Vienna, Austria
Email: hello@tippspielapp.com
2. Data we collect
Account data
When you create an account, we collect:
- Your email address (used as your login and for service communication)
- A password (stored securely as a salted hash — we never see your plaintext password)
- The display name you choose (visible to other players in leagues you join)
Game data
While using the Service, we store:
- Your score predictions for each match
- League memberships and your role in each league (admin or member)
- Points awarded and your position on leaderboards
- Bonus predictions (e.g. World Cup winner, top scorer)
Push notification token
If you enable push notifications, we store a device-specific token issued by Apple (APNs) or Google (FCM) so we can send reminders and result alerts. You can revoke this at any time in your device settings.
Analytics & error tracking
We use Google Firebase Analytics to understand how the Service is used (e.g. which screens are visited, when, how often) and Google Firebase Crashlytics to receive crash reports and error logs that help us fix bugs.
These services may collect technical data such as device model, operating system version, app version, anonymous installation ID, and approximate location derived from your IP address. This data is processed by Google LLC in the United States.
3. Why we process your data
We process your data on the following legal bases:
- Performance of contract (Art. 6(1)(b) GDPR): to provide the Service — running the prediction game, managing your account, calculating leaderboards.
- Legitimate interest (Art. 6(1)(f) GDPR): to keep the Service secure and reliable, prevent abuse, and improve the product through aggregated analytics and crash reports.
- Consent (Art. 6(1)(a) GDPR): for push notifications, which you can opt into and out of at any time.
4. Third-party processors
To run the Service we rely on the following processors. Each is bound by a data processing agreement and processes your data only on our instructions.
- Supabase Inc. (USA) — backend, database, and authentication. Project hosted in the EU region.
- Google LLC (USA) — Firebase Cloud Messaging for push notifications, Firebase Analytics for usage statistics, Firebase Crashlytics for error reporting.
- Render Inc. (USA) — hosting for the web app and marketing site.
- Cloudflare Inc. (USA) — DNS and content delivery network.
Transfers to the United States are protected by EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
5. Data retention
The WM2026 Tippspiel is built around the FIFA World Cup 2026 tournament. All personal data — including accounts, predictions, leagues, and leaderboards — will be permanently deleted by 1 January 2027.
You can delete your account at any time before that date from the profile screen in the app. When you do, your account data is removed and your contributions to public leaderboards are anonymized.
6. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you (Art. 15)
- Have inaccurate data corrected (Art. 16)
- Have your data deleted (Art. 17)
- Restrict processing of your data (Art. 18)
- Receive your data in a portable format (Art. 20)
- Object to processing based on legitimate interest (Art. 21)
- Withdraw consent at any time, without affecting prior processing
To exercise any of these rights, email hello@tippspielapp.com. We will respond within 30 days.
You also have the right to lodge a complaint with a supervisory authority. In Austria, this is the Datenschutzbehörde (dsb.gv.at).
7. Security
We use industry-standard measures to protect your data: TLS encryption in transit, encrypted storage at rest, hashed passwords, and Row-Level Security on our database to ensure users can only access their own data. No system is perfectly secure, but we work continually to keep your data safe.
8. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top of the page reflects the most recent revision. Material changes will be announced in the app.
9. Contact
Questions about this policy or about your personal data? Get in touch: