Cookie Policy

Last updated October 6, 2026

This Cookie Policy explains how Scorbot LLC (“Scorbot”, “we”, “us”) uses cookies and similar technologies on scorbot.app and its subdomains (the “Services”). It is the Cookie Notice referred to in our Privacy Policy, which describes the personal information we collect and how we use it.

The short version

  • We set a small number of first-party cookies to keep you signed in, protect your account and remember your time zone.
  • We do not use advertising cookies, tracking pixels or cross-site trackers, and we do not sell or share your personal information for targeted advertising.
  • Our analytics are cookieless: they count visits without storing anything on your device that identifies you.
  • A few embedded services (maps, videos, payments) are run by other companies and may set their own cookies, listed below.

What cookies are

Cookies are small text files a website stores in your browser so it can recognise you on your next request. Similar technologies, such as browser localStorage and sessionStorage, keep information in the browser without sending it to the server on every request. This policy covers both.

Strictly necessary cookies

These cookies are required for the Services to work. They are set by Scorbot, are never used for advertising, and cannot be switched off without breaking sign-in. Cookie names beginning with __Secure- or __Host- are only sent over HTTPS.

NamePurposeDuration
__Secure-next-auth.session-tokenKeeps you signed in. Holds an encrypted session token; without it every page would ask you to sign in again.30 days
__Host-next-auth.csrf-tokenProtects sign-in and account forms against cross-site request forgery.Session (deleted when you close the browser)
__Secure-next-auth.callback-urlRemembers the page to return you to after you sign in.Session
scorbot_deviceMarks a browser you have already verified with a one-time code so we can skip the code on your next sign-in. Stores a random secret only; it never contains your phone number or personal details.180 days
scorbot_shopify_installTies an in-progress Shopify app installation to the browser that started it. Only set while a director is connecting a Shopify store.10 minutes
scorbot_shopify_openStops a Shopify installation from looping between Shopify and Scorbot if the store returns to us before the connection has finished. Holds the store domain only; set only during a Shopify store connection.3 minutes

Functional cookies

These cookies remember a preference or let a feature work smoothly. The Services still work without them, but with less accurate times or a live feed that must reconnect more often.

NamePurposeDuration
tzStores your browser’s time zone (for example "America/New_York") so schedules, reports and dates are shown in your local time instead of UTC.1 year
scorbot_schedule_viewerA random, signed viewer identifier for the live schedule feed when you are not signed in. It lets the live connection resume and limits abuse; it is not linked to your identity.30 days
scorbot_rankings_viewerThe same as above, for the live rankings feed.30 days

Affiliate attribution cookie

Scorbot runs an affiliate program that pays partners when someone they referred becomes a customer. If you follow an affiliate link, we set one cookie to remember which partner referred you. It is not used to build a profile of you or to show you advertising, on Scorbot or anywhere else. If you never follow an affiliate link, this cookie is never set.

NamePurposeDuration
scorbot_affOnly set if you arrive through a Scorbot affiliate link (a URL starting with scorbot.app/a/). Records the affiliate code so the referring partner can be credited if you later create an account. It is not shared with advertisers and is not used to show you ads.30 days

Analytics and error monitoring (no cookies)

We measure how the Services are used without cookies or cross-site identifiers:

  • Scorbot page analytics. When you view a public event page we record the page, the referring site, your country and region, device type and browser. To count unique visitors we combine your IP address with a random value that changes every day and keep only the resulting hash; the IP address itself is never stored, and visitors cannot be recognised from one day to the next. A random session id in your browser’s sessionStorage groups the pages you view within 30 minutes.
  • Vercel Web Analytics and Speed Insights. Our hosting provider counts page views and measures page load speed. Vercel does not use cookies for this and identifies a visit by a hash that is discarded after the day ends. See Vercel’s analytics privacy statement.
  • Sentry. When something goes wrong in the app we send an error report to Sentry, our error-monitoring provider, together with a short recording of the affected tab in which all text is masked and all images and video are blocked. Sentry sets no cookies. See Sentry’s privacy policy.

Services provided by other companies

Some parts of the Services load content from other companies. When they do, your browser connects to that company directly, the company receives your IP address, and it may set its own cookies under its own privacy policy. We do not control those cookies.

  • Google Maps — event and facility maps and address look-up in registration forms. Google may set cookies on google.com domains. How Google uses cookies.
  • YouTube — product videos on our home page. YouTube may set cookies when the player loads.
  • Mapbox — pin and boundary maps on some event and facility pages. Mapbox sets no cookies but receives anonymous usage statistics from the map.
  • DUPR — if you connect a DUPR pickleball rating, the DUPR sign-in is shown inside an embedded frame and uses DUPR’s own cookies.
  • TinyMCE — the rich-text editor used by event directors loads from Tiny’s content delivery network.
  • Stripe and PayPal — payments are completed on Stripe’s or PayPal’s own checkout pages, which use their cookies under their policies. We do not load their scripts on Scorbot pages.

Browser storage we use

Besides cookies, the Services keep the following in your browser’s localStorage or sessionStorage. None of it is sent to third parties.

NamePurposeDuration
sessionStorage: sb_pv_sessionA random session id, the page you arrived on and the referring site, used to count visits to public event pages. Expires after 30 minutes of inactivity.Until the tab is closed
localStorage: signInPrefill, playerProfileCreatedCarries the phone number you just verified from one onboarding step to the next, and shows a one-time "your profile is ready" message on the dashboard. Each item is removed the first time the next step reads it. If you abandon onboarding before that step, the item stays in your browser until you finish signing in or clear site data.Until read; otherwise until you clear site data
sessionStorage: scorbot-agent:pendingWhen you start a Scorbot Assistant conversation from the dashboard, the text of your first message is handed to the Assistant page through sessionStorage instead of the URL, so it never lands in your browser history. It is removed as soon as the Assistant page opens.Until read, or until the tab is closed
localStorage: scorbot-agent-context, scorbot-agent:read-aloud:<user>, scorbot-agent:last:<user>:<organization>Remembers which organization the Scorbot Assistant was last used for, the last open conversation and whether read-aloud is on, per signed-in user.Until you clear site data
sessionStorage: scorbot.auth.recovery-reloadIf your session could not be read because of a momentary network problem, the page reloads itself once to recover instead of sending you to sign in. This item records the time of that reload so it can never loop.Until the tab is closed
sessionStorage: sentryReplaySessionError monitoring keeps a short, text-masked recording of the current tab in memory so that, if a crash happens, we can see what went wrong. Nothing is sent unless an error occurs.Until the tab is closed

Your choices

  • Browser settings. Every major browser lets you view, delete and block cookies, either for all sites or for scorbot.app alone. Blocking the strictly necessary cookies will prevent you from signing in.
  • Signing out removes your session cookie. Clearing site data for scorbot.app removes every cookie and storage item listed on this page, including the trusted-device marker, so your next sign-in will ask for a verification code again.
  • Third-party content. Blocking third-party cookies in your browser stops Google, YouTube and DUPR from setting cookies through our pages; maps and videos keep working.
  • Do Not Track and Global Privacy Control. We do not sell or share personal information for targeted advertising, so there is nothing for these signals to opt you out of. We honour them by continuing not to.

Changes to this policy

We will update this page when we add, remove or change a cookie, and change the date at the top. Material changes will also be announced in the Services.

Questions

Email support@scorbot.app with any question about cookies or this policy.

ExploreLog inUpcoming