Privacy Policy
Draft pending legal review. This describes how Chiprally actually works today. It has not been reviewed by a lawyer, and it does not yet make jurisdiction-specific commitments (GDPR/UK GDPR/CCPA roles, international transfer mechanisms). Have it checked before selling outside the United States.
Two kinds of people are described here
League operators subscribe to Chiprally and run a league on it. League members are the players in someone's league. For an operator's account we decide what to collect. For a league's member data we act on the operator's behalf. The operator decides what goes in, and we process it to provide the service.
What we collect
From league operators
- Account details: name, email, and the sign-in credentials held by our identity provider.
- Subscription details: plan, billing status, and the identifiers our payment processor gives us. We never see or store your full card number.
- Operational logs: IP address, browser type, and request records kept for security and debugging.
From league members (on the operator's behalf)
- Profile: name, email, and anything they choose to add such as a display name, bio, or picture.
- League activity: game results, standings, attendance, RSVPs, achievements, feed posts, comments, and messages to league staff.
- Notification preferences and the record of consent behind them.
How leagues are kept apart
Every league gets its own separate database. Requests are routed to a league's database by hostname, and a request that cannot be matched to a league is refused rather than being served from someone else's data. Uploaded files and backups are stored under per-league prefixes, and a backup can only be restored into the league it came from.
This is the single most important property of the system, and it is enforced in code rather than by convention.
Why we process it
To run the service you subscribed to: standings and statistics, RSVPs, the member feed, achievements, staff tooling, and, where a member has opted in, email notifications. We also use aggregate, non-identifying figures to understand how the product is used.
We do not sell personal information, and we do not use your data to train machine-learning models.
Transactional email (a reply to your support ticket, a rules notice, a ban decision) is part of the service. Anything promotional requires an explicit opt-in. Every email carries a one-click unsubscribe, and unsubscribing is honoured immediately. Addresses that hard-bounce or report spam are suppressed automatically and are not mailed again.
Who else processes data
- Amazon Web Services: hosting, databases, file storage, sign-in, and outbound email. United States.
- Stripe: subscription billing, once billing begins. Card details will go to Stripe directly and never through our servers.
- Social platforms (X, Facebook): only if an operator connects one, and only for posts they explicitly approve.
To be completed by the operator: confirm this list before launch, and add a data-processing addendum if you sell to customers who require one.
Cookies and tracking
We use what the service needs to function: a session token to keep you signed in, and short-lived cookies that protect the sign-in flow from cross-site request forgery. The marketing site sets no advertising or cross-site tracking cookies.
A league's own public pages may show advertising, which the operator controls. That is described in the privacy policy of the league's own site, not here.
Retention and deletion
- While a subscription is active, league data is kept so the league works.
- After cancellation, data is retained for a limited window so an operator can export it or change their mind, and is then deleted.
- Backups age out on their own schedule after that.
- A member can ask their league operator to remove or anonymise their profile; the operator controls their league's data.
League data is retained while the operator's subscription is active. When a subscription ends, the operator has 30 days to export their league's data; after that window the league's database is deleted. Off-site backups expire automatically within 28 days of being taken and database point-in-time snapshots within 7 days, so deleted data also ages out of every backup within a further month. These windows match how the backup systems are actually configured.
Security
Data is encrypted in transit and at rest. Sign-in is handled by a managed identity provider, so we never store passwords ourselves. Platform credentials for connected social accounts are held in a secrets manager, not in any league's database. Support access to a league is recorded and is visible to that league rather than hidden.
No system is perfectly secure. If a breach affects your data, we will tell affected operators promptly and describe what happened.
Children
Chiprally is not intended for children. Leagues are run at venues with their own age requirements, and operators are responsible for enforcing them.
Changes
If this policy changes materially, we will tell subscribers before the change takes effect and update the date above.
Contact
The data controller is Chip Rally LLC, a Florida limited liability company, doing business as Chiprally.
To be completed by the operator: the LLC's postal address, required by several privacy laws and by bulk-email rules.