Back to Ralyy

Legal

Privacy Policy

Effective June 22, 2026 · Last updated June 22, 2026

1. Introduction

Ralyy LLC ("Ralyy," "we," "us," or "our") operates a platform for discovering, booking, and managing racket-sport court reservations, events, memberships, open ralyys, and related activities, available at ralyy.com and through our applications (collectively, the "Service").

This Privacy Policy explains what personal data we collect, how and why we use it, who we share it with, and the choices and rights you have. It applies to people who use the Service in the United States, which is the only region the Service is currently intended for.

By using the Service, you acknowledge this Policy. If you do not agree with it, please do not use the Service.

2. Who We Are

Ralyy LLC is the controller for data processed through the Service. When you book with a club, that facility acts as an independent controller governed by its own privacy policy for its on-site operations. However, to protect our community, Ralyy contractually prohibits all partner facilities from selling data received through our platform or using it for third-party targeted advertising.

Our contact details are in Section 17 (Contact Us).

3. Personal Data We Collect

We collect personal data in three ways: information you give us, information we collect automatically, and information we receive from third parties.

3.1 Information you provide to us

  • Account & profile — name, email address, phone number, password, profile photo, the sports you play, skill level, and onboarding status. You confirm you are 18 or older when you create an account.
  • Bookings, events & open ralyys — the courts, facilities, events, and times you book; party size; notes; and the name, email, and phone number of any guests or party members you add (see Section 11).
  • Memberships — your plan, billing cycle, and any cancellation reason you provide.
  • Waivers & consents — when you sign a liability waiver, your typed and/or drawn signature, the consent text you agreed to, the date and time, and the IP address and device information present at signing, kept as a record of consent.
  • Payments — billing details you enter are collected and processed by our payment processor, Stripe; we receive limited transaction data but not your full card number (see Section 8).
  • Communications & inquiries — messages you send us, support requests, and information submitted through business or partnership inquiry forms.

3.2 Information we collect automatically

  • Usage data — pages and screens you view, clubs, facilities, and events you browse, and steps in the booking and registration flow. Before you log in, we associate these with a pseudonymous device identifier rather than your name.
  • Device & connection data — IP address, browser type and user-agent, referring page, and session identifiers.
  • Performance data — page-load and web-vitals metrics, via Vercel Analytics and Speed Insights.

3.3 Information from third parties

  • Authentication provider (Supabase) — your email, name, and phone associated with sign-up or login.
  • Payment processor (Stripe) — transaction status and limited payment metadata. We never receive your full card number, CVC, or bank credentials.

3.4 Sensitive information

A limited amount of what we collect may be considered sensitive under state privacy laws — for example, date of birth or information indicating a person is a minor, and waiver signatures, which we collect only where needed to run events lawfully and record consent. We do not sell sensitive personal data, and we do not sell or share biometric data.

4. How We Use Personal Data

We use personal data to:

  • Provide the Service — create and secure your account, authenticate you, and process bookings, event tickets, memberships, open ralyys, payments, tax, and (for clubs) payouts.
  • Coordinate activities — manage party invitations, check-ins, and waivers.
  • Communicate with you — send transactional messages such as booking confirmations and cancellations, payment receipts and refunds, reminders, password resets, and account notices.
  • Market the Service — where permitted, send promotional messages and measure their effectiveness, subject to your choices (Section 6). We are not sending promotional messages at this time, but may do so in the future as described here.
  • Improve and secure the Service — analyze usage, debug, prevent fraud and abuse, and maintain safety and integrity.
  • Comply with law — meet legal, tax, and regulatory obligations and enforce our terms.

5. How We Share Personal Data

We share personal data only as described here:

  • Clubs and facilities you book with or attend, so they can fulfill your reservation, run events and memberships, verify check-ins and waivers, and support you. Clubs act as independent controllers for their own use of this data.
  • Other participants on a shared booking or event, to the extent needed to coordinate it.
  • Service providers that process data on our behalf, under contract and only as needed (see Section 5.1).
  • Legal, safety & rights — to comply with law or lawful requests, enforce our terms, or protect the rights, property, or safety of users, the public, or Ralyy.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.

We do not sell your personal data, we do not process it for targeted (cross-context behavioral) advertising, and we do not use it for profiling that produces legal or similarly significant effects. If this ever changes, we will update this Policy and provide any opt-out the law requires.

5.1 Our service providers

We use the following providers, each receiving only the data needed for its function:

  • Supabase — authentication and identity (email, name, phone, auth identifiers).
  • Stripe — payments, tax calculation, and club payouts (payment tokens, transaction and tax data, facility tax address).
  • Resend — email delivery, transactional and, in future, marketing (recipient email, message content).
  • Twilio — SMS delivery where enabled (recipient phone number, message content).
  • Cloudflare R2 — image and file storage such as avatars and photos (uploaded images and associated keys).
  • Vercel — hosting, analytics, and performance (page, usage, and performance data, pseudonymous).

6. Marketing Communications and Your Choices

We are not currently sending promotional messages, but we may in the future. If we do, you will be able to control them through your notification preferences, which separate transactional messages (which you generally cannot opt out of while you hold an account, such as booking confirmations) from marketing messages across email, SMS, push, and in-app channels.

  • Email — unsubscribe via the link in any marketing email or your preferences.
  • SMS — reply STOP where enabled, or update preferences. Message and data rates may apply.
  • Push — disable in your browser or device settings, or in your preferences.

Opt-outs may take a short time to take effect across all systems.

7. Cookies and Similar Technologies

We use a small set of first-party technologies:

  • Authentication cookie — a first-party, HTTP-only cookie that keeps you signed in. Strictly necessary.
  • Local storage — non-sensitive profile display data and your light or dark theme preference.
  • Analytics — first-party usage tracking plus Vercel Analytics and Speed Insights for product and performance analytics.

We do not use third-party advertising cookies or cross-site tracking pixels, so no cookie-consent banner is required. If we add such technologies, we will update this Policy and provide any consent or opt-out the law requires.

8. Payments

Payments are processed by Stripe. We do not collect or store your full card number, CVC, or bank details — Stripe tokenizes that information. We store a Stripe customer or payment-method identifier, transaction amount and status, currency, sales-tax breakdown, and (for clubs) payout details via Stripe Connect. Your payments are also governed by Stripe's Privacy Policy.

9. Where Your Data Is Stored

We and our service providers store and process personal data in the United States. The Service is intended for U.S. users only.

10. Data Retention

We retain your personal data only for the duration of your active account status. Upon explicit request or account closure, your profile data, contact information, and booking logs will be permanently deleted or fully anonymized within thirty (30) days. When we process de-identified or anonymized data, we commit to maintaining it in a fully non-identifiable state — we will not attempt to re-identify the data, nor will we permit our partners or service providers to do so.

To satisfy legal, tax, and accounting obligations, or to maintain definitive compliance records, signed liability waivers and associated transaction metadata will be securely retained for a maximum period of seven (7) years following account closure, after which they will be permanently destroyed.

11. Information About Other People

When you add guests or party members to a booking or event, you provide their name, email, and phone number solely to coordinate that specific reservation.

To ensure transparency, Ralyy will notify the added guest, provide a link to this Privacy Policy, and include a clear, one-click mechanism allowing them to opt out and remove their contact information from our active records.

12. Children's Privacy

The Service is for adults 18 and older. We do not knowingly collect personal data from anyone under 18 as a user. Where a minor participates in a booking or event, we collect limited information (such as date of birth and a guardian's signature on a waiver) from the responsible adult, not from the minor directly. If you believe a minor has provided us personal data, contact hello@ralyy.com and we will delete it.

13. Your Privacy Rights

Ralyy extends the same high-standard, transparent data rights to all U.S. users, regardless of state, including the right to access, correct, delete, and port your personal data.

How to exercise your rights: email hello@ralyy.com with your request. We verify it using information associated with your account and fulfill valid requests within 45 days. If we decline a request, you may appeal by emailing hello@ralyy.com with "Privacy Appeal" in the subject line.

Depending on your state, you may also have the right to opt out of the sale of personal data or targeted advertising. As stated above, we do not sell personal data or conduct targeted advertising. We will not discriminate against you for exercising any of your privacy rights.

14. Third-Party Links

The Service may link to third-party sites and services (such as a club's own website or Stripe checkout). We are not responsible for their privacy practices; please review their policies.

15. Security

We use technical and organizational safeguards appropriate to the data, including encryption in transit (HTTPS), hashing of passwords and security tokens, tokenization of payments via Stripe, access controls, and reputable infrastructure providers. No method of transmission or storage is fully secure, and we cannot guarantee absolute security.

16. Changes to This Policy

We may update this Policy from time to time. We will revise the "Last updated" date and, for material changes, provide prominent notice (such as an in-app popup or email). Your continued use of the Service after changes take effect constitutes acceptance.

17. Contact Us

Ralyy LLC

This Policy is governed by the laws of the State of Texas and applicable U.S. federal law, except where a privacy or consumer-protection statute of your state of residence applies.