Privacy Policy
Effective Date: March 13, 2026 | Last Updated: March 13, 2026
1. Introduction
Welcome to Roots of Glory (“the App,” “our App”). This Privacy Policy explains how Themelios Holding, LLC (“Themelios Holding,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects your personal information when you use the Roots of Glory mobile application on iOS devices and our website at rootsofglory.app (collectively, the “Service”).
Roots of Glory is a FIFA World Cup 2026 companion app that helps fans connect with their heritage, track matches, and explore the stories behind the nations competing in the tournament. We are committed to handling your personal data responsibly, transparently, and in compliance with applicable privacy laws.
By downloading, installing, or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the Service.
Questions about this policy: hello@rootsofglory.app
2. Who We Are (Data Controller)
Themelios Holding, LLC
Email: hello@rootsofglory.app
For users in the European Economic Area (EEA), United Kingdom, or Switzerland, Themelios Holding, LLC acts as the data controller for your personal data under the General Data Protection Regulation (GDPR) and applicable national data protection laws.
3. Age Requirements (COPPA Compliance)
The App is intended for users 13 years of age or older. We do not knowingly collect personal information from children under 13. If you are under 13, do not use the App or provide any information.
If we discover that we have inadvertently collected personal information from a child under 13, we will delete it immediately. Parents or guardians who believe we may have collected information from a child under 13 should contact us at hello@rootsofglory.app.
For users between 13 and 16 in the EEA, processing of personal data requires parental consent under GDPR Article 8. We rely on users to provide accurate age information.
4. The App Works Without an Account
You can use Roots of Glory without creating an account. Anonymous users can browse heritage stories, explore host cities, and view match information without providing any personal data.
When you use the App anonymously, we collect only technical data necessary to operate the App (e.g., device locale for displaying correct time zones) and aggregate, non-identifiable analytics if you opt in.
Account creation unlocks personalized features but is never required to access core content.
5. Information We Collect
5.1 Information You Provide Directly
Account Registration:
- Email address
- Password (stored as a cryptographic hash — we never store your plaintext password)
- Authentication method (Apple Sign-In, Google Sign-In, or Email/Password)
Profile Information:
- Display name (first name only)
- Avatar selection (preset options only — no photo uploads)
Heritage & Personalization Data:
- Country of residence (user-selected)
- Heritage countries (user-declared ancestral countries — multi-select, voluntary)
- Favorite teams (from World Cup 2026 nations)
- Favorite players
Communication Preferences:
- Newsletter/email marketing opt-in consent (unchecked by default; explicit opt-in required)
- Notification preferences (match alerts, goals, scores, player news, heritage stories, tournament milestones)
- Language preference
5.2 Information Collected Automatically
Device & Technical Data:
- Device locale (used to suggest your country of residence; you can change this)
- Push notification tokens (Apple Push Notification Service / APNs device tokens)
- App version and operating system version (for crash reporting and compatibility)
Usage Analytics (Optional — Requires Your Consent):
- Features used within the App
- Content viewed (heritage stories, team pages, player profiles)
- Tap interactions and navigation patterns
- Session duration and frequency
Analytics are collected in aggregate and anonymized form. You can opt out at any time via Settings → Privacy & Data → Analytics.
5.3 Website Data
When you visit our website (rootsofglory.app), we may collect:
- Email address — when you sign up for our waitlist or newsletter
- Usage data — pages visited, scroll depth, button clicks, and time spent on pages
- Device information — browser type, operating system, and screen resolution
- IP address — for general geographic location (not precise location)
- Referral data — how you arrived at our site (UTM parameters, referring URLs)
- Cookies and similar tracking technologies for analytics and performance measurement
5.4 Information We Do NOT Collect
We do not collect:
- Precise or approximate GPS location data
- Contacts or address book data
- Photos, camera, or microphone data
- Financial or payment information (the App is free)
- Social media profile data beyond what is needed to authenticate (name and email)
- Sensitive personal data such as biometrics, health data, or government ID numbers
6. How We Use Your Information
We use your information for the following purposes:
- Account management: Creating and managing your account (Legal basis: Contract performance)
- Personalization: Personalizing your experience based on heritage and favorites (Legal basis: Legitimate interest / Consent)
- Push notifications: Sending match alerts, goals, and heritage stories (Legal basis: Consent)
- Email communications: Sending newsletters and updates you opted into (Legal basis: Consent — explicit opt-in)
- App improvement: Improving the App through analytics (Legal basis: Consent)
- Support: Responding to support inquiries (Legal basis: Legitimate interest)
- Legal compliance: Complying with legal obligations (Legal basis: Legal obligation)
- Enforcement: Enforcing our Terms of Service (Legal basis: Legitimate interest)
We do not use your heritage country data for any purpose other than personalizing your in-app experience. We do not infer, validate, or share your heritage information with third parties.
7. Push Notifications
If you grant permission, we send push notifications about:
- Match kickoff for your favorite teams
- Goals scored by your favorite teams
- Final match scores
- Player news and lineup changes for your favorite players
- New heritage stories
- Tournament milestones (knockout rounds, semifinals, final)
You control all notification types individually within the App (Settings → Notifications). You can also disable all notifications through your device's iOS Settings at any time. Disabling notifications does not delete your account or affect other features.
8. Email Communications
If you opt in to email updates during account creation or in your profile settings, we may send you:
- World Cup match updates and results
- Heritage stories and cultural content
- Roots of Glory news and feature announcements
Opt-out: Every marketing email includes an unsubscribe link. You can also withdraw consent at any time via Profile → Privacy & Data → Email Updates toggle. We will process your opt-out within 10 business days.
We do not send marketing emails without your explicit, affirmative consent.
9. Sharing Your Information
We do not sell your personal information. We do not share your personal data with advertisers or data brokers.
We share data only in the following limited circumstances:
Service Providers (Processors)
We use trusted third-party service providers to operate the Service. These providers act as data processors and are bound by contractual obligations to protect your data:
- Railway — Backend hosting and database
- Apple (APNs) — Push notification delivery
- Google (Firebase Cloud Messaging) — Push notification delivery
- Google (Google Sign-In) — Authentication
- Apple (Sign In with Apple) — Authentication
- Email service provider — Newsletter delivery (opted-in users only)
- Analytics tools — Website traffic analysis
- API-Football / API-Sports — Sports data (no user data shared — read-only sports API)
Legal Requirements
We may disclose your information if required by law, court order, or government request, or if we believe disclosure is necessary to protect the rights, property, or safety of Themelios Holding, our users, or the public.
Business Transfers
If Themelios Holding, LLC undergoes a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you via email or in-app notice at least 30 days before any such transfer.
10. Sign In with Apple — Special Notice
If you use Sign In with Apple, Apple may provide a relay email address instead of your real email address. This relay address works for account login but may affect your ability to receive newsletters or email updates.
If you used a relay address and want to receive email communications, you can add your real email address in Profile → Edit Profile.
11. Data Retention
- Account and profile data: Retained while your account is active. Deleted within 30 days of account deletion request.
- Heritage and favorites data: Same as account data.
- Newsletter consent records: Retained for 3 years after opt-out (legal compliance).
- Anonymous analytics data: Retained for up to 24 months in aggregated, non-identifiable form.
- Push notification tokens: Deleted within 30 days of account deletion.
- Support correspondence: Retained for 2 years.
- Backup copies: May persist in encrypted backups for up to 90 days after deletion.
When you delete your account, we begin the deletion process immediately. Your data is removed from active systems within 30 days. Residual data in encrypted backups is purged within 90 days.
12. Your Privacy Rights
All Users
Regardless of your location, you have the right to:
- Access: Request a copy of the personal data we hold about you
- Correction: Request that inaccurate data be corrected
- Deletion: Delete your account and associated data (via Profile → Privacy & Data → Delete Account or by contacting us)
- Export: Download your data in a portable format (via Profile → Privacy & Data → Export My Data)
- Opt-out of email marketing: Unsubscribe at any time
- Opt-out of analytics: Toggle off in Profile → Privacy & Data → Analytics
California Residents (CCPA / CPRA)
California residents have additional rights:
- Right to Know what personal information we collect, use, disclose, and sell (we do not sell)
- Right to Delete personal information we have collected
- Right to Correct inaccurate personal information
- Right to Opt-Out of Sale/Sharing: We do not sell or share personal information for cross-context behavioral advertising
- Right to Non-Discrimination for exercising your CCPA rights
We collect heritage/ancestral country data, which may be considered sensitive personal information under CCPA. We use this only to personalize your in-app experience and do not disclose it to third parties.
EEA, UK, and Swiss Residents (GDPR)
If you are in the EEA, UK, or Switzerland, you have the following rights under GDPR:
- Right of Access (Article 15) — Obtain confirmation of whether we process your data and request a copy
- Right to Rectification (Article 16) — Have inaccurate data corrected
- Right to Erasure (Article 17) — Request deletion of your data (“right to be forgotten”)
- Right to Restriction (Article 18) — Request that we restrict processing of your data
- Right to Data Portability (Article 20) — Receive your data in a structured, machine-readable format
- Right to Object (Article 21) — Object to processing based on legitimate interests
- Right to Withdraw Consent (Article 7) — Withdraw consent at any time without affecting prior lawful processing
- Right to Lodge a Complaint with your local supervisory authority
To exercise any GDPR right: hello@rootsofglory.app. We will respond within 30 days.
13. Data Security
We implement industry-standard security measures to protect your information:
- Passwords are stored as cryptographic hashes (never in plaintext)
- Data is encrypted in transit using TLS/HTTPS
- Database access is restricted to authorized personnel only
- Our hosting infrastructure provides encrypted storage
- Access controls and authentication are required for all backend systems
No security system is perfect. In the event of a data breach affecting your rights, we will notify affected users and applicable regulators as required by law.
14. International Data Transfers
Roots of Glory is operated from the United States. If you are located outside the United States, your data will be transferred to and processed in the United States and potentially other countries where our service providers operate.
For EEA/UK/Swiss users, we ensure that international transfers are protected by appropriate safeguards, including Standard Contractual Clauses (SCCs) as approved by the European Commission, or other lawful transfer mechanisms under GDPR Chapter V.
15. Cookies and Tracking (Website)
Our website may use cookies and similar tracking technologies (pixels, web beacons) to collect usage data. Cookies are small data files stored on your device.
You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, some features of the website may not function properly without cookies.
We use cookies for:
- Analytics and performance measurement
- UTM campaign tracking
- A/B testing (when applicable)
App Tracking Transparency: We do not engage in cross-app or cross-site tracking and do not use Apple's Advertising Identifier (IDFA) for advertising purposes.
16. Apple App Store — Additional Disclosures
This App is distributed through the Apple App Store. Apple's collection and use of your data is governed by Apple's Privacy Policy. Themelios Holding is solely responsible for the App and its content. Apple is not a party to this Privacy Policy.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the “Last Updated” date at the top of this policy
- Notify you via in-app notification or email at least 30 days before changes take effect
- For material changes affecting how we use your data, request your fresh consent where required by law
Continued use of the Service after the effective date of updated terms constitutes acceptance of the updated policy.
18. Contact Us
For any privacy-related questions, requests, or complaints:
We will respond to all legitimate inquiries within 30 days.