Privacy Policy
Effective and last updated: July 13, 2026
This Privacy Policy explains how the community tournament organizers operating SpikeSync (the "Operator") collects, uses, discloses, displays, protects, and retains information through SpikeSync (the "Service"). It applies to the website, tournament-administration features, connected Discord activity, provider refreshes, and information submitted to tournament staff through the Service. The Operator is responsible for the purposes and means of this processing except where an event notice identifies another organizer or third party as separately responsible.
1. Information collected and processed
Discord identity and Service account
- Discord user ID, username, global display name, and avatar URL provided through Discord sign-in;
- the SpikeSync display name and Service roles or permissions, such as player, captain, moderator, or administrator;
- account creation and update times, Riot-profile consent and confirmation times, and signed session information.
Discord sign-in provides basic identity information. The Operator does not receive your Discord password. The application uses a Discord OAuth access token to obtain the identity response during sign-in and does not persist that token after the sign-in request is complete.
Riot profile, rank, and match information
- Riot game name and tag, confirmation status, and a profile snapshot associated with your Service account;
- current and peak rank, rank score, selected or inferred role, recent-performance value, calculated tournament cost, manual override, and locked-value history;
- recent match records, which may include an external match ID, date, queue, map, agent, result, rank change, combat score, kills, deaths, assists, team scores, and round scores;
- provider and source status, refresh attempts, retry timing, errors, and synchronization timestamps.
Riot or a provider may return a Riot PUUID or similar account identifier while a refresh is being performed. The current synchronization flow uses that identifier to request supported data but does not persist it in the normalized SpikeSync account or player record. External match identifiers and provider/source metadata may be retained.
Manually entering a Riot ID and accepting tournament consent does not constitute Riot Sign On. SpikeSync will only enable identified Riot API access after the required product approval, account authorization, and backend controls are in place. A separately configured provider may process supported data under its own terms and the permissions described at the time of collection.
Tournament, team, and competition information
- registration, availability, waitlist, eligibility, notes, team, captain, roster, draft, budget, cost, trade, vote, and captain-election records;
- bracket configuration, seeds, queue order, scheduling, maps, match submissions, scores, approvals, corrections, revisions, and results;
- team names, colors, uploaded logos, and associated upload paths;
- alternate-account reports, report details, reporter and reviewer identifiers, review status, and moderation or enforcement records;
- administrator and moderator actions, audit records, reasons, deduplication identifiers, and associated metadata;
- information imported through authorized CSV uploads and information included in authorized CSV exports.
Discord server resources and notifications
- configured Discord guild, category, channel, role, captain-role, and message identifiers;
- guild and channel names or types retrieved when an administrator checks or synchronizes the configured Discord server;
- notification type, title, body, image URL, recipient or channel, delivery status, attempt count, timestamps, Discord message ID, and delivery error information;
- settings such as announcement channels, whether cost is included, and whether draft-turn notifications are enabled.
Uploads, messages, and support information
- team logos, names, report descriptions, review reasons, match evidence, and other material submitted to tournament staff;
- the contents and metadata of a privacy, support, legal, accessibility, or tournament-review request;
- technical metadata embedded in an uploaded PNG or JPEG file, because the current logo uploader validates but does not re-encode the original file.
Technical, security, and request information
- request time, route, response status, user agent, referring page, and IP address where recorded by the hosting provider, reverse proxy, security layer, or server logs;
- an IP-derived key held in application memory for the active sign-in rate-limit window;
- validation failures, availability and health information, security events, and diagnostic errors needed to maintain the Service.
2. Sources of information
Information may come from:
- you, including profile, registration, report, match, logo, and support submissions;
- authorized tournament staff, captains, and other participants acting through the Service;
- Discord OAuth, Discord's bot API, and Discord's content-delivery network;
- Riot services, Riot-authorized APIs, and other configured game-data providers;
- event actions and records generated by SpikeSync, including drafts, trades, notifications, brackets, audits, and calculations;
- hosting, proxy, network, storage, and security systems that automatically create operational logs.
3. Purposes for using information
- authenticate users, maintain sessions, link accounts, and enforce role-based permissions;
- register participants, confirm Riot identities, prepare player pools, review eligibility and alternate-account concerns, and communicate event requirements;
- create teams, administer captains and Discord resources, run drafts and trades, schedule and score matches, and publish brackets, standings, and results;
- calculate or infer ranks, roles, performance values, costs, seeds, queue order, and other tournament inputs;
- deliver and troubleshoot Discord messages, draft-turn alerts, match updates, trades, results, and administrative notices;
- moderate content, investigate reports, resolve disputes, preserve competitive integrity, and audit staff actions;
- secure, operate, test, back up, diagnose, improve, and recover the Service;
- comply with applicable law, valid legal process, Riot or Discord requirements, and obligations needed to protect users, the Service, or others.
4. Legal grounds where applicable
Privacy laws differ by location. Where a legal ground is required, the Operator may rely on one or more of the following, as applicable:
- performance of an agreement or steps you request: to provide sign-in, registration, tournament participation, drafts, matches, and related features;
- consent: for optional Riot-profile processing, optional notifications, or another purpose presented for consent; consent can be withdrawn for future processing, subject to event and legal consequences explained at the time;
- legitimate interests: to operate a fair community tournament, secure the Service, prevent fraud and abuse, communicate operational information, maintain records, and resolve disputes where those interests are not overridden by your rights;
- legal obligation, legal claims, and safety: to comply with law, respond to valid process, preserve evidence, enforce rights, and protect a person or system.
The Operator will not use information for a materially new and incompatible purpose without providing notice and obtaining consent where required.
5. Public, participant, and staff visibility
Tournament pages are designed to publish event information. Depending on event settings and state, public or participant-facing views may display a name or alias, Riot ID, rank, role, team, captain or waitlist status, draft position, player value, provider status, performance or recent-match information, schedule, bracket, trade, and result. Match details and brackets can be public or limited to signed-in users. Discord identities, usernames, user IDs, profile links, and Discord-hosted avatars are not included in public-facing player or tournament views.
A hidden or randomized identity is a display control, not deletion or guaranteed anonymity. The Operator and authorized administrators may retain the real Discord and Riot identities. Stable technical record identifiers, team and role context, performance values, provider status, or recent-match information may remain available according to the tournament's current field and access settings and may permit linkage when combined with other information.
Captains receive information needed to draft and manage their team. Moderators and administrators may receive additional account, scoring, report, audit, and operational information according to their permissions. Authorized CSV exports can contain personal information; once downloaded, the recipient is responsible for securing and using the file only for its authorized tournament purpose.
6. Calculations, inference, and human review
SpikeSync can calculate player values and seeds and can infer a role or performance value from rank and match information. These outputs may affect draft order, player valuation, team balance, or tournament administration. Authorized staff can review, correct, override, lock, or recalculate them. You may request correction or review through the event's published channel. They are not used by SpikeSync to make credit, employment, housing, insurance, or other similarly significant legal decisions.
7. Disclosures and service providers
Information may be disclosed to:
- the public, participants, captains, and tournament staff: according to the visibility, role, and event-operation rules described above;
- Discord: for sign-in, avatar delivery, guild and resource synchronization, direct or channel messages, and deletion or status checks;
- Riot and VALORANT data providers: when a Riot ID or transient provider identifier is used to retrieve supported account, rank, or match data;
- hosting and infrastructure providers: for application hosting, routing, DNS, TLS, storage, backups, logging, security, and delivery;
- Google Fonts: when a browser requests the externally hosted fonts used by the current interface; Google may receive the visitor's IP address, user agent, and request metadata;
- professional advisers, authorities, and affected parties: where reasonably necessary for legal advice, a valid request, safety, fraud or abuse investigation, enforcement, or the establishment, exercise, or defence of legal claims;
- a successor operator: if operation or relevant assets are reorganized or transferred, subject to appropriate notice and applicable privacy obligations.
Third parties process information under their own policies, including the Discord Privacy Policy, applicable Riot policies, and the Google Privacy Policy. The Operator does not authorize a service provider to use SpikeSync information for an unrelated purpose merely because the provider receives it to deliver a requested service.
8. Cookies and external resources
- The signed, HTTP-only session cookie normally expires after 14 days and is removed when you sign out or clear it.
- Temporary Discord OAuth state and redirect cookies normally expire after 10 minutes.
- Cookies use SameSite protections, and production authentication cookies require secure transport.
- The current application does not set advertising or cross-site behavioural-advertising cookies.
Blocking required cookies prevents sign-in or persistent sessions. Loading a Discord avatar or a Google-hosted font makes a direct request from your browser to that third party and exposes ordinary network metadata even if you do not click an external link.
9. Sale, advertising, Global Privacy Control, and Do Not Track
The Operator does not sell personal information, exchange it for cross-context behavioural advertising, or use SpikeSync for third-party behavioural advertising. Because the Service does not currently perform those activities, a Global Privacy Control or browser Do Not Track signal does not change its behaviour. If advertising, analytics, or a legally defined sale or sharing practice is introduced, this Policy and any required consent or opt-out control must be updated before that practice begins.
10. Retention, authorization withdrawal, and deletion schedule
- OAuth state and sign-in rate-limit data: OAuth cookies expire after about 10 minutes. The sign-in rate-limit key is held in process memory for the active one-minute window and is not written to the primary database.
- Session data: the signed session expires after 14 days unless removed sooner. The underlying Service account remains until separately deleted or de-identified.
- Account and tournament records: user profiles, participant records, drafts, teams, matches, brackets, trades, reports, votes, notifications, and audits currently have no single automatic deletion date. They may be kept while needed for the event, event history, integrity, disputes, security, and administration.
- Provider snapshots and match records: may remain in a restricted internal cache with the related account or participant record until removed, replaced, de-identified, or no longer reasonably needed; scheduled category-wide deletion is not currently implemented. Withdrawing Riot authorization does not physically delete that cache.
- Team logos: the current server copy is removed when an authorized administrator replaces or removes it, but prior copies and embedded metadata may remain temporarily in backups, browser or proxy caches, or downloaded copies.
- Notifications and Discord messages: delivery and audit records remain until an authorized administrator clears applicable history or the record is otherwise deleted. Removing a SpikeSync record does not necessarily delete a message already delivered through Discord, and Discord may refuse or be unable to delete some messages.
- Backups: when the supplied backup process runs, its default setting removes backup files older than 14 days; the operator can configure a different period or run backups on a different schedule.
- Infrastructure logs: retained according to the verified hosting, proxy, security, and system-log configuration.
Information may be retained longer where reasonably necessary for a legal obligation, security investigation, active dispute, legal claim, protection of another person's rights, or a documented competition-integrity reason. The Operator will review retained information and delete, de-identify, or securely dispose of it when it is no longer reasonably required, subject to those exceptions and the technical limits described above.
11. Your choices and privacy rights
Depending on your location and subject to legal exceptions, you may have rights to request access, correction, deletion, restriction, objection, portability, information about disclosures, withdrawal of consent, or review of a decision. You may also have a right not to receive discriminatory treatment for exercising a privacy right and to complain to the privacy regulator responsible for your location.
SpikeSync does not currently provide a self-service complete account export or deletion control. Submit a request through the contact method below. The Operator may ask for information reasonably needed to verify identity and scope the request and will respond within the period required by applicable law. A request may be limited where disclosure or deletion would harm another person's rights, compromise security or tournament integrity, or conflict with a legal duty or active claim. The Operator will explain a refusal where required.
Withdrawing optional Riot-profile consent stops future consent-based processing after the request is completed but does not make prior processing unlawful. The self-service Riot withdrawal control soft-revokes the active account link, stops future identified provider refreshes, and quarantines cached Riot provider data from public, player, captain, and moderator views. Authorized administrators may retain limited internal access for the retention, integrity, security, legal, and operational purposes described in this Policy. This control is not a deletion request. If you later reauthorize, retained data may become available and displayed again, subject to the consent, event settings, and policies then in effect. If verified rank or identity information is required by Event Rules, withdrawal may prevent continued participation. You can opt out of optional draft-turn notifications through the applicable tournament setting or by asking tournament staff; operational or security notices may still be sent.
12. Tournament removal is not account deletion
Removing a participant from a tournament deletes the tournament player record and related player snapshots and recent matches handled by that removal process. It does not by itself delete the underlying SpikeSync user account, Discord identity, Riot profile, consent and confirmation timestamps, account-level profile snapshot, audit history, or records that must be retained for the reasons described above. Request account-level deletion separately through the privacy contact.
13. Security and incidents
The Service uses measures including signed HTTP-only cookies, server-side authorization, role restrictions, request validation, upload limits and file checks, protected backend communication, audit records, backups, and secret validation. Access is limited according to operational roles. No online service is completely secure, and the Operator cannot guarantee that information will never be lost, accessed, altered, or disclosed without authorization.
Use a strong Discord password, enable Discord's available account protections, and report suspected unauthorized access promptly. If a security incident affects personal information, the Operator will investigate, mitigate, preserve required records, and notify affected people or regulators where applicable law requires it.
14. International processing
Discord, Riot, VALORANT data providers, Google, and hosting or network providers may process information outside your province, state, or country. Information may therefore be subject to the laws and lawful-access rules of those locations. Where applicable law requires it, the Operator will use appropriate contractual, technical, or organizational measures for the transfer and remain accountable for service providers processing information on its behalf.
15. Children and young participants
The Service is not intended for anyone below age 13 or the higher minimum age required by Discord, Riot Games, applicable law, or the Event Rules. The Operator does not knowingly request information from a child who cannot lawfully use the Service. A parent or guardian who believes a child provided information improperly should contact the Operator so the account and event records can be reviewed and appropriate action taken. Events involving minors must apply any required guardian-consent and safeguarding procedures.
16. Third-party sites and independent copies
This Policy does not govern an independent website, Discord server, Riot account, stream, social platform, downloaded export, or other third-party service. Information made public or delivered to an independent recipient can be copied, indexed, cached, or redistributed beyond the Operator's control. Review third-party policies and avoid publishing personal information that is not needed for the event.
17. Changes to this Policy
The Operator may update this Policy as the Service, providers, event practices, or law changes. The effective date will be updated, and material changes may also be announced through the Service or tournament Discord. If a new purpose requires consent under applicable law, the Operator will seek that consent before using information for the new purpose.
18. Contact, requests, and complaints
To ask a privacy question, request access, correction, deletion, portability or withdrawal of consent, or report a privacy or security concern, contact the tournament organizer through the official tournament Discord server. Identify the relevant account and event and describe the request, but do not send passwords, authentication tokens, government identifiers, or unnecessary sensitive information. If a concern is not resolved, you may have the right to contact the privacy regulator responsible for your location.