ShuttleSmart — Privacy Policy

ShuttleSmart Badminton Draws, for Android and iOS (com.brainbloomer.shuttlesmart).

Last updated: September 7, 2026

The short version. ShuttleSmart needs an account, so we hold your email address. We also hold the list of badminton players you have chosen to watch, because your alerts are generated on our servers, not on your phone. We use a random install identifier for analytics and notifications, and a crash reporter for diagnostics. We run no advertising or tracking SDK and we do not sell your data. The tournament and ranking information the app shows is public BWF data about players, not data about you.

1. Who we are

ShuttleSmart is operated by Benetti Corporation, a Texas C-Corporation ("Benetti", "we", "us").

ShuttleSmart is not affiliated with, endorsed by, or sponsored by the Badminton World Federation. This policy covers the ShuttleSmart mobile app and the ShuttleSmart pages on app.brainbloomer.com. Other BrainBloomer apps have their own policies; this one describes ShuttleSmart only.

2. What ShuttleSmart collects

Email address (your account)

Signing up and signing in both use your email address, and nothing else about you: no name, no phone number, no postal address. There is no password for you to choose. To sign in you enter your email, we send a one-time code to it, and you type that code back. Account records are held in Google Firebase Authentication under our project, and the sign-in exchange goes to our own server at brainbloomer.com.

Behind the scenes the app generates a long random secret for your account so Firebase has a credential to work with. It is stored in your device's secure keystore, protected by your device unlock, and it is never shown to you or used as a login you have to remember.

The players you watch

The players you add to your watch list are stored on our servers against your account, not only on your phone — that is what lets us watch the entry lists and rankings on your behalf and alert you when something moves. Adding, listing and removing a watch are authenticated requests carrying the player's public BWF id and, optionally, their display name.

Your watch actions also appear in our product analytics: when you add, pick or remove a player, the event we record includes that player's public BWF id alongside your install identifier. We use this to understand how the app is used. It is not sold, and it is not used for advertising.

Alert preferences

If you change alert frequency, quiet hours or which alert types are muted, those preferences are stored on our servers against your account so alerts behave the same on every device.

Install identifier

On first launch the app generates a random UUID and keeps it in the device's secure storage. It is not your advertising ID. It is attached to analytics events, to remote-configuration and experiment requests, and to purchase records so an entitlement can be matched to the install.

Usage events

ShuttleSmart sends product-analytics events to our own backend. Each event carries the event name, the install identifier, the product id, environment, platform, app version, timestamps, a flag marking non-production traffic, and event-specific properties (including the watched-player ids described above).

Crash and diagnostic data

The production build reports crashes and performance traces to Sentry. ShuttleSmart does not attach your email or account id to those reports. Console logs are dropped before they leave the device and routine network failures are filtered out; recent analytics events are mirrored into a report as breadcrumbs.

Separately, the app reports its own warnings, errors and failed HTTP requests to our backend as diagnostic events. A failed-request report contains the request method, the URL, the status code, how long it took, and up to the first 600 characters of the response our server sent back. Values under keys named for tokens, passwords, authorization headers, secrets or API keys are redacted before anything is sent, and request bodies are not forwarded off the device.

Push notification token

Only if you turn notifications on. The registration is authenticated and carries the device push token, platform, provider, app bundle id and push environment. Notifications are optional and every core feature works without them.

Purchases

The app ships with a free allowance of watch slots. If you buy additional slots, our server creates a Stripe Checkout session tied to your account and opens it in your normal browser; Stripe collects your payment details on its own page. The in-app subscription rail is built but currently switched off. We never see or store your card number.

Biometric unlock

You can optionally require your device's fingerprint or face unlock to open the app. That check happens entirely on your device through the operating system. We never receive your fingerprint, face data or any biometric template — only whether the device said the check passed.

3. What ShuttleSmart does not collect

4. Where data goes

RecipientWhat it receivesWhy
Benetti backend (Google Cloud, United States)Your email, your watch list, alert preferences, install identifier, analytics events, diagnostic reports, push token, purchase recordsTo run your account, watch the draws, and send your alerts
Google Firebase AuthenticationYour email and the account credentialTo hold the account and issue sign-in tokens
SentryCrash and diagnostic reports with breadcrumbsTo find and fix errors
StripeYour payment details, which it collects directlyTo take payment for extra watch slots

Each provider operates under its own privacy policy. All traffic between the app and our servers uses HTTPS. Our servers are in the United States.

5. Public badminton data

Entry lists, draws, rankings, tournament histories and player profile images shown in ShuttleSmart are public information published by or about the Badminton World Federation and the players themselves. That content is not personal data about you, and deleting your account does not affect it.

6. What is stored on your device

Uninstalling the app removes all of it. Your account and watch list remain on our servers until you delete the account.

7. Retention and deletion

You can delete your account from inside the app: Settings → Delete account, confirmed by typing the confirmation phrase. Deletion is scheduled with a 30-day grace period — sign back in within those 30 days and the deletion is cancelled. After that the account, your watches and your monitoring history are permanently removed. If you can no longer sign in, email benettimedia@gmail.com from the address on the account and we will verify ownership and complete the deletion within 30 days.

Billing records are retained for the period tax law requires.

8. Your rights

You can access, correct, export or delete your personal data, and you can turn notifications off at any time in Settings or in your device settings. To make a request, email benettimedia@gmail.com from your account address.

9. Children

ShuttleSmart is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us personal information, contact us and we will delete it.

10. Security

We use HTTPS for all app-to-server traffic, the platform's secure keystore for your credential and install identifier, token-authenticated requests for everything tied to your account, encryption at rest on our cloud provider, and role-based access controls on the backend. No system is perfectly secure; we do not claim otherwise.

11. Changes to this policy

We may update this policy. Material changes will be posted on this page with a new "Last updated" date.

12. Contact

Benetti Corporation · 1401 Lavaca Street #40044, Austin, Texas 78701, USA · benettimedia@gmail.com · +1 878-888-6823