Global Pool Players

GPP Privacy Notice

Version privacy-v1.0 · dated 2026-07-31

This is the privacy notice for GPP — Global Pool Players, a membership association for amateur pool players operating in the United States. It is a dated document, like every GPP legal document: if the words change, the version string changes with them and this file stays where it is, so you can always read the exact version you were shown.

It is written in plain English on purpose. If anything here is unclear, the last section says how to reach a person.


1 · What GPP collects

Everything GPP holds about you, you typed or took yourself:

  • Your mobile number. The account itself: one number, one account. It is verified by a texted code when you sign up and when you sign in. There is no email and no password.
  • Your date of birth. GPP is 18 and over, and the date is how that is checked. It is not editable after signup.
  • Your photo. Required, because your opponent sees it before you meet — that is its whole job.
  • Your display name. Chosen by you. It does not have to be your real name.
  • Your matches and your rating. The results you and your opponents record, and the rating built from them — shown to you with the arithmetic, not just the number.
  • Consent records. When you agree to something, GPP keeps the exact words that were on your screen at the time, so the record shows what you actually read.

Two narrower cases:

  • Registering for a tournament asks for your legal name, kept for the event's own records. It is not shown to other players.
  • Keeping automated abuse out. Signup runs through a reCAPTCHA check, and the network address a sign-in code was requested from is recorded. Signup sends real text messages, and this is what keeps machines from requesting them by the thousand.

2 · What GPP does not collect

  • No home address. There is no field for one, on any screen, in any version. Matches happen in poolrooms.
  • No email address and no password. Your phone number is the only credential.
  • No government identifiers. No Social Security number, no taxpayer ID, no ID document. Where an event ever requires paperwork of that kind, it is taken on paper, by hand, and kept off this system.
  • No payment details. No card, no bank account, no wallet.
  • No background location. GPP reads your location only at the moment you ask it to: when you tap "Sort by distance" in the room directory, or when you start a rated match — once, to note that the match happened at a listed room. Saying no to location never blocks anything.

3 · Your photo

  • It lives in a private storage bucket. There is no public link to it, ever. When the app shows your photo, it makes a link that expires after 15 minutes.
  • Before the photo leaves your phone, the app re-encodes it. That strips the hidden metadata cameras embed — where the picture was taken, when, and on what device. Those facts never reach GPP.
  • Nothing automated ever looks at it. No face detection, no face matching, no machine processing of the image, ever. Humans compare photos; machines never. Whether a photo is really you is judged by the person across the table, and enforced by a player report read by a human.
  • Delete your account and the photo is deleted with it. No archive of former members' photos is kept.

4 · Your phone number

  • One number, one account. That rule is the backbone of the anti-duplicate design, and it is why there is no second way to sign in.
  • Number changes are kept as a dated history against your account, so changing numbers never resets a record and never sheds a sanction.
  • Your full number is not shown to other players. Where the product refers to your number back to you, it is masked.

5 · Who sees what

  • Other players see your display name, your photo and your rating. That is the membership working as designed: the photo exists so one opponent can check one face, once, in person.
  • A group invite link shows your display name and photo to whoever holds the link. That is what the link is for — share it the way you would share an invitation.
  • Tournament rosters — legal names and full phone numbers — are visible only to the named managers of the event, never to the field.
  • Search engines are told not to index member pages. Your face and your name are not meant to be search results, and GPP says so to crawlers in the standard ways.
  • GPP does not sell personal data. Not to anyone, not in bulk, not "anonymised". There are no ads on GPP and no sharing of your data for anyone else's marketing.

6 · Who works on GPP's behalf

GPP runs on Google Cloud, in the United States:

  • Firebase Authentication verifies your number and delivers sign-in codes.
  • Cloud SQL holds the database; Cloud Storage holds photos.
  • reCAPTCHA Enterprise checks signup requests for automation.

When messaging features are active, messages are delivered through GoHighLevel and Twilio, and a line-type lookup may confirm that a number belongs to a real mobile carrier before a code is sent.

When something in the app breaks, an error report may be sent to Sentry so the failure can be found and fixed. Error reports describe the app's behaviour, not a profile of you.

These providers process data to provide their service to GPP, under their own contractual terms — never for their own marketing.

7 · How long GPP keeps things

  • While you are a member: for as long as the account exists.
  • Your record is yours. It leaves with you — complete, in one tap, from Settings — and stays available to you for at least 24 months after you go.
  • Matches are shared records. A match you played is part of your opponent's history too, and their rating is computed from it. Deleting your account removes you — see the next section — while the match rows survive with your identity removed from them.
  • Verification and consent records are append-only ledgers, kept as evidence of what was agreed, by which number, and when.
  • Where a retention period is not written here, it has not been decided yet. When it is decided, this notice changes — with a new version string next to a new date, and the old version still published at its own address.

8 · Your controls

  • Export. Settings → Your data hands you your record, complete, in one tap.
  • Delete. Deleting your account marks the membership terminated, deletes your photo, and releases your number from the sign-in system. Match rows stay, with your identity removed, for the reason in the section above.
  • Block and report. Blocking another member is immediate and silent. Reports are read and decided by a person.
  • No automated decisions about you. Photos are compared by humans, reports are reviewed by humans, and the rating — which is arithmetic — shows you its working every time it moves.

9 · Age

GPP is 18 and over. The date-of-birth step at signup enforces it: an under-18 date ends the signup on the spot, the sign-in record created during the attempt is deleted, and no membership is created. GPP does not knowingly hold an account for anyone under 18.

10 · Where GPP stands

GPP operates in the United States, and membership is US-only today. This notice is read under the law of the State of Connecticut and applicable US federal law. Nothing in it takes away a right the law does not allow to be taken away.

11 · Changes to this notice

The words never move under a version string. A change means a new version, a new date, and the old file staying published at its own address — so what you were shown on the day you agreed is always producible, years later.

12 · Reaching a person

Questions about your data, requests to export or delete, or anything this notice should answer and does not: contact the address published on the GPP support page. A person reads it and replies.


Version privacy-v1.0, dated 2026-07-31.

This notice is published by NJ Developments.

The monitored address, for anything above: javflores.ct@gmail.com