Privacy Policy – Cric11: Cricket Scoring App
Effective date: 16 September 2026
Version: 2.0
1. Introduction
This Privacy Policy (“Policy”) describes how BOSC Tech Labs Pvt. Ltd. (“BOSC Tech Labs”, “we”, “us” or “our”) collects, uses, discloses, stores, transfers, retains and deletes personal data in connection with the Cric11: Cricket Scoring App mobile application (the “Application”) and the cloud services accessed through it (together, the “Service”).
BOSC Tech Labs is the data controller responsible for personal data processed through the Service.
This Policy applies exclusively to the Application. It does not govern any other product, website or service.
Please read this Policy carefully. By registering for an account or otherwise using the Application, you acknowledge that you have read and understood this Policy. Capitalised terms not defined in this Policy have the meaning given to them in the Terms and Conditions applicable to the Application.
2. Scope of the Application
The Application enables registered users to create teams and tournaments, record ball-by-ball cricket scoring, capture and store match video, and view individual and team performance statistics. The personal data described in this Policy is collected solely for those purposes and for the ancillary purposes set out in Section 4.
An account is required in order to use the Application. Account registration is available through Google Sign-In, Sign in with Apple, or verification of a mobile telephone number by one-time passcode.
3. Personal Data We Collect
3.1 Account and profile data
| Data | Source |
|---|---|
| Display name, first name, last name | Provided by you, or received from your sign-in provider |
| Email address | Provided by you, or received from your sign-in provider |
| Mobile telephone number | Provided by you during one-time passcode verification or profile editing |
| Profile photograph and profile tagline | Provided by you |
| Country and language preference | Selected by you |
| Account identifier and sign-in method | Generated by the Service |
3.2 Data received from Google Sign-In
Where you elect to register or sign in using your Google Account, the Application requests the OAuth scopes email and profile only. Through these scopes we receive:
- your Google Account email address and its verification status; and
- basic profile information, namely your name, given name, family name, profile picture URL and Google Account identifier.
The Application does not request, and we do not receive, access to Gmail, Google Drive, Google Contacts, Google Calendar, Google Photos, location history or any other Google API scope. The restrictions governing our use of this data are set out in Section 7.
3.3 Data received from Sign in with Apple
Where you elect to register or sign in using Sign in with Apple, the Application requests the email and fullName scopes. If you use Apple’s Hide My Email feature, we receive only the anonymised relay address generated by Apple and use that address for all account communications.
3.4 Content you create within the Application
- Teams, squads and player records you create, including the names of players you add;
- Matches, tournaments, ball-by-ball scoring records, results and match commentary;
- Batting, bowling, fielding and captaincy statistics, ranking points and awards derived from your scoring activity;
- Photographs, images and video recordings you capture or upload, including match ball recordings, team logos and profile photographs; and
- Feedback, ratings and support correspondence you submit to us.
Content you publish within the Application may be visible to other users with whom you share a match, team or tournament, and to participants in tournaments you join, including through shared scorecard links. You should not enter personal data relating to any other individual unless you are authorised to do so.
3.5 Device, technical and usage data
The Application collects the following data automatically:
- device model, operating system and version, device language and time zone;
- Application version and build number, and installation identifiers;
- Internet Protocol (IP) address, and the approximate country or city-level region derived from it;
- push notification tokens and subscription identifiers;
- in-application activity, including screens viewed, features used, matches and tournaments created, session timestamps and last-active time;
- diagnostic data, including crash reports, error logs, stack traces and performance traces; and
- the advertising identifier made available by your device operating system, where available and permitted, for the purposes described in Section 6.4.
3.6 Subscription and transaction data
Where you purchase a paid subscription, we process your subscription status, entitlement level, plan, purchase and renewal dates, platform transaction identifiers and an application-specific subscriber identifier.
All payments are processed by the applicable application store. We do not receive, process or store payment card numbers, bank account details or billing addresses.
3.7 Device permissions
The Application requests the following permissions at the point at which the relevant feature is used. Each permission may be withdrawn at any time through your device settings, and the remainder of the Application will continue to function.
| Permission | Purpose |
|---|---|
| Camera | Recording match ball video and capturing profile and team photographs |
| Microphone | Recording audio accompanying match ball video |
| Photo library and media storage | Selecting images and video for upload, and saving scorecards and images to your device |
| Notifications | Delivering match, tournament and account notifications |
| Location (iOS, optional) | Requested by our notification delivery provider to support location-relevant notification delivery. The Application does not collect, store or display your precise location, and all features remain available if the permission is declined. |
The Application does not access your contacts, text messages, call records or health data.
3.8 Local storage on your device
The Application stores match, team and tournament data locally within its private, sandboxed storage on your device, together with your preferences and session credentials. This enables scoring to continue without an internet connection; the data is synchronised with our cloud services when connectivity is restored. Local data is removed when the Application is uninstalled.
4. Purposes for Which We Process Personal Data
We process personal data for the following purposes only:
- Provision of the Service — to create and authenticate your account, and to deliver the scoring, statistics, team and tournament features you request;
- Synchronisation and continuity — to store your data locally and reconcile it with our cloud services, so that your records remain available across sessions and devices;
- Communications — to deliver match, tournament and account notifications, to send service announcements, and to respond to support enquiries;
- Security and integrity — to detect, prevent and investigate fraud, abuse and misuse, to secure our systems, and to enforce our Terms and Conditions;
- Service improvement — to analyse aggregate feature usage, diagnose defects and monitor performance;
- Subscription administration — to validate purchases, apply entitlements and provide billing support;
- Advertising — to display and measure advertising within the advertising-supported tier of the Application, as described in Section 6.4; and
- Legal compliance — to comply with applicable legal, regulatory, tax and accounting obligations and to respond to lawful requests from competent authorities.
We do not:
- sell personal data, or disclose it to data brokers or information resellers;
- use data received from Google APIs, or content you create within the Application, for advertising or advertising measurement purposes;
- use personal data to assess creditworthiness or for lending purposes; or
- use personal data to develop, improve or train generalised or non-personalised artificial intelligence or machine learning models.
5. Legal Bases for Processing
Where the General Data Protection Regulation (EU) 2016/679 or the UK GDPR applies, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Account registration, provision of the Service, subscription administration | Performance of a contract (Article 6(1)(b)) |
| Service improvement, security, fraud prevention, service communications | Legitimate interests (Article 6(1)(f)) |
| Personalised advertising; camera, microphone, photo library, notification and location permissions | Consent (Article 6(1)(a)) |
| Retention of transaction and tax records | Compliance with a legal obligation (Article 6(1)(c)) |
Where we rely on consent, you may withdraw it at any time within the Application or through your device settings. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
6. Disclosure of Personal Data
6.1 Service providers
We disclose personal data to the service providers listed below, each of which processes that data solely on our documented instructions and under contractual obligations of confidentiality and security.
| Service provider | Function | Categories of data disclosed |
|---|---|---|
| Google Firebase (Authentication, Firestore, Cloud Storage, Cloud Messaging, Remote Config) | Authentication, cloud database, media storage and notification delivery | Account identifiers, profile data, Application content, device data, notification tokens |
| Supabase | Primary cloud database and media storage | Account identifiers, profile data, matches, teams, tournaments, statistics and uploaded media |
| Google Firebase Analytics, Crashlytics and Performance Monitoring | Usage analytics and diagnostic reporting | Pseudonymous application-instance identifier, device data, usage events, crash and performance logs |
| Mixpanel | Product analytics | Pseudonymous user identifier, in-application events, device data |
| OneSignal | Notification delivery | Notification subscription identifier, device data, notification interaction data |
| RevenueCat | Subscription entitlement management | Subscriber identifier, transaction receipts, subscription status |
| Google AdMob | Advertising delivery and measurement | Advertising identifier, device data, IP address, advertisement interaction data |
6.2 Legal disclosure
We may disclose personal data where we believe in good faith that disclosure is necessary to comply with a legal obligation or valid legal process; to protect the rights, property or safety of BOSC Tech Labs, our users or the public; to investigate suspected breaches of our Terms and Conditions; or to establish, exercise or defend legal claims.
6.3 Corporate transactions
In the event of a merger, acquisition, reorganisation or sale of assets, personal data may be transferred to the acquiring entity. We will notify you before any personal data becomes subject to a materially different privacy policy.
6.4 Advertising
The advertising-supported tier of the Application displays advertising served by Google AdMob, which may process your advertising identifier, IP address and advertisement interaction data in order to deliver and measure advertising, including personalised advertising. You may:
- reset or delete your advertising identifier, or opt out of advertising personalisation, through your device privacy settings;
- manage advertising preferences at https://adssettings.google.com; or
- subscribe to the paid tier of the Application, in which no advertising is displayed.
Data received from Google Sign-In is never used for advertising purposes.
7. Google API Services — Limited Use
The Application’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In respect of data received from Google APIs, we confirm that:
- such data is used only to provide and improve user-facing features of the Application that are prominent in its user interface, namely account registration, authentication and population of your Cric11 profile;
- such data is not transferred to third parties except to the service providers identified in Section 6.1 acting on our behalf under equivalent confidentiality and security obligations, where necessary to comply with applicable law, or in connection with a merger, acquisition or sale of assets following notice to users and their consent;
- such data is not used or transferred for the purpose of serving advertising, including retargeted, personalised or interest-based advertising;
- such data is not sold, and is not transferred to data brokers, information resellers or credit bureaus, nor used for the assessment of creditworthiness or for lending purposes;
- such data is not used to develop, improve or train generalised or non-personalised artificial intelligence or machine learning models; and
- no human reads such data, unless we have obtained your affirmative consent for a specified purpose, it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or the data has been aggregated and anonymised for internal operational purposes.
You may withdraw the Application’s access to your Google Account at any time at https://myaccount.google.com/permissions. Withdrawal prevents further authentication through Google Sign-In; to have data already held by us erased, please follow the procedure in Section 10.1.
8. Security
We implement technical and organisational measures appropriate to the risks presented by our processing, including:
- Encryption in transit — all communications between the Application and our cloud services are protected using TLS;
- Encryption at rest — data held in our cloud database and media storage is encrypted at rest by the infrastructure provider;
- Access control — row-level security policies restrict each account’s data to that account and to the users with whom it has been shared; internal administrative access is limited to authorised personnel on a need-to-know basis;
- Delegated authentication — authentication is performed by Google, Apple or one-time passcode verification, and we neither receive nor store your Google or Apple account password;
- Device isolation — offline data is held within the Application’s private, sandboxed device storage; and
- Monitoring — continuous error, crash and security monitoring of our cloud services, with remediation of identified vulnerabilities.
No method of transmission over the internet or method of electronic storage is entirely secure. While we apply commercially reasonable measures to protect personal data, we cannot guarantee absolute security. In the event of a personal data breach, we will notify affected users and the competent supervisory authorities to the extent and within the timeframes required by applicable law.
9. Retention
We retain personal data only for as long as necessary for the purposes set out in this Policy.
| Category | Retention period |
|---|---|
| Account and profile data | For the duration of the account |
| Matches, teams, tournaments, statistics and uploaded media | For the duration of the account, so that your historical records remain available |
| Analytics and event data | Up to 14 months (Firebase Analytics); up to 24 months (Mixpanel) |
| Crash, error and performance logs | Up to 90 days |
| Notification tokens | Until the Application is uninstalled, notifications are disabled, or the account is deleted |
| Transaction and subscription records | Up to 7 years, where required by applicable tax and accounting law |
| Support correspondence | Up to 24 months following resolution |
| Backup copies containing deleted data | Purged within 30 days of deletion |
Where an account has been inactive for 24 consecutive months, we may delete or anonymise the associated data following prior notice to the email address on record.
10. Your Rights
10.1 Deletion of your account and data
You may delete your account at any time:
- Within the Application — select Settings → Delete Account and confirm the request; or
- By email — write to contact@bosctechlabs.com from the email address registered to your account, stating “Cric11 account deletion” in the subject line.
Upon deletion, we erase your authentication record, profile, personal content and uploaded media from our production systems within 30 days, and from backup media within a further 30 days. Statistical records forming part of a shared match or tournament may be retained in anonymised form, with your identifying details removed, so that the records of other participants remain complete. We retain data that applicable law requires us to retain, including transaction records.
10.2 Other rights
Subject to applicable law, including the EU and UK GDPR and the Digital Personal Data Protection Act, 2023 (India), you have the right to:
- access the personal data we hold about you and obtain a copy of it;
- rectify inaccurate or incomplete data, the majority of which may be corrected directly within your profile;
- erase your personal data, in accordance with Section 10.1;
- restrict or object to processing, including processing carried out on the basis of legitimate interests;
- portability — receive your personal data in a structured, commonly used and machine-readable format;
- withdraw consent at any time in respect of processing based on consent;
- nominate another individual to exercise your rights in the event of death or incapacity, where provided by the Digital Personal Data Protection Act, 2023; and
- lodge a complaint with your competent supervisory authority.
To exercise any of these rights, contact contact@bosctechlabs.com. We respond to verified requests within 30 days and may require reasonable proof of identity before acting. We do not discriminate against users who exercise their rights under this Policy.
11. International Transfers
BOSC Tech Labs is established in India. Our infrastructure providers operate data centres that may be located in India, the United States and the European Union. Personal data may therefore be transferred to, stored in, and processed in jurisdictions whose data protection laws differ from those of your own jurisdiction.
Where personal data is transferred outside the European Economic Area or the United Kingdom, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum. A copy of the relevant safeguards is available on request to contact@bosctechlabs.com.
12. Children
The Application is not directed to children under the age of 13, and we do not knowingly collect personal data from children under the age of 13. Users aged between 13 and 18, or below the applicable age of digital consent in their jurisdiction, may use the Application only with the consent and under the supervision of a parent or legal guardian.
If you are a parent or legal guardian and believe that a child has provided personal data to us without appropriate consent, please contact contact@bosctechlabs.com and we will erase the data without undue delay.
13. Amendments to This Policy
We may amend this Policy from time to time. The amended Policy will be published at this address and the “Effective date” above will be updated. Where an amendment is material, we will provide advance notice by email or by prominent notice within the Application, and, where required by applicable law, obtain your consent before the amendment takes effect. Continued use of the Application after the effective date of an amended Policy constitutes acceptance of that Policy.
14. Contact
BOSC Tech Labs Pvt. Ltd.
405, Kabir Shilp, opposite Kansar Hotel, Kudasan, Gandhinagar, Gujarat 382421, India
Privacy and data protection enquiries: contact@bosctechlabs.com