Privacy
Roll On is a football team-management app for grassroots coaches in the UK. This policy is written for coaches using the app, and for parents or guardians of players whose details a coach has added. The app is distributed in the UK only and is intended for adult coaches and team managers — children do not use it themselves.
The same app runs on iPhone and on iPad, and this policy covers both. There is no separate iPad version and no separate iPad storage: an iPad reads and writes the same teams in the same iCloud account, which is what makes a squad entered on one appear on the other.
It covers the Apple Watch app too. The watch keeps no teams of its own: it shows what the paired iPhone sends it for the match being played — the clock, the score, the opponent's name, and the squad list when you are choosing a scorer — and sends your taps back. That exchange is between your own two devices, and nothing about it reaches the developer.
And it covers Siri. Asking Siri one of Roll On's questions is answered on the phone, out of the same teams already stored there. No player's name is added to the device-wide Spotlight index, nothing is sent to the developer, and Apple's own handling of what you say to Siri is covered by Apple's privacy policy rather than this one.
| Information | Where it lives | Who can see it |
|---|---|---|
| Player details — name, squad number, position, match history | Your private iCloud | You, and coaches you invite to that team |
| Your coach profile — name and role on each team | Your private iCloud | You, and coaches on that team |
| Team details — name, colour, optional badge, squad size | Your private iCloud | You, and coaches you invite |
| Fixtures, formations, line-ups, substitutions, notes | Your private iCloud | You, and coaches you invite |
| A session plan you attach to a training session — a PDF, or a photo from your library | Your private iCloud | You, and coaches you invite |
| A link to a match recording — the web address you paste for a match, and nothing else about it | Your private iCloud | You, and coaches you invite |
| An invite code you create — carries the team name and the invited coach's name | Shared lookup area | Whoever holds the code. Deleted when it's used, cancelled, its team is deleted, or after 7 days |
| A request to join a team — your display name and iCloud email address | Shared lookup area | The team's manager, and whoever holds that team's code. Deleted by your device once you're in, or after 14 days if nobody answers |
| Next-event widget summary — each team's name, colour and resized crest, plus its next couple of events (title and date) | Your device only | Nobody. It never leaves that device |
When a coach uses Roll On to manage a team, the app keeps the following in that team's private iCloud storage, rather than sending it to the developer. Where this information is stored sets out the one exception:
Roll On does not ask for or store financial information, home addresses, health or medical records, or precise location data. It contains no advertising, and uses no analytics or tracking SDKs.
One thing the app has no say in: if you have left "Share With App Developers" switched on in your iPhone's or iPad's Settings → Privacy & Security → Analytics & Improvements, Apple gives the developer anonymous, aggregate figures — how many devices have the app, how often it's opened, and crash reports. That comes from Apple, is not tied to you or your team, and switching it off stops it.
All of the information above is stored in a private database in your own iCloud account, using Apple's CloudKit service. This is how the app keeps your data in sync across your own devices — an iPhone and an iPad see the same teams — and lets it survive a new phone.
A match can carry a link to its recording — a Veo page, usually. This is the one place the app will take you somewhere that isn't ours, so it's worth setting out plainly.
Because this data lives in your own iCloud account, you're in direct control of it at all times.
Step-by-step instructions are on the support page.
If you're a parent or guardian and have a question about how a club or coach is using Roll On to store your child's details, the data controller is the coach or club who entered that information, not the Roll On developer — they're best placed to action a correction or deletion request. If you need help reaching them, or have a question about the app itself, get in touch at the address below.
Information stays in your iCloud account for as long as you keep it in the app. There's no separate backend copy — deleting a player or team in the app deletes it from iCloud too, on your next sync.
The shared lookup area works differently, and it's worth being exact, because nothing there expires on its own — each entry is deleted by the device that put it there. An invite code goes when it's used, cancelled, or its team is deleted, and a code that's generated and then forgotten goes once it lapses at 7 days. A join request goes when the join completes, and one that's turned down or never answered goes once it lapses at 14 days — and only the device that sent it can do that, which is why it's your copy of the app that does. In every case the deletion happens the next time that person opens Roll On.
Roll On is used by adult coaches to record details of youth players for team-management purposes — line-ups, substitutions, and playing time. We recommend that clubs and coaches using the app for youth teams do so under their existing safeguarding and parental-consent arrangements, for example an FA-affiliated club's standard registration consent, and enter only the minimum information needed to run training and matches.
Everything above is about the app. The website is a separate thing, and worth being precise about: these pages are plain files. They set no cookies, run no analytics, and load nothing from anyone else's servers, so there is nothing here to consent to.
They are served by Cloudflare, though, and that part is not nothing. Like any host, Cloudflare handles every request and keeps its own logs, which include your IP address, to deliver the pages and to block attacks on them. It also adds two small scripts of its own to every page: one that spots automated traffic, and one that restores the address behind the contact links above, which is kept out of the page so that it cannot be collected and sold. Neither is analytics and neither is used to build a picture of you, but they are Cloudflare's rather than ours, and what Cloudflare does with request data is covered by its own privacy policy.
None of that tells us who you are. Nothing here is logged by us, and there is no account to tie a visit to; what we can see is Cloudflare's count of how many people came, not which people.
If this policy changes, the "last updated" date at the top will change with it. Material changes will be reflected here before they take effect.
Questions about this policy, or a request to correct or delete something: send an email. Requests about a specific child's details are better directed at the coach or club who entered them, as described above.