Pre-launch test environment — payments use test credentials and data may be reset before launch.

Legal

Privacy Policy

Version draft-2026-09-04 · Effective 1 Oct 2026 · Written for India’s Digital Personal Data Protection Act, 2023 (DPDP).

1. Who is responsible for your data

Tournabot is operated by cintemp, the data fiduciary for the personal data this policy describes. For data inside a tournament — registrations, rosters, results — the organisation running the event decides why and how it is processed; Tournabot processes it on that organisation’s behalf to provide the service.

2. What we collect, and what we deliberately do not

  • Organisation staff. When you sign in to the dashboard we receive your Discord account identity (ID, username, avatar) through Discord’s OAuth flow, and an email address if you provide one for billing or notifications. Signing in sets a session cookie — strictly necessary to keep you signed in, not used for tracking.
  • Participants. Players never create a Tournabot account. There is no player login, no password and no player credential store. Participant identity reaches us inside Discord interaction payloads — the Discord ID, display name and the registration details a player submits for an event — scoped to the event being run. Web registration forms (paid plans) additionally collect what the form asks for, including an email address used to deliver the claim code for that registration.
  • No age data. Tournabot does not collect player dates of birth or age data. Age compliance is an organisation-level attestation, so no children’s data is knowingly processed.
  • Payments. Subscription payments are processed by Razorpay. We receive the payment status and invoice details; we never see or store your card number or UPI credentials.
  • Media and results. Result screenshots submitted for OCR extraction, highlight clips and overlay assets are stored for the organisation that uploaded them, inside its plan’s storage and retention limits.
  • Operational logs. Audit events (who did what, when) and service logs, kept for security, support and the tamper-evident audit records the product provides.
  • Coarse network signal (anti-fraud). At registration, signed ticket-form submit and staff dashboard session start we store a salted hash of a truncated network prefix (/24 or /48) — never the raw address, never a device fingerprint — for a short retention window (default 30 days) so organisers can review possible alt-account stacking. It never automatically bans or refuses anyone.

3. What we use it for

Running the service you asked for: registrations, slots, brackets, results, overlays, notifications and support. Billing and GST invoicing. Keeping the platform safe — abuse prevention, rate-limit protection, security features the organisation turns on. Aggregate, non-identifying product analytics. We do not sell personal data, and we do not use it for third-party advertising.

4. This website

Measurement on tournabot.com is first-party and cookie-less: aggregate visit counting, no cross-site tracking, no personal profile, nothing stored on your device — which is why there is no consent banner to click.

5. Where your data lives, and who touches it

  • Tenant data is hosted on infrastructure in India (Mumbai).
  • Processors we use to run the service: our hosting provider, Razorpay for payments, and the mail service that delivers registration emails (sent under the organisation’s name from a Tournabot-operated mail domain). Discord is the platform your community already runs on — messages and interactions there are governed by Discord’s own privacy policy as well.
  • We disclose personal data beyond that only when the law requires it, and to the extent it requires it.

6. The Conduct Network

Organisations can record conduct reports about players in their own events — structured, category-limited records written by the organisation’s staff, with an audit trail. Cross-organisation reading of those reports is not enabled: it stays switched off at the platform level pending independent Indian data-protection counsel review, and this policy will be updated before that ever changes.

7. How long we keep it

  • Tournament and community data follows the organisation’s plan retention window — 45 days on Free, 12 months on Scrim, 24 on Pro, 48 on Circuit — and is deleted in the normal cycle after it.
  • A lapsed organisation’s Discord application credential record is kept for 12 months so re-subscribing reconnects without re-onboarding, then purged.
  • Billing records are kept as long as Indian tax law requires. Security and audit logs are kept no longer than their purpose needs.

8. Your rights under the DPDP Act

You can ask for access to your personal data, correction of what is wrong, erasure of what we no longer need to keep, and you can nominate a person to exercise these rights for you. Where processing rests on consent, you can withdraw it as easily as you gave it. Participants whose data lives inside an organisation’s event should start with that organisation — it decides the purposes — but you can always contact us directly and we will help route the request. We respond to grievances within the window published below.

Grievance officer

Vikramaditya · [email protected] · response within 3. If you are not satisfied with our response, you may complain to the Data Protection Board of India.

9. Changes to this policy

We may update this policy as the product or the law changes. Material changes are announced to workspace owners before they take effect, and the current version always lives at this address. See also the Terms of Service, the Refund Policy and the Acceptable Use Policy.