Privacy Policy
RAM - Rinks Arena Manager
This policy explains how this application handles information and how to contact us about privacy.
Information we process
RAM — Rinks Arena Manager stores the rink profile and optional logo image, event schedule, maintenance tasks and history, defect descriptions and attached photos, staff display name, and reminder preferences on your device. When backup and synchronization are used, the app sends the rink profile, completed and skipped maintenance history, defect records, and attached defect photos to our server. The server assigns an installation identifier and stores a hash of a randomly generated installation secret; the secret itself is held in the device Keychain. Requests also reach Railway hosting infrastructure, which may process technical information such as IP address, request time, route, and error details in service logs. We do not ask you to create an account or provide an email address to use the app.
How we use information
Local information supports scheduling, automatically generated ice preparation tasks, maintenance tracking, defect documentation, checklists, and reminders. Backup is enabled by default at profile setup and can be turned off before saving; Settings can change it later. Server copies support synchronization of maintenance history and defects and backup of the rink profile and attached defect photos for the same installation. The installation secret restricts access to that installation's server data. Technical request information helps operate and troubleshoot the service.
Service providers and sharing
The server and its PostgreSQL database run on Railway, which provides hosting and may process request and infrastructure logs as a service provider. We do not integrate advertising networks, analytics providers, email delivery services, or social sign-in. We do not sell personal data or expose rink records and photos through public API endpoints. The public privacy page does not require an account or cookie.
Data retention
On-device records remain until you successfully delete them in the app or remove the app, subject to your device's backup settings. Turning off backup stops sending updates but does not delete records already stored on the server. Server records remain while the installation exists, until an authenticated delete request removes the installation and its active profile, history, defects, and photo rows. When a defect photo is replaced with backup enabled, the prior server photo is removed from active storage after the new image and defect record synchronize; the prior copy can remain if backup is off or synchronization has not completed. Railway database backups and infrastructure logs may persist after active data is deleted under Railway's own retention processes; we do not claim a fixed duration or immediate erasure of those copies. We do not create a separate export or recovery account, and data cannot be recovered through a new installation if its secret is lost.
Deleting your information
Use the delete rink data action in the app to request deletion of the installation's server data and erase local rink records, photos, and the Keychain secret. If a server copy exists, the app waits for confirmation before erasing local data; while offline or if the request fails, it keeps the data and secret and reports failure so you can retry. If no server secret was issued, it removes local data directly. Removing the app before a server deletion succeeds may leave a server copy because its secret is lost. You may contact talfryn.larkspur@icloud.com about a privacy request, but without the installation secret we may be unable to identify or access the associated private server records. Active database rows are removed together through the installation deletion; replaced photo rows are also removed after successful synchronization. Provider backup and log copies follow Railway's retention processes.
Permissions and your choices
Camera permission is used only when you choose to photograph a rink defect. Photo library selection is used only when you choose an existing image for a defect or rink logo. The logo stays on the device and is not included in server backup. Notification permission allows local task reminders. You can decline or withdraw these permissions in iOS Settings; doing so prevents the related capture, selection, or reminder function but does not remove records already saved. The app does not request location permission or use a geographic map.
Your privacy rights
You can view and edit your rink information in the app and delete the installation's local and server data using the delete action. For privacy questions or requests, email talfryn.larkspur@icloud.com. Because there are no user accounts, we may need the installation identifier or proof of control of the installation to locate a server record, and loss of the secret can prevent access to it. Rights available under applicable law may vary by location.
Security
Private API requests require a randomly generated installation secret stored in the iOS Keychain; the server stores only its SHA-256 hash and checks it for every private request. Records and photos are separated by installation in database queries, and the service uses HTTPS in deployment. Access to the device and its backups, the secret, and hosting systems remains relevant to security; no system can guarantee absolute protection.
Children’s privacy
RAM is designed for adult rink managers and technical staff, not for children. We do not knowingly design features to collect information from children.
Changes to this policy
We may update this policy when app features or processing practices change. The revised policy will be published at this page with a new effective date. You can contact talfryn.larkspur@icloud.com with questions about a change.