Effective and last updated: July 28, 2026
Muay Thai Live is a Muay Thai discovery app. This policy describes the data the app is designed to use for events, fighters, stadiums, rankings, notifications, analytics, monitoring, and feedback. Professional legal review is recommended before commercial expansion or broader data collection.
Information We Use
The app can process public event data, fighter information, stadium and promotion details, rankings, ticket/watch/map links, saved events, followed fighters or promotions, notification preferences, and feedback. Event cards, schedules, tickets, broadcasts, and results may change after publication.
Optional Accounts And Sync
Accounts are optional: public browsing and local guest choices remain available without one. When account sign-in is configured, Supabase Auth processes email to provide passwordless sign-in. The current app can offer email links and may show Google only when that provider is configured; Apple is not currently presented. Account sync stores a minimal display profile, preferences, followed fighters/promotions/stadiums, and saved events.
An account export contains those account records and safe device summaries. It excludes access tokens, refresh tokens, magic-link data, provider payloads, push endpoints, subscription keys, raw device identifiers, and server security logs. Deleting an account removes its synced account records and Auth user while retaining only a minimal server-only operational deletion record where needed for operations. Supabase may retain limited authentication and email-delivery event records for security, abuse prevention, troubleshooting, and operations. Access to those provider-managed records is restricted to authorized project administrators and the service provider, and their retention follows the provider and project policy. Account deletion does not promise immediate removal of those limited provider security or operational records.
Muay Thai Live does not intentionally send email identities to application analytics. Tokens, magic links, and session secrets are not intentionally logged by the application.
Analytics
Analytics are optional and privacy-filtered. Plausible is the preferred cookieless provider. Google Analytics 4 and PostHog are supported only when configured. Analytics may record page type, broad route/entity context, broad browser/device/locale, app version, release/commit, ticket/map/watch clicks, save/follow/reminder actions, notification preference changes, and feedback/report category.
Search analytics do not send raw search text. They send query length, a broad length bucket, result count, result type, and zero-result status. Analytics are suppressed in development and tests by default, on admin routes unless explicitly enabled, for automated browsers, when Do Not Track is enabled, or when this device sets mtl_analytics_opt_out=true in local storage.
The private Admin audience panel stores only a server-hashed, random daily browser token, date, page category, selected action category, country code supplied by the hosting network, coarse device category, and broad acquisition source for up to 90 days. It does not store an account ID, email, IP address, city, raw referrer URL, full URL, search text, or a cross-day browser identifier. Its daily unique-browser totals are estimates of browsers, not identified people. A device can opt out with the same analytics setting, and an owner can exclude their own browser.
Error Monitoring
If a Sentry-compatible provider is configured, client and server errors may include a redacted error message, stack text, route, app version, release/commit, build/deployment metadata, broad browser/device context, and feature area. The app redacts emails, push endpoints, coordinates, tokens, secrets, cookies, service-role keys, and subscription data. Source-map upload is not yet configured.
Notifications
Browser and PWA notifications require browser permission and a browser push subscription. The Android and iPhone apps ask for system notification permission only after you choose Enable in notification settings, and native targets are account-bound rather than created for guests. The backend may store browser subscription data or a native provider token, a server-side digest of a local device proof, user ID where applicable, notification preferences, timezone, quiet hours, scheduled reminder rows, delivery state, cancellation/skipped-delivery history, and failure status.
Account settings shows safe device names, platform, notification status, last activity, and delivery outcome. It does not show raw browser endpoints, browser subscription keys, FCM or APNs tokens, device proofs, or internal delivery IDs. Those values are server-only and are excluded from account exports, analytics, and user-facing delivery history. A signed-in user can disable or remove only that user's own device; sign-out and account deletion revoke the current native target. Browser/PWA and native delivery are kept as separate targets to prevent duplicate delivery to one transport.
You can disable notifications in notification settings, remove browser or app permission in browser or OS settings, unsubscribe from the app, or clear local site data. Browser, OS, push service, and network behavior can affect delivery. FCM and APNs delivery is enabled only after the corresponding provider credentials are configured; this policy does not claim a provider is active in every build.
Location
Some stadium and travel features can use browser geolocation for distance calculations if you grant permission. Coordinates are intended for local distance calculations and are not sent through feedback, analytics, or monitoring. City-guide and manual location context may be used as broad public-route context.
Local Storage, Caches, And Device Data
The app uses browser storage for saved events, followed fighters/promotions/stadiums, notification preferences, anonymous browser device ID, analytics opt-out, app install/PWA state, and service-worker caches. A native app may also retain a local non-secret device proof used to associate the current signed-in device safely. Clearing site data or removing the app removes local saved state on that device.
Supabase And Admin Workflows
Supabase stores public content, admin/editorial data, automation history, notification subscriptions/targets, scheduled notifications, token-safe delivery history, and device notification preferences. Access to account and device records is ownership-checked; raw native tokens and raw browser subscription material are not client-readable. Automated imports and GitHub Actions may process external source data to refresh public event, fighter, stadium, promotion, ranking, and result records.
Feedback And Corrections
The feedback flow opens an email draft. It includes category, optional email, message, public page/entity context, app version, commit, and broad browser/device context. It does not collect precise location, screenshots, push subscriptions, auth tokens, or private browser storage. Feedback is retrievable through the owner email workflow; a database-backed report queue is a future admin enhancement.
Third-Party Services
Muay Thai Live links to third-party ticket sellers, map providers, promotions, stadiums, watch/broadcast services, analytics providers, monitoring providers, Supabase, Vercel, GitHub Actions, and scheduling tools. Those services have their own privacy practices. Ticket sellers and watch providers do not share this policy.
Retention And Choices
Local browser data remains until you remove it or clear site data. Supabase notification and token-safe delivery records remain until removed, revoked, or subject to future retention automation. Analytics and monitoring retention depends on the configured provider. You can opt out of analytics, revoke browser or app permissions, disable/remove a device, clear local data, or contact Muay Thai Live to request correction or deletion of feedback or device-linked records where practical.
Contact
For privacy questions, deletion requests, or corrections, use the Contact page or the feedback form.