ArbiterArbiter

Privacy Policy

Last updated: August 2026

In short: we hold your account details and the tournament data you create, and we use them to run Arbiter for you — nothing else. We do not sell personal data, do not run advertising or cross-site tracking, and do not train AI models on your content. For the player and candidate data inside your tournaments, the organiser is in charge and we act on their instructions. Payment card details never reach our servers.

1.Scope and our two roles

This policy covers chess-arbiter.com, the Arbiter web application, the desktop application, and the public registration forms hosted for tournaments. It is issued by the individual operating Arbiter as a sole proprietorship (“we”, “us”).

Which role we play depends on whose data it is, and the distinction decides who you should approach with a request:

DataWho decidesOur role
Your account, profile, billing and support historyWe doData fiduciary / controller
Community posts and comments you writeWe doData fiduciary / controller
Player IDs, registrations, standings, norm recipients and other tournament dataThe tournament organiser doesData processor, acting on the organiser's instructions
If you are a player or candidate whose details appear inside someone's tournament, your first point of contact is that tournament's organiser — see section 13. We will always help, and will pass a request on to the organiser where it is theirs to answer.

2.What data we hold

Everything below is data the Service actually stores. Some categories exist only if you use the feature they belong to.

About you, as an account holder

CategoryFields
IdentityName, email address, email-verification timestamp, profile image (if you sign in with Google), account creation and update timestamps.
CredentialsFor email sign-up, a password hash held by our authentication provider — we never see or store your password. For Google sign-in, the Google account identifier and the profile fields you consent to share.
Chess identifiersYour own FIDE ID and AICF ID, if you add them. These prefill norm forms and member lookups.
SubscriptionPlan, status, trial start and end, current period end, payment-failure timestamps, our payment provider's customer and subscription identifiers, and an append-only ledger of billing events (activation, renewal, failure, cancellation).
QuotationsQuotation code, negotiated amount, validity period, redemption timestamp and the tournament it is bound to.
CommunicationsTransactional emails we send you (invitations, billing notices, trial and grace-period reminders) and any support correspondence.
TechnicalSession cookies, IP address, browser and device information, request timestamps and server error logs.

Inside your tournaments

FeatureWhat is stored
Tournaments & membersTournament name, dates, venue and other details you enter, any uploaded tournament image, and the list of members with their owner / editor / viewer role.
InvitationsThe invited email address, an invitation token, its status (pending, accepted, rejected, revoked, expired) and timestamps — including for people who never create an account.
Membership analysisThe FIDE and AICF IDs you submit, and the public record retrieved for each: name, ratings, title, federation, year of birth or age, activity status and membership status. Plus the generated Excel report and per-session progress.
Online entriesEverything a candidate submits: name, email, phone, FIDE ID, AICF ID, date of birth, rating, category, answers to your custom questions, the payment reference and any payment screenshot they upload, the fee amount and currency, plus the entry and payment status and who reviewed it and when.
Entry configurationYour published payment instructions, UPI ID and payment QR image, entry cap, closing date and custom field definitions.
Pairing sheetsUploaded pairing rows for each round, the file's headers, arbiter names and their board ranges.
Prize book & prize listPrize categories, amounts, currencies and filters; uploaded final standings; and the generated allocation, including the reasoning recorded for each award.
Norm formsFor each recipient: name and FIDE ID copied onto the record at the time of issue, plus the event statistics, tournament details and signatory information you enter. Documents are generated on request and not stored.
BroadcastFTP host, port, username, remote path and security setting; the FTP password, encrypted; captured PGN game files and upload status.
Rulebook AIYour conversations with the assistant — the questions you ask, the answers returned, and which manual sections were cited.
Audit logsFor every change to a tournament: who made it, what operation it was, when, a human-readable description, and structured context such as a role change from and to. This log is append-only — it cannot be edited or deleted, by you or by us.

Community

Posts, comments, reactions and the display name shown next to them. These are visible to other signed-in users.

What we never hold

  • Card and bank details. Subscription payments go directly to our payment provider; we receive only the identifiers and status described above. Entry fees do not pass through the Service at all — candidates pay organisers directly.
  • Your account password in readable form.
  • Location beyond what an IP address implies, contact lists, or data from other sites you visit.

3.Where the data comes from

  • From you — when you sign up, fill in your profile, create tournaments and use features.
  • From candidates — when they submit a public registration form for a tournament.
  • From other organisers — when someone invites your email address to their tournament, or records you as a norm recipient.
  • From Google — if you choose Google sign-in.
  • From FIDE and AICF — public player records retrieved when you run a membership analysis. We are not affiliated with either body.
  • Automatically — technical data generated as you use the Service.

4.Why we process it

The legal basis column reflects the GDPR framing; under India's Digital Personal Data Protection Act, 2023 the equivalent grounds are your consent and certain legitimate uses.

PurposeData usedLegal basis
Create and secure your account, authenticate you, keep you signed inIdentity, credentials, technicalPerformance of a contract
Provide the features you use — analysis, entries, pairings, prizes, norms, broadcast, rulebookTournament dataPerformance of a contract; for candidate data, processing on the organiser's instructions
Take payment, manage subscriptions and quotations, prevent duplicate trialsSubscription, quotation, identityPerformance of a contract; legitimate interests (preventing abuse)
Send transactional email — invitations, billing notices, trial and grace reminders, security noticesIdentity, subscriptionPerformance of a contract; legitimate interests
Maintain tournament audit logs so changes are attributableAudit logsLegitimate interests (accountability and dispute resolution for organisers)
Keep the Service reliable and secure, debug failures, prevent abuse and rate-limit accessTechnical, usageLegitimate interests
Answer support requestsIdentity, communications, relevant tournament dataPerformance of a contract; legitimate interests
Run the community areaCommunity content, display namePerformance of a contract
Meet tax, accounting and other legal obligationsSubscription, billing ledgerLegal obligation

We do not process your data for advertising, profiling or automated decision-making that produces legal effects, and we do not sell or rent personal data to anyone.

5.Cookies and local storage

  • Authentication cookies — set by our authentication provider to keep you signed in and to refresh your session. Strictly necessary; the Service cannot work without them.
  • Theme preference — stored in your browser's local storage so light or dark mode persists. It never leaves your device.
  • No advertising or cross-site tracking cookies, and no third-party analytics on the marketing site. Desktop app downloads are proxied through our own server, so the release host does not see your IP address.

Public registration forms set no cookies beyond what is needed to submit the form.

6.Who we share it with

We share personal data only with the processors below, only for the purpose listed, and under contracts requiring them to protect it.

ProviderPurposeWhat it receives
SupabaseHosting, database, authentication and file storageEffectively all stored data, including account details, tournament data and uploaded files
Our application hosting and CDN providerServing the website and appRequest metadata, IP address, and data in transit while a request is served
GoogleOptional sign-inOnly what is needed to complete OAuth — we receive your identifier, name, email and profile image
RazorpaySubscription paymentsYour name, email and payment details you enter with them; we receive back only identifiers and payment status
ResendTransactional emailRecipient email address and the content of the message (invitation, billing notice, reminder)
AnthropicGenerating Rulebook assistant answersYour question, the retrieved manual passages and the conversation context
OpenAITurning your question into a search embedding for the Rulebook assistantThe text of your question
GitHubHosting desktop app release filesNothing about you — downloads are proxied through our server

Other sharing

  • With FIDE and AICF — running a membership analysis sends the player IDs you submitted to their public services in order to read the corresponding records.
  • With your tournament members — everyone you add to a tournament sees its data at the level their role permits.
  • With an organiser — if you register for a tournament, your entry goes to that organiser and their members.
  • Legal and safety — where we are required by law, or where disclosure is necessary to establish or defend legal claims or to protect the rights and safety of users. We will notify you unless legally barred.
  • Business transfer — if the Service is acquired or merged, data may transfer to the successor under this policy. We will notify you before it takes effect.

7.AI processing

The Rulebook assistant is the only feature that sends data to AI providers. When you ask a question, the text of that question is converted into a search embedding, matched against the FIDE Arbiters' Manual, and the question plus the retrieved passages and your conversation history are sent to a large language model to compose an answer.

  • Your content is not used to train models — ours, our providers', or anyone else's. We use these providers under API terms that exclude training on submitted data.
  • Providers may retain submitted content briefly for abuse monitoring in line with their own policies.
  • Your conversations are stored in your account so you can return to them, and you can delete a conversation at any time.
  • No other feature — membership analysis, entries, prizes, norms — sends data to an AI provider.
  • Because the request leaves our systems, do not paste player personal data, disciplinary details or anything confidential into the assistant.

8.International transfers

Our providers operate globally, so personal data may be processed outside India — including in the United States and the European Union. Where data leaves the EU or UK, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision, together with the technical measures in section 10. Transfers from India are made in accordance with the Digital Personal Data Protection Act, 2023 and any restrictions notified under it.

You can ask us for details of the safeguards applying to a specific provider.

9.How long we keep it

DataRetention
Account and profileUntil you delete your account, then removed — see section 12
Tournament data, entries, pairings, prizes, norm recipientsUntil the organiser deletes the record or the tournament, or the account is deleted
Membership analysis sessions and reportsKept with the tournament. Download links to generated reports are short-lived and expire after 7 days; the report can be regenerated
Payment proof screenshotsKept with the entry, in private storage, reachable only through short-lived signed links
Captured broadcast game filesAutomatically cleaned up about 7 days after capture; the upload metadata stays for the audit trail
Tournament audit logsFor the life of the tournament — append-only, and deliberately not editable or deletable
Rulebook conversationsUntil you delete the conversation or the account
Community posts and commentsUntil you delete them, or we remove them under the Terms
Billing records and the billing event ledgerRetained as long as required by applicable tax and accounting law, typically 8 years, even after account deletion
InvitationsUntil revoked, accepted or expired; expired records are cleared periodically
Server and error logsTypically 30–90 days
BackupsRolling backups are retained for up to 30 days; deleted data disappears from backups as they rotate

10.How we protect it

  • Encryption in transit (TLS) and at rest for the database and file storage.
  • Row-level security enforced in the database itself, so tournament data is reachable only by that tournament's members — not merely hidden in the interface.
  • Role-based access per tournament (owner, editor, viewer), checked on every write and on document generation.
  • Private storage buckets. Payment screenshots, prize lists, analysis reports and the manual are not publicly readable; they are served through short-lived signed links only.
  • Encrypted FTP passwords — broadcast credentials are encrypted before they are stored and are never returned to the browser in readable form.
  • Append-only audit logs, so a change to a tournament cannot be made to disappear.
  • Least privilege — administrative database keys are server-side only and never exposed to the browser or the desktop app.
  • Webhook verification — billing callbacks are signature-verified and deduplicated against a ledger.

No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authority — including the Data Protection Board of India and, where the GDPR applies, the competent supervisory authority within 72 hours — as the law requires.

11.Your rights

Under India's DPDP Act, 2023

  • Access — a summary of the personal data we process about you and who it has been shared with.
  • Correction and erasure — correct inaccurate or incomplete data, and have data erased where it is no longer needed and no law requires us to keep it.
  • Grievance redressal — raise a complaint with our grievance officer (section 16), and escalate to the Data Protection Board of India if you are not satisfied.
  • Nomination — nominate someone to exercise your rights if you die or become incapacitated. Email us to record one.
  • Withdraw consent — as easily as it was given, where processing rests on consent.

Under the GDPR / UK GDPR

  • Access, rectification and erasure.
  • Restriction of processing, and objection to it.
  • Portability — a machine-readable copy of data you provided. The Service's own Excel and XML exports cover most of this immediately.
  • Withdrawal of consent, without affecting prior processing.
  • Complaint to your local supervisory authority.

How to exercise them

Email hello@chess-arbiter.com from your registered address, or tell us enough for us to locate your records. We respond within 30 days, and will tell you if we need longer. We may ask you to verify your identity first, and there is no charge for a reasonable request.

Several rights are self-service: edit your profile in settings, export any tournament's data to Excel, delete a Rulebook conversation, remove a community post, or delete your account outright.

Where we hold data as a processor for an organiser — registrations, player records, norm recipients — we forward your request to that organiser rather than acting on it ourselves, unless they instruct us otherwise.

12.Deleting your account

You can delete your account from the settings page. It signs you out, removes your authentication record, and cascades to your profile.

  • Deletion is immediate and permanent. Export anything you need first — tournament exports, reports and generated documents cannot be recovered afterwards.
  • Hand over tournaments first. If you are the sole owner of a tournament your co-arbiters still need, transfer ownership or add another owner before you delete, or their access goes with your account.
  • What survives, and why: billing records are kept for the statutory period; audit log entries stay so a tournament's history remains intact for its other members, and norm recipient records keep the name and FIDE ID captured at issue so an already generated form stays reproducible. Community posts may remain visible detached from your profile.
  • Backups rotate out within 30 days.

13.If you registered for a tournament

You did not create an account — you filled in an organiser's registration form. That organiser decided what to ask for and is responsible for how your details are used. We store them on their behalf.

  • What is held about you: the details you entered (name, email, phone, FIDE and AICF IDs, date of birth, rating, category, answers to custom questions), any payment reference or screenshot you uploaded, and the status the organiser set for your entry.
  • Who can see it: the organiser and the members they added to that tournament. Payment screenshots are private and opened only through short-lived signed links.
  • What it is used for: processing your registration, verifying your payment, checking your federation membership, seeding the pairing program, and allocating prizes.
  • To correct or delete it: contact the tournament organiser. If you cannot reach them, email us at hello@chess-arbiter.com with the tournament name and we will pass your request on and follow up.
  • We never use candidate data to market to you, and never share it outside the processors in section 6.

14.Children's data

Accounts are for arbiters and organisers and require you to be 18 or over. We do not knowingly let a child create an account; if we learn one has, we delete it.

Junior and age-category events mean tournament data routinely includes children — names, dates of birth and ratings submitted by an organiser or a parent. In that case the organiser is responsible for obtaining verifiable parental or guardian consent as required by the DPDP Act, 2023 and any other applicable law. We never use children's data for tracking, behavioural monitoring or advertising, and we do not process it for any purpose beyond running the tournament it belongs to.

A parent or guardian who wants a child's data corrected or removed should contact the tournament organiser, or us — we will route the request.

15.Changes to this policy

We update this policy as the Service changes. The “last updated” date at the top always reflects the current version. For material changes — a new category of data, a new processor, or a new purpose — we will notify you by email or in the app before they take effect. Continued use after that date means you accept the updated policy.

16.Contact and grievance officer

For any privacy question, request or complaint, including as our Grievance Officer under the DPDP Act, 2023 and as the contact for data protection matters under the GDPR:

hello@chess-arbiter.com
Arbiter, [CITY], India

We acknowledge grievances within 7 days and aim to resolve them within 30. If you are not satisfied, you may complain to the Data Protection Board of India or, where the GDPR applies to you, to your local supervisory authority.

See also our Terms of Service.