Privacy Policy
Effective September 19, 2026.
Puck Passport keeps a record of the hockey games you’ve been to, on iPhone, Android and the web at puckpassport.app. This policy explains what it stores about you and what it doesn’t. There are no ads, no tracking, and your data is never sold.
Who we are
Puck Passport is run by Matt Donders. Questions about this policy or your data go to support@puckpassport.app.
What we collect
- Your email address, from Sign in with Apple (which may be a private relay address), Google, or the address you type. It’s used to sign you in, send sign-in codes and find your account.
- Account identifiers: an internal account ID, and the account IDs Apple or Google give us when you sign in with them.
- The games you log and your team preference. This is your Passport.
- Your game searches. When you search by team and season or by date—including pasted dates and dates read from photos—the app sends those choices to our server to find matching games. On iPhone and Android, opponent and home/away filters stay on your device. On the web, those filters are included in the search URL and processed by our server. With JavaScript available, pasted text is reduced to recognized dates before it is sent. Without JavaScript, the web form sends the full pasted list in the search URL, including any unrecognized lines. We do not use these searches to build a profile.
- Session and security records: which devices are signed in and when they were last used, sign-in attempt counters that prevent abuse, and a log of sign-in and account-linking events.
- A sign-up record noting when your account was created and which sign-in method you used.
What we don’t collect
- Your location. When you log today’s game, the app reads your device’s location once to put the nearest arenas first. That happens on your device, and the location is never sent to us or saved.
- Your photos and photo locations. When you import games from photos, the app reads the dates and, where present, locations on your device. Your photos and photo locations are never uploaded. The app sends only each date as a game search, as described above.
- Contacts, advertising identifiers or device identifiers. The apps contain no advertising, analytics or crash-reporting software.
Who processes it
We use a few service providers to run Puck Passport. They handle data only to provide their service to us:
- Cloudflare: website and server hosting, and the database.
- Resend: delivering sign-in emails.
- Sentry: server error reports, used to find and fix bugs.
- Apple and Google: signing in with your Apple or Google account.
When matching schedule data is not already available, our server may send the team, season or date from a game search to the NHL’s public schedule service.
HockeyGameBot
A Puck Passport account is a HockeyGameBot account. Signing in to either one shows the same attended games, and this policy covers that shared account data.
On your device
The apps keep your sign-in session, a copy of your Passport, and any games waiting to sync on your device. Signing out or deleting your account clears them.
How long we keep it
We keep your data until you delete your account. Sessions expire after 30 days without use. When you delete your account, the security log and sign-up records are kept without any link to you.
We do not save game searches to your Puck Passport account. Cloudflare request logs can keep a URL used for a game search—including the web URL containing filter choices or a full pasted list—for up to seven days. Team-and-season lookup results can also be cached by the query URL for up to 24 hours. These records expire automatically.
Deleting your account
You can delete your account and every game you’ve logged at any time:
- in the app: Settings (the profile button on your Passport) → Account → Delete account;
- on the web at puckpassport.app/account/delete; or
- by emailing support@puckpassport.app from the address on your account.
Children
Puck Passport is not directed at children under 13, and we don’t knowingly collect data from them.
Changes
If this policy changes, we’ll update it here and change the effective date at the top.