1. INTRODUCTION
Privacy Policy for CIFA Mobile App
Last Updated: December 4, 2025
Invovibe Tech Cayman (“I.T. Cayman”, “we”, “us”, or “our”) operates the CIFA Mobile App (the “App”). This Privacy Policy informs you of our policies regarding the collection, use, and disclosure of personal information when you use our App.
1. Information We Collect
Account Information:
- Email address (for authentication)
- Display name (optional, for user profile)
- User role (public user or administrator)
Device Permissions:
- Camera: Used when you choose to upload photos for match reports, news articles, or profile pictures. We only access your camera when you explicitly grant permission and choose to take a photo within the app.
- Photo Library: Used to select existing photos from your device for uploading to match reports, news articles, or profile pictures. Access is only granted when you choose to upload an image.
- Internet Access: Required to sync data with our servers, display live match information, league tables, news, and Instagram content.
- Notifications: Used to send you updates about matches, news, league standings, and CIFA announcements. You can disable notifications at any time in your device settings.
2. How We Use Your Information
We use the collected information for:
- Providing and maintaining the App functionality
- User authentication and account management
- Displaying football matches, fixtures, league tables, and standings
- Presenting news articles and announcements
- Showing Instagram content from official CIFA accounts
- Sending push notifications about matches, results, and updates
- Allowing authorized administrators to manage content, matches, and news
- Improving app performance and user experience
3. Data Storage and Security
- Your data is stored securely using Firebase (Google Cloud Platform)
- All data transmission is encrypted using HTTPS/SSL
- We implement industry-standard security measures to protect your information
- We do not sell, trade, or rent your personal information to third parties
- Photos uploaded through the camera or photo library are stored securely in Firebase Storage and used only for app content purposes
- Access to administrative features is restricted to authorized personnel only
4. Third-Party Services
We use the following third-party services that may collect information:
- Firebase (Google): For authentication, real-time database, cloud storage, and hosting
- Instagram Graph API: To display official CIFA Instagram content and stories
- Expo Push Notifications: For sending match updates and news alerts
These services have their own privacy policies governing the use of your information. We encourage you to review their privacy policies.
5. Data Retention
We retain your personal information only for as long as necessary to provide you with our services and as described in this Privacy Policy. We will retain and use your information to comply with our legal obligations, resolve disputes, and enforce our agreements.
6. Children’s Privacy
Our App is designed for football fans of all ages. We do not knowingly collect personal information from children under 13 without verifiable parental consent. If you are a parent or guardian and believe your child has provided us with personal information, please contact us so we can delete such information.
7. Your Rights
You have the right to:
- Access your personal data stored in our systems
- Request correction of inaccurate or incomplete data
- Request deletion of your account and associated data
- Opt-out of push notifications through your device settings
- Revoke camera and photo library permissions through your device settings
- Request a copy of your data in a portable format
To exercise these rights, please contact us using the information provided below.
8. Changes to This Privacy Policy
We may update our Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by posting the new Privacy Policy within the App and updating the “Last Updated” date at the top of this policy. We encourage you to review this Privacy Policy periodically.
9. International Data Transfers
Your information may be transferred to and stored on servers located outside of your country of residence, including the United States, where our service providers (such as Firebase) operate. By using our App, you consent to the transfer of your information to these locations.
10. California Privacy Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, delete your personal information, and opt-out of the sale of your personal information. We do not sell personal information.
11. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Invovibe Tech Cayman (I.T. Cayman) Email: info@invovibetech.com Website: https://invovibetech.com Location: Cayman Islands
This privacy policy is effective as of December 4, 2025, and applies to the CIFA Mobile App developed by Invovibe Tech Cayman for the Cayman Islands Football Association (CIFA).
2. DATA COLLECTED
DATA STORAGE LOCATION
We are Cyprus based company and operate web servers hosted in Germany. Our hosting provider Hetzner Online GmbH adheres to the EU/US “Privacy Shield”, ensuring that your data is securely stored and GDPR compliant. For more information on Hetzner Online GmbH privacy policy, please see here: Hetzner Data Privacy Policy.
REGISTRATION DATA
If you register on our website, we store your chosen username and your email address and any additional personal information added to your user profile. You can see, edit, or delete your personal information at any time (except changing your username). Website administrators can also see and edit this information.
PURCHASE DATA
To receive product support, you have to have one or more Envato/AxiomThemes purchase codes on our website. These purchase codes will be stored together with support expiration dates and your user data. This is required for us to provide you with downloads, product support and other customer services.
SUPPORT DATA
If you have registered on our website and have a valid support account, you can submit support tickets for assistance. Support form submissions are sent to our third party Ticksy ticketing system. Only the data you explicitly provided is sent, and you are asked for consent, each time you want to create a new support ticket. Ticksy adheres to the EU/US “Privacy Shield” and you can see their privacy policy here: Ticksy Privacy Policy.
COMMENTS
When you leave comments on the website we collect the data shown in the comments form, and also the IP address and browser user agent string to help spam detection.
CONTACT FORM
Information submitted through the contact form on our site is sent to our company email, hosted by Zoho. Zoho adheres to the EU/US “Privacy Shield” policy and you can find more information about this here: Zoho Privacy Policy.
These submissions are only kept for customer service purposes they are never used for marketing purposes or shared with third parties.
GOOGLE ANALYTICS
We use Google Analytics on our site for anonymous reporting of site usage. So, no personalized data is stored. If you would like to opt-out of Google Analytics monitoring your behavior on our website please use this link: Google Analytics Opt-out.
CASES FOR USING THE PERSONAL DATA
We use your personal information in the following cases:
- Verification/identification of the user during website usage;
- Providing Technical Assistance;
- Sending updates to our users with important information to inform about news/changes;
- Checking the accounts’ activity in order to prevent fraudulent transactions and ensure the security
- over our customers’ personal information;
- Customize the website to make your experience more personal and engaging;
- Guarantee overall performance and administrative functions run smoothly.
3. EMBEDDED CONTENT
Pages on this site may include embedded content, like YouTube videos, for example. Embedded content from other websites behaves in the exact same way as if you visited the other website.
These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged-in to that website. Below you can find a list of the services we use:
The Facebook page plugin is used to display our Facebook timeline on our site. Facebook has its own cookie and privacy policies over which we have no control. There is no installation of cookies from Facebook and your IP is not sent to a Facebook server until you consent to it. See their privacy policy here: Facebook Privacy Policy .
X
We use the X API to display our tweets timeline on our site. X has its own cookie and privacy policies over which we have no control. Your IP is not sent to a X server until you consent to it. See their privacy policy here: X Privacy Policy .
YOUTUBE
We use YouTube videos embedded on our site. YouTube has its own cookie and privacy policies over which we have no control. There is no installation of cookies from YouTube and your IP is not sent to a YouTube server until you consent to it. See their privacy policy here: YouTube Privacy Policy.
4. COOKIES
This site uses cookies – small text files that are placed on your machine to help the site provide a better user experience. In general, cookies are used to retain user preferences, store information for things like shopping carts, and provide anonymized tracking data to third party applications like Google Analytics. Cookies generally exist to make your browsing experience better. However, you may prefer to disable cookies on this site and on others. The most effective way to do this is to disable cookies in your browser. We suggest consulting the help section of your browser.NECESSARY COOKIES (ALL SITE VISITORS)
- cfduid: Is used for our CDN CloudFlare to identify individual clients behind a shared IP address and apply security settings on a per-client basis. See more information on privacy here: CloudFlare Privacy Policy.
- PHPSESSID: To identify your unique session on the website.
NECESSARY COOKIES (ADDITIONAL FOR LOGGED IN CUSTOMERS)
- wp-auth: Used by WordPress to authenticate logged-in visitors, password authentication and user verification.
- wordpress_logged_in_{hash}: Used by WordPress to authenticate logged-in visitors, password authentication and user verification.
- wordpress_test_cookie Used by WordPress to ensure cookies are working correctly.
- wp-settings-[UID]: WordPress sets a few wp-settings-[UID] cookies. The number on the end is your individual user ID from the users database table. This is used to customize your view of admin interface, and possibly also the main site interface.
- wp-settings-[UID]:WordPress also sets a few wp-settings-{time}-[UID] cookies. The number on the end is your individual user ID from the users database table. This is used to customize your view of admin interface, and possibly also the main site interface.
5. WHO HAS ACCESS TO YOUR DATA
If you are not a registered client for our site, there is no personal information we can retain or view regarding yourself. If you are a client with a registered account, your personal information can be accessed by:- Our system administrators.
- Our supporters when they (in order to provide support) need to get the information about the client accounts and access.
6. THIRD PARTY ACCESS TO YOUR DATA
We don’t share your data with third-parties in a way as to reveal any of your personal information like email, name, etc. The only exceptions to that rule are for partners we have to share limited data with in order to provide the services you expect from us. Please see below:
ENVATO PTY LTD
For the purpose of validating and getting your purchase information regarding licenses for our theme, we send your provided tokens and purchase keys to Envato Pty Ltd and use the response from their API to register your validated support data. See the Envato privacy policy here: Envato Privacy Policy.
TICKSY
Ticksy provides the support ticketing platform we use to handle support requests. The data they receive is limited to the data you explicitly provide and consent to being set when you create a support ticket. Ticksy adheres to the EU/US “Privacy Shield” and you can see their privacy policy here: Ticksy Privacy Policy.
7. HOW LONG WE RETAIN YOUR DATA
When you submit a support ticket or a comment, its metadata is retained until (if) you tell us to remove it. We use this data so that we can recognize you and approve your comments automatically instead of holding them for moderation.
If you register on our website, we also store the personal information you provide in your user profile. You can see, edit, or delete your personal information at any time (except changing your username). Website administrators can also see and edit that information.
8. SECURITY MEASURES
We use the SSL/HTTPS protocol throughout our site. This encrypts our user communications with the servers so that personal identifiable information is not captured/hijacked by third parties without authorization.
In case of a data breach, system administrators will immediately take all needed steps to ensure system integrity, will contact affected users and will attempt to reset passwords if needed.
9. YOUR DATA RIGHTS
GENERAL RIGHTS
If you have a registered account on this website or have left comments, you can request an exported file of the personal data we retain, including any additional data you have provided to us.
You can also request that we erase any of the personal data we have stored. This does not include any data we are obliged to keep for administrative, legal, or security purposes. In short, we cannot erase data that is vital to you being an active customer (i.e. basic account information like an email address).
If you wish that all of your data is erased, we will no longer be able to offer any support or other product-related services to you.
GDPR RIGHTS
Your privacy is critically important to us. Going forward with the GDPR we aim to support the GDPR standard. AxiomThemes permits residents of the European Union to use its Service. Therefore, it is the intent of AxiomThemes to comply with the European General Data Protection Regulation. For more details please see here: EU GDPR Information Portal.
10. THIRD PARTY WEBSITES
AxiomThemes may post links to third party websites on this website. These third party websites are not screened for privacy or security compliance by AxiomThemes, and you release us from any liability for the conduct of these third party websites.
All social media sharing links, either displayed as text links or social media icons do not connect you to any of the associated third parties, unless you explicitly click on them.
Please be aware that this Privacy Policy, and any other policies in place, in addition to any amendments, does not create rights enforceable by third parties or require disclosure of any personal information relating to members of the Service or Site. AxiomThemes bears no responsibility for the information collected or used by any advertiser or third party website. Please review the privacy policy and terms of service for each site you visit through third party links.
11. RELEASE OF YOUR DATA FOR LEGAL PURPOSES
At times it may become necessary or desirable to AxiomThemes, for legal purposes, to release your information in response to a request from a government agency or a private litigant. You agree that we may disclose your information to a third party where we believe, in good faith, that it is desirable to do so for the purposes of a civil action, criminal investigation, or other legal matter. In the event that we receive a subpoena affecting your privacy, we may elect to notify you to give you an opportunity to file a motion to quash the subpoena, or we may attempt to quash it ourselves, but we are not obligated to do either. We may also proactively report you, and release your information to, third parties where we believe that it is prudent to do so for legal reasons, such as our belief that you have engaged in fraudulent activities. You release us from any damages that may arise from or relate to the release of your information to a request from law enforcement agencies or private litigants.
Any passing on of personal data for legal purposes will only be done in compliance with laws of the country you reside in.
