This Privacy Policy describes how Goalio ("we," "us," or "our") collects, uses, stores, and shares information when you use our application at goalio.tech. Goalio is developed and operated by the Goalio team. Goalio is an unofficial fan project and is not affiliated with FIFA.
Goalio helps you follow FIFA World Cup 2026 matches by syncing fixtures, reminders, and live results to your Google Calendar. BecauseGoalio uses Google Sign-In and Google Calendar, this policy includes specific disclosures about Google user data, as required by Google's API Services User Data Policy.
Google user data we collect
When you choose to sign in with Google or connect Google Calendar,Goalio may access the following categories of Google user data:
- Google account identifier — a unique ID associated with your Google Account
- Email address — your primary Google Account email
- Profile information — your name and profile picture, if made available by Google
- Google Calendar event data — only when you separately connect Google Calendar, we create, read, update, and delete calendar events that Goalio creates for World Cup matches you choose to follow
- OAuth tokens — encrypted access and refresh tokens needed to maintain your Google Calendar connection
We do not request access to your Gmail, Google Drive, Google Contacts, or other Google services beyond sign-in and calendar events.
How Goalio uses Google user data
Goalio uses Google user data only to provide and improve the features you request. Specifically, we use Google user data to:
- Authenticate you and maintain your Goalio account
- Create, update, and delete Google Calendar events for World Cup matches based on your team and reminder preferences
- Update calendar event titles and descriptions with live scores
- Add new knockout-stage fixtures when teams you follow advance
- Operate, secure, troubleshoot, and improve Goalio
- Respond to your support requests
We do not use Google user data for advertising, marketing, selling data, creditworthiness determinations, or any purpose unrelated to providing or improvingGoalio's calendar-sync functionality.
Sharing, transfer, and disclosure of Google user data
We do not sell Google user data. We do not transfer or disclose Google user data to third parties for their own independent use, advertising, or data brokerage.
We share or disclose Google user data only with service providers that help us operate Goalio, and only as needed to provide or improve the application:
- Google — to authenticate you and access Google Calendar on your behalf when you authorize it
- Supabase — to store your account profile and encrypted OAuth tokens
- Vercel — to host the application
- Trigger.dev — to run scheduled jobs that update match results and sync calendars
These providers process data under contractual obligations and only for the purposes described in this policy. We may also disclose information if required by law or to protect the rights, safety, and security of users and Goalio.
Other information we collect
In-app preferences. We store the teams you follow, reminder settings, timezone, and other settings you configure inside Goalio.
Usage and technical data. We may collect standard server logs (such as IP address, browser type, and pages visited) and error reports to keep the service reliable and secure.
Data retention and deletion
We retain Google user data only for as long as needed to provideGoalio or until you delete your account or revoke access.
- Account data — retained while your account is active
- Google Calendar OAuth tokens — deleted when you disconnect Google Calendar in Settings or revokeGoalio's access in your Google Account
- Calendar events — remain in your Google Calendar until you delete them; Goalio does not delete events automatically when you disconnect, unless you ask us to
You may request deletion of your Goalio account and associated personal data by emailing mehbubwork@gmail.com. We will delete or anonymize your data within a reasonable period, except where retention is required by law.
Data protection and security
We use technical and organizational measures to protect Google user data and other personal information, including:
- Encryption of Google OAuth tokens at rest (AES-256-GCM)
- HTTPS for data in transit
- Row-level security on database tables
- Restricted access to production systems and secrets
- Service-role credentials used only in trusted server-side code
No method of transmission or storage is completely secure. If you believe your account has been compromised, revoke Goalio's access in your Google Account permissions and contact us.
Your choices and controls
You can control how Goalio uses your Google user data by:
- Disconnecting Google Calendar at any time from Settings
- Revoking Goalio's access in your Google Account permissions
- Requesting account and data deletion by contacting us
- Stopping use of the service at any time
Children
Goalio is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us data, contact us and we will delete it.
International users
Goalio is operated from the United States. If you access the service from elsewhere, your information may be processed in the U.S. or other countries where our providers operate.
Changes to this policy
We may update this Privacy Policy from time to time, including if we change how Goalio accesses, uses, stores, or shares Google user data. We will post the revised version on this page and update the effective date above. If changes are material, we will make reasonable efforts to notify users through the app or by email.
Contact
Questions about this policy? Email us at mehbubwork@gmail.com.
Goalio is an unofficial fan project and is not affiliated with FIFA.