1.Who is responsible
Tournler is operated by Valentin Asenov, an individual based in Bulgaria, who is the controller of your personal data under the EU General Data Protection Regulation (GDPR) and the Bulgarian Personal Data Protection Act.
For anything about your data, including the requests described below, email valentin@qo.ax.
2.Data we collect
Account data
- Email address, if you sign in with a magic link or Discord.
- Nickname, bio and avatar you set during onboarding or on your profile.
- Discord account ID and the access token Discord issues when you sign in with or link Discord.
- Steam ID (your SteamID64) when you link Steam. We receive only the ID through Steam's OpenID sign-in, not your Steam password or library.
- Your account role (for example player or tournament admin) and when the account was created.
Competition data
- Teams you create or join, team invitations, team names and logos.
- Tournaments you organise or play in, and the matches you take part in, including side, captain status, draft picks and map veto actions.
- Match statistics reported by the game server: kills, deaths and assists per match, and results derived from them.
- Match demos: recordings of the match that the game server uploads. A demo contains every player's in-game name, Steam ID and gameplay.
- Badges awarded to your profile and in-app notifications (for example team invites).
Technical data
Our hosting provider processes your IP address and basic request information (browser, time, requested page) to deliver the site and keep it secure. We don't run analytics, advertising or tracking tools.
3.Why we use it, and our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Creating your account, signing you in, and running teams, tournaments and matches you join | Performance of our contract with you (Art. 6(1)(b)) |
| Sending your Steam ID and nickname to the match's game server so only rostered players can connect | Performance of contract (Art. 6(1)(b)) |
| Publishing profiles, rosters, results, stats and demos so competitions are transparent and verifiable | Legitimate interest in running fair, public competitions (Art. 6(1)(f)) |
| Looking up your public FACEIT level from your Steam ID to show on your profile | Legitimate interest (Art. 6(1)(f)); unlink Steam to stop it |
| Security, preventing cheating and abuse, and enforcing our Terms | Legitimate interest (Art. 6(1)(f)) |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c)) |
4.What is public
Tournler is a public competition platform. Anyone, signed in or not, can see your nickname, avatar, bio, team, badges, Steam and Discord IDs, match history, stats and demos, and your FACEIT level if one is found. Uploaded avatars, team logos and demos are stored as publicly accessible files.
Your email address is never shown on your profile. Don't put anything in your nickname, bio or team name that you don't want to be public.
5.Who we share it with
We don't sell your data or share it for advertising. We use these service providers (processors) to run Tournler:
- Vercel: hosting, and storage for avatars, logos and demos (Vercel Blob).
- Our database host: stores the account and competition data above.
- Convex: delivers real-time in-app notifications.
- Our email provider: sends sign-in links to your email address.
- CS2 game servers we run for each match: receive rostered players' Steam IDs and nicknames, and send back scores, stats and demos.
We also exchange data with these independent services when you use them:
- Discord and Steam (Valve), when you sign in with or link those accounts. Their own privacy policies apply.
- FACEIT: we send your Steam ID to FACEIT's public Data API and receive your CS2 skill level and Elo. We cache the answer for about an hour and don't store it in our database.
We may disclose data if the law requires it, or to protect the safety of users or the service.
6.International transfers
Some of our providers, including Vercel and Convex, are based in or process data in the United States. Where data leaves the European Economic Area, we rely on the EU–U.S. Data Privacy Framework where the provider is certified, or on the European Commission's Standard Contractual Clauses.
7.How long we keep it
- Account data: for as long as your account exists.
- Sign-in links: expire within 24 hours.
- Session cookie: up to 30 days, or until you sign out.
- Competition records (results, brackets, stats, demos): kept after a match so tournament history stays accurate. When you delete your account, we remove your account, profile, linked accounts, avatar, notifications and personal stats. Captaincy of your team passes to a teammate. On request we also remove or anonymise your name elsewhere where we reasonably can. Demos already published may still contain your in-game name and Steam ID. Organisers and news authors need to remove or hand over their tournaments and posts first, so other players' results aren't lost.
8.Cookies and browser storage
We only use what the site needs to work, so we don't ask for cookie consent:
- Sign-in cookies that keep you logged in and protect forms against cross-site request forgery.
- A cookie that remembers whether the sidebar is open, on pages that have one.
- Session storage that remembers which page to return you to after signing in, and whether you finished onboarding. It is cleared when you close the tab.
No analytics, advertising or third-party tracking cookies are used.
9.Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and get a copy of it;
- correct inaccurate data (you can edit your nickname, bio and avatar yourself);
- have your data erased;
- restrict or object to processing based on our legitimate interests, including publication of your stats;
- receive your data in a portable, machine-readable format.
You can do the most common ones yourself on your profile page, under Your data: Download my data gives you a JSON file of everything we store about you, and Delete account erases it. You can also unlink Steam there at any time.
For anything else, email valentin@qo.ax from the address on your account, or tell us your profile link. We answer within one month.
You can also complain to the Bulgarian supervisory authority, the Commission for Personal Data Protection (cpdp.bg), or to the authority where you live.
10.Age requirement
You must be at least 14 to create an account, the age at which you can consent to online services yourself in Bulgaria. If you are under the digital-consent age where you live, you need a parent or guardian's permission. If you believe a younger child has created an account, email valentin@qo.ax and we will delete it.
11.Security
We use encrypted connections (HTTPS), sign-in without passwords, and role-based access for staff tools. No system is perfectly secure; if a breach affects your data, we will notify you and the authority as the GDPR requires.
12.Changes to this policy
We will update this page when our data practices change and move the “Last updated” date. If a change is significant, we will tell signed-in users on the site before it takes effect. See also our Terms of Service.