Introduction & Scope
This Privacy Policy (the "Policy") describes how Lean6 Technology Ltd., a corporation incorporated under the laws of Alberta ("Lean6", "we", "us", or "our"), collects, uses, discloses, and safeguards personal information in connection with the RefManager software platform, including the web application, the native applications for Apple iOS and Google Android, and all related features and services (collectively, the "Service").
RefManager is a referee-management platform used by fencing organizations to manage their referee cadres, tournament assignments, development evaluations, scheduling, expense reimbursement, and related administration. This Policy applies to all personal information processed through the Service, regardless of the device or platform through which it is accessed.
We are committed to handling personal information in accordance with the Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5 (PIPEDA) and the Personal Information Protection Act, S.A. 2003, c. P-6.5 (PIPA Alberta), as applicable.
Who We Are & Our Role
RefManager operates on a multi-tenant basis: each fencing organization that uses the Service (a "tenant" — for example, a provincial fencing association) has its own segregated workspace, and its data is kept logically separate from that of every other organization.
Organizations as the Controlling Party
The referee roster and related records within a tenant are entered and managed by that organization's administrators. In respect of that information, the organization determines what is collected and how it is used, and Lean6 processes the information on the organization's behalf in order to operate the Service. If you are a referee or member of an organization, that organization is your first point of contact for questions about the information it holds about you.
Our Direct Responsibility
Lean6 is directly responsible for the personal information associated with your sign-in account (such as your name and email address) and for operating the underlying platform securely. We handle all personal information — whether held on our own behalf or on behalf of an organization — in accordance with this Policy and applicable law.
Information We Collect
We collect only the information needed to provide the Service. The categories below reflect what the Service actually stores.
Account & Identity Information
When you sign in, we collect your name and email address. Sign-in is handled by Firebase Authentication using one of the following methods you choose: Sign in with Google, Sign in with Apple, or a one-time email sign-in code / sign-in link sent to your email address. We do not create or store passwords for the Service.
Referee Roster Records
Organization administrators enter and maintain referee records, which may include a referee's name, email address, phone number, club, city and province, weapon ratings, examination and certification history, and — where recorded in a referee's development profile — a date of birth and a designation indicating whether the referee is a minor.
Evaluations & Development Notes
Evaluators and administrators may record development evaluations, progression tracking, and notes relating to a referee's performance and readiness.
Tournament Assignments & Availability
The Service stores tournament assignments, hiring status, and the availability that referees indicate for events.
Expense Claims & Receipts
Referees may submit expense claims, which can include amounts, categories, mileage, and photographs of receipts. Receipt images are stored in Firebase Storage.
Device & Notification Information
When you enable notifications in the iOS or Android app, the app stores a device push-notification token (an "FCM token") so we can deliver alerts such as assignment and availability requests. These tokens identify a device installation, not the content of your device.
Preferences & Activity
We store your interface-language preference (English or French) and maintain audit logs of administrative actions taken within an organization's workspace, which record what change was made, by whom, and when, for security and accountability.
How We Use Information
We use personal information only for the purposes for which it was collected, namely to:
- authenticate users and provide secure access to the Service;
- operate referee registration, ratings, assignments, scheduling, and development tracking;
- administer tournaments and communicate assignment and availability information;
- process expense claims and reimbursement workflows;
- send transactional communications such as sign-in codes, assignment notices, and administrative digests;
- deliver optional push notifications to devices where enabled;
- extract information from receipts and pasted schedules when you choose to use the AI features described in Section 8;
- maintain security, prevent abuse, and keep audit records of administrative activity; and
- operate, maintain, and improve the Service.
We do not use personal information for automated decision-making that produces legal or similarly significant effects, and we do not use it for advertising.
Consent & Legal Basis
We collect, use, and disclose personal information on the basis of consent and in accordance with the principles set out in PIPEDA and PIPA Alberta, including accountability, identifying purposes, limiting collection, limiting use and disclosure, accuracy, safeguards, openness, and individual access.
Where an organization enters personal information about a referee or other third party (including a minor) into the Service, that organization represents that it has the authority and any consent required to do so, and that it will keep that information accurate. Organizations are responsible for informing their members about how referee information is used within the Service.
By using the Service, you consent to the collection, use, and disclosure of your personal information as described in this Policy. You may withdraw consent as described in Section 13, subject to legal or contractual restrictions and reasonable notice; withdrawing consent may limit or prevent your continued use of the Service.
Where Information Is Stored & Processed
The Service is built on Google Firebase, a cloud platform operated by Google. Personal information is processed and stored using the following Firebase services:
- Cloud Firestore — the primary database, hosted in the northamerica-northeast2 (Toronto, Canada) region;
- Firebase Storage — used for uploaded files such as receipt images and organization logos;
- Cloud Functions — server-side processing (for example, sending email and running AI extraction), which executes in Google's us-central1 region in the United States;
- Firebase Cloud Messaging — delivery of push notifications to enrolled devices; and
- Firebase Authentication — management of sign-in identity.
Because certain processing occurs on servers located in the United States, and because some service providers described in Section 7 operate outside Canada, personal information may be stored or processed outside your province of residence and may be subject to the laws of the jurisdictions in which it is handled.
Third-Party Service Providers
We share personal information with a limited number of service providers who process it on our behalf, solely to operate the Service and under obligations of confidentiality. We do not authorize any of these providers to use the information for their own independent purposes.
- Google — provides Firebase infrastructure (database, storage, functions, authentication, messaging) and the "Sign in with Google" option.
- Apple — provides the "Sign in with Apple" option.
- Resend — delivers transactional email (sign-in codes, assignment and availability notices, and digests) sent from noreply@refmanager.ca. Recipient email addresses and message content are processed to deliver these messages.
- Anthropic — provides the AI extraction described in Section 8, and receives only the receipt image or pasted text that you submit when you invoke those optional features.
- OpenStreetMap-based services — when a referee uses the optional mileage-estimate helper, the city or address text entered is sent to the Nominatim geocoding and OSRM routing services to estimate a driving distance. This lookup is optional and only occurs when the feature is used.
We may also disclose personal information where required to do so by law, to comply with a valid legal process, or to protect the rights, safety, or property of Lean6, our users, or the public.
Artificial-Intelligence Features
The Service offers optional AI-assisted features that help you enter data more quickly: reading a photographed expense receipt into structured fields, and turning a pasted or uploaded tournament schedule or flyer into a draft event list or tournament.
When — and only when — you invoke one of these features, the relevant content (the receipt image, or the schedule or flyer text or image you provide) is sent to the Anthropic Claude API for processing, and the extracted result is returned to the Service. The content is transmitted for the purpose of that single extraction and is not used to build user profiles or for advertising. Each organization's AI usage is subject to an internal spend cap.
Mobile Apps & Push Notifications
The RefManager applications for iOS and Android provide the same core functionality as the web application and are covered by this Policy.
Notifications are optional. Push notifications are only sent if you grant the operating-system notification permission on your device. When enabled, the app registers a device push-notification token so that alerts (such as hire and availability requests) can be delivered to you.
Invalid or expired device tokens are pruned automatically: when a delivery attempt shows that a token is no longer registered, that token is removed from our records. You can also stop notifications at any time by disabling the notification permission in your device settings.
Cookies & Local Storage
RefManager does not use advertising cookies or cross-site tracking technologies. The Service uses your browser's local storage and session storage only to support core functionality and to remember preferences, including:
- your sign-in session and the last organization you accessed;
- your interface-language preference; and
- interface state such as expanded or collapsed sections and column widths.
This information stays on your device to make the Service work and to improve your experience. It is not used to track you across other websites or services.
Disclosure & No Sale of Information
We never sell your personal information — not to advertisers, not to data brokers, not to anyone — and we never rent, trade, or otherwise disseminate it for any third party's own use. Your information exists in RefManager for one purpose: running your organization's refereeing program.
The only circumstances in which personal information leaves our systems are:
- within your organization's workspace, to the administrators, evaluators, organizers, and other authorized users of that organization, according to their roles;
- to the service providers listed in Section 7, who process it strictly on our instructions to operate the Service and are prohibited from using it for their own purposes; and
- where we are compelled by applicable law or valid legal process.
If Lean6 is ever reorganized or acquired, this Policy continues to bind whoever operates the Service — your information is never separated from these commitments.
Data Retention
We retain personal information for as long as it is needed to provide the Service — generally for as long as the relevant organization maintains an active account and the referee record remains part of that organization's roster — and for any additional period required to meet legal, accounting, or security obligations.
When a referee record or account is deleted within the Service, the associated personal information is removed from active systems. Residual copies may persist for a limited time in routine encrypted backups before those backups are cycled out in the ordinary course. Audit records may be retained for a reasonable period to support security and accountability.
Organizations control the retention of the roster and evaluation data within their own workspace. If you would like data about you deleted, see Section 13.
Your Privacy Rights
Subject to applicable law, you have the right to:
- access the personal information we hold about you;
- request correction of inaccurate or incomplete information;
- request deletion of your personal information; and
- withdraw consent to our use of your personal information, subject to legal or contractual restrictions.
Because much of the information in the Service is controlled by your organization, the fastest way to exercise these rights over roster and evaluation data is usually to contact your organization's administrator. You may also contact Lean6 directly using the details in Section 17. We will respond to verified requests within thirty (30) days, subject to any exceptions permitted under Canadian privacy law, and we may need to verify your identity before acting on a request.
Children & Minors
The Service is administered by fencing organizations, not marketed to or used directly by young children. Some referees are minors, and the Service allows a referee record to be flagged as a minor.
Where information about a minor is held in the Service, that information is provided and controlled by the organization and, where applicable, the minor's parent or guardian — it is not collected by Lean6 directly from the child. The organization is responsible for obtaining any consent required to enter and use a minor's information and for supervising a minor's access where one is granted.
Security Safeguards
We implement technical and organizational safeguards appropriate to the sensitivity of the information, including:
- encryption of data in transit and at rest, provided by the underlying Google Firebase infrastructure;
- server-side security rules that enforce per-tenant segregation, so one organization cannot access another organization's data;
- role-based access controls that limit what each user can see and do within an organization; and
- audit logging of administrative actions.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach of security safeguards involving personal information that poses a real risk of significant harm, we will respond in accordance with our obligations under applicable privacy legislation.
Changes to This Policy
We may update this Policy from time to time. When we make material changes, we will update the "Effective Date" at the top of this document and, where reasonably practicable, provide notice through the Service or by email.
Your continued use of the Service following the posting of a revised Policy constitutes your acknowledgement of the updated Policy. The most current version will always be available at refmanager.ca/privacy.
Contact Information
All questions, requests, and concerns relating to this Policy or to your personal information — including access, correction, and deletion requests — should be directed to:
Lean6 will acknowledge receipt of written inquiries within five (5) business days and will endeavour to respond substantively within thirty (30) days.