Reel Neet SolutionsTalent

Privacy Policy

Reel Neet Solutions Talent — talent.reelneetsolutions.com

Last updated: 16 September 2026 Effective: 16 September 2026


1. Introduction

This Privacy Policy explains what personal information Michael Wesley Schiff (an individual trading as a sole proprietor under the name Reel Neet Solutions) ("we", "us", "our") collects through the Reel Neet Solutions Talent platform at talent.reelneetsolutions.com and the commentator applications served from it (the "Service"), why we collect it, who we share it with, and what rights you have.

It covers three groups of people, and they are treated differently:

Read this alongside our Terms of Service.

2. Summary — the short version

3. Information we collect about members

3.1 Account information

Data Why How obtained
Account id An internal identifier that stands for you inside the Service, so that your notes, seats and sessions stay yours when your email address changes. It is never shown to anyone and never reused Created automatically when you sign up
Name How you are named to other members — on your notes, in the booth, and on a graphic you ask for Given by you at sign-up, and changeable in account settings
Email address What you sign in with, and where we send the emails in Section 3.9 Given by you at sign-up, and changeable in account settings
Password (hashed) To authenticate you Chosen by you at sign-up, and changeable in account settings
Account creation date, and when you accepted the Terms Account administration, and a record that you agreed to the Terms when you signed up Recorded automatically
Account state: whether your email is verified, whether your access request is waiting, approved or suspended, and whether you are an admin So that only approved, unsuspended members can sign in, and only admins can approve and assign Recorded automatically, and changed by an admin
The shows you are a commentator on, and the seats you have held So the Service can give you that show's notes and its booth, and keep a history of who was assigned to which show and seat, and when Set by an admin
Whether you have asked not to be recorded in the usage record So that Section 3.4's opt-out is kept on your account Set when you ask
Session records (your account id, when each session started and when it expires) So signing out ends that session, and so we can end every session you hold if a device is lost or access ends Recorded automatically each time you sign in
One-time links: email verification, password reset and email change To prove that an email address is yours before it is used Created when you sign up, ask for a reset, or change your email

Signing up. Anyone may ask for access by signing up with a name, an email address and a password, and accepting the Terms. We send a link to that address; once it is followed, your sign-up becomes an access request, and an admin approves or declines it. You cannot sign in until an admin approves you. A declined request is deleted, and no email is sent about it; you may ask again later. If you sign up with an address that already has an account, you are told the same thing as anyone else — check your email — and the email tells you that you already have an account, so the sign-up form cannot be used to find out who is registered.

We never store your password. It is hashed with scrypt (a deliberately slow, memory-hard algorithm) using a random 16-byte salt unique to your account. We cannot read, recover or tell you your password. If you forget it, you can ask for a password-reset link by email; a reset signs out every other device.

Passwords must be at least 8 characters. There are no other composition rules. A password that appears on a list of commonly used passwords is refused; that list is bundled with the Service and checked on our own server, so your password is never sent to any outside service to be checked.

There is no two-factor sign-in. An email address and password are the whole of what signs you in. We have chosen to keep sign-in simple for now; a strong password that you use nowhere else is therefore your main protection.

One-time links are stored only as a hash, work once, and expire: a verification link after 24 hours, a password-reset link after 1 hour, and an email-change link after 24 hours. Changing your email address requires your current password, the new address only takes effect once you follow the link sent to it, and your old address is told of the change.

A guest commentator's account is a different kind of account, with no password and no sign-up; Section 3.10 says what it holds.

3.2 Session cookie

The Service sets one cookie. It is strictly necessary for the Service to function — without it you cannot stay signed in.

Cookie Contents Duration Flags
rns_talent A random session identifier and an expiry timestamp — cryptographically signed (HMAC-SHA256) so it cannot be altered or forged. It does not contain your email address 30 days HttpOnly, Secure, SameSite=Lax

The 30-day life is deliberate: it means a commentator is not signed out on the morning of a competition, on venue wifi, minutes before going on air.

A guest commentator is given the same cookie when they open their invite link, on each device they open it on. Their session ends when their invite ends (Section 3.10), even if that is sooner than 30 days. A call-in guest is never given a cookie.

HttpOnly means page scripts cannot read it. Secure means it is only ever sent over HTTPS. It is a first-party cookie, it is not used for tracking or advertising, and it is not shared with anyone.

We use no other cookies. There are no analytics cookies, no advertising cookies, and no third-party cookies, so there is nothing to consent to or opt out of beyond signing out.

3.3 IP address — form protection only

When you submit the sign-in, sign-up or password-reset form, or open an invite link, your IP address is used to rate-limit attempts (a limit per account and a looser limit per address, because a commentary booth shares one venue connection).

So that a restart of the sign-in service does not reset these limits, each attempt is recorded in the sign-in service's own database for a rolling five-minute window. Your IP address is not stored as written: it is recorded only as a keyed hash, which cannot be turned back into the address without the service's secret key. The record is deleted when the window passes, and when you sign in successfully. It is not used to identify, locate, profile or track you.

3.4 Server logs and usage records

Our web server and reverse proxy generate operational logs in the ordinary course of serving requests, which may include IP address, timestamp, requested path, response status, and user agent. These are used only to operate and secure the Service and to diagnose faults, and are not shared with any advertising or analytics provider.

Separately, we keep a usage record for signed-in members and guest commentators using the commentator applications, so that we can tell what is worth building, what is worth removing, and what is quietly broken. It is first-party: it is written to our own server by our own sign-in service, and no third party is involved in producing, storing or reading it.

It contains, for each entry:

Recorded Example
The date and time 2026-08-25T13:04:11Z
The account your account id (Section 3.1) — an internal identifier, not your email address
The page requested, without its query string /shows/eventing/aec-2026-08/
For in-application activity, the name of the control used citation, course-map
The division and phase on screen, and your text-size and daylight settings Preliminary, cross-country, large, sun
A coarse device class and a screen width rounded to the nearest 100 pixels tablet, 1000
Any error the application encountered TypeError … app.js:2211

It deliberately does not contain, and this is enforced in the software rather than by policy alone:

We do not use it to evaluate you as a professional, and it is not shared with the broadcaster, the competition organiser, or anyone else. It is retained for the period given in Section 7. If you would prefer not to be recorded, write to privacy@reelneetsolutions.com and we will switch it off for your account. That choice is kept on your account itself, so it stays in force if you change your email address.

3.5 Stored on your device, never sent to us

The commentator applications remember a small preference in your browser's local storage. It stays on your device. It is never transmitted to us and we cannot read it.

Stored item What it is
booth.volume.v2 The volume levels you set in the Booth — for the programme, for your own microphone in your headphones, and for each other voice by seat number

You can clear it by clearing site data in your browser.

3.6 Operational content you generate

When you ask for a graphic from the booth, your name (Section 3.1) is sent to the production system along with your request, so the operator knows who asked. This is visible to production personnel on the operator console.

When you write a note on a rider, horse or pair, the note is stored on our server with your account id, and is shown with your name to the other commentators on that show. The same is true of a line you mark as said on air.

3.8 The live commentary booth

If you are seated in a show's commentary booth, the Booth screen connects your browser to a live audio and video call so you can hear and see the broadcast and your fellow commentators, and they and the production can hear you. The call runs through VDO.Ninja, a third-party peer-to-peer (WebRTC) service: your microphone and camera travel directly between the participants' browsers and the production machine, relayed by VDO.Ninja's servers only where a direct connection cannot be made. The Service does not record the call. The production may broadcast your voice, and at times your picture, as part of the programme — that is the purpose of the booth. Your browser asks your permission before your microphone or camera is used, and you can mute yourself at any time.

We store which seat you hold against your account so the Booth can put you in it. When you ask for a graphic, your name is sent with the request (see 3.6).

Call-in guests. A call-in guest joins through VDO.Ninja too, from the page their invite link opens, but first into a waiting room: a separate VDO.Ninja call that is not the booth. Their name, as it appears on the invite, is their label in the queue, and their camera and microphone are connected from the moment they join it. Admins, and the member commentators on that show, see the names of the call-in guests who are waiting, and one of them lets a guest into the booth, where the guest can be heard and seen on air. Only one call-in guest is on air at a time. The Service does not record the waiting room or the call. To show who is waiting and to let a guest in, our server asks VDO.Ninja for the waiting room's queue and tells it which waiting guest to move; it sends VDO.Ninja nothing about the guest beyond what the guest's own browser already gave it. A call-in guest never sees rider data, notes or graphics.

3.7 What we do not collect

We do not collect: payment or financial information; government identification; date of birth; precise location or GPS; contacts; photographs of you; biometric data; device fingerprints; advertising or cross-site behavioural profiles; health information; or any special category / sensitive personal information as those terms are used under GDPR or U.S. state privacy laws.

The usage record described in Section 3.4 is a record of how our own software was used, held by us and used only to improve it. It is not an advertising or cross-site profile, it is never combined with data from anywhere else, and the fields most useful for building a profile — your IP address, your user agent, your exact screen size and anything you type — are the ones it specifically refuses to keep.

The emails we send carry no open or click tracking: no tracking pixel, and no link rewritten to pass through a tracking address. This is switched off at Resend and stays off. If that ever changes, this policy will change first.

We do not track you across other websites, and the Service sends no "do not sell or share" signal-relevant data to anyone because there is no such sharing.

3.9 Email we send

We send email only to run your account. We send no newsletters, no marketing and no reminders. Every email is sent through Resend (Section 5), from a reelneetsolutions.com address. Resend is the only service that sends email for that domain.

Email Sent to When
Verify your email address You When you sign up
You already have an account You When someone signs up with an address that already has an account
An access request is waiting Every admin, with the name and email address of the person asking When an access request's email address has been verified
You're approved You When an admin approves your access request
Reset your password You When a reset is asked for with your address
Confirm your new email address Your new address When you change your email address
Your email address was changed Your old address When the change takes effect
You're invited as a guest commentator The invited guest, at the address given by the member who invited them When the invite is made, and again with a new link if it is reissued
You're invited as a call-in guest The invited guest, at the address given by the member who invited them When the invite is made, and again with a new link if it is reissued

No email is sent when an access request is declined.

3.10 Invited guests

A guest does not sign up. A member — an admin, or a member commentator on that show — invites them onto one show by giving us their name and email address, and we email them a personal invite link. The invite works from the moment it is made and ends at midnight at the venue at the end of the show's last day, or sooner if it is revoked. Reissuing an invite ends the old link and emails a new one. In this section "you" means an invited guest.

What we hold about any invite:

Data Why How obtained
Your name So the people you are working with know who you are, and so the invite email can greet you Given by the member who invited you
Your email address Where we send your invite link Given by the member who invited you
Which kind of guest you are, and the show So the link lets you into that show, in the right way, and nowhere else Set by the member who invited you
The invite link (hashed) To let you in without a password Created when the invite is made or reissued. We keep only a hash of it
The invite's status and when it ends: active, revoked or expired So a revoked or expired link stops working, and so inviters and admins can see and manage their invites Recorded automatically, and changed when the invite is revoked or reissued
When you agreed to the Terms A record that you agreed before you entered Recorded when you agree on the invite page

If you are a guest commentator, the invite creates an account for you of the guest kind. It has no password and no email sign-in; your link is what lets you in, on any device you open it on, until the invite ends. It holds:

Data Why How obtained
Account id As for a member (Section 3.1): it keeps your notes and seat yours, and is never shown or reused Created automatically when you are invited
Name How you are named to the show's commentators — on your notes, said-on-air marks and in the booth Taken from the invite
The seat you hold A guest commentator is given the next free seat that is not on air; an admin may move you on air Set automatically when you are invited, and changed by an admin
Session records As for a member (Section 3.1). Revoking your invite ends every session it created Recorded each time you open your link on a device

A guest commentator can read every show and every subject, as a member can, and can write notes and mark lines as said on air on the show they were invited to only. Those notes are stored and shown with your name exactly as a member's are (Section 3.6). A guest commentator cannot invite anyone or let a call-in guest in. Your use of the applications is in the usage record (Section 3.4) under your account id, and you can ask us to switch that off.

If you are a call-in guest, you have no account, no session and no cookie. Your link opens a page with instructions and a camera and microphone check; once you agree to the Terms there, it lets you join the waiting room (Section 3.8). What reaches others is your name, in the waiting-room queue, seen by admins and the show's member commentators, and your camera and microphone, in the waiting room and then in the booth. Your use of that page is not in the usage record.

4. How we use member information

We use the limited information above only to:

Purpose Data used Legal basis (GDPR, where applicable)
Authenticate you and keep you signed in Email, password hash, account state, session cookie Performance of a contract; legitimate interests
Take a sign-up and verify that the email address belongs to the person signing up Name, email, password hash, verification link, IP address (transient) Steps taken at your request before entering into a contract; legitimate interests (security)
Tell admins an access request is waiting, and let an admin approve or decline it Name, email, account state Steps taken at your request before entering into a contract; legitimate interests (controlling access to confidential material)
Tell you that you are approved Name, email Performance of a contract
Reset a forgotten password, or change your email address Email, password-reset or email-change link, IP address (transient) Performance of a contract; legitimate interests (security)
Issue, administer, suspend and withdraw access, and assign commentators and seats Account id, name, email, creation date, account state, show assignments and seat history, session records Legitimate interests (controlling access to confidential material)
Invite a guest commentator or a call-in guest onto a show, email them their link, let them in, and revoke or reissue the invite The guest's name and email address as given by the member inviting them, the show, the kind of guest, the invite link (hashed), the invite's status and expiry, and for a guest commentator their seat and session records; IP address (transient) Legitimate interests (bringing a guest the show has chosen into its commentary, and controlling access to confidential material); performance of a contract once the guest has agreed to the Terms on the invite page
Show a call-in guest's name in the waiting-room queue, and move them into the booth The call-in guest's name, as the label on their place in the queue Legitimate interests (letting the right person into a live broadcast); performance of a contract once the guest has agreed to the Terms
Protect the forms from brute-force attacks and automated sign-ups IP address (transient) Legitimate interests (security)
Operate, secure and debug the Service Server logs Legitimate interests (security and service integrity)
Understand which parts of the applications are used, so we can improve them and remove what is not Usage record (Section 3.4) Consent, which you may withdraw at any time by writing to us
Find and fix errors the applications hit while you are on air Usage record (error entries) Legitimate interests (service integrity)
Receive and act on a bug report or feature request you send The text you write, and the screen you were on Performance of a contract; legitimate interests
Contact you about your access, or a material change to our terms Email Legitimate interests; legal obligation where applicable
Name you on your notes, in the booth, and on a graphic you ask for Name Performance of a contract

The information about an invited guest comes from the member who invited them, not from the guest.

We do not use your information for marketing, advertising, automated decision-making, or model training. Every access request is decided by a person, an admin. We do not profile you as a person: the usage record in Section 3.4 measures how the software was used so that we can improve it, and is never used to evaluate you, rank you, or make any decision about you.

5. Who we share information with

We do not sell your personal information. We do not share it for advertising or cross-context behavioural advertising. We do not disclose it to data brokers. We have not done so in the preceding twelve months.

We share information only in these circumstances:

Recipient What they receive Role
Our hosting provider (virtual private server) Everything stored on the server, incidentally, as the operator of the infrastructure Processor
Production personnel for the competition you are working on Your name when you ask for a graphic Joint operational use
Other members Your name, on your notes and said-on-air marks and in the booth; and, for admins, your name, email address and account state so they can approve, suspend and assign Within the Service
Other members and guest commentators, about an invited guest A guest commentator's name, on their notes and said-on-air marks and in the booth, as for a member. A call-in guest's name, in the waiting-room queue, to admins and that show's member commentators. The list of invites — each guest's name, email address, kind and status — to admins for every show, and to member commentators for their own show Within the Service
VDO.Ninja (peer-to-peer call service) Only if you are seated in a commentary booth: your live microphone and camera, and your name as the call label, while the Booth is open. For a call-in guest: their live microphone and camera, and their name as the label on their place in the waiting-room queue, from when they join the waiting room until they leave the booth. Not recorded by us (see 3.8) Service provider
Resend (Plus Five Five, Inc., USA), which sends the Service's email For each email in Section 3.9: the recipient's email address and name, the subject, the full message including any verification, password-reset or invite link in it, the record of whether it was delivered, and the log of our request to send it. Resend keeps this for 30 days, and in its backups for 7 days more; if we stop using Resend, what remains is deleted within 90 days. An address that bounces or complains may stay on its list of addresses not to send to. It is stored in the United States and delivered through Amazon Web Services' email service. Resend uses sub-processors, listed at resend.com/legal/subprocessors, and gives at least 14 days' notice before it adds or replaces one. Open and click tracking is off (see 3.7) Processor
GitHub (GitHub, Inc.), where our source code and issue tracker live Two things. When you send a bug report or feature request from inside an application: the text you wrote, your account email, and the screen you were on. And our encrypted backup (Section 8): a copy of the account records (including access requests, invites and guest commentators' accounts), session records, the record of which shows and seats each account is assigned to, and notes held on our server. It is copied over an encrypted connection to a short-lived GitHub build machine, which holds it only in memory and encrypts it there before it is stored; GitHub does not hold the key that opens it, so it cannot read what it stores. Nothing else reaches them — the usage record in Section 3.4 never leaves our own server Processor
OpenStreetMap Nominatim (run by the OpenStreetMap Foundation), a place-name lookup Only the name and address of a competition venue, once, when a show is set up, so that we can work out the show's timezone. It never receives anything about a person — no member's, no competitor's — and your browser never contacts it Service provider
Apify (Apify Technologies s.r.o.), a data-collection service Only the public account name of a competitor on Instagram, Facebook or Threads, when we refresh a show's social posts, so that it can return the addresses and dates of that account's newest public posts. It never receives anything about you, and your browser never contacts it Service provider
Instagram, Facebook and Threads (Meta Platforms, Inc.), TikTok, YouTube (Google LLC) and X (X Corp.) Only when you view a rider's social posts on a pair's page (Section 5.2): what any browser gives a site it loads content from — your IP address, your browser's details, and that the post was shown on our site. The platform may set its own cookies and run its own code inside the post, under its own privacy policy. We send it nothing about your account Independent controller
Legal or regulatory recipients Only where compelled by valid legal process, or where necessary to establish, exercise or defend legal claims, or to protect the safety of any person As required
A successor In connection with a merger, acquisition or sale of assets, subject to this policy Controller

5.1 A note on the live scoring proxy

When a Show Application displays live scores, the request goes to our own scoring service rather than directly to the competition's scoring provider. That relay is configured to strip your IP address, your cookies and the referring page before the request leaves our infrastructure. The upstream provider therefore receives no information identifying you or your session.

5.2 A note on fonts, images and social content

Typefaces are self-hosted — downloaded when the Service is built and served from our own domain. Rider photographs are fetched once, when the application is built, downscaled, and embedded directly into the application file.

Riders' social media posts are different, and are the one place a social media platform's own code runs in the Service. When you open a pair's page and the rider has public posts we show, each post appears in the platform's own embed — the same post, drawn by the platform, that you would see on Instagram, Facebook, Threads, TikTok, YouTube or X — and your browser loads it directly from that platform. That means the platform receives what any embedded post gives it: your IP address, your browser's details, and that the post was shown on our site. It may set its own cookies and run its own code inside the post, under its own privacy policy. We send it nothing about your account. To keep this small:

The posts shown are chosen on our server, not in your browser: before a show, our server fetches the addresses and dates of each rider's newest public posts — through Apify for Instagram, Facebook and Threads, and directly from TikTok, YouTube and X. Those requests name the rider's public account and carry nothing about you.

Apart from riders' social posts, your browser makes no request to Google, Meta, X, TikTok, YouTube or any other third party, and none of them learn that you opened the Service. The other exception is the booth call in Section 3.8, which your browser joins through VDO.Ninja only when you open the Booth, or, for a call-in guest, when you join the waiting room. A downloaded Show Application makes no network request at all.

There are three places where information about you reaches a third party from our server, and it is never your browser that sends it: when we send you an email, our own server passes it to Resend; if you choose to file a bug report or feature request, our own server passes it to GitHub; and our backup is encrypted on a GitHub build machine and stored with GitHub, which cannot read it. All three are described in the table above, as is the venue lookup, which carries nothing about any person. Our server also asks VDO.Ninja who is waiting in a waiting room, and tells it which waiting guest to move into the booth (Section 3.8); that passes VDO.Ninja nothing it did not already have from the guest's own browser. Nothing else does — in particular the usage record in Section 3.4 is written to our own disk, goes nowhere, and is not in the backup.

6. International transfers

The Service is operated from the United States and runs on a virtual private server supplied by a third-party hosting provider. If you access the Service from outside the country in which that server sits, your information will be transferred across borders.

Where personal information of individuals in the European Economic Area or the United Kingdom is transferred to the United States, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses where applicable, and we minimise what is transferred — for members and invited guests, that is a name, an email address and the emails in Section 3.9. Those emails are stored by Resend in the United States; that transfer relies on the Standard Contractual Clauses (Module Two, controller to processor) built into Resend's data processing agreement, with the UK Addendum for the United Kingdom, and on Resend's certification under the EU-U.S. Data Privacy Framework and its UK Extension. You may ask us at privacy@reelneetsolutions.com where the Service is currently hosted.

7. Data retention

Data Retained
Account record (account id, name, email, password hash, dates, account state) For as long as your account exists. When the account is deleted, see Deleting an account below
A sign-up whose email address is never verified Deleted after 24 hours
An access request no admin has decided Deleted after 30 days
A declined access request Deleted when it is declined. No email is sent
Invites (the guest's name and email address, the show, the kind of guest, the invite's status and expiry, and when the guest agreed to the Terms; the link kept only as a hash) The link works until midnight at the venue at the end of the show's last day, or until the invite is revoked or reissued. The invite record is then kept with the show's assignment and seat history, as a production record of who was invited onto which show
A guest commentator's account (account id, name, seat) Kept after the invite ends, so that their notes and said-on-air marks stay credited to them; it can no longer be used. When it is deleted, see Deleting an account below
One-time links (email verification, password reset, email change) Until used or expired — 24 hours, 1 hour and 24 hours respectively — and kept only as a hash
Session cookie and session record 30 days from sign-in — for a guest commentator, no later than the end of their invite — or until you sign out, sign out everywhere, reset or change your password, change your email, or we revoke it or the invite that created it; the record is deleted then, or when the account is deleted
Login rate-limit data (IP address as a keyed hash) Five minutes
Server logs For a short operational period, then rotated and discarded in the ordinary course
Usage record (Section 3.4) Through the competition season it was recorded in, and deleted after 90 days
Resend's copy of each email (Section 5) 30 days, plus 7 days in Resend's backups
Show assignments and seat history Retained as a production record of who called which show
Notes and said-on-air marks Retained as a production record of past competitions. When the author's account is deleted, see below
Encrypted backups (Section 8) of account records, access requests, invites, session records, show assignments and notes Kept in our private source repository as a history of past backups, so that the Service can be recovered. A record removed from the server remains, encrypted, in backups taken before its removal; only we hold the key, and a backup is opened only to recover the Service
Show content (dossiers, orders, prepared copy) Retained as a production record of past competitions

Deleting an account. You can delete your account yourself from account settings, an admin can delete it, or you can write to us and we will. Deletion removes your name, your email address and your password, and ends every session you hold. The notes you wrote and the lines you marked as said on air stay, because the other commentators on those shows rely on them, but they are credited to "a former commentator" rather than to you. The account id that tied them together is kept only for that purpose; it is never shown and never given to anyone else. Usage-record entries under that id are deleted on their normal 90-day schedule. A guest commentator has no account settings: to have their account or an invite deleted, a guest writes to us, and the same rules apply — their notes stay, credited to "a former commentator".

Suspension. An admin may suspend an account. A suspended account is kept whole — including your name on your past notes — but cannot sign in until an admin lifts the suspension.

Note that we cannot retrieve or delete any Show Application you have already downloaded to your own device — that copy is in your control, and under our Terms you must delete it.

8. Security

Security is the reason this Service is built the way it is. Measures include:

No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and any regulator as required by applicable law.

9. Your rights

Depending on where you live, you may have the right to:

Given how little we hold about members, most requests can be answered simply: for almost every member, the complete record is an account id, a name, an email address, a password hash, a few dates, the state of the account, the shows and seats it has been assigned, its open sessions, and the notes it has written. You can change your name, email address and password, and delete your account, yourself in account settings.

For an invited guest the record is smaller still: the invite (a name, an email address, a show, a status and an expiry), and, for a guest commentator, an account id, a seat, sessions and the notes written. A guest has no account settings, so a guest exercises every right by writing to us.

To exercise any right, write to privacy@reelneetsolutions.com. We will respond within the time required by applicable law (generally 30 days under GDPR, 45 days under California law, extendable where permitted). We may need to verify your identity, which we normally do by corresponding with the email address on the account.

9.1 If you are in the European Economic Area or the United Kingdom

You may lodge a complaint with your local supervisory authority. We would appreciate the chance to address your concern first.

9.2 If you are a California resident

Under the CCPA/CPRA, in the preceding twelve months we have collected the category of identifiers (name, email address, IP address) and internet or network activity, including browsing and interaction history with our own applications (server logs, and the usage record described in Section 3.4) for the business purposes described in Section 4.

We have not sold or shared personal information, and do not do so. We do not use or disclose sensitive personal information for purposes requiring a right-to-limit disclosure. You have the rights described in Section 9, and we will not discriminate against you for exercising them. You may use an authorised agent, with proof of authorisation.

9.3 Other U.S. states

Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and others) have broadly equivalent rights of access, correction, deletion, portability and appeal. Write to privacy@reelneetsolutions.com. If we decline a request you may appeal by replying to our decision; we will respond to an appeal within the period your state's law requires.

10. Information about competitors, owners and others featured in the Service

This section is about people who are not our members.

10.1 What the Service holds

To support broadcast commentary, the Service assembles research about the competitors and horses entered in a competition. Depending on the competition and the individual, this may include:

Each item carries an internal record of where it came from — a scoring or entry registry, a governing body, published research, or a social media post.

10.2 Where it comes from

This information is obtained from: the competition's entry and scoring provider; governing body athlete databases; publicly available published sources; and public social media posts. It is not obtained from the individuals themselves, and they do not have accounts.

10.3 Why we process it, and our legal basis

We process it for the legitimate interests of preparing and delivering broadcast commentary about a public sporting competition — an established and expected use of information about competitors who have entered a public event. We have considered the interests and rights of those individuals and limited what we hold to what serves that purpose.

Where a competitor is in the EEA or the UK, our legal basis is legitimate interests (GDPR Article 6(1)(f)). Where information has manifestly been made public by the individual, such as a public social media post, we also rely on that fact.

10.4 How it is protected and limited

10.5 Rights of competitors and other featured individuals

If you are a competitor, a horse owner, or another person featured in the Service, you may ask us to:

Write to privacy@reelneetsolutions.com. Tell us your name and the competition. We will act on a correction promptly. On an objection or deletion request we will stop processing and remove the material unless we have compelling legitimate grounds that override your interests, and we will explain our reasoning either way.

Note that we cannot alter information held by a governing body, a scoring provider or a social media platform — only what appears in our Service — and we cannot recall an application already downloaded to a member's device, though we will remove the material from any future build.

11. Children's privacy

The Service is a professional tool for accredited broadcast personnel. It is not directed to children, and we do not knowingly approve accounts for, invite, or knowingly collect personal information from, anyone under 18. If we learn that we have collected personal information from a child under 13 (or the applicable age in your jurisdiction), we will delete it promptly. Contact privacy@reelneetsolutions.com if you believe this has occurred.

Note that competitors at equestrian competitions may include minors, and entry and result information about a junior competitor may therefore appear in the Service as part of the official record of a public competition. We hold no more about a junior competitor than the competition's own published entry and result data, and we apply Section 10.5 to requests concerning a minor, which a parent or guardian may make.

12. Changes to this policy

We may update this Privacy Policy. The "Last updated" date at the top always reflects the current version. If a change is material, we will make reasonable efforts to notify account holders by email or by a notice within the Service before it takes effect.

13. Contact

For any privacy question, request or complaint:

Michael Wesley Schiff, trading as Reel Neet Solutions Privacy: privacy@reelneetsolutions.com General: mschiff05@gmail.com

We handle privacy requests by email. If you require a postal address, ask and we will provide one.

We are the controller of the personal information described in this policy.