Effective 20 September 2026
Privacy policy
This policy explains what personal data MediaVault processes, why, for how long and with whom. It covers the website at mvt.sh, the MediaVault application and its API.
MediaVault is a service for sports organisations. Most personal data in the product — match photos and video, player rosters, face-matching results — belongs to the organisation using the product (the club). For that data the club is the controller and PLACEHOLDER — registered company name is a processor acting on its instructions. For your account and for this website, PLACEHOLDER — registered company name is the controller.
Draft: company details in this document are placeholders and must be completed before publication.
01Who is responsible
PLACEHOLDER — registered company name, PLACEHOLDER — CIF, PLACEHOLDER — registered address, city, postcode, Spain. Data-protection enquiries: privacy@mvt.sh.
Where a club has uploaded media in which you appear, the club decides why that media is processed. Requests about that media can be sent to the club directly or to us; we will forward them to the club and help it respond.
02What we process
| Data | Where it comes from | Controller |
|---|---|---|
| Account: name, email address, phone number, password hash or sign-in code, passkeys, avatar | You, at sign-up or invitation | PLACEHOLDER — registered company name |
| Session: session token, IP address, browser user-agent, timestamps | Your browser, on each sign-in | PLACEHOLDER — registered company name |
| Team membership: role, which clubs you belong to, access grants and their expiry | The club administrator | The club |
| Media: photos and video, capture time and place (EXIF), captions, tags | Uploaded by the club's staff | The club |
| Roster: player and staff names, shirt numbers, reference photos | Entered by the club | The club |
| Face matching: face templates derived from reference photos; match results and confidence scores | Generated from the club's media by our processing | The club |
| Sponsor detection: brand names and where they appear in media | Generated from the club's media | The club |
| Activity: gallery opens and downloads, including anonymous opens through a public share link | Recorded as the product is used | The club |
| Contact form: name, email, organisation, message; IP address for rate limiting only | You, on the website | PLACEHOLDER — registered company name |
| API keys and agent access: key prefix, scopes, last use | Created by a club administrator | The club |
03Face recognition and biometric data
To route media to the people in it, MediaVault compares faces in uploaded media against reference photos of the club's registered players and staff. This produces biometric data (face templates) that is special-category data under GDPR article 9.
- Face matching runs only against people the club has registered. Nobody else in a photo is identified, and unknown faces are not stored as identities.
- The club is responsible for having a lawful basis, typically the explicit consent of each player or, for minors, of a parent or guardian, before registering them. Our terms require this.
- Face templates are held in a collection dedicated to that club and are deleted when the reference photo or the person is removed.
- Templates, face identifiers and confidence internals are never exposed through the API, embeds or the MCP server.
- Any person can dismiss a match as “not me” from their own feed. The dismissal is applied server-side and the photo is removed from that person's results everywhere, permanently.
- Matching is tuned to favour recall (missing nobody) and notifications are sent only above a stricter confidence threshold, so a low-confidence match is never pushed to a phone.
04Why we process it
| Purpose | Legal basis |
|---|---|
| Providing the service: accounts, sign-in, storing and delivering media, galleries, notifications | Performance of a contract (GDPR art. 6(1)(b)); for club data, the club's instructions |
| Face matching and sponsor detection | Processed on the club's behalf; the club relies on explicit consent (art. 9(2)(a)) obtained from each person or guardian |
| Security: rate limiting, abuse prevention, session records with IP and user-agent | Legitimate interest in keeping the service secure (art. 6(1)(f)) |
| Answering enquiries sent through the contact form | Steps taken at your request before a contract (art. 6(1)(b)) |
| Usage metering for billing and add-ons | Performance of a contract |
| Legal obligations, including tax records | Legal obligation (art. 6(1)(c)) |
05Who we share it with
We use the following providers to run the service. Each acts on our instructions under a data-processing agreement.
| Provider | What for | Location |
|---|---|---|
| Railway | Application hosting and database | EU region |
| Tigris | Object storage for uploaded media and renditions | Global, S3-compatible; media served from the nearest region |
| Amazon Web Services — Rekognition | Face detection and matching | eu-west-1 (Ireland) |
| Amazon Web Services — SES | Transactional email (sign-in codes, notifications) | eu-west-1 (Ireland) |
| Twilio Ireland Limited | Transactional SMS (phone sign-in codes) | EEA (Twilio Ireland); some routing may leave the EEA under SCCs |
| Google — Gemini | Captions, tags and sponsor-logo detection on media; search embeddings | Google Cloud; data not used to train Google's models under the API terms |
| OpenAI | Creative studio only: chat and image drafts, when a club uses that feature | United States, under Standard Contractual Clauses |
We do not sell personal data and we do not use advertising or third-party analytics on the website or in the product. We do not use Cloudflare.
Where a provider is outside the EEA, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision.
06How long we keep it
- Account data: for as long as the account exists, then deleted within 30 days of a deletion request.
- Sessions: 30 days from last activity, then expired and removed.
- Club media, rosters, matches and galleries: for as long as the club's subscription is active and the club has not deleted them. When a club's account is closed, its data is deleted within 30 days.
- Face templates: deleted immediately when the reference photo or person is removed by the club, and with the club's data on closure.
- Contact-form messages: 12 months.
- Rate-limit counters (IP address): minutes, in memory only.
- Invoices and tax records: as required by Spanish law (generally 6 years).
07Your rights
You can ask for access to your data, correction, deletion, restriction, portability, and you can object to processing based on legitimate interest. Where processing relies on consent, you can withdraw it at any time; this does not affect processing before withdrawal.
Write to privacy@mvt.sh. We answer within one month. If the request concerns media held by a club, we will involve the club, which remains responsible for the decision.
You can also complain to the Spanish supervisory authority, the Agencia Española de Protección de Datos (aepd.es), or to the authority in the EU country where you live.
08Minors
Many clubs use MediaVault for youth teams. Media of minors is processed only on the club's instructions and only where the club has obtained the guardian's consent. We do not knowingly open accounts for people under 14. If you believe a minor's data has been processed without proper consent, contact us and we will act on it promptly.
09Security
- Every database query is scoped to a single club; access rules are enforced in one shared layer, not per screen.
- Passwords are stored as salted hashes. Share-link and API-key secrets are stored only as hashes and shown once at creation.
- API keys are read-only by default, scoped per action, expire after 30 days and can be revoked at any time.
- Data is encrypted in transit (TLS) and at rest by our hosting and storage providers.
10Changes to this policy
When we change this policy we update the date at the top. For material changes affecting existing users we also notify account holders by email.
PLACEHOLDER — registered company name · PLACEHOLDER — CIF · PLACEHOLDER — registered address, city, postcode, Spain
Questions about this document: hello@mvt.sh