California Privacy Notice
Business: JSB Holdings LLC, a Delaware limited liability company (“JSB Holdings”, “we”, “us”), operator of the Live Tennis API at livetennisapi.com (the “Service”). This notice is for California residents under the California Consumer Privacy Act as amended by the CPRA. It is the California companion to our Privacy Policy, and it says plainly where we do and do not have a clean answer.
1. Categories of personal information we collect
Using the CCPA’s own category names, over the last 12 months we have collected:
- Identifiers — your email address; the identifier of your Google or GitHub account if you sign in that way; account, API-key and Stripe customer/subscription identifiers; for affiliates, a name and a payout email; cookie and device identifiers set by our analytics and advertising tags. Affiliate fraud checks and referral-click records store a hashed IP address, not the address itself.
- Customer records (Cal. Civ. Code §1798.80(e)) — payment and payout details, held by Stripe; we keep the identifiers that point at them, and which tax form an affiliate has on file.
- Commercial information — the plan you bought, your subscription history, how many API calls and errors your key made each day, and the affiliate commission ledger.
- Internet or other electronic network activity — pages viewed, referrer, device and browser, the browser’s user-agent string on a referral click, and session replays and heatmaps (Microsoft Clarity, as described in Privacy Policy §2).
- Geolocation data — approximate, country- or region-level location inferred from your IP address by our CDN and analytics. We do not collect precise geolocation.
- Sensitive personal information — one item only: your account log-in credentials (your email address together with a hashed password, or your linked Google/GitHub identifier). We use them to authenticate you and for nothing else, which is a purpose §1798.121 permits without a further opt-out. We do not collect Social Security or government-ID numbers, precise geolocation, biometric or health data, racial or ethnic origin, religious beliefs, union membership, or the contents of your mail or messages.
We do not collect professional or employment information, education records, or biometric information, and we do not generate our own inferences or profiles about you.
2. Where it comes from
- From you — when you create an account, subscribe, configure alerts, join the affiliate programme, or email us.
- Automatically from your device — through our own site analytics, the CDN, and (outside the EU/EEA) the analytics and advertising tags described in §5.
- From our service providers — chiefly Stripe, for the billing and payout events that keep your subscription in step.
- From public sources — only for affiliate recruitment: the public contact detail of a creator we consider inviting.
3. Why we use it
To provide, secure, meter and bill the Service; to deliver the alerts you asked for; to prevent abuse and fraud; to answer support; to pay affiliates and meet the tax obligations that come with it; to measure our own marketing; and to comply with law. We do not use your personal information to train models about you, and we do not build cross-site profiles of our own.
4. Who we disclose it to
To service providers and contractors who process it for us under contract: Stripe (payments and payouts), Cloudflare (delivery, security, cookieless analytics), Google (Analytics 4, Google Ads), Microsoft (Clarity), PostHog (cookieless product analytics), Resend (email), Twilio (SMS and WhatsApp alerts, if you add such a channel), and our hosting provider. We also disclose personal information where the law requires it.
5. Selling and sharing — the honest answer
We do not sell personal information. No one pays us for your data and we run no data-broker arrangement.
We do, however, “share” it as the CPRA defines that word. For visitors outside the EU/EEA — which includes California — our pages load Google Ads conversion and remarketing tags and Microsoft Clarity. Passing identifiers and browsing activity to Google so that it can build remarketing audiences is cross-context behavioural advertising, and the honest label for it is sharing, not an exemption. So: we share identifiers and internet or other electronic network activity with Google (and Microsoft, for Clarity) for advertising and measurement. We do not share your account credentials, your billing details, your API usage, your alert endpoints, or anything else in §1.
We do not knowingly collect, sell or share the personal information of consumers under 16.
6. Your California rights
- Right to know — the categories and specific pieces of personal information we hold about you, where we got them, why we have them, and who we disclosed them to.
- Right to delete — deletion of what we hold, except what an exception in §1798.105(d) lets us keep (chiefly billing and tax records, and security records).
- Right to correct — correction of inaccurate personal information.
- Right to opt out of sharing — see §7 for what that means here in practice.
- Right to limit the use of sensitive personal information — the only sensitive information we hold is your log-in credential, used solely to sign you in, so there is no additional use to limit. Ask anyway if you want that confirmed in writing.
- Right to non-discrimination — exercising any of these changes nothing about your price, your plan, your rate limits or the support you get. Nothing in our systems treats a request as a signal.
- Authorized agents — you may use one; we will ask for written permission signed by you, and may still ask you to confirm the request directly.
7. How to exercise them — and what an opt-out really does
Email [email protected] with “California privacy request” in the subject and tell us which right you are exercising. We verify by matching the request to the email on the account, or by sending a confirmation email to it; for a right-to-know request about specific pieces of information we may ask you to confirm a detail only the account holder would know. We acknowledge within 10 business days and respond within 45 days, extendable once by a further 45 with notice. There is no charge, and you may make a free right-to-know request twice in any 12-month period.
On an opt-out request we stop using your information for advertising — including sending any conversion tied to your subscription to Google Ads — and we confirm when it is done. Be aware of what we cannot do from our side: the advertising and analytics tags run in your browser, and we do not currently detect a Global Privacy Control signal, so we will not pretend that an email switches them off in your browser. To stop the tags themselves, block third-party and advertising cookies for this site, use Google’s own My Ad Center controls, or use Microsoft’s privacy controls for Clarity. We would rather say this plainly than claim an opt-out mechanism we have not built.
8. How long we keep it
Account, API-key and daily usage records last as long as the account, then are deleted or anonymized once any legal, accounting or security need has passed. Billing, commission and payout records are kept for the period tax law requires. The one-time plaintext key shown after checkout is deleted the moment it is displayed. Analytics data follows each provider’s standard retention window. Support email is kept while the thread is useful.
9. Contact
California privacy requests and questions: [email protected] (JSB Holdings LLC). See also our Privacy Policy and our GDPR notice.
Last updated: 25 July 2026.