Legal & Governance

Privacy Policy

Effective: July 19, 2026 Governing Law: Province of Alberta, Canada Version 1.0
This Privacy Policy explains how RefManager handles personal information. It applies to the RefManager web application at refmanager.ca and to the RefManager applications for iOS and Android. It should be read together with our Terms of Service, which govern your use of the Service.
Section 01

Introduction & Scope

This Privacy Policy (the "Policy") describes how Lean6 Technology Ltd., a corporation incorporated under the laws of Alberta ("Lean6", "we", "us", or "our"), collects, uses, discloses, and safeguards personal information in connection with the RefManager software platform, including the web application, the native applications for Apple iOS and Google Android, and all related features and services (collectively, the "Service").

RefManager is a referee-management platform used by fencing organizations to manage their referee cadres, tournament assignments, development evaluations, scheduling, expense reimbursement, and related administration. This Policy applies to all personal information processed through the Service, regardless of the device or platform through which it is accessed.

We are committed to handling personal information in accordance with the Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5 (PIPEDA) and the Personal Information Protection Act, S.A. 2003, c. P-6.5 (PIPA Alberta), as applicable.

Section 02

Who We Are & Our Role

RefManager operates on a multi-tenant basis: each fencing organization that uses the Service (a "tenant" — for example, a provincial fencing association) has its own segregated workspace, and its data is kept logically separate from that of every other organization.

Organizations as the Controlling Party

The referee roster and related records within a tenant are entered and managed by that organization's administrators. In respect of that information, the organization determines what is collected and how it is used, and Lean6 processes the information on the organization's behalf in order to operate the Service. If you are a referee or member of an organization, that organization is your first point of contact for questions about the information it holds about you.

Our Direct Responsibility

Lean6 is directly responsible for the personal information associated with your sign-in account (such as your name and email address) and for operating the underlying platform securely. We handle all personal information — whether held on our own behalf or on behalf of an organization — in accordance with this Policy and applicable law.

Section 03

Information We Collect

We collect only the information needed to provide the Service. The categories below reflect what the Service actually stores.

Account & Identity Information

When you sign in, we collect your name and email address. Sign-in is handled by Firebase Authentication using one of the following methods you choose: Sign in with Google, Sign in with Apple, or a one-time email sign-in code / sign-in link sent to your email address. We do not create or store passwords for the Service.

Referee Roster Records

Organization administrators enter and maintain referee records, which may include a referee's name, email address, phone number, club, city and province, weapon ratings, examination and certification history, and — where recorded in a referee's development profile — a date of birth and a designation indicating whether the referee is a minor.

Evaluations & Development Notes

Evaluators and administrators may record development evaluations, progression tracking, and notes relating to a referee's performance and readiness.

Tournament Assignments & Availability

The Service stores tournament assignments, hiring status, and the availability that referees indicate for events.

Expense Claims & Receipts

Referees may submit expense claims, which can include amounts, categories, mileage, and photographs of receipts. Receipt images are stored in Firebase Storage.

Device & Notification Information

When you enable notifications in the iOS or Android app, the app stores a device push-notification token (an "FCM token") so we can deliver alerts such as assignment and availability requests. These tokens identify a device installation, not the content of your device.

Preferences & Activity

We store your interface-language preference (English or French) and maintain audit logs of administrative actions taken within an organization's workspace, which record what change was made, by whom, and when, for security and accountability.

What we do not collect: The Service does not use advertising networks, does not run Google Analytics or comparable web-analytics tracking, does not build advertising profiles, and does not collect payment-card information.
Section 04

How We Use Information

We use personal information only for the purposes for which it was collected, namely to:

  • authenticate users and provide secure access to the Service;
  • operate referee registration, ratings, assignments, scheduling, and development tracking;
  • administer tournaments and communicate assignment and availability information;
  • process expense claims and reimbursement workflows;
  • send transactional communications such as sign-in codes, assignment notices, and administrative digests;
  • deliver optional push notifications to devices where enabled;
  • extract information from receipts and pasted schedules when you choose to use the AI features described in Section 8;
  • maintain security, prevent abuse, and keep audit records of administrative activity; and
  • operate, maintain, and improve the Service.

We do not use personal information for automated decision-making that produces legal or similarly significant effects, and we do not use it for advertising.

Section 05

Consent & Legal Basis

We collect, use, and disclose personal information on the basis of consent and in accordance with the principles set out in PIPEDA and PIPA Alberta, including accountability, identifying purposes, limiting collection, limiting use and disclosure, accuracy, safeguards, openness, and individual access.

Where an organization enters personal information about a referee or other third party (including a minor) into the Service, that organization represents that it has the authority and any consent required to do so, and that it will keep that information accurate. Organizations are responsible for informing their members about how referee information is used within the Service.

By using the Service, you consent to the collection, use, and disclosure of your personal information as described in this Policy. You may withdraw consent as described in Section 13, subject to legal or contractual restrictions and reasonable notice; withdrawing consent may limit or prevent your continued use of the Service.

Section 06

Where Information Is Stored & Processed

The Service is built on Google Firebase, a cloud platform operated by Google. Personal information is processed and stored using the following Firebase services:

  • Cloud Firestore — the primary database, hosted in the northamerica-northeast2 (Toronto, Canada) region;
  • Firebase Storage — used for uploaded files such as receipt images and organization logos;
  • Cloud Functions — server-side processing (for example, sending email and running AI extraction), which executes in Google's us-central1 region in the United States;
  • Firebase Cloud Messaging — delivery of push notifications to enrolled devices; and
  • Firebase Authentication — management of sign-in identity.

Because certain processing occurs on servers located in the United States, and because some service providers described in Section 7 operate outside Canada, personal information may be stored or processed outside your province of residence and may be subject to the laws of the jurisdictions in which it is handled.

Section 07

Third-Party Service Providers

We share personal information with a limited number of service providers who process it on our behalf, solely to operate the Service and under obligations of confidentiality. We do not authorize any of these providers to use the information for their own independent purposes.

  • Google — provides Firebase infrastructure (database, storage, functions, authentication, messaging) and the "Sign in with Google" option.
  • Apple — provides the "Sign in with Apple" option.
  • Resend — delivers transactional email (sign-in codes, assignment and availability notices, and digests) sent from noreply@refmanager.ca. Recipient email addresses and message content are processed to deliver these messages.
  • Anthropic — provides the AI extraction described in Section 8, and receives only the receipt image or pasted text that you submit when you invoke those optional features.
  • OpenStreetMap-based services — when a referee uses the optional mileage-estimate helper, the city or address text entered is sent to the Nominatim geocoding and OSRM routing services to estimate a driving distance. This lookup is optional and only occurs when the feature is used.

We may also disclose personal information where required to do so by law, to comply with a valid legal process, or to protect the rights, safety, or property of Lean6, our users, or the public.

Section 08

Artificial-Intelligence Features

The Service offers optional AI-assisted features that help you enter data more quickly: reading a photographed expense receipt into structured fields, and turning a pasted or uploaded tournament schedule or flyer into a draft event list or tournament.

When — and only when — you invoke one of these features, the relevant content (the receipt image, or the schedule or flyer text or image you provide) is sent to the Anthropic Claude API for processing, and the extracted result is returned to the Service. The content is transmitted for the purpose of that single extraction and is not used to build user profiles or for advertising. Each organization's AI usage is subject to an internal spend cap.

Your choice: These AI features are optional. If you prefer not to send content to the AI extraction service, you can enter expenses and tournament details manually using the standard forms.
Section 09

Mobile Apps & Push Notifications

The RefManager applications for iOS and Android provide the same core functionality as the web application and are covered by this Policy.

Notifications are optional. Push notifications are only sent if you grant the operating-system notification permission on your device. When enabled, the app registers a device push-notification token so that alerts (such as hire and availability requests) can be delivered to you.

Invalid or expired device tokens are pruned automatically: when a delivery attempt shows that a token is no longer registered, that token is removed from our records. You can also stop notifications at any time by disabling the notification permission in your device settings.

Section 10

Cookies & Local Storage

RefManager does not use advertising cookies or cross-site tracking technologies. The Service uses your browser's local storage and session storage only to support core functionality and to remember preferences, including:

  • your sign-in session and the last organization you accessed;
  • your interface-language preference; and
  • interface state such as expanded or collapsed sections and column widths.

This information stays on your device to make the Service work and to improve your experience. It is not used to track you across other websites or services.

Section 11

Disclosure & No Sale of Information

We never sell your personal information — not to advertisers, not to data brokers, not to anyone — and we never rent, trade, or otherwise disseminate it for any third party's own use. Your information exists in RefManager for one purpose: running your organization's refereeing program.

The only circumstances in which personal information leaves our systems are:

  • within your organization's workspace, to the administrators, evaluators, organizers, and other authorized users of that organization, according to their roles;
  • to the service providers listed in Section 7, who process it strictly on our instructions to operate the Service and are prohibited from using it for their own purposes; and
  • where we are compelled by applicable law or valid legal process.

If Lean6 is ever reorganized or acquired, this Policy continues to bind whoever operates the Service — your information is never separated from these commitments.

Section 12

Data Retention

We retain personal information for as long as it is needed to provide the Service — generally for as long as the relevant organization maintains an active account and the referee record remains part of that organization's roster — and for any additional period required to meet legal, accounting, or security obligations.

When a referee record or account is deleted within the Service, the associated personal information is removed from active systems. Residual copies may persist for a limited time in routine encrypted backups before those backups are cycled out in the ordinary course. Audit records may be retained for a reasonable period to support security and accountability.

Organizations control the retention of the roster and evaluation data within their own workspace. If you would like data about you deleted, see Section 13.

Section 13

Your Privacy Rights

Subject to applicable law, you have the right to:

  • access the personal information we hold about you;
  • request correction of inaccurate or incomplete information;
  • request deletion of your personal information; and
  • withdraw consent to our use of your personal information, subject to legal or contractual restrictions.

Because much of the information in the Service is controlled by your organization, the fastest way to exercise these rights over roster and evaluation data is usually to contact your organization's administrator. You may also contact Lean6 directly using the details in Section 17. We will respond to verified requests within thirty (30) days, subject to any exceptions permitted under Canadian privacy law, and we may need to verify your identity before acting on a request.

Section 14

Children & Minors

The Service is administered by fencing organizations, not marketed to or used directly by young children. Some referees are minors, and the Service allows a referee record to be flagged as a minor.

Where information about a minor is held in the Service, that information is provided and controlled by the organization and, where applicable, the minor's parent or guardian — it is not collected by Lean6 directly from the child. The organization is responsible for obtaining any consent required to enter and use a minor's information and for supervising a minor's access where one is granted.

For organizations and guardians: Requests to access, correct, or delete a minor's information should be made through the organization's administrator or to the contact address in Section 17.
Section 15

Security Safeguards

We implement technical and organizational safeguards appropriate to the sensitivity of the information, including:

  • encryption of data in transit and at rest, provided by the underlying Google Firebase infrastructure;
  • server-side security rules that enforce per-tenant segregation, so one organization cannot access another organization's data;
  • role-based access controls that limit what each user can see and do within an organization; and
  • audit logging of administrative actions.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach of security safeguards involving personal information that poses a real risk of significant harm, we will respond in accordance with our obligations under applicable privacy legislation.

Section 16

Changes to This Policy

We may update this Policy from time to time. When we make material changes, we will update the "Effective Date" at the top of this document and, where reasonably practicable, provide notice through the Service or by email.

Your continued use of the Service following the posting of a revised Policy constitutes your acknowledgement of the updated Policy. The most current version will always be available at refmanager.ca/privacy.

Section 17

Contact Information

All questions, requests, and concerns relating to this Policy or to your personal information — including access, correction, and deletion requests — should be directed to:

Lean6 Technology Ltd.
Legal & Privacy Matters
Email: legal@lean6.ca
Website: refmanager.ca

Lean6 will acknowledge receipt of written inquiries within five (5) business days and will endeavour to respond substantively within thirty (30) days.