Privacy Policy – 3Steps

Last updated: 24 August 2026 · Version: 2.0

This policy explains how Readplay AS processes personal data when you use 3Steps. We comply with the General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act. This is a translation; in case of any discrepancy, the Norwegian version prevails.

1. Who is the data controller?

Readplay AS Organisation number: 933 239 292 Address: Hamar, Norway Contact: support@readplay.app

For privacy enquiries, use the email address above.

2. Two roles – read this section first

3Steps is used both by individual users and by clubs/teams. Our role depends on the context:

A) Data controller (for account holders). For coaches, club administrators and others who create an account with us, Readplay AS is the data controller for the account data (name, email, login data, billing, usage data).

B) Data processor (for player data entered by a club). When a club or team uses 3Steps to register players and match data, the club/team is the data controller for that data. Readplay AS is the data processor and processes the data only on the club's instructions under a data processing agreement (DPA) – which is part of our terms of service.

About player data:

  • The club decides which details are registered about each player, within the categories the service offers (see section 3). The club is responsible for having a valid legal basis for the registration, and for informing players (and guardians, where the player is a minor) that data is processed. Readplay AS does not verify the duty to inform on the club's behalf.
  • Player data is only accessible to authorised users within the player's own club. 3Steps has no public player profiles.
  • National identity numbers, health data or other special categories of personal data must not be registered in 3Steps.
  • We refer to the guidelines from the Norwegian Olympic and Paralympic Committee and Confederation of Sports (NIF) and the Norwegian Data Protection Authority (Datatilsynet) on the processing of personal data and images in sport.

3. What data do we process?

  • Account data (role A): name, email, phone (optional), role, club affiliation, language preference. Sign-in is handled by Microsoft Entra ID – we do not store passwords.
  • Billing data (role A): organisation, billing address, subscription, payment status. Card details are handled by Stripe – we never store card numbers.
  • Usage data (role A): login times, IP address, browser/device, event logs, error reports.
  • Player data (role B – the club is the data controller): name, date of birth, nationality, position, shirt number and team affiliation; profile photo; contact details (email, phone, address); next of kin / emergency contact; height, weight and sizes (shoes/clothing); participation (squads and matches), individual match performance and statistics; match video and video clips in which players may be identifiable. Which of these fields are actually filled in is decided by the club.
  • Communication: support requests and emails you send us.
  • Providing and operating the service – contract (GDPR art. 6(1)(b)).
  • Billing and accounting – contract and legal obligation (art. 6(1)(b) and (c)).
  • Security, troubleshooting and abuse prevention – legitimate interest (art. 6(1)(f)).
  • Product improvement based on anonymised or aggregated usage data – legitimate interest (art. 6(1)(f)).
  • Email marketing to existing customers – Norwegian Marketing Control Act § 15 (existing customer relationship), with an opt-out in every message.
  • Newsletters and other marketing – consent (art. 6(1)(a) and the Marketing Control Act § 15).

For player data (role B), the club's legal basis applies – typically consent or legitimate interest in a sporting context. Additional requirements apply for minor players, see section 9.

5. Where is the data stored? (Data residency)

Where data is stored depends on the type of content:

  • Account, player and match data (database and infrastructure): Microsoft Azure, region Norway (norwayeast).
  • Sign-in and identity: Microsoft Entra ID, Europe.
  • Match video and images: Cloudflare. Cloudflare is a US company with a global network; the transfer is based on the EU Standard Contractual Clauses (SCC) and Cloudflare's certification under the EU–US Data Privacy Framework.
  • Payment data: Stripe, EU and USA (SCC and the EU–US Data Privacy Framework).

Beyond this, we do not transfer personal data outside the EU/EEA as part of primary operations.

6. Sub-processors

We use the following sub-processors to provide the service. All have a valid data processing agreement with us.

  • Microsoft Azure – hosting, database and infrastructure. Location: Norway (norwayeast).
  • Microsoft Entra ID – sign-in and identity. Location: Europe.
  • Microsoft Azure Communication Services – transactional email. Location: EU.
  • Microsoft Azure OpenAI – AI-generated match summaries. Location: EU.
  • Cloudflare – storage and streaming of match video and images. Location: global network, headquartered in the USA (transfer under SCC and the EU–US Data Privacy Framework).
  • Stripe – payment processing. Location: EU and USA (transfer under SCC and the EU–US Data Privacy Framework).
  • PostHog – product analytics and error tracking. Location: EU.
  • Payload CMS – website content. Location: EU.

An up-to-date list is available on request. We notify customers of material changes to sub-processors.

7. How long do we keep the data?

  • Account data: as long as the account is active + 30 days after deletion.
  • Billing data: 5 years (Norwegian Bookkeeping Act).
  • Usage data / logs: stored with masked/reduced personal information for as long as necessary for security, troubleshooting and abuse prevention. Product analytics data (PostHog) is kept for 30 days.
  • Player data (role B): for the duration of the customer's subscription + 30 days, or until the club requests deletion.
  • Support communication: up to 2 years.
  • Backups: deleted data is removed from active systems on deletion and falls out of backups within 30 days. Individual records cannot be removed from existing backups; backups are rotated out automatically.

We delete or anonymise data when the purpose has been fulfilled.

8. Your rights

Under the GDPR you have the right to:

  • access the data we hold about you
  • have inaccurate data corrected
  • have data erased ("the right to be forgotten")
  • restrict processing
  • data portability (receive your data in a machine-readable format)
  • object to processing based on legitimate interest
  • withdraw consent at any time, where processing is based on consent

For player data (role B): contact your club first. We forward requests to the correct data controller.

Send requests to support@readplay.app. We respond within 30 days.

You also have the right to lodge a complaint with the Norwegian Data Protection Authority (datatilsynet.no).

9. Minors

Clubs may register players under 18 in 3Steps. The club is the data controller for this data and is responsible for ensuring the registration has a valid legal basis – including consent in line with NIF's guidelines for publishing images and film of children (for players under 15, consent is required from both the player and their guardians; the player's own wish not to be depicted must be respected) and the Norwegian Data Protection Authority's guidance on children's and young people's personal data in sport.

In addition, for minor players:

  • The data is only accessible to authorised users within the player's own club. 3Steps has no public player profiles.
  • The club must not register more data than the purpose requires (data minimisation), and must delete data when the player leaves or consent is withdrawn.
  • If the club, the player or a guardian requests deletion, we delete the data without undue delay on the instructions of the data controller.

10. Security

We use industry-standard security measures: encryption in transit (TLS) and at rest (Azure services), access control based on the principle of least privilege, multi-factor authentication for staff, security logging and monitoring. In the event of a breach that may pose a risk to affected individuals, we notify the Norwegian Data Protection Authority within 72 hours and affected customers without undue delay.

11. Cookies

3Steps uses necessary cookies for sign-in and security. Product analytics (PostHog) is only activated after consent; the consent choice itself is stored in a necessary cookie. Details are available in the cookie notice in the application.

12. Changes

We may update this policy. Material changes are announced by email or in the application at least 30 days before they take effect. The current version is always available in 3Steps.

13. Complaints

If you believe we process personal data in breach of the rules, you can complain to:

Datatilsynet (Norwegian Data Protection Authority) Postboks 458 Sentrum, 0105 Oslo, Norway postkasse@datatilsynet.no datatilsynet.no