Privacy Policy
Poker Clock Pro is designed as a tournament utility with a complete offline mode. This policy explains what stays on your device and what is processed when you choose cloud features.
Who is responsible
Grayston Technologies (“Grayston,” “we,” or “us”) develops Poker Clock Pro and is responsible for its cloud processing. Privacy questions and rights requests can be sent to support@mypokermaps.com.
Data that stays on your device
Local tournaments, structures, clock events, player counts, prize values, preferences, and imported files remain in the app’s local database unless you export, share, or enable cloud sync. Browser operations require one verified account entry, while the installed native Base app remains account-optional. Signing in does not upload local tournament content unless you choose a cloud feature. You control any file or screen share you initiate.
Account and cloud processing
If you choose an account, we process your email address or Apple/Google authentication identifier, user ID, profile settings, workspace membership and role, registered devices, legal-policy acceptance version and time, subscription entitlement, paid-app ownership, cloud templates, synced tournament content, branding uploads, paired-display grants, and workspace audit history. Synced content can include information you enter, such as tournament, player, payout, and custom-message data. We use this information to authenticate you, synchronize the features you request, enforce roles and plan limits, recover clocks, protect the service, and provide support.
Purchases
Stripe processes US web subscriptions, invoices, tax calculation, payment methods, and its customer portal. Apple and Google process native downloads and subscriptions. RevenueCat helps validate and synchronize entitlements across those sources. We receive customer and transaction identifiers, product status, renewal or expiration dates, billing country, and store environment—not your full payment card number. Limited billing records may be retained where tax, accounting, dispute, or fraud-prevention law requires it.
Optional diagnostics and analytics
These are off until you choose “Allow diagnostics.” If enabled, Sentry can receive scrubbed crash and performance information, and PostHog can receive a random device identifier plus a limited event vocabulary such as onboarding completion, clock start, display or pairing, paywall view, trial, and conversion. Autocapture, advertising, person profiles, and session replay are disabled. We do not send player names, tournament names, payouts, custom messages, tokens, or precise personal content to these tools. You can withdraw consent at any time in Settings → Data & privacy without losing app functionality.
Service providers and disclosure
We use Vercel for the public web app, Supabase for authentication, database, storage, and server functions, SMTP2GO for account and invitation email, Stripe for web billing, Apple and Google for sign-in and store services, RevenueCat for entitlement validation, and—only after your choice—Sentry and PostHog for diagnostics and analytics. These providers may process device, browser, network, or IP information needed to deliver and secure their services. They act under their own terms and privacy commitments. We do not run ads, sell or rent personal data, or share it for third-party advertising. We may disclose the minimum necessary information to comply with law, protect users and the service, or complete a business transfer with appropriate notice and safeguards.
Legal bases
Where privacy law requires a legal basis, we process requested account, cloud, support, and subscription features to perform our contract with you; protect accounts, prevent abuse, and maintain reliability for our legitimate interests; honor legal obligations; and process optional diagnostics and analytics with your consent. You can decline or withdraw optional consent without affecting the paid Base app.
Security
Cloud data is sent over encrypted connections. We use access controls, row-level authorization, short-lived display identities, secure credential storage, audit trails, and data minimization. No storage or transmission system can be guaranteed completely secure, so please protect account access and do not publish one-time pairing codes.
Retention, export, and deletion
Local data remains until you delete it, clear the app, or uninstall it, subject to device backups you control. Cloud account data remains while the account is active and as needed to provide requested features. You can export or delete local data in Settings and export or permanently delete a cloud account at Account & subscription. Account deletion removes authentication, personal workspaces and content, devices, billing linkage, and the RevenueCat customer record. Confirmed deletion cancels an active Stripe subscription before erasing the account. Apple and Google subscriptions must be canceled in their stores and may remain active after account deletion. If you own a shared Venue workspace, deletion is blocked until you explicitly transfer that workspace through support or remove its other members and choose to delete it. Clock never silently selects a new owner. A “Deleted user” marker and limited pseudonymous audit or security records may remain while needed to preserve shared-workspace integrity, prevent abuse, resolve disputes, or meet legal obligations. Customer content is removed from active systems immediately after a successful confirmed deletion and from routine encrypted backups within 30 days, except for a backup retained longer solely for a legal, security, or disaster-recovery obligation. Provider security logs follow their controlled retention cycles. Apple and Google retain store transaction records under their own requirements; deleting Clock does not cancel a store subscription.
Your rights
Depending on where you live, you may ask to access, correct, export, or delete personal data, restrict or object to processing, withdraw consent, or complain to your local privacy regulator. We may need to verify your identity before acting. Use the in-app controls or Clock Support; we will not discriminate against you for exercising applicable privacy rights.
International processing
Our providers may process data in the United States and other countries. Where required, we rely on provider contractual safeguards and recognized transfer mechanisms. Local privacy rights continue to apply to your data.
Children
Clock is a professional event utility and is not directed to children. Cloud accounts and purchases require the account holder to be at least 18. Contact us if you believe a child provided account data.
Changes and contact
We may update this policy as the app or law changes. We will update the effective date and provide additional notice when a material change requires it. Questions and requests can be submitted through Clock Support or the email address above.