Legal

Privacy Policy

Last updated: 25 August 2026

1. Controller

Dartshift is run by:

Niels Verbunt
c/o POSTFLEX PFX-618-039
Emsdettener Straße 10
48268 Greven
Germany

Email: dartshift@outlook.com

2. About Dartshift

Dartshift is a web app for managing dart leagues and tournaments, including players, games, schedules, results and standings.

It's built for invited league admins and players. Private app data isn't meant to be publicly accessible without an account.

3. Personal data we process

Depending on how you use Dartshift, we may process:

  • Your email address
  • Your password and authentication data
  • Your player name or Autodarts nickname
  • User account identifiers
  • Information linking your user account to a player
  • League, tournament, schedule, game, result and standings data
  • Login and session data
  • Password reset data
  • Technical information such as IP addresses, timestamps, browser or request information and server logs, where this is processed by our hosting or authentication providers
  • Discord authentication data, if you sign in with Discord
  • If you use the Dartshift browser extension, completed Autodarts match data submitted through it. This can include the match ID, scores, legs, sets, averages and the participants' Autodarts account IDs and display names. If you explicitly confirm it, we can also store a permanent link between your Dartshift player and your Autodarts account. More on this in section 11.

We don't currently ask for phone numbers, profile pictures, billing information or payment information.

4. Why we process personal data

We process personal data to:

  • Create and manage user accounts
  • Provide login and authentication
  • Connect users to player profiles
  • Manage leagues, tournaments, players, schedules, games, results and standings
  • Show authorized users the app data they're allowed to see
  • Provide admin and player features
  • Protect the app and prevent misuse
  • Handle password resets and account recovery
  • Investigate and fix technical problems
  • Respond to support requests, feedback and deletion requests
  • Import Autodarts match results, connect an Autodarts account to a Dartshift player and, when all the verification requirements in section 11 are met, automatically finalize a league or tournament result

5. Legal bases

Where the GDPR applies, we rely on the following legal bases:

  • Art. 6(1)(b) GDPR, where processing is necessary to provide the app and its account functionality
  • Art. 6(1)(f) GDPR, for legitimate interests such as app security, preventing abuse, troubleshooting, maintaining competition history and protecting the integrity of league and tournament records

6. Hosting, database and authentication providers

Dartshift relies on outside providers to operate the app.

Vercel

Vercel hosts and delivers the Dartshift web app.

Supabase

Supabase provides Dartshift's database, authentication system and Supabase Auth emails. The Supabase project is hosted in the Ireland region.

Discord

Discord can be used as an external login provider. If you choose to sign in with Discord, you're redirected to Discord and then back to Dartshift. We don't intentionally store your Discord username, avatar or email ourselves, but Supabase and Discord may still process authentication-related information as part of the login process.

7. Cookies and session technologies

Dartshift uses cookies and similar session technologies that are necessary for the app to work: for login, authentication, session management, access to protected routes, token refresh and password reset security.

This includes Supabase's authentication and session cookies, plus a Dartshift cookie called sb-recovery-pending. It's used during password reset and expires after 30 minutes.

We don't currently use analytics cookies, marketing cookies, advertising pixels or newsletter tracking.

More information is available in the Cookie Policy.

8. Support communication

You can contact Dartshift by email or Discord.

If you contact us by email, your message and contact details are processed so we can respond to you.

If you contact the operator through Discord, Discord may process your message and account information according to its own systems and policies.

9. Data retention

Account and app data is generally kept for as long as your account or your use of Dartshift continues.

You can request account deletion from /my. Your account is not deleted immediately. You first need to confirm the deletion request by email, and the confirmation link expires after 24 hours.

When an account is deleted, personal information may be deleted or anonymised. This can include the Supabase Auth account, profile and player information, email-linked data, user-scoped games, league join requests, league invitations created by the user and Discord link information.

If you're taking part in an active league or tournament, your participation may be converted into a withdrawal instead of being removed entirely.

Historical competition records may remain in anonymised form where this is necessary to preserve the integrity of league and tournament history.

10. Account deletion and right to erasure

You can start an account deletion request from /my.

In the Danger Zone, enter DELETE and submit the request. We'll then send you a confirmation email. Deletion only continues after you open the confirmation link, and that link expires after 24 hours.

We don't store the raw confirmation token. Only a hashed version of it is stored while the deletion request is pending.

After you confirm the request, personal information may be deleted or anonymised. This can include your Auth account, profile and player data, email-linked data, user-scoped games, user-scoped requests and invitations, and Discord link data.

Participation in an active league or tournament may be converted into a withdrawal. Historical competition records may remain in anonymised form so that past league and tournament results stay consistent.

If you linked a Discord account, we may also try to remove you from the Dartshift Discord server after the app-level deletion succeeds. That cleanup is best-effort and can't be guaranteed.

A final confirmation email is sent before your Supabase Auth account is deleted.

For privacy or account deletion questions, contact dartshift@outlook.com.

11. Dartshift browser extension

Dartshift offers an optional browser extension that connects your completed Autodarts matches with your Dartshift account.

This lets eligible match results be imported into Dartshift. In some cases, a result can also be finalized automatically, once all the verification requirements below are met.

The extension only watches match information on the Autodarts website, at play.autodarts.com. It is not injected into dartshift.com and does not read the contents of the Dartshift website. It separately talks to dartshift.com when it needs to perform an authenticated Dartshift action, such as submitting an imported match or confirming an identity link.

What the extension reads

When you're signed in to Autodarts and viewing a completed match, the extension reads match information that the Autodarts website has already loaded. This includes:

  • Match ID
  • Match type
  • Match format
  • Finish time
  • Match-scoped player ID
  • Autodarts account ID, when available
  • Display name
  • Legs won
  • Sets won
  • Final average
  • Per-leg averages

This information is read for both players in the match, not only for you. That happens whether or not an identity link has already been confirmed.

Separately, the extension reads the account ID and display name of the Autodarts account currently signed in. This is how it can offer to connect that account to your Dartshift player.

The extension does not read:

  • Autodarts avatars
  • Country information
  • Membership status
  • Board IDs
  • Dart throw coordinates
  • Full turn or throw history
  • Checkout details
  • Autodarts login credentials
  • Autodarts cookies
  • Autodarts authentication tokens

What it sends to Dartshift

Only the match and account fields described above are sent to Dartshift. Avatars, country information, membership data, board IDs, throw-by-throw data and raw Autodarts payloads are not sent to Dartshift.

Requests to Dartshift use the same Dartshift session cookie you already have when signed in to the website. The extension does not create a separate Dartshift login, and your Autodarts credentials are never sent to Dartshift.

Importing a match does not link your identity

An imported match may contain an Autodarts account ID and display name for you or your opponent, because those details were part of the match data.

That alone does not create a permanent connection between an Autodarts account and a Dartshift player.

A permanent identity link is only created after you explicitly confirm it once, through the extension.

Dartshift does not treat a display name as proof of identity. A confirmed, stable Autodarts account ID is required.

When an imported match can become an official result

A single imported match is normally only a personal record. It does not change a league or tournament result by itself.

An imported match can automatically become an official league or tournament result, without manual confirmation from an admin or either player, but only when all of the following are true:

  • Both scheduled players have confirmed Autodarts identity links
  • Both players independently import the same completed match from their own Autodarts accounts
  • The two participants in the imported match exactly match those two confirmed accounts
  • There is exactly one scheduled league fixture or tournament match the imported match can belong to
  • Both imports report the same result

If any of these conditions is missing, unclear or contradictory, the match is not finalized automatically. For example, this happens if two possible fixtures could match the import, or if the two players report different results. In that case, the imports remain personal records only.

When a league result is finalized automatically, it can affect the league standings. When a tournament result is finalized automatically, the tournament bracket advances the same way it would after a manually confirmed result.

What the extension stores

On your device, the browser extension keeps the currently detected match or status for each open Autodarts tab. This can include the match information listed above.

That stored information is replaced when the tab moves to another match or leaves Autodarts. It is removed when you close the tab, or when you use the extension's "Clear local debug state" option. Otherwise, the extension keeps this information only for a small number of recently active tabs.

The Autodarts account currently signed in to a tab is tracked separately, and only for the current browser session. This is cleared when the browser closes.

The extension does not store raw Autodarts payloads, throws, turn history, dart coordinates, cookies, authorization headers or authentication tokens on your device.

On Dartshift's servers, imported matches and confirmed identity links are stored under your account and protected by the same access controls used for the rest of your Dartshift data. See section 6 for information about our service providers.

Deleting your data and removing links

There is currently no separate unlink option for the Autodarts identity connection.

Deleting your Dartshift account, as described in section 10, permanently removes your Autodarts identity link and your personal Autodarts import records.

If an imported match has already become an official league or tournament result, that result is treated as regular competition data. It follows the same competition history and deletion rules described in sections 9 and 10. It is not deleted solely because the personal import that originally created it is removed.

No selling, advertising or unrelated use

Information read by the extension is used only to import matches and connect an Autodarts account to a Dartshift player, as described above. It is not sold, used for advertising or used for unrelated purposes.

No remotely executed code

The extension runs only code that is included in and reviewed as part of the extension package.

Responses received from Autodarts and Dartshift are treated as data. They are not executed as code.

Questions about the browser extension can be sent to dartshift@outlook.com.

12. No analytics, marketing or payments

Dartshift currently does not use analytics tools, marketing tools, advertising tools, newsletters or payment processing.

13. Your rights

If the GDPR applies to you, you may have the following rights:

  • The right to access your personal data
  • The right to correct inaccurate personal data
  • The right to request deletion of your personal data
  • The right to restrict certain processing
  • The right to object to certain processing
  • The right to data portability, where applicable
  • The right to lodge a complaint with a competent data protection authority

To exercise these rights, contact dartshift@outlook.com.

For North Rhine-Westphalia, the competent supervisory authority is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW).

14. Automated decision-making

Dartshift does not currently use automated decision-making or profiling that produces legal or similarly significant effects.

15. Changes to this Privacy Policy

This Privacy Policy may change when Dartshift, its service providers or the applicable legal requirements change.

The latest version will always be available on this page.