TermsHome

Effective August 25, 2026

Privacy Policy.

This Policy explains what information Community-Funded Tournaments receives, why it is used, when it may be shared, and the choices available to you.
On this page
Scope Information collected How information is used Google account data Sharing Retention Your choices Children Security International use Changes and contact

1. Scope

This Privacy Policy applies to CFT, meaning Community-Funded Tournaments, including its website, account features, tournaments, waitlists, subscriptions, and related community operations (collectively, the “Platform”). It does not govern Google, Roblox, payment providers, hosting providers, or other third-party services, which publish their own policies.

2. Information CFT collects

Google sign-in information

When you choose Google sign-in, CFT requests the minimum OpenID Connect scopes currently needed: openid, profile, and email. Google may provide a unique account identifier, display name, email address, email-verification status, and profile-picture URL. CFT does not receive your Google password.

Account and tournament information

CFT keeps an account registration record when a Google-authenticated player first uses the Platform. That record includes the Google account identifier in one-way hashed form, display name, email address, profile-picture URL, email-verification state, registration and recent-activity timestamps, VIP state, and suspension state. Identifying profile fields are encrypted at rest. Authorized operators may view these records in a protected player directory to provide support, administer VIP access, and enforce community rules. When related features are offered, CFT may also process account preferences, tournament entries, confirmations, waitlist position, eligibility checks, check-in status, results, rule violations, prize records, and communications needed to operate an event.

Subscriptions and payments

If paid entry or subscriptions are enabled, CFT may receive transaction identifiers, payment status, subscription tier, renewal and cancellation dates, refunds, chargebacks, and limited billing details supplied by the payment provider. Checkout will identify the payment provider. Full payment-card numbers should be collected and handled by that provider rather than CFT.

Profile pictures and local preferences

A custom profile picture selected in the Profile Editor is resized in your browser and uploaded to CFT's hosting provider so it can appear across devices and pages where your profile is shown. Theme preference and the local data-version marker remain stored in your browser.

Technical information

CFT and its hosting provider may automatically process IP address, request time, requested page, browser or device information, referring page, error details, security events, and cookies needed to deliver and protect the Platform.

3. How CFT uses information

  • Authenticate accounts and keep users signed in securely.
  • Display account and profile information chosen by the user.
  • Operate tournament registration, waitlists, VIP priority, brackets, check-in, results, prizes, and disputes when those features are available.
  • Process subscriptions, entry payments, refunds, fraud checks, and billing support when payments are available.
  • Apply the VIP priority rule, including identifying the newest non-VIP waitlisted member when an eligible VIP member receives priority.
  • Provide authorized operators with account information needed to administer VIP status, review accounts, and apply or remove suspensions.
  • Protect players, enforce rules, prevent cheating and abuse, debug errors, and maintain Platform security.
  • Comply with legal, tax, accounting, sanctions, and prize-reporting obligations.
  • Improve user-facing Platform features using aggregated or appropriately de-identified information where practical.

4. Google account data

CFT uses Google account data only to provide sign-in, account identification, profile display, account administration, security, and closely related user-facing features. CFT does not use Google account data for advertising or sell it. Access is limited to the verified operator and service providers where necessary for account administration, security, support, legal compliance, or with your permission.

The OAuth access token is used server-side to request Google UserInfo during sign-in and is not included in the CFT session sent to your browser. CFT stores a signed session containing the limited profile fields needed for the account rather than storing your Google password.

CFT’s use and transfer of information received from Google APIs will follow the Google API Services User Data Policy, including applicable Limited Use requirements.

5. When information may be shared

CFT may share limited information with:

  • Service providers that host, secure, process payments for, communicate for, or otherwise support the Platform, under appropriate contractual or technical restrictions.
  • Tournament participants and organizers where display names, bracket placement, results, or moderation decisions must be visible to run an event.
  • Authorities or affected parties where reasonably necessary to comply with law, protect rights and safety, investigate fraud, or respond to valid legal process.
  • A successor operator in a merger, financing, reorganization, or transfer of the Platform, subject to appropriate notice and continued protection of personal information.

CFT does not sell Google profile information. If CFT introduces materially different data sharing, this Policy and any required consent flow will be updated first.

6. Retention

  • The current signed login session expires after approximately seven days unless you sign out earlier.
  • The Google access token used during sign-in is not retained in the CFT browser session and is not currently stored for ongoing Google API access.
  • Custom profile pictures remain in CFT's storage until you reset the picture, request account-data deletion, or CFT removes it under the Terms or applicable retention requirements.
  • Account registration, VIP, and moderation records remain while the account is active and may be retained afterward where reasonably needed for safety, disputes, legal compliance, or prevention of suspension evasion.
  • When tournaments, subscriptions, or payments are enabled, associated records may be retained as needed for operations, disputes, fraud prevention, tax and accounting duties, legal compliance, and enforcement of the Terms.
  • Hosting and security logs may be retained according to the hosting provider’s settings and operational needs.

CFT will delete or de-identify information when it is no longer reasonably needed, subject to legal, security, backup, and dispute-resolution requirements.

7. Your choices and privacy rights

  • Sign out: use the Sign Out control to clear the CFT session cookie.
  • Google access: review or revoke CFT’s access from your Google Account’s third-party connections controls.
  • Profile picture: use "Use Google Picture" to remove the uploaded custom picture and return to your Google profile picture.
  • Subscription: use the cancellation method identified at purchase to stop future renewals. Signing out or clearing cookies does not itself cancel billing.
  • Privacy request: request access, correction, deletion, or a copy of applicable account information through the official CFT support channel. Identity verification may be required.

Rights vary by location. CFT will not unlawfully discriminate against a user for exercising an applicable privacy right.

8. Children’s privacy

CFT is not directed to children under 13 and does not knowingly collect personal information from a child under 13. Users must be at least 13. A user under the age of legal majority must have a parent or guardian approve Platform use and payments.

If CFT learns that information was collected from a child under 13 without legally sufficient authorization, it will take reasonable steps to delete that information and disable the related account. A parent or guardian may raise a concern through the official CFT support channel.

9. Security

CFT uses safeguards designed for the nature of the information it handles, including HTTPS, encryption of identifying player-registry fields at rest, owner-only directory authorization, server-side OAuth code exchange, PKCE and state validation, signed HttpOnly cookies, limited OAuth scopes, security headers, and separation of client secrets from public code. No online service can guarantee absolute security.

You should secure your Google account and device, sign out on shared devices, and report suspected unauthorized access through the official support channel.

10. International use

CFT and its providers may process information in countries other than the one where you live. Those countries may have different privacy laws. Where required, CFT will use lawful safeguards for cross-border processing.

11. Policy changes and contact

CFT may update this Policy as account features, tournaments, subscriptions, providers, or law change. The effective date will be updated, and material changes will be reasonably communicated before they take effect where required.

Privacy questions and requests should be submitted through the official CFT support channel identified by the Platform or the community through which you received access. Do not send passwords, complete payment-card details, or unnecessary sensitive information.

Community-Funded Tournaments
Terms of ServiceSign In