Privacy Policy
Last updated: March 14, 2026
This Privacy Policy describes how the World Rock Paper Scissors Association ("WRPSA," "we," "us") collects, uses, and protects information when you use our website and services at wrpsa.com (the "Platform").
1. Information We Collect
1.1 Information You Provide
- Account details (display name, email address, username)
- Profile information (avatar image, bio)
- Payment information (processed by Stripe; we do not store full card numbers)
- Content you create (chat messages, social posts, tournament descriptions)
- Support requests and correspondence
1.2 Information Collected Automatically
- Device and browser information (user agent, screen resolution, operating system)
- IP address and approximate geolocation (country/region level)
- Usage data (pages viewed, features used, match history, session duration)
- Performance data (error reports via Sentry)
1.3 Cookies and Similar Technologies
We use the following cookies:
- Essential cookies - session authentication (httpOnly, Secure). Required for the Platform to function.
- Analytics - Sentry for error tracking and performance monitoring. No third-party advertising trackers are used.
You can manage cookie preferences in your browser settings. Disabling essential cookies will prevent you from logging in.
2. How We Use Your Information
- Provide, operate, and improve the Platform
- Match you with opponents and calculate Elo ratings
- Maintain leaderboards, statistics, and achievement records
- Process payments and manage your wallet balance
- Send transactional emails (password resets, match results, tournament updates)
- Monitor platform security and prevent abuse
- Enforce our Terms of Service
3. Information Sharing
We do not sell your personal information. We share data only in these circumstances:
- Service providers - Stripe (payments), Sentry (error tracking), and infrastructure providers who process data on our behalf under strict confidentiality agreements
- Legal requirements - When required by law, subpoena, or to protect the rights, safety, or property of WRPSA or others
- Public profile data - Your username, avatar, Elo rating, and match statistics are visible to other users
4. Data Retention
- Account data - Retained while your account is active. Upon deletion request, personally identifiable information is erased within 30 days; anonymized match statistics may be retained for leaderboard integrity.
- Chat messages - Retained for 90 days, then automatically purged.
- Payment records - Retained for 7 years as required by tax and financial regulations.
- Server logs - Retained for 30 days for security monitoring.
5. Security
We implement industry-standard security measures including encrypted connections (TLS), httpOnly authentication cookies, bcrypt password hashing, rate limiting, and regular security audits. No system is 100% secure, and we cannot guarantee absolute security.
6. Your Rights
6.1 All Users
Regardless of your location, you may:
- Access and download your personal data
- Correct inaccurate information
- Delete your account and associated data
- Opt out of non-essential communications
6.2 European Economic Area (GDPR)
If you are in the EEA, you additionally have the right to:
- Data portability - receive your data in a structured, machine-readable format
- Restrict processing of your data
- Object to processing based on legitimate interests
- Lodge a complaint with your local data protection authority
Our legal basis for processing is contract performance (providing the service you signed up for) and legitimate interests (security, fraud prevention, platform improvement).
6.3 California (CCPA/CPRA)
California residents have the right to:
- Know what personal information we collect and how it is used
- Request deletion of personal information
- Opt out of the sale of personal information (we do not sell personal information)
- Non-discrimination for exercising privacy rights
To exercise any of these rights, email privacy@wrpsa.com. We will respond within 30 days.
7. Children
WRPSA is not intended for children under 13. We do not knowingly collect information from children under 13. If we discover we have collected data from a child under 13, we will delete it promptly. If you believe a child under 13 has provided us with personal information, please contact us.
8. International Data Transfers
Our servers are located in North America. If you access the Platform from outside North America, your data will be transferred internationally. We ensure appropriate safeguards are in place for such transfers.
9. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes by posting a notice on the Platform or emailing registered users. Your continued use after changes constitutes acceptance.
10. Contact
Privacy questions or data requests? Email privacy@wrpsa.com.