Privacy Policy
Last updated: August 2026
1.Scope and our two roles
This policy covers chess-arbiter.com, the Arbiter web application, the desktop application, and the public registration forms hosted for tournaments. It is issued by the individual operating Arbiter as a sole proprietorship (“we”, “us”).
Which role we play depends on whose data it is, and the distinction decides who you should approach with a request:
| Data | Who decides | Our role |
|---|---|---|
| Your account, profile, billing and support history | We do | Data fiduciary / controller |
| Community posts and comments you write | We do | Data fiduciary / controller |
| Player IDs, registrations, standings, norm recipients and other tournament data | The tournament organiser does | Data processor, acting on the organiser's instructions |
2.What data we hold
Everything below is data the Service actually stores. Some categories exist only if you use the feature they belong to.
About you, as an account holder
| Category | Fields |
|---|---|
| Identity | Name, email address, email-verification timestamp, profile image (if you sign in with Google), account creation and update timestamps. |
| Credentials | For email sign-up, a password hash held by our authentication provider — we never see or store your password. For Google sign-in, the Google account identifier and the profile fields you consent to share. |
| Chess identifiers | Your own FIDE ID and AICF ID, if you add them. These prefill norm forms and member lookups. |
| Subscription | Plan, status, trial start and end, current period end, payment-failure timestamps, our payment provider's customer and subscription identifiers, and an append-only ledger of billing events (activation, renewal, failure, cancellation). |
| Quotations | Quotation code, negotiated amount, validity period, redemption timestamp and the tournament it is bound to. |
| Communications | Transactional emails we send you (invitations, billing notices, trial and grace-period reminders) and any support correspondence. |
| Technical | Session cookies, IP address, browser and device information, request timestamps and server error logs. |
Inside your tournaments
| Feature | What is stored |
|---|---|
| Tournaments & members | Tournament name, dates, venue and other details you enter, any uploaded tournament image, and the list of members with their owner / editor / viewer role. |
| Invitations | The invited email address, an invitation token, its status (pending, accepted, rejected, revoked, expired) and timestamps — including for people who never create an account. |
| Membership analysis | The FIDE and AICF IDs you submit, and the public record retrieved for each: name, ratings, title, federation, year of birth or age, activity status and membership status. Plus the generated Excel report and per-session progress. |
| Online entries | Everything a candidate submits: name, email, phone, FIDE ID, AICF ID, date of birth, rating, category, answers to your custom questions, the payment reference and any payment screenshot they upload, the fee amount and currency, plus the entry and payment status and who reviewed it and when. |
| Entry configuration | Your published payment instructions, UPI ID and payment QR image, entry cap, closing date and custom field definitions. |
| Pairing sheets | Uploaded pairing rows for each round, the file's headers, arbiter names and their board ranges. |
| Prize book & prize list | Prize categories, amounts, currencies and filters; uploaded final standings; and the generated allocation, including the reasoning recorded for each award. |
| Norm forms | For each recipient: name and FIDE ID copied onto the record at the time of issue, plus the event statistics, tournament details and signatory information you enter. Documents are generated on request and not stored. |
| Broadcast | FTP host, port, username, remote path and security setting; the FTP password, encrypted; captured PGN game files and upload status. |
| Rulebook AI | Your conversations with the assistant — the questions you ask, the answers returned, and which manual sections were cited. |
| Audit logs | For every change to a tournament: who made it, what operation it was, when, a human-readable description, and structured context such as a role change from and to. This log is append-only — it cannot be edited or deleted, by you or by us. |
Community
Posts, comments, reactions and the display name shown next to them. These are visible to other signed-in users.
What we never hold
- Card and bank details. Subscription payments go directly to our payment provider; we receive only the identifiers and status described above. Entry fees do not pass through the Service at all — candidates pay organisers directly.
- Your account password in readable form.
- Location beyond what an IP address implies, contact lists, or data from other sites you visit.
3.Where the data comes from
- From you — when you sign up, fill in your profile, create tournaments and use features.
- From candidates — when they submit a public registration form for a tournament.
- From other organisers — when someone invites your email address to their tournament, or records you as a norm recipient.
- From Google — if you choose Google sign-in.
- From FIDE and AICF — public player records retrieved when you run a membership analysis. We are not affiliated with either body.
- Automatically — technical data generated as you use the Service.
4.Why we process it
The legal basis column reflects the GDPR framing; under India's Digital Personal Data Protection Act, 2023 the equivalent grounds are your consent and certain legitimate uses.
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and secure your account, authenticate you, keep you signed in | Identity, credentials, technical | Performance of a contract |
| Provide the features you use — analysis, entries, pairings, prizes, norms, broadcast, rulebook | Tournament data | Performance of a contract; for candidate data, processing on the organiser's instructions |
| Take payment, manage subscriptions and quotations, prevent duplicate trials | Subscription, quotation, identity | Performance of a contract; legitimate interests (preventing abuse) |
| Send transactional email — invitations, billing notices, trial and grace reminders, security notices | Identity, subscription | Performance of a contract; legitimate interests |
| Maintain tournament audit logs so changes are attributable | Audit logs | Legitimate interests (accountability and dispute resolution for organisers) |
| Keep the Service reliable and secure, debug failures, prevent abuse and rate-limit access | Technical, usage | Legitimate interests |
| Answer support requests | Identity, communications, relevant tournament data | Performance of a contract; legitimate interests |
| Run the community area | Community content, display name | Performance of a contract |
| Meet tax, accounting and other legal obligations | Subscription, billing ledger | Legal obligation |
We do not process your data for advertising, profiling or automated decision-making that produces legal effects, and we do not sell or rent personal data to anyone.
7.AI processing
The Rulebook assistant is the only feature that sends data to AI providers. When you ask a question, the text of that question is converted into a search embedding, matched against the FIDE Arbiters' Manual, and the question plus the retrieved passages and your conversation history are sent to a large language model to compose an answer.
- Your content is not used to train models — ours, our providers', or anyone else's. We use these providers under API terms that exclude training on submitted data.
- Providers may retain submitted content briefly for abuse monitoring in line with their own policies.
- Your conversations are stored in your account so you can return to them, and you can delete a conversation at any time.
- No other feature — membership analysis, entries, prizes, norms — sends data to an AI provider.
- Because the request leaves our systems, do not paste player personal data, disciplinary details or anything confidential into the assistant.
8.International transfers
Our providers operate globally, so personal data may be processed outside India — including in the United States and the European Union. Where data leaves the EU or UK, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision, together with the technical measures in section 10. Transfers from India are made in accordance with the Digital Personal Data Protection Act, 2023 and any restrictions notified under it.
You can ask us for details of the safeguards applying to a specific provider.
9.How long we keep it
| Data | Retention |
|---|---|
| Account and profile | Until you delete your account, then removed — see section 12 |
| Tournament data, entries, pairings, prizes, norm recipients | Until the organiser deletes the record or the tournament, or the account is deleted |
| Membership analysis sessions and reports | Kept with the tournament. Download links to generated reports are short-lived and expire after 7 days; the report can be regenerated |
| Payment proof screenshots | Kept with the entry, in private storage, reachable only through short-lived signed links |
| Captured broadcast game files | Automatically cleaned up about 7 days after capture; the upload metadata stays for the audit trail |
| Tournament audit logs | For the life of the tournament — append-only, and deliberately not editable or deletable |
| Rulebook conversations | Until you delete the conversation or the account |
| Community posts and comments | Until you delete them, or we remove them under the Terms |
| Billing records and the billing event ledger | Retained as long as required by applicable tax and accounting law, typically 8 years, even after account deletion |
| Invitations | Until revoked, accepted or expired; expired records are cleared periodically |
| Server and error logs | Typically 30–90 days |
| Backups | Rolling backups are retained for up to 30 days; deleted data disappears from backups as they rotate |
10.How we protect it
- Encryption in transit (TLS) and at rest for the database and file storage.
- Row-level security enforced in the database itself, so tournament data is reachable only by that tournament's members — not merely hidden in the interface.
- Role-based access per tournament (owner, editor, viewer), checked on every write and on document generation.
- Private storage buckets. Payment screenshots, prize lists, analysis reports and the manual are not publicly readable; they are served through short-lived signed links only.
- Encrypted FTP passwords — broadcast credentials are encrypted before they are stored and are never returned to the browser in readable form.
- Append-only audit logs, so a change to a tournament cannot be made to disappear.
- Least privilege — administrative database keys are server-side only and never exposed to the browser or the desktop app.
- Webhook verification — billing callbacks are signature-verified and deduplicated against a ledger.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authority — including the Data Protection Board of India and, where the GDPR applies, the competent supervisory authority within 72 hours — as the law requires.
11.Your rights
Under India's DPDP Act, 2023
- Access — a summary of the personal data we process about you and who it has been shared with.
- Correction and erasure — correct inaccurate or incomplete data, and have data erased where it is no longer needed and no law requires us to keep it.
- Grievance redressal — raise a complaint with our grievance officer (section 16), and escalate to the Data Protection Board of India if you are not satisfied.
- Nomination — nominate someone to exercise your rights if you die or become incapacitated. Email us to record one.
- Withdraw consent — as easily as it was given, where processing rests on consent.
Under the GDPR / UK GDPR
- Access, rectification and erasure.
- Restriction of processing, and objection to it.
- Portability — a machine-readable copy of data you provided. The Service's own Excel and XML exports cover most of this immediately.
- Withdrawal of consent, without affecting prior processing.
- Complaint to your local supervisory authority.
How to exercise them
Email hello@chess-arbiter.com from your registered address, or tell us enough for us to locate your records. We respond within 30 days, and will tell you if we need longer. We may ask you to verify your identity first, and there is no charge for a reasonable request.
Several rights are self-service: edit your profile in settings, export any tournament's data to Excel, delete a Rulebook conversation, remove a community post, or delete your account outright.
12.Deleting your account
You can delete your account from the settings page. It signs you out, removes your authentication record, and cascades to your profile.
- Deletion is immediate and permanent. Export anything you need first — tournament exports, reports and generated documents cannot be recovered afterwards.
- Hand over tournaments first. If you are the sole owner of a tournament your co-arbiters still need, transfer ownership or add another owner before you delete, or their access goes with your account.
- What survives, and why: billing records are kept for the statutory period; audit log entries stay so a tournament's history remains intact for its other members, and norm recipient records keep the name and FIDE ID captured at issue so an already generated form stays reproducible. Community posts may remain visible detached from your profile.
- Backups rotate out within 30 days.
13.If you registered for a tournament
You did not create an account — you filled in an organiser's registration form. That organiser decided what to ask for and is responsible for how your details are used. We store them on their behalf.
- What is held about you: the details you entered (name, email, phone, FIDE and AICF IDs, date of birth, rating, category, answers to custom questions), any payment reference or screenshot you uploaded, and the status the organiser set for your entry.
- Who can see it: the organiser and the members they added to that tournament. Payment screenshots are private and opened only through short-lived signed links.
- What it is used for: processing your registration, verifying your payment, checking your federation membership, seeding the pairing program, and allocating prizes.
- To correct or delete it: contact the tournament organiser. If you cannot reach them, email us at hello@chess-arbiter.com with the tournament name and we will pass your request on and follow up.
- We never use candidate data to market to you, and never share it outside the processors in section 6.
14.Children's data
Accounts are for arbiters and organisers and require you to be 18 or over. We do not knowingly let a child create an account; if we learn one has, we delete it.
Junior and age-category events mean tournament data routinely includes children — names, dates of birth and ratings submitted by an organiser or a parent. In that case the organiser is responsible for obtaining verifiable parental or guardian consent as required by the DPDP Act, 2023 and any other applicable law. We never use children's data for tracking, behavioural monitoring or advertising, and we do not process it for any purpose beyond running the tournament it belongs to.
A parent or guardian who wants a child's data corrected or removed should contact the tournament organiser, or us — we will route the request.
15.Changes to this policy
We update this policy as the Service changes. The “last updated” date at the top always reflects the current version. For material changes — a new category of data, a new processor, or a new purpose — we will notify you by email or in the app before they take effect. Continued use after that date means you accept the updated policy.
16.Contact and grievance officer
For any privacy question, request or complaint, including as our Grievance Officer under the DPDP Act, 2023 and as the contact for data protection matters under the GDPR:
hello@chess-arbiter.com
Arbiter, [CITY], India
We acknowledge grievances within 7 days and aim to resolve them within 30. If you are not satisfied, you may complain to the Data Protection Board of India or, where the GDPR applies to you, to your local supervisory authority.
See also our Terms of Service.

