Built for youth sport

Safety & privacy at MatchReel.

Match video of children is sensitive. Here is exactly where yours lives, who can see it, and the controls you and your club have over it — written plainly, for the parents and volunteers who have to sign off on it.

Start free → Ask us a privacy question
Honest framing

MatchReel is designed around the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs), with defaults chosen for youth sport. We are not currently independently certified against ISO 27001, SOC 2 or IRAP. Where we say "aligned", we mean our architecture and defaults are built to help your club meet its obligations — not that a third party has audited us. We'll tell you the same thing on a call.

Private by default

When someone uploads or streams a match, it is visible to only that person and admins — not the whole club, and never the public. Sharing footage with a team is a deliberate action the uploader takes, not something that happens automatically. If you do nothing, your video stays private to you.

This is the opposite of the usual social-video default, and it is deliberate: with children's footage, the safe default is "seen by no one until you decide otherwise".

Data residency — your footage stays in Australia

Every live stream, recording, thumbnail and highlight clip is stored and served from AWS Sydney (ap-southeast-2). Your video does not leave the region for storage or playback. For an Australian club or association asked "where does this footage physically sit?", the answer is a single, in-country region.

Signed, private playback

MatchReel never serves your footage from a public, guessable URL. Streams and recordings are delivered through expiring signed links scoped to the viewer's session. A link that leaks is useless once it expires, and access to the app is authenticated per person.

Access follows real club structure rather than an open sign-up:

  • Anyone can create an account and watch public video and their own uploads.
  • Joining a team as a member, coach or manager is a request — team managers approve members and coaches, and admins approve managers.
  • A team's shared footage is visible to that team; a child's video isn't exposed to people who aren't part of their team.

The result is that seeing a young player's match requires being an approved part of that player's team, or the person who uploaded it.

Takedown & removal on request

Any parent or member can request that a video be removed. Requests go to admins, who can take footage down — including a soft-delete that immediately pulls a video from view while it's reviewed. You should never have to argue with a platform to get your child out of a video: ask, and it comes down.

Retention & deletion

You can delete your own uploads, and admins can delete anything across the club. Access to footage is logged so a club can see who viewed what, and those logs are kept only as long as they're useful and then aged out. When you leave, your data can be exported or erased — it isn't held hostage.

Minimal by design

MatchReel is a tool for clubs to record and share their own matches — it is not a people-search product, and it isn't built to profile or identify children beyond the player tags a club adds to its own footage. We collect what's needed to run the service (an email to sign in, and the video you choose to upload), and not more.

Alignment with the Australian Privacy Act & the APPs

Our defaults are chosen to help your club meet obligations that commonly apply when handling footage of identifiable people — especially minors — including:

  • APP 3 & 5 (collection & notice) — we collect the minimum to run the service and are upfront about it.
  • APP 6 (use & disclosure) — private-by-default, signed playback and role-based team access keep footage to the people who should see it.
  • APP 11 (security) — in-region storage, encryption in transit and expiring links reduce the surface for misuse or loss.
  • APP 11.2 / APP 12–13 (retention, access & correction) — you set what you keep, and you can export, correct or erase on request.

This is provided as plain guidance to help your own assessment; it is not legal advice. If your association, state body or the Privacy Act's Tranche 2 reforms impose stricter requirements, tell us — we'd rather scope that with you up front.

At a glance

Who can see it

Only the uploader and admins — until it's deliberately shared with a team. Never public by default.

Private · role-based

Where it's stored

AWS Sydney only. Footage does not leave ap-southeast-2 for storage or playback.

AWS Sydney · ap-southeast-2

How it's served

HTTPS/TLS everywhere; playback via expiring signed links, never a public URL.

TLS · signed · expiring

Your control

Request a takedown anytime; delete your uploads; export or erase your data.

Takedown · export · erase