Privacy Policy

Effective: 2026-05-11

Version 1.2 — Last updated: 2026-05-11

At a Glance

A short, plain-language summary. The full policy below controls in case of conflict.

What we collect

What we do with it

What we don't do

Your controls

1. Effective Date and Version

This Privacy Policy is effective 2026-05-11 (Version 1.2). Earlier versions are archived and available on request.

2. Data Controller

The data controller responsible for processing your personal data is:

When required by Article 37 of the GDPR or by other applicable law, we will appoint a Data Protection Officer (DPO). If you are an EEA resident, you may direct DPO inquiries to [email protected] with the subject line "DPO".

3. Categories of Personal Data We Collect

We collect the following categories:

4. Sources of Data

5. Legal Bases for Processing (GDPR Art. 6)

We rely on the following legal bases:

For sensitive categories of data, we do not process them. We do not collect health, biometric, racial, political, religious, or sexual-orientation data. Gender is collected only where relevant for tournament categories, may be left blank, and is treated as ordinary data, not sensitive data.

6. Purposes of Processing

We process personal data to:

7. Cookies and Similar Technologies

At launch we use a minimal set of strictly necessary storage:

We do not currently use third-party advertising cookies or analytics cookies. Sentry collects technical error context (stack traces, user-agent, route) when an error occurs; this may include limited identifiers tied to your Account for debugging purposes.

If we add non-essential cookies in the future, we will request your consent through a banner and allow you to decline without losing access to essential features.

8. Sharing with Third Parties (Sub-Processors)

We share personal data only with vetted sub-processors who act on our behalf under written agreements that include confidentiality, security, and (where applicable) GDPR Art. 28 and standard contractual clauses:

We may also share data:

We do not sell personal data and we do not "share" personal data for cross-context behavioral advertising as those terms are defined under California's CCPA/CPRA.

9. International Transfers

Racketify is operated by South Lab Technologies (1242033 B.C. LTD.) in British Columbia, Canada, and our sub-processors operate in multiple regions including the United States, the European Union, and globally distributed networks (Cloudflare). Your data may therefore be transferred to and processed in countries other than your own.

For transfers from the EEA, the United Kingdom, or Switzerland to countries without an adequacy decision, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by appropriate technical and organizational safeguards (encryption in transit and at rest, access controls).

For transfers from Canada, we ensure that comparable protections apply under contract.

10. Data Retention

We retain personal data only as long as necessary:

11. Your Rights

Depending on where you live, you have the following rights. We honor all of them globally where feasible.

11.1 GDPR / UK GDPR (EEA, UK, Switzerland)

11.2 CCPA / CPRA (California)

11.3 PIPEDA and Provincial Equivalents (Canada)

Right of access, correction, and challenge of compliance, in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and equivalent provincial laws, including British Columbia's Personal Information Protection Act (PIPA BC, S.B.C. 2003, c. 63) and Quebec's Act respecting the protection of personal information in the private sector (Law 25). Residents of British Columbia may also contact the BC Office of the Information and Privacy Commissioner (OIPC).

11.4 How to Exercise Your Rights

You can also lodge a complaint with the Office of the Privacy Commissioner of Canada, with the British Columbia Office of the Information and Privacy Commissioner (OIPC), with your EEA national supervisory authority, with the UK Information Commissioner's Office (ICO), with the Chilean data-protection authority (currently the Consejo para la Transparencia, transitioning to the Agencia de Protección de Datos under Ley 21.719), or with your U.S. state Attorney General as applicable.

12. Security

We implement industry-standard technical and organizational measures, including:

No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and the competent authorities as required by law (within 72 hours under GDPR Art. 33 where applicable).

13. Children and Minors

The Service is not directed at individuals under the age of 13 creating their own Account (or under 16 in the EEA, UK, and Switzerland). Minors below those ages may participate in the Service only when their Account or Player profile is registered and managed on their behalf by a parent, legal guardian, or an authorized club administrator who has obtained the necessary parental consent under applicable law.

We do not knowingly collect personal data directly from minors creating their own Accounts. Photographs, birth dates, and contact details of minors registered through a guardian or club administrator are processed solely for tournament and club operations, minimized to what is strictly necessary, and deleted on request from the minor's parent or guardian or upon termination of the relevant club membership.

If you believe a minor has registered their own self-managed Account in violation of this section, contact [email protected] and we will investigate and, where appropriate, suspend or delete the Account promptly.

14. Automated Decision-Making

We do not engage in automated decision-making, including profiling, that produces legal or similarly significant effects about you, within the meaning of GDPR Art. 22. ELO and ranking calculations are deterministic statistical computations based on match results you participate in, and do not constitute such automated decision-making.

15. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be announced by email to your registered address and via a banner in the dashboard at least fifteen (15) days before they take effect. The "Last updated" date at the top reflects the most recent revision. Older versions are available on request.

16. Contact

For privacy questions, complaints, or to exercise your rights:

If you reside in Canada, you may also contact the Office of the Privacy Commissioner of Canada (federal) and/or your provincial Information and Privacy Commissioner (e.g., the British Columbia OIPC). If you reside in the EEA, UK, or Switzerland and believe your rights have been infringed, you may contact your national data protection authority. If you reside in Chile, you may contact the relevant national authority designated under Ley 21.719 (Agencia de Protección de Datos Personales) once operational, or the Consejo para la Transparencia in the interim.