Plain English Summary: We collect only what we need to operate EsportsVerse. We do not sell your personal data. Ever.
1. Overview
EsportsVerse (โweโ, โourโ, or โusโ) operates the EsportsVerse website and related services (collectively the โPlatformโ). This Privacy Policy governs how we collect, use, and protect information about users (โyouโ) in connection with our Platform. By using our Platform you agree to the practices described in this policy.
This policy is governed by the Information Technology Act, 2000 (India) and the Digital Personal Data Protection Act, 2023 (DPDPA). If you are located in the EU/EEA, additional GDPR rights may apply.
2. Information We Collect
Account Information โ When you register you provide:
- Email address (required)
- Username / gamer tag (required)
- Password (stored as a salted bcrypt hash โ never in plain text)
- Display name and avatar (optional)
Platform Activity โ Generated as you use the service:
- Layouts you upload (title, control codes, images)
- Likes and interactions with community content
- Login timestamps and session data
Technical Data โ Collected automatically:
- IP address
- Browser type and version
- Operating system
- Referring URLs and pages visited on our Platform
- Device identifiers
We do not collect payment information, government IDs, or biometric data.
3. How We Use Your Data
We use the information we collect to:
- Create and maintain your account
- Provide, operate, and improve the Platform
- Authenticate your sessions and protect your account
- Send service-related emails (account verification, security alerts)
- Display your content and username in community sections
- Analyse usage patterns to improve user experience (aggregated & anonymised)
- Enforce our Terms of Service and prevent abuse
- Comply with legal obligations
We do not use your data for targeted advertising.
4. Data Sharing
We share your personal data only in the following limited circumstances:
- Service providers: hosting (Vercel), database (PostgreSQL), file storage โ bound by data processing agreements
- Legal compliance: when required by law, court order, or to protect the rights and safety of users
- Business transfers: in the event of a merger or acquisition, with advance notice to users
- With your consent: any other sharing only with your explicit permission
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
5. Cookies & Tracking
We use the following types of cookies and local storage:
- Authentication tokens: stored in localStorage to keep you signed in between sessions
- Session cookies: expire when you close your browser
- Analytics: we may use privacy-respecting analytics (e.g., Plausible or Vercel Analytics) that do not fingerprint individual users
You can clear localStorage at any time via your browser settings, which will log you out. You can also block cookies in your browser โ some features may not work correctly if you do.
6. Data Retention
We retain your personal data for as long as your account is active, or as needed to provide services. Specifically:
- Account data: retained until you delete your account
- Uploaded layouts: retained until you delete them or your account
- Server logs: retained for up to 90 days
- Anonymised analytics: retained indefinitely
After account deletion, personal identifiers are removed within 30 days. Some data may be retained longer if required by law.
7. Your Rights
Under applicable Indian and global data protection laws, you have the right to:
- Access: Request a copy of the personal data we hold about you
- Correction: Ask us to correct inaccurate or incomplete data
- Deletion: Request deletion of your account and associated personal data
- Portability: Receive your data in a machine-readable format
- Objection: Object to processing based on legitimate interests
- Withdraw consent: Where processing is based on your consent
To exercise any of these rights, email us at privacy@esportsverse.in. We will respond within 30 days.
8. Security
We implement industry-standard security measures to protect your data:
- HTTPS/TLS encryption for all data in transit
- Passwords stored as bcrypt hashes (never reversible)
- JWT tokens with short expiry for session management
- Regular security audits and dependency updates
- Access controls limiting who can access production data
However, no system is 100% secure. If you discover a vulnerability, please disclose it responsibly to security@esportsverse.in.
9. Children's Privacy
EsportsVerse is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has created an account, please contact us and we will promptly delete the account and associated data.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email or a prominent notice on the Platform at least 14 days before the change takes effect. Your continued use of the Platform after that date constitutes acceptance of the updated policy.
Previous versions of our Privacy Policy are available upon request.
11. Contact Us
If you have questions, concerns, or requests regarding this policy:
EsportsVerse
๐ง privacy@esportsverse.in
๐ esportsverse.in
๐ India