This website uses cookies for login and basic functionality. By using this site you agree to our Privacy Policy.

Please rotate your device to portrait

MESHPRO Shotmetrix BETA
🇩🇪
Latest
Compete August Championship LIVE MY10 Masters Duel Groups Leaderboard
Live now 0
More Analysis About the app Community Guidelines

Sign in to access all features

Privacy Policy

Last updated: 24 August 2026 · Version 2.0

Thank you for your interest in MESHPRO Shotmetrix. Protecting your personal data matters to us. Below we inform you pursuant to Articles 13 and 14 GDPR which data we process, for what purpose, on what legal basis, how long we store it and what rights you have. The German version prevails in case of discrepancies.

1. Controller

Kemmer Edelstahlschlosserei GmbH
Böhringerstraße 39/1
78315 Radolfzell am Bodensee, Germany
Local Court Singen/Htwl., HRB 550308

Email: support@shotmetrix.com
Data protection enquiries: support@shotmetrix.com

Further details can be found in the imprint.

2. Principles

  • We only collect data we need to operate the platform.
  • We use no tracking, analytics or advertising cookies and share no data for advertising purposes.
  • We do not sell personal data.
  • All transmission is encrypted (TLS/HTTPS); passwords are never stored in plain text, only as a cryptographic hash using a recognised, deliberately slow algorithm reflecting the current state of the art.

3. Hosting and server log files

Shotmetrix runs on servers of a hosting provider located in Germany. A data processing agreement pursuant to Art. 28 GDPR is in place with that provider.

With every request the server automatically processes access data: IP address, date and time, requested address, volume of data transferred, status code, referrer, and browser and operating system identifiers. This data is technically required to deliver the page and serves stability and security (detecting and preventing attacks and abuse).

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure, functional operation). Retention: access and error logs are kept only as long as needed for troubleshooting and abuse prevention, as a rule for a maximum of 90 days, after which they are deleted or anonymised.

4. Processing activities in detail

4.1 User account and login

Data: username, email address, password hash, optional profile details (display name, avatar, bio, club, disciplines, language, display options), registration and last-activity timestamps, email confirmation status.
Purpose: providing and administering your account, login, attributing your content, password reset, security notices.
Legal basis: Art. 6(1)(b) GDPR (user agreement).
Retention: until the account is deleted.

4.2 Content, posts and analysis data

Data: uploaded images and files, imported analysis data (e.g. hit coordinates, ring values, Teiler, timestamps, discipline, equipment used), post texts, comments, likes, follows, group membership, streaks, points and badges.
Purpose: displaying your results and posts, analysis and comparison features, social features, groups and statistics.
Legal basis: Art. 6(1)(b) GDPR.
Visibility: public posts may — depending on platform settings — be visible to visitors who are not logged in and may be indexed by search engines. You can set posts to private, archive or delete them at any time.
Image files: metadata contained in a file (EXIF, e.g. capture time or geolocation) may be transmitted on upload. Where possible, upload images without unnecessary metadata.
Retention: until you delete the content or your account.

4.3 Automated analysis (image recognition and AI)

We use image recognition and AI models to evaluate target photos, result documents and session files.

  • Processing on our own infrastructure: detection of shot holes and preparation of the data take place on servers operated by us.
  • External AI service: to read result documents (text recognition) we transmit the relevant file or image section to a specialised provider of machine text recognition, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (with possible onward processing by Google LLC, USA). Transmitted are the document and the analysis request — no account data. According to the provider, content submitted via the API is not used to train its models.

Purpose: extracting results from your uploads so you do not have to enter them manually.
Legal basis: Art. 6(1)(b) GDPR (providing the analysis you requested); where you expressly consent to AI analysis when booking a competition entry, additionally Art. 6(1)(a) GDPR.
Third-country transfer: processing in the USA is possible. It is based on the European Commission's adequacy decision for the EU-US Data Privacy Framework or on standard contractual clauses pursuant to Art. 46(2)(c) GDPR.
Retention: results are stored with your post; intermediate processing files are deleted on completion or shortly thereafter.

No automated decision with legal effect: the analysis serves to display and compare results. Automated plausibility checks may mark a competition result as invalid; on request such a decision will be reviewed by a human (Art. 22(3) GDPR).

4.4 Data import from measuring devices and third-party services

When you import a QR code from an electronic scoring system (e.g. DISAG), Shotmetrix retrieves the corresponding analysis data from that provider's servers. The identifier contained in the QR code is transmitted; the provider is responsible for processing on its own systems.
Legal basis: Art. 6(1)(b) GDPR (import initiated by you).

4.5 Competitions, duels and public leaderboards

Data: display name or name, where applicable club/team, discipline, submitted results, submission time, scoring status.
Purpose: running and documenting competitions, 1vs1 duels, group scoring and challenges, and displaying leaderboards. Competition leaderboards may be publicly accessible.
Legal basis: Art. 6(1)(b) GDPR (participation) and Art. 6(1)(f) GDPR (legitimate interest in transparent, manipulation-free scoring).
Retention: for the duration of the competition and its documentation; afterwards anonymised or deleted.

4.6 MY10 MASTERS (start cards and start codes)

For the “MY10 MASTERS” competition there is an interface to the organiser's shop. Data: email address, start code, booked discipline and entry type, order reference, timestamp, payment status (without payment details), participation and result status, team/partner details. We do not process payment data; it stays with the shop and its payment provider.
Purpose: matching your start card, issuing and validating the start code, granting upload access, scoring and competition communication.
Legal basis: Art. 6(1)(b) GDPR.
Retention: until the competition is concluded; the organiser's tax and commercial retention obligations remain unaffected.

4.7 Email notifications

We send transactional emails (registration confirmation, password reset, start code, security notices) on the basis of Art. 6(1)(b) GDPR.

Competition notifications (e.g. start of the qualifying round, reminders, results) are sent only if you enabled them when booking or in your settings — legal basis: Art. 6(1)(a) GDPR. To evidence consent we store the time, the subject of the consent and the IP address (Art. 7(1) GDPR). You may withdraw consent at any time — via the unsubscribe link in every notification email, in your settings, or by emailing us. Withdrawal takes effect for the future.

Emails are delivered by an SMTP service provider acting on our behalf (processing agreement pursuant to Art. 28 GDPR).

4.8 Messages and groups

Direct messages and group posts are stored for delivery and display. They are not end-to-end encrypted; administrators may access them for abuse prevention and when content is reported. Legal basis: Art. 6(1)(b) and (f) GDPR. Retention: until deleted by the participants or until account deletion.

4.9 Security, abuse prevention and moderation

To prevent attacks, spam and multiple use we store IP addresses and timestamps for login attempts, form submissions and uploads (rate limiting), content reports, moderation decisions, and logs of administrative actions and failed uploads.
Legal basis: Art. 6(1)(f) GDPR (platform security, enforcing the terms of service).
Retention: rate-limit records for a short period (hours to days); reports and moderation records for as long as needed to handle them, keep them auditable and prevent repeat violations.

4.10 Contacting us

If you write to us by email, we process your details to handle your enquiry (Art. 6(1)(b) or (f) GDPR). Correspondence is deleted once it is no longer needed and no retention obligation applies.

5. Cookies and local storage

We use strictly necessary cookies and local storage only:

  • Session cookie (e.g. PHPSESSID): keeps you logged in during your visit; deleted when the browser closes or the session expires.
  • Preferences: language, appearance (light/dark), collapsed menu sections and similar interface states — partly as cookies, partly in your browser's local storage (localStorage).
  • Security tokens protecting forms against cross-site request forgery (CSRF).

This storage is strictly necessary to provide the service you expressly requested (Section 25(2) no. 2 TDDDG); no consent is required for it. Legal basis for the subsequent processing: Art. 6(1)(b) and (f) GDPR. No tracking, statistics or advertising cookies are set and no profiles are built for advertising purposes.

6. Recipients and external content

We disclose personal data only where necessary for operation or where we are legally obliged to. Categories of recipients:

  • Hosting provider (server operation, data centre in Germany) — processor.
  • Email service provider (SMTP delivery) — processor.
  • Google Ireland Limited / Google LLC — machine text recognition in result documents (see 4.3).
  • Providers of electronic scoring systems (e.g. DISAG) — for the QR import you initiate (see 4.4).
  • Competition organisers — to run and score the entry you booked (see 4.6).
  • Authorities and courts — only where legally required.

6.1 External fonts and libraries

For presentation we load fonts and styling libraries from external delivery networks (fonts.googleapis.com and fonts.gstatic.com, operated by Google Ireland Limited, and cdn.jsdelivr.net, operated by the jsDelivr organisation via delivery partners). When you open the page your browser connects to these servers, transmitting your IP address, which may be processed in the respective provider's server logs. Processing outside the EU is possible, based on the adequacy decision for the EU-US Data Privacy Framework or on standard contractual clauses.
Purpose: consistent, performant presentation of the interface. Legal basis: Art. 6(1)(f) GDPR.

7. Retention and deletion

We store personal data only as long as necessary for the stated purposes or as required by statutory retention periods. You can delete your content yourself at any time. You may request deletion of your account at any time by emailing support@shotmetrix.com; we will act without undue delay. Results already scored may be retained in anonymised form in the competition documentation. Data may persist in backups for a limited period and is overwritten with the backup rotation cycle.

8. Data security

We implement technical and organisational measures pursuant to Art. 32 GDPR: encrypted transmission (TLS), storage of passwords only as a cryptographic hash (deliberately slow, state-of-the-art algorithm, upgraded automatically as standards evolve), access restrictions and role separation, protection of upload directories against direct access and code execution, protection against automated bulk requests, security headers, and logging of administrative actions.

9. Your rights

You have the right at any time to:

  • access the data stored about you (Art. 15 GDPR),
  • rectification of inaccurate data (Art. 16 GDPR),
  • erasure (Art. 17 GDPR),
  • restriction of processing (Art. 18 GDPR),
  • data portability in a structured, commonly used format (Art. 20 GDPR),
  • object to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR),
  • withdraw consent with effect for the future (Art. 7(3) GDPR).

An email to support@shotmetrix.com is sufficient. We may request additional details to verify your identity.

Independently of this, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). We ask that you contact us first — most matters can be resolved directly.

10. Obligation to provide data

Providing a username, email address and password is necessary to create an account; without them we cannot provide an account. All other details (profile information, club, avatar) are voluntary.

11. Minors

Shotmetrix is intended for persons aged 16 and over. Younger persons may use the platform only with the consent of their legal guardians. If we learn that an account is held contrary to this requirement, we will delete it.

12. Changes to this privacy policy

We update this policy when the legal situation, our services or our processing changes. The version published on this page applies; the date is shown above.

Community Guidelines · Terms · Impressum · Datenschutz · meshpro.de · meshpro.shop
● 4 Online
© 2026 MESHPRO Shotmetrix
Latest Sign in Sign up
Edit post

Max 10 images per post in total.

Training note optional
What did you work on?
How did it go?
Conditions
Note
Report a problem

The technical details of this analysis are attached automatically — you do not need to look anything up.

The more precise, the faster it can be fixed. The expected value helps most.
Report Content
Notifications