Privacy Policy
Version 2026-09-17. Draft — not yet published. Effective date TODO: date of publication.
RacketPilot is a badminton stringing service operated by Mokuo Software LLC (“Mokuo”, “we”), registered at 5441 S Macadam Ave Ste N, Portland, OR 97239, United States. This policy covers the RacketPilot mobile apps, this website, and the accounts service at TODO: IdentityServer public hostname.
RacketPilot is operated from the United States and is offered in the United States. If you use it from somewhere else, your information is handled here.
For anything in this policy, write to privacy@racketpilot.com, or call 971-717-8866.
What we collect, and why
| What | Why |
|---|---|
| Your name and email address | To create your account, to sign you in, and so a stringer knows whose racket they have. |
| Your password, or your Google sign-in, or a passkey | To prove it is you. Passwords are stored only as a salted hash and never in a form we can read. A passkey stores a public key — the private half never leaves your device. |
| Your rackets, and the jobs you request — string, tension, extras, notes, and what happened to each | This is the service. It is also what lets a racket carry its own stringing history, so “the same as last time” means something. A racket record can include a brand, model, color, nickname and serial number, all of them yours to enter or leave blank. |
| The messages you send about a job | To deliver them, to keep the conversation readable afterwards, and to be the record when something needs sorting out. We store what you write. Blocking somebody stops further messages in both directions; it does not delete what was already said, because the record of a job belongs to both of you. |
| Reviews and ratings you leave | To show other players what a stringer’s work is like. A published review carries no reviewer name — we do not put one on it. Be aware that a stringer can often work out who left a review from the job it belongs to, because they know who they strung for. |
| Reports you make about a message or a review | So a person can look at it. A report records who reported what, the reason, and anything you typed. The person you report is not told that you did. |
| The stringers you mark as favorites | To put them at the top of your own list. Nobody else sees it. |
| If you are a stringer: your catalog and prices, your string stock, and the locations you serve | To price jobs, to keep your shelf figures right, and to show customers where you work. A serving location includes a street address, which you type; see what is public below, because the address is not. |
| If you are a stringer: the walk-in customers you write down | So a job for somebody who never used RacketPilot still has a name against it. You choose what to enter, and a phone number or email address is optional. You are the one who collected it, so tell that person it is here if they would want to know. |
| If you are a stringer: the labels you print, and the rackets you stick them on | So that scanning a sticker at the bench brings up the right frame. We store the code, the sheet it was printed on, when it was issued, and which racket it ended up on. A label carries no name and nothing about the racket - see labels on rackets below. |
| A profile photo, if you choose to add one | So the people you string for — or who string for you — know who they are dealing with. It is optional, you can replace or remove it at any time, and nothing about the service needs one. We remove the location and camera details a phone stores inside a photograph before we save it. Phones record where a picture was taken, and a photo taken at home would otherwise carry your address; we discard that on our own servers rather than trusting the app to do it, and we never keep the original file. |
| A photo you choose to send in a conversation | So you can show the other person what you mean - a cracked frame, a string that went, the grip you want. A message can carry one photo, with or without words. Only the two of you in that conversation can see it, plus, if the message is reported to us, whoever here reviews that report, who can take it down. We remove the location and camera details from it exactly as we do for a profile photo. Deleting your account deletes the photos you sent; the photos the other person sent you stay theirs. A photo that has been taken down or deleted shows as “Photo removed”. |
| Access to your camera or photo library, when you add a photo or scan a label | Two things use the camera, and you are asked at the moment you use either. Adding a photo, to your profile or to a message, lets you choose or take that one picture; we do not read your photo library, and nothing is uploaded but the image you pick. Scanning a label reads the code through the viewfinder on the phone itself - no picture is taken, nothing is saved, and the only thing that reaches us is the eight characters printed on the sticker. |
| A push notification token, if you turn notifications on | So we can tell you a racket is ready or a message arrived. It identifies your device to Apple’s or Google’s notification service, not you to them. Turn notifications off in your device settings and it stops being used; signing out retires it. |
| Technical logs — IP address, timestamps, error diagnostics | To keep the service running and to investigate faults and abuse. |
Location
If you are looking for a stringer, the app can use your device location, and it never leaves your phone. You are asked only when you tap for it, on the screen where you choose where to search from, and never when the app starts. The coordinates are kept in your device’s secure storage and used on the phone itself to work out roughly how far away each stringer is. They are not sent to us. There is a button on that same screen to forget them, and you can refuse or withdraw the permission in your device settings instead.
You can skip it entirely and type a zip code or a city. That is handled by your phone’s own address lookup.
If you are a stringer, we do not ask for your device location at all. You type the address of each place you serve, and the phone turns it into a map point. That address and that point are stored, and they are how a customer is told where to bring a racket.
Your street address is never published. On your public profile, and everywhere a customer or a passer-by can see, the address is withheld and the map point is deliberately blunted to roughly a kilometer, so it shows the area you work in and not your front door. That is done on our servers, not in the app, so it holds however the page is reached. Many stringers work from home, which is why it is built this way rather than left to a setting somebody has to find.
Labels on rackets
A stringer can print QR stickers and put one on a racket, so that scanning it at the bench brings up the right frame rather than the wrong one of two identical rackets. The sticker carries a code and nothing else - eight characters and a web address, with no name, no shop and nothing about the racket on it. A sticker on a frame in a bag can be read by anyone standing near it, which is exactly why there is nothing on it to read.
A code means something only to the shop that printed it. Scanning somebody else’s label in RacketPilot tells you nothing at all, and the answer is the same whether the code was never issued, was peeled off, or is on a racket in another stringer’s book. That is deliberate: telling those apart would confirm that a code is real and that some other shop knows that frame.
A label can be taken off, and once it is, that code is finished. It is never reissued, and nothing is ever printed twice.
What we do not collect
We do not take payment details. RacketPilot has no payments feature: money changes hands between you and your stringer directly, and no card number, bank detail or payout account passes through us. If that changes, this policy changes with it, and before the feature ships.
A screenshot of a payment that you choose to send your stringer is a message you sent, like any other photo in a conversation. It is not payment information we collect, and we do not read it unless the message is reported to us.
There is no analytics in RacketPilot, and no crash reporting. The app carries no analytics library, no crash reporter, no advertising library and no third-party maps library. We do not track what you tap, we do not build advertising profiles, we do not sell personal data to anybody, and we never have.
This website sets no cookies. It runs no analytics and loads nothing from anybody else — the fonts and styling are served from here. There is no cookie banner because there is nothing to consent to.
We do not ask for your contacts, your calendar, your microphone, or your location in the background.
Who else sees it
- Your stringer. When you request a job, the stringer you request it from sees your name and the details of that job. That is the point of the service.
- Anybody browsing, if you are a stringer. A stringer’s profile is public — that is how customers find one — so the display name, the description, the prices, the reviews, the general area and the photo on it are public too, and can be seen without an account. A player’s photo is not: it is shown only to the stringers they have booked with or messaged. Do not put anything in a public profile field that you would not want read by a stranger.
- SendGrid, which sends our account email. To send you a confirmation or a password reset they receive your email address, your name, and the link in the message. They send it on our behalf and may not use it for anything else.
- Firebase Cloud Messaging, run by Google, which delivers push notifications. It receives your device’s notification token and the short line you see on the lock screen. A message alert shows who it is from and the words “New message”, so Google receives the sender's name. We deliberately do not put message text, prices or racket details in a notification — you open the app to read what was said.
- Google, if you choose to sign in with Google. They tell us your email address and name; we tell them nothing about your rackets or your jobs. Google’s own privacy policy governs their side.
- Our hosting provider, TODO: hosting provider and region, which stores the data and the photos on our behalf and may not use it for anything else. Photos are held in private storage; every request for one goes through us.
- Somebody buying or merging with the business, if that ever happens. Your information would move with the service, still covered by a policy at least as protective as this one, and we would tell you.
- The authorities, where the law requires it of us, or where it is genuinely necessary to protect somebody’s safety or to deal with fraud.
- Nobody else.
Your data is stored in TODO: storage region.
How long we keep it
Your account and its job history stay until you delete your account. Deleting it from inside the app takes effect immediately: your name and contact details are removed everywhere they appear, your profile picture, the photos you sent in conversations and your notification tokens are deleted outright, and your sign-in credentials - password, passkeys, any Google link - are destroyed along with the login itself. Any label stuck to one of your rackets comes off at the same time, and that code is finished for good. Technical logs are kept for TODO: log retention period.
Being precise about what “removed” means here. RacketPilot is built on an append-only record of what happened, which is what lets a stringer keep an accurate history of work they carried out. Deleting your account removes your personal data from every part of the service: no screen, search or export can reach it, and nobody using RacketPilot sees it. A copy remains in that internal record, which is not shown to anyone and is not used to rebuild an account.
Three things survive deliberately:
- A stringer’s own business records of work they carried out, stripped of anything identifying you.
- Messages you sent, in the other person’s conversation, shown as being from a former user - their record of what was agreed as much as yours. Any photo you sent is not among them; it shows as removed.
- Reports you filed about somebody else, which are how that person is dealt with.
Your choices, and your rights
Whoever and wherever you are, you can ask us to:
- give you a copy of what we hold about you;
- correct anything that is wrong — most of it you can edit in the app yourself;
- delete your account and the data with it - in the app, under Account → Delete account, or by email if you cannot get in (see Support);
- stop sending you notifications, which you can also do in your device settings.
If you live in California, Colorado, Connecticut, Texas, Virginia or another state with a consumer privacy law, that law may give you the rights above by name, along with the right to appeal if we turn a request down. Ask, and we will tell you what we did and why. We do not sell personal information, and we do not share it for cross-context behavioral advertising — there is no advertising in RacketPilot at all. We will not treat you differently for exercising any of this.
Write to privacy@racketpilot.com. We may need to check it is really you before we act, which usually means replying from the address on the account.
Children
RacketPilot is not for children under 13, and we do not knowingly collect their information. Stringing for other people through RacketPilot is for adults, so a stringer must be 18. Junior players are common in badminton, so if a parent or guardian tells us we hold a child’s data we will delete it promptly — write to the address above.
Security
Traffic runs over HTTPS. Passwords are salted and hashed. Sign-in tokens are held in the device keystore — the Android Keystore or the iOS Keychain — rather than in ordinary app storage. No system is perfect, and we will tell you and the relevant authority if a breach affects you.
Changes
When this policy changes we will update the version and the date at the top, and for anything material we will tell you in the app before it takes effect.