Effective date: September 6, 2026
Applies to: BowlersDash for iOS and macOS, published by Comet Innovations, LLC.
Summary
BowlersDash is designed so that your data stays yours. League data you enter is stored on your device and synced privately through your own iCloud account using Apple's CloudKit framework. If you invite bowlers to follow a league, a redacted copy of that league — names, scores, and standings, but no financial detail — is shared through CloudKit so they can see where they stand; see 2.2. We don't run analytics on the app, don't use third-party trackers, and never sell your data. The only services that receive anything are the two listed in Sharing and disclosure.
The only personal information we receive about you is what Apple relays when you use Sign in with Apple to create an account, and anything you choose to send us — a support email, or a note through the app's feedback form, which is submitted anonymously. See 2.6 In-app feedback.
If you run a league, you'll also enter information about your bowlers — some of whom may be minors. That data stays yours to control and is used only to run your league. See Children's privacy.
1. Who we are
BowlersDash is published by Comet Innovations, LLC ("Comet Innovations," "we," "us," "our"), a California limited liability company located at 1807H Santa Rita Rd Ste 266, Pleasanton, CA 94566. You can reach us about privacy at privacy@cometinnovations.com.
2. Information we collect
2.1 Account information (Sign in with Apple)
Sign in with Apple is the only way to create a BowlersDash account, and creating one is optional — you can choose "Continue without signing in" and use the app as a guest. Bowlers and league officers use the same optional account.
When you do sign in, Apple provides the app on your device with:
- A stable, anonymous user identifier (so the app can recognize you across sessions and devices).
- If you choose to share your email, either your real email address or a private relay email Apple controls. We don't see your real email if you choose to keep it private.
- Optionally, your first and last name as you choose to provide them.
That account record is stored the same way as your league data — locally on your device using Apple's SwiftData framework, and in your own private iCloud account via CloudKit when iCloud sync is available. BowlersDash does not operate an account server: we keep no copy of your identifier, email, or name, and we cannot look up or access your account. Signing out and deleting your account both happen on your device.
We don't collect your Apple ID, password, or any other Apple account information. Apple's privacy practices for Sign in with Apple are governed by Apple's Privacy Policy.
2.2 League and bowler data you enter (including youth bowlers)
As you use the app, you may enter information including: league names, team and bowler names, scores, schedules, payment records, and notes. This information is stored:
- Locally on your device using Apple's SwiftData framework.
- In your private iCloud account via Apple's CloudKit framework, when iCloud sync is available.
Sharing a league with your bowlers. Those two places are the whole story until you invite bowlers. When you generate an invite code for a league — the code, QR, or link you hand out so bowlers can follow along — BowlersDash begins publishing a redacted copy of that league to a shared area of Apple's CloudKit, separate from your private iCloud. Anyone holding that league's invite code can read that copy, and it refreshes automatically as you enter scores and record payments. A league you never generate an invite code for is never published.
The league-wide copy — the one any invite-code holder can read — is deliberately narrow. It includes the league's name and schedule, team and bowler names, scores, standings, and starting averages — what a bowler needs to see where they stand. Before it is written, BowlersDash strips out every bowler's financial detail: starting balances, payment history, membership-card status, and each bowler's personal access code. It also strips the gender field, which is used only in your own officer tools and would be personal information on the shared copy for no benefit.
Where each bowler's money detail goes. Keeping that detail out of the league-wide copy does not mean it stays on your device. BowlersDash publishes each bowler's financial detail to that same shared area, as a separate per-bowler record containing their starting balance, what they have paid each week, whether they owe a membership-card fee, and any officer credit or end-of-season settlement applied to them. What keeps one bowler out of another's record is where it is filed: each record is stored under a long, unguessable name derived from that bowler's own personal access code. The app can only fetch a record whose code it already holds, and gives no way to browse or list them, so holding a league's invite code does not let someone read the league's finances. But the code is the whole key — anyone who learns a bowler's personal access code can read that bowler's financial record. Treat those codes like passwords and give each one only to the bowler it belongs to. Deleting a league removes the league-wide copy and those per-bowler records.
BowlersDash is a tool for the adult volunteer who runs a league — the treasurer or league officer. Some of the bowlers whose names, scores, and dues you record may be minors (for example, in youth or junior leagues). That information is entered and controlled by you, the adult league operator; you are responsible for having the authority and any consent needed to record it. BowlersDash stores and processes it solely to run the league on your behalf — calculating standings, tracking who owes what, and showing each bowler their own scores and balance. We never use bowler information, including any about minors, for advertising, profiling, or any purpose beyond operating the league. See Children's privacy below.
Today: the league and bowler data described above syncs through Apple's CloudKit and nowhere else. It is not sent to Supabase or any other third-party backend. The one place a third-party backend is involved today is the app's feedback form: if you choose to submit feedback, that submission goes to a database we operate with Supabase. No scores, standings, payment records, or bowler rosters go with it — see 2.6 In-app feedback for the exact list of what a submission contains.
Later: a future post-launch release will introduce server-backed sync via Supabase — primarily to enable shared league data across devices and users (officers, bowlers, and centers viewing the same league). We will update this Privacy Policy — and notify you in-app — before your league and bowler data begins flowing to Supabase.
2.3 Information we do NOT collect
- We do not use third-party analytics (no Google Analytics, no Mixpanel, no Amplitude, etc.).
- We do not use third-party advertising SDKs.
- We do not collect your location.
- We do not access your contacts, photos, microphone, or camera unless a future feature explicitly requests permission.
- We do not collect device identifiers for tracking purposes.
One clarification, so you don't have to wonder: the app version, build, device type ("iPhone" or "Mac"), and OS version that ride along with a feedback submission (see 2.6) are coarse technical details — the same information any app can read about the platform it runs on. They are not advertising IDs, device fingerprints, or tracking identifiers, they are not tied to your account, and we use them only to reproduce the problem you reported.
2.4 Payments and in-app purchases
BowlersDash 1.0 has no in-app purchases. The App Store build ships with no purchase path in it at all — there is no paywall, nothing to buy, and no feature held back behind a purchase. We therefore collect and receive no payment information of any kind: no card details, no billing address, and no transaction records.
The dues and payments you track for your league are a separate thing, and it is worth being clear about the difference. Those are bookkeeping entries you type in — who owes what, who has paid — and no money moves through BowlersDash. You collect from your bowlers however you already do, in cash or through a payment app of your own choosing, and the app just keeps the ledger. Those records are stored and shared exactly as 2.2 League and bowler data describes.
If paid upgrades are introduced in a later release, payment processing will be handled entirely by Apple through StoreKit: we would never see your card information, billing address, or other payment details, and would receive only the transaction confirmations needed to unlock what you bought. We will update this Privacy Policy — and notify you in-app — before that happens.
2.5 Push notifications
BowlersDash schedules local notifications on your device — for example, reminders before bowling time. These notifications are generated and displayed entirely on your device; they do not involve any server.
When you follow a league as a bowler, the app also registers a silent push subscription with Apple's CloudKit for that league, so your standings and balance refresh when your league officer posts an update. The subscription is held by Apple under your own iCloud account. It carries no message and displays nothing — it only tells the app that new data is waiting — and it is removed when you leave the league (see 2.7). We operate no push server of our own, and we never send you marketing notifications.
2.6 In-app feedback
BowlersDash includes a feedback form you can use to report a bug or ask for a feature. Nothing is sent unless you open that form and submit it. When you do, the submission goes to a Postgres database we operate with Supabase, Inc., hosted in the United States — the one third-party backend BowlersDash uses today.
A submission contains:
- The message you write and the category you choose.
- Your role in the app — for example, treasurer or bowler.
- The name and internal ID of your league, so we can look at the problem in the right context and reproduce it.
- Basic version and device details: the app's version and build number, the device type ("iPhone" or "Mac"), and the OS name and version.
Just as importantly, here is what a submission does not contain:
- No account identity. Feedback is submitted anonymously — your Sign in with Apple identifier, name, and email address are not attached to it.
- No league records. No scores, standings, schedules, payment or dues records, and no bowler roster are sent — only the fields listed above.
The feedback database is write-only from the app: the app can add a submission and nothing more. Reading, editing, and deleting are not permitted with the app's key, so no one holding it can pull anyone's feedback back out. Only Comet Innovations can read feedback, through the Supabase administrative dashboard, and we use it only to diagnose and fix what you told us about.
Because a submission carries no account identifier, it is not linked to your account — there is nothing in it that identifies you personally, and deleting your account does not remove feedback you previously sent. If you want a specific submission removed, email privacy@cometinnovations.com with enough detail for us to find it.
2.7 Following a league as a bowler (links, QR codes, and invite codes)
Your league officer can send you a link — or a QR code, or a short code you type in — that opens BowlersDash directly to your own scores, standings, and balance. You do not need a BowlersDash account to use it, and following one does not create an account for you. There is no sign-up, no password, and no email address to hand over.
When you follow it, the app checks the two codes it carries — one identifying the league, one identifying you — against the league your officer has already shared (see 2.2). It then saves a small record on your own device so it can bring you back to that league next time. That record holds the league's name and ID, your bowler ID, the league's invite code, your personal access code, and the date you joined. It lives in the app's own storage on your device, it is not synced to iCloud, and it is the same record the QR-code and typed-code paths have always saved.
That device-local record is the only thing following a link writes. Your view of the league is read-only: you cannot change scores, standings, or any payment record, and nothing you do in it is written back to your league officer's books. No personal information about you is collected, and none of it comes to us — the exchange is between your device and Apple's CloudKit.
How to remove it. Open Settings from your league view and tap Leave League. That deletes the device-local record described above and cancels the silent push subscription described in 2.5. You can follow the link again later, or rejoin with the invite code, whenever you like. Because that record only ever existed on your device, there is nothing on our side to delete and nothing for us to look up.
3. How we use information
- To authenticate your account so we can identify your data across your devices.
- To sync your league data to your own iCloud and back.
- To respond to support requests you initiate.
- To diagnose and fix issues you report — reproducing the bug you described in a feedback submission, and weighing the feature requests we receive.
We don't use your information for marketing, profiling, or any purpose other than operating the app for you.
4. Sharing and disclosure
We don't sell, rent, or trade your personal information. Two third-party services are involved in the operation of BowlersDash, and here is exactly what each one receives:
- Apple Inc. — Sign in with Apple (the account identifier, and your email and name if you share them), CloudKit/SwiftData sync (your league and bowler data, held in your own private iCloud account, plus the redacted shared copy of any league you've given an invite code, and the silent push subscriptions that keep bowlers' views current — see 2.2 and 2.5), the App Store, and standard iOS/macOS frameworks. No payment information is involved: BowlersDash 1.0 has nothing to buy in it, so there are no purchases and no transaction records — see 2.4.
- Supabase, Inc. — hosts the database that receives in-app feedback submissions, and nothing else. It receives only your message and category, your role, your league's name and ID, and app and OS version details. It does not receive your account identity, your scores, your dues or payment records, or your bowler roster, and it is not part of league or bowler sync — that path is CloudKit-only.
When the future server-backed sync release described in section 2.2 ships, Supabase's role will expand to shared league data. We will update this list and notify you in-app before that happens.
We may disclose information if required to do so by law, valid legal process, or to protect against fraud or harm.
5. Children's privacy (COPPA)
BowlersDash is intended for the adults who manage bowling leagues, and is not directed to children. We do not knowingly collect personal information from anyone under 13. A BowlersDash account is optional and is created only through Sign in with Apple; as described in Account information, it exists only on the user's own device and in their own private iCloud account, and we hold no copy of it.
Because leagues include youth bowlers, an adult league operator may enter information about bowlers who are minors — such as their name, scores, and dues owed. That information is provided and controlled by the adult operator, who is responsible for any parental consent required. BowlersDash acts only to store and process it for the operator, and never uses it for advertising or profiling.
One consequence an operator should understand before inviting bowlers: if you generate an invite code for a league, the redacted copy described in 2.2 includes bowler names, scores, and standings — including those of any minors on your roster — and can be read by anyone holding that league's invite code. Financial details, personal access codes, and the gender field are kept out of that league-wide copy; as 2.2 explains, each bowler's financial detail is published separately, reachable only with that bowler's own personal access code. Treat the invite code as you would a key to your league, share it only with people who should see the roster, give each bowler's personal access code only to that bowler or their parent or guardian, and delete the league if you want the shared copy removed.
If you are a parent or guardian and want a minor's information removed, contact the operator of that league (who controls the data), or email us at privacy@cometinnovations.com and we will work to have it removed. If a child under 13 has created a BowlersDash account, it can be deleted in the app at any time — see Delete your account. Because that account lives only on the device and in the user's own private iCloud, there is no copy on our side for us to delete for you.
6. Your rights
6.1 California (CCPA / CPRA)
California residents have the right to know what personal information a business has collected about them, to have it deleted or corrected, and to opt out of its "sale" or "sharing." We do not sell or share personal information, and we never have — there is no opt-out to file, because there is nothing to opt out of. We will not discriminate against you for exercising any of these rights.
What we hold is close to nothing, and that changes what these rights look like in practice. BowlersDash 1.0 operates no account server. Your account record, and the league and bowler data you enter, live on your device and in your own private iCloud — see 2.1 and 2.2. We keep no copy. For that information there is nothing on our side to disclose, correct, or delete, and no lookup we could run even if you asked us to. You exercise those rights yourself, in the app, and deletion takes effect immediately: see Delete your account.
Why we do not ask you to verify your identity. A business that receives a rights request is normally expected to confirm the requester is who they say they are. We have nothing to check you against: we hold no email address, no name, and no identifier tied to your account, so there is no record an inbound message could be matched to. We are not going to ask you to prove an identity we could not verify, and we are not going to collect identifying information from you for the sole purpose of running that check — that would mean holding more about you than we do now, not less. So we do not require it.
The two things we can actually act on:
- In-app feedback. Feedback you submit is the one category of personal information we hold ourselves, in a database we operate with Supabase. It is submitted anonymously — no name, email address, or account identifier is attached — so we cannot find "your" submissions by looking you up. To have one disclosed or deleted, email privacy@cometinnovations.com and describe it well enough for us to locate it: roughly when you sent it, the category you chose, and the league name it carried. See 2.6.
- A published league copy. If your league officer generated an invite code, a redacted copy of that league — bowler names, scores, and standings — is published to a shared area of Apple's CloudKit, along with the per-bowler financial records described in 2.2. That data is entered and controlled by your league officer, not by us; we process it to run the league on their behalf. Ask your league officer first, since deleting the league in the app removes those copies. If you cannot reach them, email us and we will work to have it removed.
If you send us a request we cannot act on — because the information is not something we hold, or not something we hold in a form linked to you, or because we cannot confirm it is yours — we will tell you that plainly and explain why, rather than leave it unanswered. You may also designate an authorized agent to make a request on your behalf.
6.2 European Economic Area, U.K., and Switzerland (GDPR / UK GDPR)
If you are in the EEA, U.K., or Switzerland, you have rights of access, rectification, erasure, restriction, portability, and objection regarding personal data we control about you. Our legal basis for processing is your consent (when you sign in) and our legitimate interest in operating the app. You may also lodge a complaint with your local data-protection authority.
6.3 Account deletion
You can delete your account at any time, in the app, and it takes effect immediately. See how to delete your account for the steps and for what deletion does and doesn't remove.
7. Data retention
Your account record is retained on your device, and in your own private iCloud when sync is available, for as long as the account exists. Deleting the account in the app removes that record immediately, and from your other signed-in devices as iCloud syncs. Because we hold no copy of it, there is no deletion window on our side to wait out and nothing for us to delete — see 2.1 Account information. There are no purchase or transaction records to retain either, because version 1.0 has nothing in it to buy — see 2.4.
Feedback submitted through the app sits outside that cycle: because it carries no account identifier, it isn't tied to your account and isn't removed when you delete your account. We keep it for as long as it's useful for diagnosing and fixing the issue reported. See 2.6 In-app feedback.
8. Security
Data on your device is protected by iOS/macOS standard data protection. Data synced through CloudKit is encrypted in transit and at rest under Apple's standard CloudKit security model. Feedback you submit is sent over HTTPS to our Supabase-hosted database, where the access rules let the app add a submission and nothing else — reads, edits, and deletions are not permitted with the app's key. When server-backed sync via Supabase ships, that data will likewise be transmitted over HTTPS and stored with industry-standard encryption at rest.
9. International data transfers
If you are located outside the United States, the infrastructure BowlersDash relies on — Apple's, and the Supabase-hosted database that receives in-app feedback — may transfer and process your data in the United States and other regions. Our feedback database is hosted in the United States. By using BowlersDash, you consent to those transfers.
10. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The effective date above will reflect the most recent version. Material changes will be flagged on this page and on the BowlersDash App Store listing.
September 6, 2026 — rewrote 6.1, which asked California residents to email us "from the email address associated with your BowlersDash account." No such address exists on our side — 1.0 has no account server — so that request described an identity check we cannot perform, against a record we do not hold. The section now says what we actually hold (almost nothing), why we therefore ask you to verify nothing, and which two categories — in-app feedback, and a league copy published by your league officer — we can act on.
September 6, 2026 — corrected section 7 and 6.3, which stated that we delete your account data within 30 days. There is no such window, because there is no copy on our side to delete: the account record lives on your device and in your own private iCloud, and deleting it in the app takes effect immediately — see 2.1 Account information. The account deletion page was rewritten for the same reason; it had described a server-side deletion process, an identity check, and a confirmation email, none of which exist.
September 6, 2026 — corrected 2.4, which described a freemium model with in-app purchases. Version 1.0 ships with no purchase path, so there is no payment information to collect; the section now says so and describes what would apply if paid upgrades are introduced later. Removed in-app purchase processing from the list of things Apple handles in section 4, and the Apple-transaction-records carve-out from the retention rules in section 7.
September 5, 2026 — added 2.6 In-app feedback and named Supabase, Inc. as a third-party processor for feedback submissions in section 4. League and bowler sync remains CloudKit-only.
September 5, 2026 — added 2.7, covering how a bowler follows a treasurer's link, QR code, or invite code without creating an account, what is stored on their device, and how to remove it. Described in 2.2 what an invited league's redacted shared copy contains and what is stripped from it, added that each bowler's financial detail is published to that same shared area as a separate record reachable only with that bowler's personal access code, and noted the roster implications for youth leagues in section 5. Corrected 2.5, which previously stated that the app used no remote push notifications: bowlers' league views are refreshed by silent CloudKit push subscriptions.
11. Contact
Questions about this Privacy Policy or how BowlersDash handles your data:
- Email: privacy@cometinnovations.com
- Mail: Comet Innovations, LLC, 1807H Santa Rita Rd Ste 266, Pleasanton, CA 94566, USA