Privacy Policy
Last updated: February 2026
1. Privacy at a glance
The following information provides a simple overview of what happens to your personal data when you visit this website or use our application. Personal data is any data that can be used to personally identify you.
2. Data controller
[Name / Company name]
[Street and number]
[Postal code City]
Austria
Email: support@turniermeister.at
3. Hosting
Our website and application are hosted on a server in Germany. The server is operated by us. When you visit the website, the following information is automatically stored in server log files:
- IP address
- Browser type and version
- Operating system
- Referrer URL
- Time of the server request
This data is not merged with other data sources. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in error-free operation).
4. Authentication (Clerk)
For registration and login, we use Clerk (Clerk, Inc., USA). Clerk enables login via:
- Google account (OAuth)
- Apple account (OAuth)
- Email address
The following data is transmitted to or processed by Clerk:
- Email address
- First and last name
- Profile picture (if provided by the OAuth provider)
- Clerk user ID
Clerk stores this data on servers in the USA. The Clerk Privacy Policy applies. Data transfer to the USA is based on Standard Contractual Clauses (Art. 46(2)(c) GDPR). Legal basis: Art. 6(1)(b) GDPR (contract performance).
5. Data we store
In our database (PostgreSQL, server in Germany) we store the following personal data:
- User ID, first and last name, email address
- Profile picture URL
- Selected plan (Basic, Pro, Premium) and subscription status
- Payment information: Polar customer ID, subscription ID, payment timestamps
- Registration date, trial expiration date, plan expiration date
- User settings (e.g. display preferences)
- Tournament data: tournaments, schedules, results, teams, participants
- Tournament templates
Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest).
6. Payment processing (Polar.sh)
For payment processing, we use Polar.sh (Polar Software Inc.). When making a purchase or subscription, you are redirected to Polar's checkout page. Polar processes:
- Email address
- Payment information (credit card, PayPal, SEPA direct debit, Apple Pay, Google Pay)
- Customer ID and subscription ID
We do not store any credit card numbers or bank details. The Polar.sh Privacy Policy applies. Legal basis: Art. 6(1)(b) GDPR (contract performance).
7. Analytics (PostHog)
We use PostHog (PostHog, Inc.) to analyze the usage of our application. PostHog is operated on EU servers (eu.i.posthog.com). We collect:
- Page views and interactions (manually defined events, no automatic tracking)
- Device and browser information
- For logged-in users: user ID, plan and subscription status
PostHog creates user profiles only for identified (logged-in) users. Data is stored in the browser's localStorage. Session recordings are only active in the production environment.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in improving our service).
8. Real-time communication (WebSocket)
For live updates of tournament results, we use WebSocket connections (Socket.IO). Tournament data is transmitted in real time between server and browser. No additional personal data is collected.
9. Local storage (localStorage)
We store the following in your browser's localStorage:
- Theme preference (light/dark mode)
- PostHog analytics data (anonymous session information)
This data does not leave your browser and can be deleted at any time via your browser settings.
10. Cookies
Our application uses cookies from Clerk for authentication (session management). These are technically necessary and cannot be disabled without limiting functionality. We do not use advertising or tracking cookies.
11. Your rights (Art. 15–21 GDPR)
You have the right at any time to:
- Access (Art. 15 GDPR) – What data we have stored about you
- Rectification (Art. 16 GDPR) – Correction of inaccurate data
- Erasure (Art. 17 GDPR) – Deletion of your data
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR) – Export of your data in a common format
- Objection (Art. 21 GDPR) – Against processing based on legitimate interests
To exercise your rights, contact us at support@turniermeister.at.
12. Data deletion
When you delete your account, all personal data is removed from our database. Tournament data you created is also deleted. Data held by third-party providers (Clerk, Polar.sh) is handled according to their respective privacy policies.
13. Data security
Communication between your browser and our servers is exclusively encrypted via HTTPS/TLS. Access to our servers is protected by firewalls and SSH keys.
14. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority in Austria is:
Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40–42
1030 Vienna, Austria
www.dsb.gv.at
15. Changes
We reserve the right to update this privacy policy to reflect changes in the law or our service. The current version is always available on this page.