Legal
Privacy Policy
Last updated: 2026-08-10
This page explains what personal information Rook Ready collects, how we use it, who we share it with, and the rights you have over it. If you only read one section, read Your rights.
1. Who we are
Rook Ready ("we", "us") provides chess-club management software at rookready.com. This Privacy Policy explains what personal information we collect when you use the service, how we use it, and the rights you have over it.
For privacy questions or to exercise any of the rights described below, email support@rookready.com.
2. Information we collect
We collect only what we need to run a club-management product:
- Account information — name, email address, password (hashed), and the clubs you create or join. An account is for people aged 13 and over, so when you sign yourself up we ask for your date of birth, check it, and keep it. A phone number, a school grade and a gender are optional, and we only hold them if you fill them in.
- Member records — names, dates of birth (optional), contact emails, role within the club, and any custom fields the club admin chooses to track. Clubs decide what to record here and should have their members' agreement before entering it. Where the member is a child, see Children — the duty under children's privacy law is ours, not the club's.
- Event and registration data — RSVPs, attendance, and any registration-form responses you submit. A club writes its own registration form, so what it asks for is up to the club; if the form has a file question, the file you attach is stored with the answer.
- Chess ratings and rating-body IDs — if you give us a US Chess or FIDE ID we store it, and we look your rating up from US Chess and keep the result, along with a snapshot of your rating at the moment you entered each tournament. We only ever read from US Chess; the only thing that leaves us is the ID number, and — when a director searches for a player by name — the name they typed.
- Who is connected to whom — where a parent, guardian or coach is linked to a player, we store that link. It lets them register and act for that player, see the profile details on this list, and receive the club's messages about them. The link records that two people are connected; it is not a check that anyone is a legal guardian.
- Messages and notes — we store the full text of announcements, of messages between a tournament director and a participant or their guardian, and of any private note a club writes on a roster entry. See Sharing for who inside a club can read them.
- Technical records — when someone submits a public registration form or sends us feedback we record the IP address and browser the submission came from, and every action our own staff take on an account is logged with the IP address it came from. These are kept to investigate abuse and to answer "who changed this".
- Billing data — handled by Stripe. No card field is ever shown by us, on the website or in the app: paying always hands you over to a page Stripe runs, so we never see or store a card number. What we keep is the identifiers Stripe gives us back — a customer ID, a subscription ID, which plan you are on, whether it is monthly or annual, and when a trial ends — plus, for a club that collects entry fees, its Stripe account ID and whether Stripe has cleared it to take payments. A club admin viewing their own billing page is shown the card brand, last four digits and expiry, which we fetch from Stripe when the page loads and do not store. Stripe's privacy policy applies to the payment data they process.
- Usage data, on the website and the web app only — pages visited, features used, browser and device information. We use PostHog for this, and it is set to honour Do Not Track, so switching that on in your browser stops it. On the web app PostHog also records a replay of the session, with the contents of every input box masked out, which we use to see where people get stuck. The mobile app sends no analytics of any kind — there is no analytics SDK in it and nothing in it records what you do.
- Crash reports from the mobile app — when the mobile app stops unexpectedly it sends a crash report to Sentry: the error, the stack trace showing where in our code it happened, and the model and operating-system version of the device it happened on. A crash report carries no name, email address or account identifier, and everything the crash reporter would otherwise attach is turned off by name — no screenshots, no view of what was on screen, no record of what you tapped, no list of the requests the app had made, and no performance tracing.
- Push notifications and the device they reach — when you sign in on a phone, the app asks Firebase for a delivery token for that install and sends it to us, so we know where a notification should go. The token identifies the app on that device, not you. Sending you a notification means handing that token, the title and the one line of text to Google's Firebase Cloud Messaging, which is what actually puts it on your screen — so the subject of an announcement, or the line telling you your next pairing, passes through Google on the way. Signing out removes the token from your account, and we clear it when Google tells us the install is gone.
- Email delivery problems — when we send an announcement or a transactional email on a club's behalf, our delivery provider tells us if it bounced, if the recipient marked it as spam, or if they unsubscribed, and we record that so we stop mailing an address that is not working or does not want us. We do not track whether you opened an email or clicked a link in it — those events are thrown away and nothing here stores them. What a club admin can see is the negative side of that: the names of members whose mail was held back because the address bounced, was never confirmed, or opted out.
3. How we use your information
We use the data above to provide, secure, and improve the service. Specifically:
- To authenticate you and keep your account safe.
- To deliver the announcements, RSVPs, and notifications you and your club have asked for.
- To take payment through Stripe — for a club's own subscription to us, and, where a club has connected its own Stripe account, for the entry fees its players pay it.
- To monitor uptime, debug errors, and improve the product.
- To look up a rating from US Chess when you give us a rating ID, and to build the report a director submits for a rated event.
- To contact you about your account or important service changes.
We do not sell personal information, and we do not run third-party advertising on the service.
4. Sharing your information
We share data only with the providers we use to run the service ("subprocessors"):
- Stripe — payment processing.
- Hetzner and DigitalOcean — the servers the application and its database run on.
- Amazon Web Services (S3) — the files you upload. A club logo, a roster spreadsheet you import, and any file answered onto a registration form are stored there rather than on our own servers.
- Sentry — error reporting for the website, the web app, our servers and the mobile app. What reaches it from a phone is a crash report stripped of anything that identifies you, as described above.
- PostHog — product analytics for the website and the web app only, as described above. The mobile app sends it nothing.
- Google (Firebase Cloud Messaging) — delivers push notifications to the mobile app. It receives the device's delivery token and the text of the notification we are sending. We do not use Firebase for analytics, for storing your data, or for signing you in.
- Email delivery provider — sends transactional and announcement email on behalf of clubs you belong to.
Each subprocessor is contractually limited to processing data on our behalf for the purposes listed above. We will also share data when required by law (court order, subpoena), to protect the rights or safety of users, or if Rook Ready is acquired (in which case we will notify you before your data is transferred).
Two disclosures belong here even though they are not subprocessors, because they are not us handing data to a supplier. The first is public tournament pages. Standings, pairings, wall charts and brackets for a running tournament can be read by anyone with the link, without signing in, and they show each player's name and rating — including a junior player's. That is how chess results have always worked and it is what lets a parent in the car park check a pairing, but it is worth knowing before you enter. Nothing else about a player is on those pages: no email address, no date of birth, no rating ID.
The second is the rating report, because it is not us doing the sending. If your club runs a rated tournament, the report that goes to the rating body identifies the players in it. The file we generate lists each player's name, their US Chess ID, their rating at entry and their results — not dates of birth, not email addresses, not contact details. Your club's chief director downloads that file and submits it; US Chess then holds its copy under its own rules rather than ours, and we cannot withdraw it on your behalf. A game cannot be rated without this, so it comes with entering a rated event.
5. How long we keep your information
Your account and the clubs you administer remain in our system for as long as the account is active. You can delete your account at any time from Account settings → Danger Zone, or follow the step-by-step instructions on our account deletion page. When you delete an account:
- Your name, email address, phone number and date of birth are erased after 30 days, along with the private notes and custom-field answers on your club roster entries.
- If you created a club, you must delete that club before you can delete your account — we block the deletion until you do, so a club is never left without an owner. Deleting a club is undoable for 30 days too, by its creator.
- During the 30-day window the deletion can be undone via the link included in the deletion-confirmation email. After 30 days the erasure is permanent and the link no longer works.
- The clubs you belonged to keep their own record of what happened — attendance, event registrations and tournament results — but it is listed under "Removed Member" rather than your name. Where you played rated chess, the rating ID on those tournament records stays, because a result cannot be rated without it; that ID is public at the rating body. Our account deletion page sets out exactly what is erased and what is kept.
- The answers you gave on a tournament entry or a club's registration form stay with that entry, along with any note a director added to it. Those are the club's record of the event, and the account scrub does not reach into them.
- We take backups — our hosting provider snapshots the servers your data lives on — and a copy of your data survives in them for a while after it is erased from the live system. We are not going to put a number on that here, because we have not confirmed how long the provider keeps a snapshot, and we would rather say so than publish a retention window we cannot stand behind. When we have pinned it down, this line will say what it is.
- Anonymized usage analytics may be retained for product improvement.
6. Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct it if it's wrong.
- Delete it (the "right to be forgotten" / GDPR Article 17 / CCPA right to delete).
- Receive a copy of it in a portable format.
- Object to or restrict certain processing.
- Withdraw consent at any time.
Email support@rookready.com to exercise any of these. We respond within 30 days.
7. Children
Many chess clubs include junior players, and Rook Ready is built so that a child does not need an account of their own. The player is a record on the club's roster, and a parent or guardian signs in to their own account, receives the club's email about that player, and can RSVP and register on their behalf.
An account of your own is for people aged 13 and over. When you sign yourself up we ask for your date of birth and refuse the account if it puts you under 13, and we keep the date so the answer does not have to be asked again.
We would rather be straight with you about where that stops. An account can also come from claiming a roster record a club created for you, or the entry you made for a tournament. There we check the date of birth already on that record and refuse it the same way — but if nobody ever entered one, there is nothing to check against and whoever opens that link gets a login. We do not collect or verify a parent or guardian's consent before that happens, and we are not going to imply that we do: where our terms are accepted during one of those claims, the acceptance we record is that person's own, not a parent's. Linking a guardian to a player records that they are connected; it is not an attestation that they are the child's legal guardian, and we do not treat it as one.
Complying with children's privacy law for the information we hold is our responsibility as the operator of this service. It is not your club's, and it is not a school's — we will not ask them to carry it for us. A club still chooses what goes on its own roster and should record only what running the club actually needs, but that is a judgement about their own members, not a transfer of our duty to them.
What we hold about a junior player is what an adult entered: their name, a contact email for them, and — only where a club or a tournament section needs it to check eligibility — a date of birth or a school grade. Neither is required to take part. We keep it for as long as the club keeps that player on its roster, and when the record or the account is deleted their name, contact details and date of birth are erased on the terms set out in section 5. We do not yet publish a retention schedule specific to children's data, saying what we keep, why we need it, and how long we keep it for. We are writing one and it will appear here.
If you are a parent or guardian and you want to see, correct or delete what we hold about your child — or you believe your child has an account with us that they should not — email support@rookready.com. We will confirm who you are before we act on it, and we will respond within 30 days.
8. Security
We take reasonable technical and organizational measures to protect your data: everything travels over an encrypted connection (TLS), passwords are stored as bcrypt hashes and never in a readable form, two-factor secrets are encrypted, access is scoped so a club only ever sees its own members, and sensitive actions are written to an audit log. Disks are encrypted where our hosting provider encrypts them. To be precise about one thing people reasonably assume: beyond the two-factor secrets, the data itself is not separately encrypted inside the database — roster records and message text sit there in readable form, protected by access control rather than by a second lock.
Two other parties can see your data. The first is our own staff, who can open an account's records in an admin tool and, when they need to reproduce something you have reported, generate a one-time link that signs them in as you for thirty minutes. Every one of those actions is logged with who did it and when. The second is your club: an admin or a director of a club you belong to can read the messages sent to and from your entries in that club's tournaments, including a private message between a director and a parent.
There is no automatic moderation of what people write. We do not scan messages, and there is no in-product way to block or report another user — if something is wrong, mail us and we will act on it. That is also why this is not a children's app on either store.
No system is perfectly secure, but we will notify you and applicable regulators in line with the law if a breach affects your personal information.
9. International transfers
Our infrastructure is hosted in the United States. If you access the service from outside the US, your information will be transferred to and processed in the US. We rely on Standard Contractual Clauses (or the equivalent) with our subprocessors to make transfers from the EEA / UK lawful.
10. Changes to this policy
We will revise this Privacy Policy as the product evolves and as the law requires. The "Last updated" date at the top reflects the most recent change. For material changes we will email account holders at least 14 days before the change takes effect.
