Scorvo

Privacy Policy

Last updated 2026-07-23

Osii runs competition management for sports clubs. This policy explains what personal data we process, why, and the rights you have over it. It is written for the people who use Scorvo — club operators — and for the players whose results operators record.

1. Who we are (data controller)

Osii (business registration 247-70-00655), represented by 이재원, is the controller of the personal data described here.

Registered address: S189, Bldg 603, 26-21, Dongtanjungsimsangga 2-gil, Dongtan-gu, Hwaseong-si, Gyeonggi-do, 18453, Rep. of KOREA. Contact: support@scorvo.io. For data-protection requests specifically, write to privacy@scorvo.io.

2. Whose data, and what we collect

Operators. When you create an operator account you sign in through our authentication provider. We process your email address and display name to identify your account and secure it. We do not see or store your password.

Players on a roster. Operators enter the people in their club — names, and the results and statistics of matches. Most players never hold an account with us; they are records an operator keeps. We deliberately do not collect dates of birth or any data that would identify a minor as such — not collecting it is the strongest protection we can offer.

Uploads. When an operator imports results, the uploaded photo, PDF, or spreadsheet is stored so it can be read and so each figure can point back to its source. Extraction reads the file to draft rows; nothing is published until the operator confirms.

Payments. Subscriptions and credit top-ups are handled by our payment provider as merchant of record. Card details go to that provider, not to us — we receive only the fact of a subscription and its tier.

3. Why we process it (legal bases)

To provide the service you asked for — running your club's competitions — which is the performance of our contract with you (GDPR Art. 6(1)(b)).

To keep the service secure, working, and improving, which is our legitimate interest (Art. 6(1)(f)), balanced against your rights.

To meet legal obligations such as tax and accounting records tied to payments (Art. 6(1)(c)).

4. Players' names on shared pages

A club's standings can be shared. By default, a publicly shareable page shows a guest player as their given name and a family-name initial (for example, "Min-jun K."), and the operator must deliberately turn on full names. Unlisted links — reachable only by the person holding the link — show full names, because the operator controls who receives them.

A guest's individual statistics page is not public unless the operator opts in. These defaults exist so that a person recorded in a club roster is not exposed more widely than the operator intends.

5. Who else processes it (subprocessors)

We use a small set of processors, each for one purpose: Clerk (account authentication), Convex (application database), Polar (payment processing, as merchant of record), Cloudflare R2 (storage of uploaded import files), OpenAI (reading uploaded files to draft import rows), and Vercel (application hosting).

Some of these operate in the United States, so some processing happens outside your country. Where that is the case, transfers rely on the safeguards those providers offer, such as standard contractual clauses. We list only the processors we actually use today; if that set changes, this policy changes with it.

6. How long we keep it

We keep account and club data for as long as the account is active, and for a reasonable period afterward to meet legal and accounting obligations. Uploaded import files are kept as the provenance of the figures read from them. When an operator removes a player from a roster, that removal also removes the player from shared pages.

7. Your rights

You may ask us to give you a copy of your personal data, correct it, delete it, restrict or object to its processing, or provide it in a portable form. To exercise any of these, write to privacy@scorvo.io.

Because a player is usually a record kept by an operator rather than an account holder, a player's request is normally handled through the operator who keeps that roster; we will help where we are the right party to act. To protect against disclosing data to the wrong person, we verify identity before we act on a request.

If you are in the EU or UK and believe we have not handled your data properly, you may complain to your local data-protection authority.

8. Cookies

We use only the cookies the service needs to work: a session cookie set by our authentication provider to keep you signed in, and a small preference cookie that remembers your language. We do not use advertising or cross-site tracking cookies.

9. Changes

If we change this policy, we update the date at the top. Material changes will be made clear on this page.

10. Contact

For anything in this policy, or to exercise a right, write to privacy@scorvo.io. For everything else, support@scorvo.io.