Privacy Policy
SPARR Privacy Policy
Last Updated: August 29, 2026
1. WHO WE ARE
SPARR is a product of NextMove, a company registered in Amman, the Hashemite Kingdom of Jordan. NextMove operates the SPARR mobile applications for Android and iOS, the SPARR website at sparr.world, and the SPARR Hub dashboard used by partner gyms (together, the "Platform"). "SPARR" is a brand and trading name. The legal entity responsible for your personal data — the data controller — is NextMove. Where this policy says "we", "us" or "our", it means NextMove acting as the operator of SPARR. Data controller: NextMove Company website: nextmoveinternational.com Registered in: Amman, Hashemite Kingdom of Jordan Privacy contact: sparrworld@gmail.com If you are in a country that requires us to name a local representative and we have appointed one, their details will be published in this section.
2. SCOPE AND HOW TO READ THIS POLICY
This policy applies to everyone who uses SPARR: fighters and individual users of the mobile apps, visitors to sparr.world, and staff of partner gyms who use the Hub dashboard. It is written to meet the requirements of Jordan's Personal Data Protection Law No. (24) of 2023, the EU General Data Protection Regulation (GDPR) and the UK GDPR, the Google Play Developer Program Policies and Data Safety requirements, the Apple App Store Review Guidelines and App Privacy requirements, and the general data protection frameworks in force across the Gulf and the United States. Where a specific law gives you rights beyond what is described here, that law applies to you in addition to this policy. Separate documents govern other things: the User Terms of Service cover your use of the app and the assumption of risk that comes with martial arts training, and the Hub Partner Terms of Service cover what a gym may do with the data it can see. Both are at sparr.world/legal. We have tried to describe what the software actually does rather than what a template would allow us to do. If you find something in the app that this policy does not describe, tell us and we will correct the policy.
3. THE SHORT VERSION
We collect what SPARR needs to work: your account details, the profile you build, your location while the app is open so the map can work, a record of the sessions you join and attend, and the photos and messages you choose to send. We use your location only while the app is in the foreground. We never track you in the background. Your profile is public to other SPARR users. That is the point of the app — other fighters need to see who you are before agreeing to train with you. We do not sell, rent or trade your personal data. We run no advertising on SPARR and we do not share your data with advertising networks or data brokers. We store your data with Google Firebase, which means it is held on servers outside Jordan. You can delete your account yourself, from inside the app or at sparr.world/legal/data-deletion. Age 16 and over only. Questions, requests, complaints: sparrworld@gmail.com.
4. INFORMATION WE COLLECT
4.1 Account Information
When you create an account we collect: Your email address Your username Your password, if you register with email and password — stored by Google Firebase Authentication in hashed form; we never see or store your password ourselves Which method you signed up with (email or Google) The date your account was created and the platform you signed up on (Android, iOS or web) If you sign up using Google Sign-In, Google gives us your name, email address and Google account identifier. We do not receive your Google password.
4.2 Profile Information You Choose to Add
Your profile is yours to fill in. All of the following are optional except your username and email: Profile photograph Biography The martial arts and combat sports you train Your gym or club name Your city and country Your Instagram handle, if you add one Anything you put on your profile is visible to other SPARR users. Please do not put an address, a phone number, an identity document number or anything else you would not want a stranger to read into your biography or your username.
4.3 Physical Information
SPARR lets you record your weight. This is optional and you can remove it at any time. If you provide it, we convert it to a weight class and display that class on your public profile. It is used for one purpose: so that other fighters can judge whether a sparring match is safe and fair before agreeing to it. In some jurisdictions — including the EEA and the UK — information about your body may be treated as health-related data with additional legal protection. We therefore collect it only where you actively enter it yourself, with your explicit consent, and you may withdraw that consent at any time by clearing the field in your profile. SPARR does not collect medical records, injury history, medication, biometric identifiers, fingerprints, face scans, heart rate or any other health-sensor data.
4.4 Location Information
SPARR asks for permission to use your device location. If you grant it, we use precise location for the following purposes only: To show you on the sparring session map To show you training sessions, activities and Hubs near you To let you create a session at a place you choose To verify that you were physically present at a session you said you attended Location is collected only while the app is open and in use. We do not request, and the app does not have, background location permission. On Android the app requests ACCESS_FINE_LOCATION and ACCESS_COARSE_LOCATION; on iOS it requests "When In Use" authorisation only. When the app is closed or in the background, SPARR is not receiving your location. We also convert your location into a city, region and country and store those on your profile, so the app can show you relevant activities without repeatedly re-checking your position. Your profile has a location visibility switch: when you turn it off, your city stops being shown to other users. You may refuse or revoke location permission at any time in your device settings. The map and nearby-session discovery will stop working; the rest of the app will not.
4.5 Attendance, QR Check-In and Your Reliability Record
SPARR keeps a record of the sessions you join and the sessions you actually attend. When you attend a session, you confirm it by scanning a QR code with your device camera while physically present at the location. We record which session, when, and that verification succeeded. From those records we calculate and publicly display two counts on your profile: how many sessions you have joined, and how many you have been verified as attending. Together these form your reliability record. Two things you should understand about this record. First, it is visible to any other SPARR user who opens your profile. Second, you can hide an individual session from being listed on your profile, but hiding it does not change the counts — a reliability figure a user can edit is not a reliability figure, and other fighters rely on it to decide whether you are likely to show up. This is a deliberate design decision, not a limit on your rights: if you delete your account, the entire record goes with it.
4.6 Content You Create
We store the content you produce inside SPARR: Photographs and videos you upload to your profile or to a Memory Wall after a session Sessions and activities you create, including their title, description, time, price information and map location Messages you send in individual and group chats, including any images shared in them Chat group names and chat background images Media you upload is processed on your device before upload — videos are compressed and transcoded locally — and then stored in Google Firebase Storage. We access your camera and photo library only for the specific file you choose or the photo you take. SPARR does not scan or index your photo library.
4.7 Connections, Blocking and Reports
SPARR is a social product, so we store your social graph: who you follow, who follows you, which Hubs you belong to, and which sessions you have joined. We also store the list of users you have blocked, and any reports you submit about another user or a piece of content. Reports include the identity of the person reporting, because a safety system that cannot be audited cannot be trusted. We use reports to investigate abuse, remove content and suspend accounts.
4.8 Device and Technical Information
We collect a limited amount of technical information automatically: Device model, operating system and app version A Firebase installation identifier — an app-instance identifier generated by Google Analytics for Firebase. It is not your device advertising identifier, and it is reset when you reinstall the app Your IP address and the approximate network location it implies Usage analytics: which screens are opened, how long a session lasts, which features are used Error and diagnostic information when something fails We use Google Analytics for Firebase for app analytics. It is configured for product analytics only and is not linked to any advertising product. SPARR contains no advertising SDK, no third-party tracker, no advertising identifier collection and no cross-app or cross-site tracking.
4.9 Push Notification Token
If you allow notifications, Google Firebase Cloud Messaging issues a device token and we store it against your account so we can deliver messages, session reminders and safety notices to your device. The token identifies a device installation, not you personally. If you turn notifications off in your device settings, the token stops working.
4.10 Website Visitors
On sparr.world we process: A cookie that remembers whether you are reading the site in English or Arabic. This is strictly necessary for the site to work in the language you chose, and is not used to track you Firebase Authentication session data, if you sign in on the web Error reports and a sample of performance traces through Sentry, which we use to find and fix faults. These may include your IP address, browser and the page you were on Cloudflare Turnstile on the gym application form, to tell a human apart from a bot. Turnstile is used specifically because it does not profile visitors or track them across sites Map tiles served by Mapbox, where a map is displayed on the website We do not run advertising cookies, marketing pixels or cross-site trackers on sparr.world.
4.11 What We Do Not Collect
To be explicit, because over-disclosure misleads as much as under-disclosure: We do not collect your phone number. SPARR has no phone field and no SMS verification We do not collect your date of birth or a government identity document We do not collect payment card details. SPARR has no in-app payment. Where a session or a gym membership has a price, that is information only, and money changes hands directly between you and the gym, outside the app We do not collect background location We do not collect your contacts, calendar, call logs or SMS messages We do not collect biometric identifiers or health-sensor data We do not use advertising identifiers, and we run no advertising
5. WHY WE USE YOUR INFORMATION, AND OUR LEGAL BASIS
Under the GDPR, the UK GDPR and Jordan's Personal Data Protection Law we must have a lawful basis for each thing we do with your data. Ours are as follows. To create and run your account, show your profile, deliver chat, run the map and record attendance — because it is necessary to perform the contract between you and us, being the Terms of Service you accepted. Without this data SPARR cannot function. To use your precise location for the map and nearby discovery — with your consent, given through the operating system permission prompt, which you may withdraw at any time in your device settings. To store and display your weight class — with your explicit consent, given by choosing to enter it, which you may withdraw by clearing the field. To send you push notifications — with your consent, given through the notification permission prompt. To keep the Platform safe: investigating reports, enforcing blocks, removing abusive content, suspending accounts, and preventing fraud and automated abuse — because we have a legitimate interest in a platform where people can arrange to meet strangers for a contact sport without being harmed, and you have a matching interest in being protected. We have weighed this against your privacy and consider it proportionate. To understand how SPARR is used and to fix faults — because we have a legitimate interest in a product that works. We keep this to aggregate product analytics and error diagnostics, and do not use it to build a profile of you. To send you service and security messages — because it is necessary to perform our contract with you and, for security notices, to comply with our legal obligations. To comply with law, respond to lawful requests, and establish or defend legal claims — because we have a legal obligation, or a legitimate interest in defending ourselves. We do not use your personal data for advertising, for marketing profiling, or for automated decisions producing legal effects concerning you.
6. WHO CAN SEE YOUR INFORMATION
6.1 Other Users
The following are public to every other SPARR user: your username, profile photograph, biography, sports, experience level, gym or club, Instagram handle if you added one, weight class if you added one, your city unless you turn location visibility off, your follower and following counts, and your joined and attended session counts. While a session is active and you are on the map, your position is shown to other users on the map. Anything you post to a Memory Wall or a community feed is visible to the users who can see that wall or feed. Messages you send in a chat are visible to the other members of that chat. Users you have blocked cannot see you or contact you.
6.2 Hubs and Gyms
If you join a Hub, or attend a session run by a Hub, that Hub's administrators can see your profile information, your membership of their Hub, and your attendance record at their sessions, through the Hub dashboard. Hub administrators can also export data about their own members as reports and CSV files. Once data is exported it leaves our systems and sits on the Hub's own computers, and the Hub becomes independently responsible for it under the Hub Partner Terms of Service. We require Hubs to handle it lawfully, but we cannot technically control a file that has been downloaded. If you are concerned about a particular gym's handling of your data, contact us and contact them. A Hub cannot see your private messages, your chats with other users, or your activity at Hubs you are not a member of.
6.3 Service Providers
We use a small number of external providers to run SPARR. Each is bound to process data only on our instructions: Google Ireland Limited and Google LLC — Firebase Authentication, Cloud Firestore, Firebase Storage, Cloud Messaging and Google Analytics for Firebase. This is where your account and content are stored Google Maps Platform — map rendering and geocoding in the mobile apps. Google receives location data in order to draw the map Mapbox — map rendering on the website Apple Inc. — App Store distribution, Sign in with Apple where used, and push notification delivery on iOS Functional Software, Inc. (Sentry) — error monitoring on the website Cloudflare, Inc. — bot protection on the website's gym application form We may add or change providers. When we do, we will update this list. We do not permit any of them to use your data for their own purposes.
6.4 Legal and Safety Disclosures
We may disclose your information where we are required to by law, a court order or a lawful request from a competent authority, or where we believe in good faith that disclosure is necessary to investigate a serious safety concern, prevent physical harm, or establish, exercise or defend a legal claim. Where we are legally permitted to tell you about such a request, we will.
6.5 Business Transfers
If NextMove is reorganised, or if SPARR is sold or merged into another business, your personal data may transfer as part of that transaction. We will notify you before your data becomes subject to a different privacy policy, and any acquirer will be bound by commitments no weaker than those in this policy.
6.6 We Do Not Sell Your Data
We do not sell your personal information. We do not rent it, trade it, or share it with data brokers, advertising networks or analytics companies acting for their own purposes. We have never done so, and this policy would have to change before we could. For the avoidance of doubt under United States state privacy laws that define "sale" and "sharing" broadly: we do not sell or share personal information for cross-context behavioural advertising, and we do not process it for targeted advertising of any kind.
7. INTERNATIONAL TRANSFERS
SPARR is operated from Jordan, and our data is stored on Google Cloud infrastructure located outside Jordan, principally in the United States and the European Union. Some of our service providers are located in the United States, Ireland and the United Kingdom. This means your personal data is transferred across borders. Where the law requires a transfer mechanism, we rely on the following: For transfers out of the EEA and the UK — the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, which form part of our agreements with Google and our other providers, together with the technical measures described in section 14 For transfers out of Jordan — the conditions for cross-border transfer set out in Jordan's Personal Data Protection Law No. (24) of 2023, on the basis that the recipient applies an adequate level of protection under binding contractual terms You may request a copy of the relevant transfer safeguards by writing to sparrworld@gmail.com.
8. HOW LONG WE KEEP YOUR DATA
We keep personal data only as long as we need it. Account and profile data — for as long as your account exists Sessions, attendance records and your reliability record — for as long as your account exists Chat messages — for as long as your account exists, or until you or the other participants delete them Uploaded photographs and videos — until you delete them, or until your account is deleted Analytics and diagnostic data — retained by Google Analytics for Firebase for up to 14 months, and by Sentry for up to 90 days, in a form not linked to your profile Reports and moderation records — up to 24 months after the matter is closed, so that repeat behaviour can be recognised When you delete your account, we remove your personal data from our active systems within 30 days. Encrypted backups may retain it for up to a further 90 days before they are cycled out; during that period it is not accessible for ordinary use. We may keep a minimal record for longer where we are legally required to, or where it is necessary to defend a legal claim or to enforce a ban against someone removed for endangering other users.
9. YOUR CONTROLS INSIDE THE APP
You do not have to write to us to exercise most of your choices. Inside SPARR you can: Edit or clear any field on your profile at any time Turn off location visibility, so your city is not shown to others Revoke location, camera, photo and notification permissions in your device settings Delete individual photographs, messages and Memory Wall posts Block and report other users Hide individual sessions from your public profile Switch the entire app between English and Arabic Delete your account permanently — in Settings, or at sparr.world/legal/data-deletion, where you can sign in and submit a deletion request directly Account deletion is genuine and self-service. It is not a support ticket that we may or may not action.
10. YOUR RIGHTS
Depending on where you live, you have some or all of the following rights over your personal data: Access — to be told whether we hold data about you, and to receive a copy Rectification — to have inaccurate data corrected and incomplete data completed Erasure — to have your data deleted Restriction — to have us stop using your data while a dispute about it is resolved Objection — to object to processing we carry out on the basis of legitimate interests Portability — to receive the data you gave us in a structured, machine-readable format, and to have it sent to another provider where technically feasible Withdrawal of consent — to withdraw any consent you gave, at any time, without affecting processing that already took place Complaint — to complain to your data protection authority To exercise any of these rights, write to sparrworld@gmail.com from the email address on your account, or use the deletion tool at sparr.world/legal/data-deletion. We will respond within 30 days. If your request is complex we may extend this by a further 30 days, and will tell you why. We do not charge for this. We may ask you to confirm your identity before we act, so that nobody else can use these rights to reach your data. If we refuse a request, we will tell you why and tell you how to challenge that refusal.
11. REGIONAL INFORMATION
11.1 Jordan
NextMove is established in Amman and processes personal data subject to Personal Data Protection Law No. (24) of 2023. You have the rights set out in that law, including access, correction, erasure, objection and withdrawal of consent, and the right to complain to the competent authority at the Ministry of Digital Economy and Entrepreneurship. References in earlier versions of this policy to a "draft 2023 framework" were out of date. The law is in force, and we treat it as binding.
11.2 European Economic Area and United Kingdom
Where the GDPR or the UK GDPR applies to you, NextMove is the controller, the legal bases are those set out in section 5, and the transfer safeguards are those set out in section 7. You have the right to lodge a complaint with your national supervisory authority, or with the Information Commissioner's Office in the United Kingdom. A note on availability: the SPARR iOS app is currently not distributed in the 27 European Union territories. That is a distribution decision relating to trader-status declaration requirements under the EU Digital Services Act, and not a statement about your privacy rights. If you are in the EEA or the UK and you use SPARR, this policy and the GDPR apply to you in full. We do not currently process EEA personal data at a scale requiring a Data Protection Officer or an Article 27 representative. If that changes, this section will name them.
11.3 Gulf Cooperation Council States
If you use SPARR in Saudi Arabia, the United Arab Emirates, Qatar, Bahrain, Kuwait or Oman, you have the rights given to you by your national data protection law — including, in Saudi Arabia, the Personal Data Protection Law, and in the United Arab Emirates, Federal Decree-Law No. 45 of 2021. Where those laws grant you rights broader than section 10, we will honour the broader right. Requests go to the same address: sparrworld@gmail.com.
11.4 United States
We do not sell or share personal information as those terms are defined in California and other United States state privacy laws, and we do not process personal information for targeted advertising. We do not use or disclose sensitive personal information for any purpose other than providing the service you asked for. Residents of California, Colorado, Connecticut, Virginia and other states with comprehensive privacy laws may exercise the rights described in section 10, and will not be discriminated against for doing so. Where a state law gives you the right to appeal a refused request, you may appeal by replying to our decision, and we will respond in writing.
11.5 Everywhere Else
If you are somewhere not named above, section 10 still applies. We apply the same standard everywhere, rather than giving people in some countries a weaker product.
12. CHILDREN AND YOUNG PEOPLE
SPARR is for users aged 16 and over. This is a deliberate choice: the app arranges physical contact sport between people who may be strangers to one another, and that is not a service to offer to children. We do not knowingly collect personal data from anyone under 16. If we learn that we have, we will delete the account and its data without delay. If you are a parent or guardian and you believe a child under 16 has created an account, write to sparrworld@gmail.com and we will act on it.
13. AUTOMATED PROCESSING
SPARR calculates your reliability record — sessions joined against sessions verified as attended — automatically, and displays it on your public profile. It is arithmetic on your own attendance history: not a prediction, not a score bought from a third party, and not a judgement about your character. We do not carry out profiling that produces legal effects concerning you or similarly significantly affects you. We do not use automated decision-making to suspend accounts: a person reviews reports before an account is suspended.
14. SECURITY
We protect your data with: Encryption in transit (TLS) for all communication between the apps, the website and our servers Encryption at rest for data stored in Google Cloud Server-side access rules in Cloud Firestore that enforce who may read and write each record, rather than relying on the app to behave Authentication handled by Google Firebase, so that we never store your password Restricted administrative access, limited to those who need it to operate the service Review of the access rules whenever the data model changes Two things you should know honestly. First, in-app chat is stored on our servers and is not end-to-end encrypted — do not send financial details, identity documents or anything else you would not want recovered. Second, no system is perfectly secure, and we cannot guarantee absolute security. Please help us: use a strong and unique password, do not share your account, and tell us at sparrworld@gmail.com if you believe someone else has accessed it.
15. DATA BREACHES
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, as required by the GDPR, and notify the Jordanian authority within the period its law requires. Where the breach is likely to result in a high risk to you, we will tell you directly and without undue delay, describing what happened, what data was involved, what we are doing about it, and what you should do. If you believe you have found a security vulnerability in SPARR, please report it to sparrworld@gmail.com rather than disclosing it publicly. We will not pursue researchers who report in good faith and give us a reasonable opportunity to fix the issue.
16. APP STORE DISCLOSURES
The Google Play Data Safety section and the Apple App Store privacy label for SPARR are derived from this policy and are intended to be consistent with it. If you find a discrepancy between a store label and this document, treat this document as the accurate one and tell us, so that we can correct the label. SPARR requests the following permissions, and each is used only for the purpose given: Location, while in use — the map, nearby sessions, and attendance verification Camera — taking a profile photo, adding photos to a Memory Wall, and scanning session QR codes Photos and media — attaching a photo or video that you select Notifications — session reminders, chat messages and safety notices Internet and network state — to reach our servers Denying any of these permissions disables the feature that needs it, and nothing else.
17. CHANGES TO THIS POLICY
We may update this policy as SPARR changes, or as the law does. The date at the top of this page is the date of the current version. If a change is material — a new category of data, a new purpose, a new recipient, or a reduction of your rights — we will tell you before it takes effect, through an in-app notice or by email, and give you a fair chance to read it. Continuing to use SPARR after that notice means you accept the updated policy. If you do not accept it, you can delete your account. We will not apply a materially different use to data we already hold about you without asking you first.
18. CONTACT AND COMPLAINTS
Data controller: NextMove — operator of SPARR Address: Al Rayyan Commercial Complex, 3rd floor, opposite Radio & Television, Amman, Hashemite Kingdom of Jordan Company: nextmoveinternational.com Privacy and data requests: sparrworld@gmail.com Delete your account: sparr.world/legal/data-deletion We aim to answer every privacy request within 30 days. If you are not satisfied with our answer, you may complain to your national data protection authority. In Jordan that is the competent unit at the Ministry of Digital Economy and Entrepreneurship; in the EEA it is your national supervisory authority; in the United Kingdom it is the Information Commissioner's Office. You do not have to come to us first, but we would rather you did — most problems are faster to fix directly.