← WeChessUp

Privacy Policy

Last updated 30 July 2026

WeChessUp is operated by CoreSync Technology Inc., a Massachusetts corporation, at 148 Concord Road, Wayland, MA 01778, United States. “We” and “us” below mean that company. You can reach us at admin@wechessup.com.

This policy explains what WeChessUp collects, why, who else processes it, and how to get it removed. It covers two quite different groups of people: the tournament directors who hold accounts, and the players and followers whose details a director enters.

1. Account data (tournament directors)

  • Your name and email address, so we can identify you and send account email.
  • A password hash, or an identifier from Google, Microsoft or GitHub if you sign in with one of those.
  • Your subscription tier and a Stripe customer reference. We never receive your card number.

2. Tournament data (players)

To pair a tournament and file a rated report, WeChessUp stores what the federations require: player names, ratings, federation IDs and expiry dates, sections, team assignments, results and, where a section is age- or grade-restricted, a date of birth, age or grade.

For this data the tournament director is the controller and WeChessUp is the processor: the director decides what to collect, and we hold and process it on their instructions. If you are a player or a parent and want to know what is held about you, contact the organiser of your event first — they can see, correct and delete it directly. We will help them, and we will act on a request sent to us where the law requires it.

3. Public event pages

A director can publish an event to a public page — pairings, standings, a schedule. What appears there is controlled per event. Where the field appears to include minors, or where ages are not known at all, the defaults reduce displayed names and restrict who can be followed. Public pages are served without authentication and can be indexed by search engines; revoking an event code stops future access.

4. Followers and notifications

  • If you follow an event, we store your email address or phone number, which channels you chose, and a record of your confirmation — the time, the IP address and the version of the disclosure you were shown.
  • Follows are double opt-in: an address is not used until it is confirmed. SMS additionally requires you to tick a separate consent box.
  • Every message includes a way to stop that needs no login: a link in the message, and the one-click unsubscribe your mail app can show as a button. Unsubscribing from one event does not stop you following another.
  • Follower records do not outlive the event. They are deleted automatically 90 days after the event ends, by a job that runs daily — not on request, and not when someone remembers to.
  • Addresses that hard-bounce, complain, or reply STOP go on a permanent suppression list. That list is kept indefinitely and deliberately — it exists so we never message those addresses again, and deleting it would defeat its purpose.

5. Processors we use

  • Supabase — database, authentication and file storage.
  • Google Cloud Run — serves the web application, and runs the pairing engine. The engine receives tournament data to compute pairings and standings and does not retain it.
  • Cloudflare — DNS, and the Turnstile human-verification widget on our sign-in, sign-up and password-reset forms.
  • Stripe — subscription payments.
  • Amazon SES — account and notification email.
  • Twilio — SMS notifications, where enabled.

Human verification on the sign-in, sign-up and password-reset forms uses Cloudflare Turnstile. It loads a script from Cloudflare and sends signals about the browser and the request — not the contents of the form — so Cloudflare can judge whether the request came from a person. It does not use cookies to profile you across sites, and we do not receive anything about you from it beyond a pass or fail. Blocking it will not stop you using WeChessUp, though the request may be refused if we cannot tell it apart from automated abuse.

The rest of our sign-up abuse prevention — rate limiting and blocking disposable email domains — runs inside our own database.

These providers process data on our instructions under their own data-processing terms. Some operate outside your country, so your data may be transferred internationally.

6. Children

WeChessUp accounts are for adults. Junior chess means the tournament data itself frequently describes children, entered by the director running the event. We do not knowingly let a child create an account, and the follow flow asks for an age confirmation before an individual can be followed. If you believe a child has given us information directly, email admin@wechessup.com and we will delete it.

7. The tournament directory

We publish a directory of upcoming chess tournaments. A directory listing describes an event — its name, dates, venue, sections, entry fee and organiser — and never describes a player. No entrant, and no child, appears in it.

Where listings come from. Most are sent to us by the organiser. Some are built by reading tournament calendars that organisers have already published publicly; we take only the factual details, always name and link to the source, and any site can have itself excluded in one email. What our crawler does, in full, is at wechessup.com/bot.

If you submit a listing. We store your name and email address so we can confirm the listing is yours and contact you about it. That address is not published unless you explicitly ask us to show it, and submitting a listing does not subscribe you to anything.

Finding events near you. Searching by distance asks for a postcode, which stays in your own browser. If you instead use the “use my location” button, your browser asks your permission first, and the coordinates are used to run that one search and are not stored on our servers or linked to you.

Search engines. Directory pages are indexable, because being found is the point of them. Live event pages under /e/ — the ones carrying player names — are not, and that distinction is deliberate; see section 3.

8. Cookies and local storage

We use browser storage for your session and your interface preferences — theme, the screen you were last on, the tournament you had open, and the postcode you last searched the directory with. We do not use advertising cookies or third-party analytics trackers.

9. How long we keep things

  • Tournament data: until you delete it or close your account. Events can be archived rather than deleted so historic results stay available.
  • Follower records: 90 days after the event ends, then deleted automatically.
  • Suppression list: indefinitely, as described above.
  • Account data: deleted when you close your account, except records we must keep for tax or legal reasons.
  • Directory listings: while the event is upcoming and for a period afterwards as a record of what took place. A submitter's contact details are removed on request at any time.

10. Your rights

Depending on where you live you may have the right to access, correct, export or delete your data, to object to processing, or to complain to a data-protection authority. Account holders can export and delete from within the app. For anything else, email admin@wechessup.com; we aim to respond within 30 days.

11. Security

Data is encrypted in transit. Every tournament table is protected by row-level security so one account cannot read another's data, and file storage is private and path-scoped. No system is perfectly secure; if a breach affects you we will notify you as the law requires.

12. Changes

We will update this policy as the service changes. The date above tells you when it last changed, and material changes will be announced in the app.


Questions about this document? Email admin@wechessup.com.