逐秒 Sport Timer

Privacy Policy

Service operator: 殞落天使
Contact: jenglue@gmail.com
Effective / updated:

This policy applies to the Sport Timer website operated by the operator identified on this page. Independently hosted installations have their own operators and do not automatically send data to the open-source author.

1. Data collected and purposes

2. Camera, files and Google data

Camera use requires your permission. Frames are decoded in the browser; the application does not record or upload video or camera images. Only decoded barcodes and related scan data are recorded. Uploaded Excel/CSV files are sent to the server and parsed into rosters; the application does not separately retain the original uploaded files.

Google user data is used only for the authentication, account and service functions described here. It is not sold or used for advertising, personalized advertising or training general-purpose AI models. This version contains no advertising trackers or analytics SDKs.

3. Access and sharing

Authorized group members can view their group's rosters and event records; group managers can maintain data, and system administrators manage accounts and data across the service. People authorized to add group members can see candidate account emails. Authorized users can export reports and are responsible for downloaded copies.

Microsoft Azure hosts and stores data, Google Identity Services supplies sign-in, and the application interface requests Google Fonts. Providers process data under their own terms and privacy policies, potentially across borders. Azure storage location depends on the operator's deployment. Necessary information may also be disclosed to meet legal requirements or address security incidents. See Google's Privacy Policy and the Microsoft Privacy Statement.

4. Cookies, device storage and security

The service uses an essential sign-in cookie (up to seven days, HttpOnly, Secure and SameSite=Strict), IndexedDB and offline caches. Signing out removes the sign-in cookie and locally stored signed-in user, but does not automatically erase pending scans, cached rosters or other offline data. The server checks account and group access on each protected request. Fully offline devices cannot immediately receive revocation notices.

Protect your device, avoid shared browser accounts and grant access only as needed. No system can guarantee absolute security.

5. Retention and deletion

Active accounts, records and rosters remain until the operator or authorized users remove them as needed. Ordinary deletion enters a 30-day trash period. Restoration stops at expiry; daily jobs then purge data in batches. Failed jobs may delay physical removal. Minimal purged identifiers remain to prevent delayed offline uploads from recreating deleted data, without retaining that record's barcode, name or scan time. Removing an account does not delete its historical activity records.

Locally rejected scans do not automatically expire. Export necessary backups before clearing site data through your browser. Clearing removes unsynchronized records that the server cannot recover. Operator backups, diagnostics and exported files have separate retention lifecycles; contact the operator about scope and deletion arrangements.

6. Choices and data requests

You can decline camera permission and use manual input, stop using the service, or manage authorization in Google account connections. Revoking Google authorization does not automatically erase existing service records or immediately invalidate an already issued service session; ask the operator to disable access if needed.

For access, copies, corrections, deletion or other rights under applicable law, follow Contact and data deletion. The operator must reasonably verify identity, others' rights and legal retention duties. There is no one-click feature that deletes every historical record associated with an account.

7. Participants and changes

Organizers must provide appropriate notice and obtain authorization required by applicable law before uploading data about others, including minors. Do not upload sensitive information unrelated to timing. Policy changes update the date on this page. Before accessing new types of Google data or changing their use, the operator must update the policy, notify users and obtain required consent under the Google API Services User Data Policy. Other material changes must also be addressed under applicable law.