GDPR
Controller: JSB Holdings LLC, a Delaware limited liability company (“JSB Holdings”, “we”, “us”), operator of the Live Tennis API at livetennisapi.com and its subdomains (the “Service”). This page is the GDPR companion to our Privacy Policy: the same processing, described in the terms the GDPR uses — what we hold, on what lawful basis, for how long, and how to exercise your rights. If the two ever disagree, tell us and we will fix it.
1. Who we are
JSB Holdings LLC is the controller for personal data processed through the Service, including the developer portal, the documentation, the API itself and the affiliate portal. We are a small operation: privacy requests are read and actioned by the operator, at [email protected]. We have not appointed a Data Protection Officer, and we do not publish a postal address or phone number — email is the channel we answer.
2. What we actually hold
This is the concrete list, not a catch-all. If something is not here, we do not store it.
- Your account: your email address, and either a hash of your password or the identifier of the Google or GitHub account you sign in with; whether the address is verified; your plan tier; the account status and its dates.
- Your API key: a label, the first characters of the key, and an HMAC digest of it. The key itself is never stored — which is why we cannot show it to you a second time, and why a database leak would expose no usable credential. Keys issued on the free tier carry the email address you signed up with in the key’s label.
- How much you call the API: one row per key per day — the date, the tier, the number of calls and the number of errors. There is no per-request log of what you queried.
- Billing: your Stripe customer and subscription identifiers, and the invoice history Stripe keeps for us. Card details go straight to Stripe; we never see or store a card number.
- Break-point Alerts, if you use them: the delivery endpoints you add (a Telegram chat, a Discord webhook, an email address, or a phone number for SMS/WhatsApp), whether each is verified, and your alert filters.
- Webhooks, if you register them: the URL you gave us and the secret that signs deliveries to it.
- Affiliates: name, login email, payout email and method, which tax form is on file (the form itself is collected by Stripe, not by us), your Stripe Connect account identifier, your referral code, your commission and payout ledger, and — if you enable two-factor authentication — your TOTP secret. Fraud checks store a hash of the IP address you signed up from, never the address; a click on your referral link records the same hashed form plus the browser’s user-agent string.
- Attribution: if you arrive with a referral or advertising parameter (
?via=,gclid,utm_*and similar), we keep it in a first-party cookie for 30 days so that a resulting subscription is credited to the right affiliate or campaign. - Site analytics and session insights: as described in Privacy Policy §2 — pages viewed, approximate location, device and browser, and (outside the EU/EEA) masked session replays and heatmaps.
- Support: the messages you send us and our replies.
- Affiliate outreach: if we consider inviting you to the affiliate programme, we hold the public contact detail we found (an email address, a handle, or a profile URL), where we found it, and our own scoring notes. Anyone who opts out is recorded on a do-not-contact list so we do not reach out again.
We do not collect special-category data (health, biometrics, religious or political views, and the rest of Article 9), we do not store card numbers, we do not store plaintext API keys, and we do not store raw IP addresses in the affiliate tables.
3. Our lawful bases
- Performance of a contract (Art. 6(1)(b)) — creating your account, issuing and authenticating your API key, enforcing your plan’s limits, taking payment, delivering the alerts you configured, and answering your support requests.
- Legal obligation (Art. 6(1)(c)) — keeping invoice, accounting and tax records, including the records behind affiliate payouts.
- Legitimate interests (Art. 6(1)(f)) — keeping the Service running and un-abused (rate limiting, fraud checks, security), metering usage, measuring our own marketing in aggregate, and contacting creators about the affiliate programme. We keep the intrusion proportionate deliberately: hashed IPs instead of raw ones, a daily usage rollup instead of a request log, and cookieless measurement for EU/EEA visitors. You can object at any time (§4).
We do not ask EU/EEA visitors for analytics or advertising consent, because we do not set analytics or advertising cookies for them — see §5.
4. Your rights
- Access (Art. 15) — a copy of the personal data we hold about you.
- Rectification (Art. 16) — correction of anything wrong, such as a mistyped payout email.
- Erasure (Art. 17) — deletion of your account and its data. We keep what the law requires us to keep (invoice and tax records), and we keep a minimal do-not-contact entry so that an opt-out is not undone by a later import.
- Restriction (Art. 18) — pausing processing while an inaccuracy or objection is worked out.
- Portability (Art. 20) — your account details, key metadata, usage rollups and affiliate ledger in a machine-readable file.
- Objection (Art. 21) — to processing we base on legitimate interests, including affiliate outreach. An objection to direct marketing is absolute: we stop, without asking why.
- Withdraw consent (Art. 7(3)) — where we relied on consent, withdrawal is as easy as giving it and applies from that point forward.
- Complain (Art. 77) — to the supervisory authority where you live or work. We would rather you came to us first, but that is your right, not our permission.
Automated decisions. We make no decision about you by automated means alone that produces legal or similarly significant effects. Automated checks can place an affiliate account on hold, but a person reviews it before anything is refused, and you can ask us to explain a hold.
5. How to exercise them
Email [email protected] from the address on your account and say what you want. If we cannot tell that the request is yours, we will ask you to confirm control of the account email — we ask for no more identification than that. We answer within one month, and tell you if a complex request needs the extension Article 12(3) allows. It is free unless a request is manifestly unfounded or excessive.
There is no self-service delete button in the portal today: deletion is done by hand when you ask, and we confirm when it is finished.
6. Cookies
Cookies we set ourselves: the session cookie that keeps you signed in to the portal, and the 30-day first-party attribution cookie described in §2. Outside the EU/EEA, analytics and advertising cookies are also set (Google Analytics 4, Microsoft Clarity, Google Ads). Our stack is configured so that visitors in the EU/EEA receive only cookieless, aggregate measurement — which is why no cookie banner is shown to them. The tool-by-tool detail is in Privacy Policy §4–§5.
7. Processors
We share the minimum necessary with providers who process on our instructions: Stripe (payments, subscriptions, affiliate payouts and their tax forms), Cloudflare (content delivery, security, cookieless web analytics and tag loading), Google (Analytics 4 and Google Ads), Microsoft (Clarity session replays and heatmaps), PostHog (cookieless product analytics, served first-party through our own domain), Resend (transactional and alert email), Twilio (SMS and WhatsApp alerts, only if you add such a channel), and our hosting provider. If you choose a Telegram or Discord alert channel, delivery goes through those platforms under their own terms.
8. International transfers
We and most of these providers operate in the United States. Where personal data of people in the EU/EEA or the UK is transferred there, the transfer relies on the safeguards in each provider’s data-processing terms — chiefly the European Commission’s standard contractual clauses.
9. Retention
- Account, API key and usage rollups — for as long as the account exists, then deleted or anonymized once any legal, accounting or security need has passed.
- The one-time key reveal — the plaintext key shown once after checkout lives in a buffer for seconds to minutes and is deleted the moment it is displayed.
- Billing, commission and payout records — kept for the period tax and accounting law requires.
- Support email — for as long as it is useful to the thread it belongs to.
- Analytics — per each provider’s standard retention window.
10. Children
The Service is a developer product, not directed to children, and we do not knowingly collect personal data from anyone under 16.
11. Changes
We may update this page; material changes are reflected in the date below and, where it matters, by notice to subscribers.
12. Contact
Data-protection questions and rights requests: [email protected] (JSB Holdings LLC). See also our Privacy Policy and California privacy notice.
Last updated: 25 July 2026.