TIFOXR WEBSITE PRIVACY POLICY

Last Updated:  August 21, 2026

1. Scope

This TifoXR Privacy Policy ("Policy") explains how Global Mobile Software LLC ("GMS," "we," "us," or "our") collects, uses, discloses, and protects information through the TifoXR website, TifoXR Immersive, TifoXR 3D Streaming, TifoXR CMS, and related TifoXR product environments. 

Some TifoXR deployments are provided in cooperation with a club partner. In those cases, the club partner may have its own privacy notice, may control certain fan data, or may provide GMS with instructions regarding processing. A club-specific privacy notice may supplement this Policy. 

This Policy should be read together with the applicable TifoXR Terms of Use, Product Terms, Cookie Policy, Acceptable Use Policy, and other applicable product-specific policies. 

2. Roles

Depending on the feature, deployment, and club arrangement, GMS may act as: 

an independent controller for GMS-operated accounts, platform operations, security, analytics, product improvement, and business communications;

a processor or service provider when processing fan or club-staff personal information on behalf of a club partner;

a joint or separate controller where GMS and a club partner jointly determine certain purposes and means of processing, and/or another legally recognized role depending on the applicable deployment and governing privacy law; and

in club-specific deployments, users may also be directed to the relevant club partner as the local privacy contact for certain processing activities.

EU/EEA and UK Representative (Article 27 GDPR):

Global Mobile Software LLC has appointed Data Protection Representative Limited (trading as DataRep) as its EU Representative at 77 Camden Street Lower, Dublin D02 XE80, Ireland and its UK Representative at 107-111 Fleet Street, London EC4A 2AB, UK.

Contact: tifoxr@datarep.com

Website: https://www.datarep.com/tifoxr

3. Information We Collect

We may collect the following categories of information, depending on your use of the TifoXR Services: 

Account information, such as name, username, email address, authentication identifiers, login status, security and session tokens, profile information, club affiliation, and account preferences. 

Guest and access information. Some TifoXR experiences may be accessible on a guest or anonymous basis, while other features require login or a registered account. 

Device and technical information, such as IP address, device type, browser, operating system, device identifiers, language settings, crash logs, diagnostics, and network information.  

Location information, such as approximate location inferred from IP address and, if enabled and permitted, more precise location data.

Usage and analytics information, such as pages viewed, content accessed, interactions, session duration, clicks, streaming quality, engagement metrics, conversion metrics, and platform logs.

XR and sensor-related information, such as device orientation, movement, interaction events, session telemetry, and other data generated by immersive or 3D experiences where such functionality is enabled. 

Content information, including text chat, usernames, avatars, reactions, friend requests, live voice or audio where enabled, and materials uploaded or submitted by authorized club personnel, administrators, CMS users, or other users where a feature specifically permits such submissions. 

Commerce information, such as transaction identifiers, purchase history, subscriptions, refunds, chargebacks, and payment status. Payment card or wallet details may be processed by third-party payment processors and may not be stored by GMS. 

Communications, such as support requests, feedback, surveys, live audio, and messages.

Cookies and similar technologies, as described in the applicable Cookie Policy. 

SSO and CRM information, including account, identity, or access-related information received from club-managed single sign-on systems, customer relationship management platforms, or related third-party identity providers used in connection with a club deployment. 

4. Sources of Information

We may collect information: 

  • directly from you;

  • automatically from your device or interaction with the TifoXR Services;

  • from club partners;

  • from payment processors;

  • from identity and authentication providers;

  • from analytics providers;

  • from support vendors; and

  • from other service providers used to operate the TifoXR Services.

In some club-specific deployments, we may also receive information from club-managed CRM systems, single sign-on providers, or other club-authorized identity and access tools. 

5. How We Use Information

We may use information to:

  • provide, operate, maintain, and secure the TifoXR Services;

  • create and manage accounts;

  • authenticate users and prevent unauthorized access;

  • review, moderate, and manage user-generated content and reported content;

  • detect and prevent abusive, unlawful, or harmful activity;

  • process and respond to content notices, abuse reports, and other user submissions;

  • deliver fan-facing experiences, streaming, immersive content, CMS workflows, and club-specific features;

  • process purchases, subscriptions, refunds, credits, and transaction records;

  • provide support and respond to inquiries;

  • provide language, region, and club-specific functionality;

  • measure engagement, performance, revenue attribution, and conversion metrics for TifoXR and applicable business partners;

  • analyze, debug, improve, and develop the TifoXR Services;

  • send service messages, security notices, updates, and marketing communications where permitted;

  • protect GMS, users, club partners, rights holders, and the public;

  • comply with applicable legal obligations, including applicable Digital Services Act requirements; and

  • establish, exercise, or defend legal claims and enforce applicable agreements.

6. Content Moderation and Automated Processing 

TifoXR may use automated tools to assist with content moderation.

Hive.ai is currently used for text chat moderation to detect categories of potentially abusive or harmful content, including toxicity, hate, harassment, self-harm, and sexual content. Depending on the applicable configuration, the system may prevent an abusive text message from being sent.

Voice chat, where enabled, is live and is not currently transcribed or subject to automated AI moderation by GMS. Additional voice moderation technology may be introduced for particular future deployments.

GMS does not use facial recognition or biometric identification for TifoXR's current content-moderation process.

Where content is reported or otherwise requires review, GMS may conduct human review in accordance with applicable TifoXR policies and law.

7. Legal Bases for Processing

Where laws such as the GDPR or UK GDPR apply, we may rely on one or more legal bases, including:

  • performance of a contract;

  • legitimate interests;

  • consent;

  • compliance with legal obligations;

  • protection of vital interests; and

  • tasks carried out in the public interest, where applicable.

The specific legal basis may depend on the feature, user location, club deployment, data category, and applicable law.

8. How We Disclose Information

We may disclose information to:

  • club partners, where necessary for club-specific deployments, fan engagement, support, analytics, transactions, or rights administration;

  • service providers and subprocessors, such as hosting, CDN, analytics, payment, authentication, communications, customer support, security, and infrastructure providers;

  • payment processors and app platforms, to process transactions and manage subscriptions;

  • rights holders and content partners, where necessary to operate licensed or club-specific experiences;

  • professional advisers, such as lawyers, accountants, auditors, insurers, and security consultants;

  • authorities, regulators, courts, and law enforcement, where required or permitted by law; and

  • transaction parties, in connection with a merger, financing, acquisition, reorganization, or sale of assets.

Current or anticipated service providers may include Microsoft Azure, Microsoft Identity Platform, Microsoft Fabric, PayPal, Stripe, Evercoast, Hive.ai, and other vendors used to operate, secure, analyze, or improve the TifoXR Services.

9. International Transfers

GMS is based in the United States. Information may be processed in the United States and other countries.

Where required by applicable law, GMS will use appropriate safeguards for cross-border transfers, which may include contractual commitments, data-processing agreements, standard contractual clauses, or other lawful transfer mechanisms.

Based on the current implementation, TifoXR data is hosted in Microsoft Azure regions located in the United States, although hosting architecture may change over time.

10. Cookies, SDKs, and Similar Technologies

We may use cookies, SDKs, local storage, pixels, device identifiers, analytics, and similar technologies.

Some technologies are necessary to provide and secure the TifoXR Services. Others may support analytics, functionality, personalization of the user experience, or performance measurement.

TifoXR may also display advertising or sponsored content managed through the TifoXR CMS. Advertising may include images or videos uploaded by authorized club personnel.

TifoXR advertising is not targeted based on user data or user profiling. Ads are intended to be shown consistently to users within the applicable space, and sensitive personal data is not used for advertising purposes.

Where required by applicable law, GMS will obtain consent before using non-essential cookies or similar technologies.

Further information about cookies and similar technologies is provided in the applicable Cookie Policy.

11. Children and Minors

The TifoXR Services are meant for users above 13.

Where applicable, TifoXR may apply age-related controls or requirements before permitting access to certain features or experiences.

If we learn that we collected personal information from a child under 13 without required consent, we will take appropriate steps to delete the information or obtain legally valid consent, as required by applicable law.

TifoXR does not use targeted advertising to minors.

12. Biometric, Camera, Microphone, and Sensitive Data

Certain immersive or device-enabled features may involve camera, microphone, motion, face, body, hand, eye, or other sensor-based data where those capabilities are enabled.

GMS will not intentionally collect biometric identifiers or biometric information unless the relevant feature is disclosed and legally required consent, retention, and deletion measures are implemented.

Current TifoXR versions may include immersive and 3D features but are not currently intended to operate on a headset unless and until GMS enables that functionality in a later version.

Where microphone or voice functionality is enabled, live voice or audio may be processed to provide the relevant communication feature. Voice is not currently transcribed or automatically moderated by AI.

13. Data Retention

We retain information for as long as reasonably necessary for the purposes described in this Policy, including to provide the TifoXR Services, maintain accounts, comply with legal obligations, resolve disputes, enforce agreements, and maintain security.

Retention periods may vary by deployment, data category, processing purpose, and club partner.

Certain categories of data, such as user metrics data, may currently be retained for up to seven (7) years.

Where a specific retention period applies to a particular category of information, the applicable product or club-specific privacy notice may provide additional details.

14. Security

We use reasonable administrative, technical, and physical safeguards designed to protect information. These may include access controls, encryption, monitoring, logging, vendor diligence, and incident-response procedures.

No system is completely secure, and we cannot guarantee absolute security.

15. Your Rights and Choices

Depending on your location and applicable law, you may have rights to request:

  • access to personal information;

  • correction of inaccurate information;

  • deletion of personal information;

  • portability of personal information;

  • restriction of processing;

  • objection to certain processing;

  • withdrawal of consent where processing is based on consent;

  • opt-out of certain sales or sharing of personal information;

  • opt-out of certain targeted advertising or similar uses, where applicable; and

  • review or appeal of certain privacy decisions, where required by applicable law.

To make a privacy request, contact compliance@globalmobisoft.com or another designated privacy contact.

We may need to verify your identity before responding. Where a club partner controls the relevant personal information, we may refer your request to the applicable club partner or assist in coordinating the request as appropriate.

16. Marketing Choices

You may unsubscribe from marketing emails by using the unsubscribe link provided in the communication or by contacting us.

We may still send non-marketing messages, including service, transactional, security, legal, or account notices.

17. Changes to This Policy

We may update this Policy from time to time.

If changes are material, we will provide notice as required by applicable law.

The "Last Updated" date will indicate when this Policy was most recently revised.

18. Contact

Privacy questions and requests may be sent to:

compliance@globalmobisoft.com

For matters concerning GMS's EU or UK representation:

Data Protection Representative Limited (DataRep)

EU Representative:
77 Camden Street Lower
Dublin D02 XE80
Ireland

UK Representative:
107-111 Fleet Street
London EC4A 2AB
United Kingdom

Contact: tifoxr@datarep.com

Portal: https://www.datarep.com/tifoxr