Privacy Policy
Last updated 1 September 2026
Racketworks is stringing-shop software: a console the shop's staff use to run the business, and an Equipment Journal their players can see. This page describes, in plain language, what data we hold and what we do with it.
Who is responsible for what. A shop decides what to record about its own customers — it is the one with the relationship, and it is responsible for what it enters and how it uses it. Racketworks processes that data on the shop's behalf, and holds it under this policy. If you are a player and want something changed or removed, your shop is the fastest route; you can also write to us and we will help.
What we collect
From the shop, about a player: name, phone and email where the shop has them, the shop's own notes about that customer, rackets and string setups, restring history, photos of a racket, how the player was referred, and payment amounts.
From a player who claims their Journal: anything they choose to add to their profile — playing level (USTA, UTR), play style and how often they play, handedness, backhand and grip, birth year, height, home courts, string preferences, arm sensitivity, budget, and contact preferences — plus how each setup felt to play, and any setup experiments they run.
From a shop owner or staff member: the name and email on their sign-in, the shop's name, branding and location (city, region, postal code), and which plan the shop is on.
From anyone who applies to the partner program: name, email, phone, shop or club, location, and what they write in the two free-text questions.
On the public pages of this website — the home page, pricing, the changelog, contact, the sign-up page and every other page anyone can reach without signing in, including this one — we count visits using Vercel Web Analytics. It records the page visited, the referring site, and coarse details like country and device type. It sets no cookies, it does not follow you across other websites, and it does not build a profile of you. Vercel also collects page-loading timings — how quickly pages render — through its Speed Insights feature, which is switched on for this site at the hosting level.
It is switched off everywhere that holds anyone's data. No measurement runs inside the shop console, the Equipment Journal, The Bench, the operator console, the setup flow, the suspended-shop notice, or the claim, racket and unsubscribe links — the addresses of those pages carry customer and racket identifiers, and no visit to them is counted. That boundary is enforced in code and covered by tests, not left to memory. The sign-up page itself is counted, and its address can carry the plan you picked, an offer code, and a partner's referral code. We should be straight about those last two rather than call them anonymous: a partner code belongs to a named partner, and an offer code is free text we choose, so either could in principle be specific to one person. They are not customer or racket identifiers, which is what that boundary above exists to keep out.
We run no advertising, no ad pixels, and no third-party trackers of any kind, anywhere in the product.
Error reports are a separate thing and we should say so. When something breaks anywhere in the product, an error report goes to Sentry, and it carries the address of the page it happened on — which on a private page can include a customer or racket identifier. It is not visit counting and it is not used to measure anything; it exists so a fault is found and fixed. We have it set not to attach personal data to those reports.
Who can see what
Data is isolated per shop — one shop never sees another shop's players or business data, and that separation is enforced by the database itself rather than by application code alone. A player sees only their own Journal.
Some fields are staff-only and are never shown to a player: the shop's notes about a customer, what stock cost the shop, and its internal payment notes.
One field is deliberately the other way round. The note a stringer writes on a string job is shown to that player in their Journal as a “Stringer note”, and it becomes visible as soon as they claim their Journal — including notes written before they claimed it. Shops should treat that field as a message to the customer, not as an internal remark.
How the data is used
To run the shop's stringing operation — drop-offs, inventory, payments, reminders when a player is due — and to power that player's Journal. The Journal matches a player's tension against public professional-player reference data to suggest “pros who string like you”. It is worked out from the player's own record and is never sold or shared outside Racketworks — but the shop that strings for them sees the same list on their customer page, which is how a stringer talks about it at the counter.
Shops that switch on the weekly digest receive an email summarising their own week, which includes their own customers' names — for example who has an unpaid pickup.
Who else touches it
We never sell player data, and never share it with another shop. We do rely on a small set of vendors to run the service:
- Supabase — the database, sign-in, and private photo storage.
- Vercel — hosting and scheduled jobs.
- Purelymail — delivering email, including sign-in codes and any notice a shop sends a player through Racketworks.
- Cloudflare Turnstile — checking that a sign-in is a person rather than a bot. It inspects the browser making the request.
- Stripe — payments. Two separate things: our own plan billing, and — where a shop has set it up — card payments a shop takes from its own customers. In the second case the charge sits on the shop's own Stripe account and the money never passes through a Racketworks balance.
- Twilio — delivering text messages a shop sends a customer through Racketworks. It receives the customer's phone number and the message.
- Sentry — error reports when something breaks, so we find out before you have to tell us. It receives the error and the address of the page it happened on. We turn off its automatic collection of personal details, and the reports we write ourselves are meant to carry identifiers and statuses rather than names, emails or phone numbers.
- Backblaze B2 — encrypted off-site backups.
- Google — two separate things: signing in, if you choose “Continue with Google”; and looking up and checking a shop's address, which sends what is typed into that field to Google Places and Address Validation.
- Your browser's push service — Apple, Google or Mozilla, depending on the device. A phone notification has to travel through whichever one issued the subscription, and the notice can name a shop, a customer or an amount owed. Whose service it is, is decided by the browser, not by us.
- GitHub — where the nightly backup job runs. The backup is taken and encrypted on a GitHub-hosted machine, so that machine briefly holds the database and the racket photos before encryption.
- BetterStack — checks whether the site is up. It holds no customer data.
They process data on our instructions and for no other purpose. Beyond that, we disclose data only if the law requires it.
Our own access. We can reach shop data in order to operate and support the service. Most administrative actions are recorded in an audit log that includes who did it and the IP address they did it from. Not every one is yet — creating or changing a trial offer code is not audited today, and we would rather say so than imply a completeness we have not built. We do not sign in as you: there is no impersonation feature in the product, and Racketworks staff hold no membership in customer shops — that last one is how we work rather than something the software enforces.
Signing in, cookies, and bot protection
Signing in works by emailed six-digit code, or with Google if you choose it. Sessions are kept in cookies that exist to keep you signed in — we set no advertising or tracking cookies, which is why this site has no cookie banner. The visit counting described above sets no cookies either, which is what keeps that true. Signing in with an emailed code is checked by Cloudflare Turnstile, which examines the browser for signs of automation; we added it after a burst of automated sign-ups in July 2026. Continue with Google does not use it — there is no email for us to send, and Google runs its own checks.
Backups and how long we keep things
The database is backed up off-site every night; racket photos are backed up weekly, because they change far less often. Backups are encrypted before they leave our systems. We keep 30 nightly database copies and one per month for a year, and 12 weekly photo archives.The automated monthly restore test covers the database, not the photos. We would rather name that than let “we test our backups” cover both.
Backups exist to restore the service — and one other thing we should name: a copy of the database is also restored into a temporary, isolated scratch database to rehearse a change before it reaches production. That rehearsal is destroyed with the machine it ran on.
Otherwise we keep a shop's data for as long as the shop has an account, since the whole point of the product is that a player's history is not thrown away.
Seeing, exporting, or deleting your data
A player should ask their shop first — the shop holds the record and can change it directly. You can also write to hello@racketworks.tennis and we will handle it.
Being straight about this: a shop's owner or manager can export its records to spreadsheet files from inside the product, whenever they like. Deletion is still a manual process we carry out by hand, not a button, and we aim to complete requests within 30 days. Because backups are kept on the schedule above, a deleted record can still exist in an encrypted backup until those copies age out.
The demo shop
The demo at /demo is a single shared account that anyone can open, and everything in it is made up. It is wiped and rebuilt every night. Do not enter real people's details into it — anything typed there is visible to other visitors until the nightly reset.
Children
Racketworks is sold to businesses, and a shop account is meant for an adult running one.Nothing in the product checks that— there is no age question anywhere at sign-up — so this is what the service is for, not a control we enforce. A shop may well string for junior players and record their details, including a birth year; that record belongs to the shop, and the shop is responsible for having the right to hold it.
Where a junior could enter something themselves. A shop can invite a customer to an Equipment Journal, and whoever holds that login can fill in their own profile — which asks for a birth year among other things. The same is true of any form on the site that anyone can reach, such as sign-up or contact.
We do not verify anyone's age. We do ask for a birth year in a player's profile, and a shop can see the age it implies on their customer page — it is there so a stringer can judge a junior's racket, not so we can know who is a child. Deciding whether to give a junior a login, and whether a parent should hold it instead, is the shop's call and the shop's responsibility.
We do not advertise to anyone and we build no advertising or tracking profiles. A player's profile in the app is theirs and their shop's, and nothing in it is used for anything beyond showing them their own rackets and helping their shop do the work. If you are a parent or guardian and want a junior's record removed, contact the shop, or write to hello@racketworks.tennis and we will help.
Changes to this policy
When something material changes we will update the date at the top of this page, and we will tell shops directly if the change affects them. This page is written to describe the product as it actually is, so it changes when the product does.
Questions
Racketworks is an early-stage product and this is a plain-language policy rather than a lawyer's document. If anything here is unclear, or you want more detail about how your data is handled, email hello@racketworks.tennis.