TIFOXR WEBSITE PRIVACY POLICY
Last Updated: August 21, 2026
1. Scope
This TifoXR Privacy Policy ("Policy") explains how Global Mobile Software LLC ("GMS," "we," "us," or "our") collects, uses, discloses, and protects information through the TifoXR website, TifoXR Immersive, TifoXR 3D Streaming, TifoXR CMS, and related TifoXR product environments.
Some TifoXR deployments are provided in cooperation with a club partner. In those cases, the club partner may have its own privacy notice, may control certain fan data, or may provide GMS with instructions regarding processing. A club-specific privacy notice may supplement this Policy.
This Policy should be read together with the applicable TifoXR Terms of Use, Product Terms, Cookie Policy, Acceptable Use Policy, and other applicable product-specific policies.
2. Roles
Depending on the feature, deployment, and club arrangement, GMS may act as:
• an independent controller for GMS-operated accounts, platform operations, security, analytics, product improvement, and business communications;
• a processor or service provider when processing fan or club-staff personal information on behalf of a club partner;
• a joint or separate controller where GMS and a club partner jointly determine certain purposes and means of processing, and/or another legally recognized role depending on the applicable deployment and governing privacy law; and
• in club-specific deployments, users may also be directed to the relevant club partner as the local privacy contact for certain processing activities.
EU/EEA and UK Representative (Article 27 GDPR):
Global Mobile Software LLC has appointed Data Protection Representative Limited (trading as DataRep) as its EU Representative at 77 Camden Street Lower, Dublin D02 XE80, Ireland and its UK Representative at 107-111 Fleet Street, London EC4A 2AB, UK.
Contact: tifoxr@datarep.com
Website: https://www.datarep.com/tifoxr
3. Information We Collect
We may collect the following categories of information, depending on your use of the TifoXR Services:
• Account information, such as name, username, email address, authentication identifiers, login status, security and session tokens, profile information, club affiliation, and account preferences.
• Guest and access information. Some TifoXR experiences may be accessible on a guest or anonymous basis, while other features require login or a registered account.
• Device and technical information, such as IP address, device type, browser, operating system, device identifiers, language settings, crash logs, diagnostics, and network information.
• Location information, such as approximate location inferred from IP address and, if enabled and permitted, more precise location data.
• Usage and analytics information, such as pages viewed, content accessed, interactions, session duration, clicks, streaming quality, engagement metrics, conversion metrics, and platform logs.
• XR and sensor-related information, such as device orientation, movement, interaction events, session telemetry, and other data generated by immersive or 3D experiences where such functionality is enabled.
• Content information, including text chat, usernames, avatars, reactions, friend requests, live voice or audio where enabled, and materials uploaded or submitted by authorized club personnel, administrators, CMS users, or other users where a feature specifically permits such submissions.
• Commerce information, such as transaction identifiers, purchase history, subscriptions, refunds, chargebacks, and payment status. Payment card or wallet details may be processed by third-party payment processors and may not be stored by GMS.
• Communications, such as support requests, feedback, surveys, live audio, and messages.
• Cookies and similar technologies, as described in the applicable Cookie Policy.
• SSO and CRM information, including account, identity, or access-related information received from club-managed single sign-on systems, customer relationship management platforms, or related third-party identity providers used in connection with a club deployment.
4. Sources of Information
We may collect information:
directly from you;
automatically from your device or interaction with the TifoXR Services;
from club partners;
from payment processors;
from identity and authentication providers;
from analytics providers;
from support vendors; and
from other service providers used to operate the TifoXR Services.
In some club-specific deployments, we may also receive information from club-managed CRM systems, single sign-on providers, or other club-authorized identity and access tools.
5. How We Use Information
We may use information to:
provide, operate, maintain, and secure the TifoXR Services;
create and manage accounts;
authenticate users and prevent unauthorized access;
review, moderate, and manage user-generated content and reported content;
detect and prevent abusive, unlawful, or harmful activity;
process and respond to content notices, abuse reports, and other user submissions;
deliver fan-facing experiences, streaming, immersive content, CMS workflows, and club-specific features;
process purchases, subscriptions, refunds, credits, and transaction records;
provide support and respond to inquiries;
provide language, region, and club-specific functionality;
measure engagement, performance, revenue attribution, and conversion metrics for TifoXR and applicable business partners;
analyze, debug, improve, and develop the TifoXR Services;
send service messages, security notices, updates, and marketing communications where permitted;
protect GMS, users, club partners, rights holders, and the public;
comply with applicable legal obligations, including applicable Digital Services Act requirements; and
establish, exercise, or defend legal claims and enforce applicable agreements.
6. Content Moderation and Automated Processing
TifoXR may use automated tools to assist with content moderation.
Hive.ai is currently used for text chat moderation to detect categories of potentially abusive or harmful content, including toxicity, hate, harassment, self-harm, and sexual content. Depending on the applicable configuration, the system may prevent an abusive text message from being sent.
Voice chat, where enabled, is live and is not currently transcribed or subject to automated AI moderation by GMS. Additional voice moderation technology may be introduced for particular future deployments.
GMS does not use facial recognition or biometric identification for TifoXR's current content-moderation process.
Where content is reported or otherwise requires review, GMS may conduct human review in accordance with applicable TifoXR policies and law.
7. Legal Bases for Processing
Where laws such as the GDPR or UK GDPR apply, we may rely on one or more legal bases, including:
performance of a contract;
legitimate interests;
consent;
compliance with legal obligations;
protection of vital interests; and
tasks carried out in the public interest, where applicable.
The specific legal basis may depend on the feature, user location, club deployment, data category, and applicable law.
8. How We Disclose Information
We may disclose information to:
club partners, where necessary for club-specific deployments, fan engagement, support, analytics, transactions, or rights administration;
service providers and subprocessors, such as hosting, CDN, analytics, payment, authentication, communications, customer support, security, and infrastructure providers;
payment processors and app platforms, to process transactions and manage subscriptions;
rights holders and content partners, where necessary to operate licensed or club-specific experiences;
professional advisers, such as lawyers, accountants, auditors, insurers, and security consultants;
authorities, regulators, courts, and law enforcement, where required or permitted by law; and
transaction parties, in connection with a merger, financing, acquisition, reorganization, or sale of assets.
Current or anticipated service providers may include Microsoft Azure, Microsoft Identity Platform, Microsoft Fabric, PayPal, Stripe, Evercoast, Hive.ai, and other vendors used to operate, secure, analyze, or improve the TifoXR Services.
9. International Transfers
GMS is based in the United States. Information may be processed in the United States and other countries.
Where required by applicable law, GMS will use appropriate safeguards for cross-border transfers, which may include contractual commitments, data-processing agreements, standard contractual clauses, or other lawful transfer mechanisms.
Based on the current implementation, TifoXR data is hosted in Microsoft Azure regions located in the United States, although hosting architecture may change over time.
10. Cookies, SDKs, and Similar Technologies
We may use cookies, SDKs, local storage, pixels, device identifiers, analytics, and similar technologies.
Some technologies are necessary to provide and secure the TifoXR Services. Others may support analytics, functionality, personalization of the user experience, or performance measurement.
TifoXR may also display advertising or sponsored content managed through the TifoXR CMS. Advertising may include images or videos uploaded by authorized club personnel.
TifoXR advertising is not targeted based on user data or user profiling. Ads are intended to be shown consistently to users within the applicable space, and sensitive personal data is not used for advertising purposes.
Where required by applicable law, GMS will obtain consent before using non-essential cookies or similar technologies.
Further information about cookies and similar technologies is provided in the applicable Cookie Policy.
11. Children and Minors
The TifoXR Services are meant for users above 13.
Where applicable, TifoXR may apply age-related controls or requirements before permitting access to certain features or experiences.
If we learn that we collected personal information from a child under 13 without required consent, we will take appropriate steps to delete the information or obtain legally valid consent, as required by applicable law.
TifoXR does not use targeted advertising to minors.
12. Biometric, Camera, Microphone, and Sensitive Data
Certain immersive or device-enabled features may involve camera, microphone, motion, face, body, hand, eye, or other sensor-based data where those capabilities are enabled.
GMS will not intentionally collect biometric identifiers or biometric information unless the relevant feature is disclosed and legally required consent, retention, and deletion measures are implemented.
Current TifoXR versions may include immersive and 3D features but are not currently intended to operate on a headset unless and until GMS enables that functionality in a later version.
Where microphone or voice functionality is enabled, live voice or audio may be processed to provide the relevant communication feature. Voice is not currently transcribed or automatically moderated by AI.
13. Data Retention
We retain information for as long as reasonably necessary for the purposes described in this Policy, including to provide the TifoXR Services, maintain accounts, comply with legal obligations, resolve disputes, enforce agreements, and maintain security.
Retention periods may vary by deployment, data category, processing purpose, and club partner.
Certain categories of data, such as user metrics data, may currently be retained for up to seven (7) years.
Where a specific retention period applies to a particular category of information, the applicable product or club-specific privacy notice may provide additional details.
14. Security
We use reasonable administrative, technical, and physical safeguards designed to protect information. These may include access controls, encryption, monitoring, logging, vendor diligence, and incident-response procedures.
No system is completely secure, and we cannot guarantee absolute security.
15. Your Rights and Choices
Depending on your location and applicable law, you may have rights to request:
access to personal information;
correction of inaccurate information;
deletion of personal information;
portability of personal information;
restriction of processing;
objection to certain processing;
withdrawal of consent where processing is based on consent;
opt-out of certain sales or sharing of personal information;
opt-out of certain targeted advertising or similar uses, where applicable; and
review or appeal of certain privacy decisions, where required by applicable law.
To make a privacy request, contact compliance@globalmobisoft.com or another designated privacy contact.
We may need to verify your identity before responding. Where a club partner controls the relevant personal information, we may refer your request to the applicable club partner or assist in coordinating the request as appropriate.
16. Marketing Choices
You may unsubscribe from marketing emails by using the unsubscribe link provided in the communication or by contacting us.
We may still send non-marketing messages, including service, transactional, security, legal, or account notices.
17. Changes to This Policy
We may update this Policy from time to time.
If changes are material, we will provide notice as required by applicable law.
The "Last Updated" date will indicate when this Policy was most recently revised.
18. Contact
Privacy questions and requests may be sent to:
For matters concerning GMS's EU or UK representation:
Data Protection Representative Limited (DataRep)
EU Representative:
77 Camden Street Lower
Dublin D02 XE80
Ireland
UK Representative:
107-111 Fleet Street
London EC4A 2AB
United Kingdom
Contact: tifoxr@datarep.com
Portal: https://www.datarep.com/tifoxr