This Privacy Policy explains how ChessOnes ("we," "us," or "our") collects, uses, shares, and protects personal information when you use the ChessOnes platform, including our web application and any related services (collectively, the "Service"). By creating an account or using the Service, you acknowledge that you have read and understood this Privacy Policy.
ChessOnes is operated by ChessOnes LLC, a company registered in the State of New Jersey, United States.
1. Who this policy applies to
This Privacy Policy applies to all users of the ChessOnes platform worldwide. If you are located in the European Union or United Kingdom, additional rights and obligations under the General Data Protection Regulation (GDPR) apply to you, as described in Section 11. If you are a resident of California, USA, additional rights under the California Consumer Privacy Act (CCPA) apply to you, as described in Section 12.
2. Platform availability
ChessOnes is currently available exclusively as a web application accessible via a browser on any device. Mobile applications for iOS and Android are in development and will be made available in the future. This Privacy Policy will be updated prior to the launch of any mobile applications to reflect any differences in data collection on those platforms.
3. Minimum age requirement
The ChessOnes Service is intended for users aged 13 and older. We do not knowingly collect personal information from children under the age of 13. If you are under 13, you may not use the Service. If we discover that we have inadvertently collected personal information from a child under 13, we will delete that information promptly.
Parents or guardians who believe we have collected data from a child under 13 may contact us at privacy@chessones.com.
Users aged 13 to 17 may use the Service, but in certain jurisdictions parental or guardian consent may be required. We encourage parents and guardians to monitor the online activities of minors in their care.
4. Information we collect
4.1 Information you provide directly at registration
- Full name
- Username (publicly visible on the platform)
- Email address
- Year of birth (used solely to verify minimum age eligibility; we do not collect your full date of birth)
- Country of residence
- Profile avatar / profile picture (if uploaded by you)
4.2 Information you submit while using the Service
- Forum posts and text content shared in public discussions
- Private messages sent to other users
- In-game chat messages
- Communications with our support team
4.3 Information collected via social login
When you choose to sign in using Google or Facebook (Meta), those services share certain profile information with us based on your account permissions, which may include your name and email address. We do not receive your social login password. The data we receive is governed by Google's and Meta's own privacy policies, as well as your privacy settings on those platforms.
4.4 Information collected automatically
When you use the Service, we automatically collect:
- IP address and approximate geolocation (country/region level only)
- Device type, operating system, and browser type
- Pages visited, features used, and time spent on the platform
- Game data: moves played, time controls used, game results, rating changes, and tournament participation records
- Log data: access times, error logs, and session identifiers
- Cookie and tracking data (see Section 6 and our Cookie Policy)
4.5 Information from third-party analytics
We use Google Analytics and Meta (Facebook) Pixel to understand how users interact with the platform. These services may collect data such as your IP address, browser identifiers, and behavioural patterns on our platform. This data is subject to Google's and Meta's respective privacy policies.
5. How we use your information
We use the personal information we collect for the following purposes:
- To create and manage your account and provide core platform functionality, including matchmaking, rating calculations, leaderboards, and tournament management.
- To verify minimum age eligibility using your year of birth.
- To verify your identity and enforce our one-account-per-person policy.
- To send transactional emails (account confirmations, password resets, security alerts).
- To send newsletters, platform updates, and promotional communications where you have opted in or where we have a legitimate interest in doing so, with an unsubscribe option available in every email.
- To personalise your experience and surface relevant content within the learning features.
- To detect, investigate, and prevent cheating, fraud, abuse, and violations of our policies.
- To analyse usage patterns and improve platform features and performance.
- To comply with legal obligations, respond to lawful requests from authorities, and enforce our Terms of Service.
- To protect the rights, safety, and property of ChessOnes and its users.
Note on future paid features: When ChessOnes introduces premium or paid features, this Privacy Policy will be updated to reflect any additional data processing related to payments and subscriptions. Users will be notified of all material changes before they take effect.
6. Legal basis for processing (GDPR)
For users in the EU and UK, we rely on the following lawful bases under the GDPR:
- Contractual necessity: Processing required to provide the Service you signed up for, including account management and game functionality.
- Legitimate interests: Analytics, fraud detection, platform security, and direct marketing to existing users, balanced against your rights and interests.
- Consent: Marketing emails to new users; activation of non-essential cookies; Meta Pixel tracking. You may withdraw consent at any time.
- Legal obligation: Compliance with applicable laws and responses to lawful authority requests.
Withdrawing consent does not affect the lawfulness of any processing that took place before withdrawal.
9. Data retention
We retain your personal information for as long as your account is active or as necessary to provide the Service and meet our legal obligations. More specifically:
- Account profile data is retained for the life of your account.
- Game records and rating history form part of the platform's competitive record and may be retained indefinitely, including after account deletion, in an anonymised or attributed form.
- Log and analytics data is retained for up to 26 months.
- Marketing consent records are retained until consent is withdrawn plus a reasonable period for compliance documentation.
Following account deletion, we will delete or anonymise your personal profile information (name, email, year of birth, country, avatar) within 30 days, subject to the retention obligations described above.
10. Data security
We implement industry-standard technical and organisational security measures to protect your personal information. These include encryption of data in transit (HTTPS/TLS), secure and hashed password storage, access controls limiting which personnel can access personal data, and periodic security reviews.
No method of transmission over the internet is completely secure. We cannot guarantee absolute security of your data, but we are committed to applying best practices and responding promptly to any security incidents.
If you believe your account has been compromised or you have identified a security vulnerability, please contact us immediately at security@chessones.com.
11. International data transfers
ChessOnes LLC is based in the United States. Your personal information is stored and processed on servers provided by Amazon Web Services (AWS), located in the United States. Data protection laws in the United States may differ from those in your country.
For users in the EU and UK, we ensure that appropriate safeguards are in place for international data transfers, including reliance on Standard Contractual Clauses (SCCs) approved by the European Commission where applicable.
12. Your rights (GDPR — EU and UK users)
If you are located in the EU or UK, you have the following rights under the GDPR:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure: Request deletion of your personal data, subject to legal retention obligations.
- Right to restriction of processing: Request that we limit how we use your data in certain circumstances.
- Right to data portability: Receive your personal data in a structured, commonly used, machine-readable format.
- Right to object: Object to processing based on legitimate interests, including direct marketing (which you may opt out of at any time).
- Right to withdraw consent: Withdraw consent at any time for any processing based on consent, without affecting prior lawful processing.
To exercise any of these rights, contact us at privacy@chessones.com. We will respond within 30 days. If you are dissatisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.
GDPR EU representative (if required by volume of EU users): [INSERT IF APPLICABLE]
13. Your rights (CCPA — California users)
If you are a California resident, you have the following rights:
- Right to know: Request disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months.
- Right to delete: Request deletion of your personal information, subject to certain legal exceptions.
- Right to opt-out of sale or sharing: We do not sell your personal information. You may opt out of the sharing of your data with third-party advertising platforms (Google Analytics, Meta Pixel) by updating your cookie preferences at any time.
- Right to non-discrimination: We will not discriminate against you for exercising any of your CCPA rights.
To submit a request, contact privacy@chessones.com or use the "Do Not Sell or Share My Data" link in the footer of the ChessOnes website.
14. Third-party links and services
The Service may contain links to third-party websites or integrate with third-party services such as Google and Facebook/Meta. We are not responsible for the privacy practices of those services. We encourage you to review their privacy policies independently before providing them with personal information.
15. Changes to this privacy policy
We may update this Privacy Policy from time to time to reflect changes in our practices, applicable law, or the features we offer (including when paid features are introduced). When we make changes, we will update the "Last Updated" date at the top of this document. For material changes, we will provide notice via email or a prominent in-platform notification at least 14 days before the changes take effect. Your continued use of the Service after the effective date of any update constitutes acceptance of the revised policy.
16. Contact us
ChessOnes Privacy Team
- Email: privacy@chessones.com
- GDPR: dpo@chessones.com
- Security: security@chessones.com
Mailing address
ChessOnes LLC[REGISTERED AGENT / OFFICE ADDRESS]
New Jersey, United States
