Last revised: 2026-08-29 (version 2026-08-29-v12 — this version corrects section 9, the chatbot: two sentences described the service as we meant to build it rather than as it works. The five-message limit is applied in your browser, not on our server — a fresh browser session resets it, and nothing on our side refuses a sixth message, so it is a cost and courtesy measure and not a security control. And conversations are kept for at most 14 days, not the 30 that v11 promised: what exists is the execution record our automation platform writes each time the chatbot answers, deleted automatically once it is more than 14 days old, while operational backups of that server may hold a copy for longer — the part a promise of automatic deletion would have hidden. Nothing else about what we collect, why, or for how long has changed.)
This Privacy Policy explains how MeetPlayNow ("we", "us", "the platform") collects, uses, and protects personal data of players, organizers, and visitors. It is written to the standard of the EU General Data Protection Regulation (GDPR), which we apply to everyone wherever they play, and it is completed by a country integration for each market whose own law requires something different — see section 7.
1. Data Controller
The data controller for personal data processed through MeetPlayNow is:
GiBSeS OÜ Juhkentali 8, 10132 Tallinn, Estonia Registered in the Estonian Business Register (Äriregister) under registry code 17231761 Email for privacy matters: privacy@meetplaynow.com
GiBSeS OÜ is registered in Estonia (EU) and there is one controller for every market: the address and the email above are the ones to write to wherever you play. Where a country's law asks us to name a local point of contact as well, that country's integration says so.
2. Data We Collect
We collect only data needed to operate the platform:
- Account data: email address (required for account creation), hashed password, locked/disabled status, audit timestamps.
- Date of birth (required): collected at sign-up, and asked once of accounts created before 2026-08-08. We use it for the age rules and nothing else. There are two: it decides whether an account may be opened at all — MeetPlayNow is not offered to people under the minimum age set out in our Terms, and a date of birth below it means the account is refused rather than created — and it applies the rule that a photo of a person under 18 is never published outside the platform (section 10). It is not shown on your profile, is not used to profile you, and is not passed to anyone. Until it is given, we treat the account's age as unknown, which for the photo rule has the same effect as being under 18 — the photo is not published outside the platform. It does not close an account that already exists: the registration threshold applies when an account is opened.
- Profile data: the display name you choose, which is the name this service shows other people and publishes in the public ranking; a public handle (slug) derived from it; your sport ratings, computed from your match results. Two further fields are optional and are published only if you ask us to: a profile photo and a short biography. Each has its own consent, each can be withdrawn on its own, and until you give it the field is not shown to anybody but you.
- Optional contact data: phone number (used only for tournament-related warnings if you opt in).
- Operational data: IP address and user agent at login, signup, and consent events (for security audit and fraud prevention).
- Tournament data: registrations, the category you declare when you enter an event (Rookie, Challenger or Elite — the one you would prefer to play in, which you choose yourself and which is not derived from your rating), payment receipts, match results, ranking history.
- Billing data (only if you choose to provide it): legal name, VAT number, billing address — collected exclusively for invoice issuance under Estonian fiscal law.
- Prize delivery data (only if you are due a physical prize): the recipient name, delivery address and phone number we need in order to send you a trophy or an object you won. We ask for it when the final of your competition is drawn — which is before it is played, so that a trophy can reach a finalist in time to be handed over on court — and we ask only the people the prize may go to, never every entrant. The phone number is required because couriers in Thailand call before delivering and a parcel with no number on it is returned to us. It is stored on your account, not on a single shipment, so that you type it once and it is already there the next time you win something: you can see it, change it and delete it at any time in /dashboard/prizes, with or without a prize on its way. This is not your billing data above and neither is used for the other: that is a fiscal record kept for invoicing, this is a courier's instructions. When we actually post a parcel we also keep a frozen copy of the address it was sent to — see section 4.
- Credits wallet data: your credit balance and an append-only ledger of credit movements (grants, purchases, spends, refunds) with amounts, reasons, and timestamps — used to operate the wallet and as accounting records of credit purchases.
- Player-to-player chat data (only if you opt in): the messages you exchange with your opponents, any image you attach to them, the organizer announcements addressed to you, and the list of participants in each conversation. You give this consent when you create your account; you can withdraw it at any time in /dashboard/privacy, and from then on nothing new you send or receive there is processed. See section 4 for how long they are kept.
- Dispute-channel data (only if the result of one of your matches is contested): the messages you, the other player, and the member of our staff handling the case exchange in the channel opened for that case, and any image attached to them. This is not part of the player-to-player chat consent above: it is how a contested result gets decided, so the channel exists whether or not you have chat enabled, and withdrawing chat consent does not take you out of it. See sections 3 and 4.
- Match photos (only if you upload one): the image file itself, the people visible in it, the match and tournament it is attached to, who uploaded it and when, and the technical metadata the file carries. See section 10 below.
- Chatbot data (only if you opt in): conversation transcripts with Khun Somtum and the locale you used. See section 9 below.
- Mobile app data (only if you use the MeetPlayNow app): an identifier for that installation of the app, a device label and the platform it runs on, the moment each session was last used, the language your phone is set to, and — only if you allow notifications — the push notification token of that installation. Section 11 sets out each one, what it is for, and how long it is kept. The app also reaches for your camera, your photos, your clipboard and your fingerprint sensor in four narrow places, all described in the same section.
We do not collect special categories of data (health, biometrics, political opinions, religion, etc.). This includes the fingerprint or face you may use to unlock the app: that check is performed by your phone and its result — yes or no — is all the app ever learns. See section 11.
What is public here, and what is not
MeetPlayNow is a public competition. A ranking nobody can see is not a ranking, and a result that disappears when it is inconvenient is not a result — so taking part means your competitive record is public, and that is not something we ask your permission for: it is what the service is. Concretely, these are visible to anyone, with no account needed:
- the display name you chose, your position, your rating and your results;
- the category you declared for an event you have entered — it is shown beside your name in that event's public list of entrants, which anyone can read;
- the player page that gathers that same record for one sport;
- the city you play in — not as a field on your page, but because the ranking can be read one city at a time, and appearing in a city's board is what says you play there.
You are not obliged to compete under your legal name. The display name is yours to pick — a nickname is perfectly acceptable — and it is the only name of yours this service publishes. Your legal name is asked only if you need an invoice, and it is never shown to anybody.
Two things are not part of that, and stay off until you switch them on: your profile photo and your biography. A tournament is played without either. That includes the public list of entrants: your name and your declared category are in it because you entered, your photo appears beside them only if you have consented to your photo, and without that consent the entry simply shows no picture.
Search engines. Player pages are served with `noindex` and are not indexed. The public ranking page is a normal indexable page, so the display name you chose can appear in search results next to your position — which is one more reason the choice of name is yours.
Leaving. When an account is deleted, the display name, photo and biography go. Match results do not: they are your opponents' record as much as yours, so they stay with the identity removed. Section 4 sets out the detail.
3. Legal Basis for Processing (GDPR Art. 6)
We rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)): account creation, tournament participation, payment processing, match scoring, the publication of your competitive record — display name, position, rating, results, and the category you declared for an event you entered — which is the service you signed up to and is described in "What is public here" above, and the delivery of a prize you won — the address and phone number in section 2 are asked for that delivery and nothing else, and are never used to contact you about anything. On the mobile app this also covers keeping you signed in without retyping your password (the installation identifier in section 11) and sending you the notifications the service is made of — a score entered against you, a match given a date, a decision on a dispute. We never send a promotional push: we hold no consent for one, and the app's four notification switches govern service messages only and cannot grant it.
- Legitimate interest (Art. 6(1)(f)): security audit logs, fraud prevention, abuse moderation, platform integrity, and the handling of contested match results — including the dispute-management channel described in section 4, which is not consent-based because a contested result has to be decided one way or the other. It also covers the device list in the app: knowing which installations hold a live session is what lets you see where you are signed in and end a session you do not recognise, and it is what lets us detect a session token being replayed by somebody who stole it.
- Legal obligation (Art. 6(1)(c)): retention of payment and invoicing records under Estonian fiscal law.
- Consent (Art. 6(1)(a)): non-essential cookies, marketing communications, your profile photo and your biography — two separate consents, each withdrawable on its own, neither of which is a condition of anything (see "What is public here") — optional phone-number contact, player-to-player chat communications, chatbot interactions (see section 9), and each of the two uses of a match photo — showing it on MeetPlayNow, and publishing it on social media and in promotional material — which are asked and recorded separately (see section 10).
- Legal obligation and the protection of minors: date of birth is processed to apply the age rules in our Terms. Its collection is a condition of using the service, not a consent, and it is used for no other purpose.
You may withdraw consent at any time without affecting the lawfulness of processing carried out before the withdrawal. For photos published outside the platform, please read section 10: withdrawal stops future use and removes the photo from the channels we control, but it cannot recall what third parties have already copied or shared.
4. Retention
- Account data: kept while your account is active. On deletion or purge request, we anonymize personal identifiers and disable login.
- Payment and invoicing records: retained for 7 years in line with Estonian fiscal obligations.
- Credit purchase records: the ledger of purchased-credit transactions is retained for 7 years as part of our accounting and invoicing records under Estonian fiscal law.
- Audit and security logs: retained for 12 months and then aggregated or deleted.
- Consents ledger: retained as long as required to evidence the lawfulness of processing (typically lifetime of the account plus statutory limitation period).
- Player-to-player chat messages: message content and any attached image are erased 90 days after the message was sent; the attached files are removed from our storage in the same operation. An empty record of the message (sender, conversation and timestamp, without any content) is retained so that abuse reports filed against that message, and the moderation history attached to it, are not lost. The 90 days run from the date of each individual message, including in conversations that are still active.
- Dispute-channel messages: when the result of a match is contested, we open a channel dedicated to that case, containing the two players involved and the member of our staff handling it. Message content and any attached image in that channel are erased 365 days after the message was sent — not 90; the attached files are removed from our storage in the same operation, and the same empty record of the message is kept. The longer window is deliberate, and the reason is not a technical one: this channel is not a private conversation between players, it is the written record of a decision we took — one that changes a match result, changes a ranking, and can have money attached to it — and either player is entitled to challenge that decision after it has been made. Erasing the exchange at 90 days would leave the ruling on file with the reasons for it gone, which is why this material is kept on the same kind of clock as our audit and security logs rather than on the chat one. Who can read it: only the two players involved and our staff. It is never shown to other players, to organizers who are not handling the case, or to anyone outside the platform. After the decision: the channel is closed to new messages and stays readable by those same people, so you can always go back to what you were asked and what you answered; it is reopened only if the same case is taken up again, and it is never deleted in order to close a case. The 365 days run from the date of each individual message, exactly as the 90 days do.
- Chatbot conversation transcripts: we keep no separate archive of them. The only durable copy is the execution record written by the automation platform that runs the chatbot, which that platform deletes automatically once it is more than 14 days old; operational backups of the server it runs on may hold a copy for longer. See section 9.
- Match photos: kept for as long as the consent that covers them stands. When you withdraw a consent, or delete your account, the photo is removed from the platform and from the social media accounts and channels we control within 30 days. Copies already re-shared, screenshotted, indexed or printed by third parties are outside our reach — see section 10.
- Prize delivery address: the address and phone number on your account are erased 90 days after the last prize delivery they served was completed, handed over or cancelled — and only once none of your deliveries is still open. The 90 days are not padding: a parcel that comes back, or a delivery you tell us never arrived, has to be re-sendable without asking you for the address again. If you have an address on file and have never had anything to deliver, we keep it as data you chose to store on your account; it is erased with the account, and you can delete it yourself at any moment in /dashboard/prizes. Deleting your account erases it in the same operation.
- Record of a parcel we posted: when a prize is actually shipped we keep the courier, the tracking number and a frozen copy of the address the parcel was addressed to, for 12 months from dispatch, and then erase all three. This copy does not follow your address: if you change or delete your address afterwards, what a parcel already on its way was addressed to stays as it was. It is kept because it is the record of something we did, and it is what lets us answer you if you tell us a prize never arrived — the same reason, and the same window, as the audit and security logs above.
- Date of birth: kept for the lifetime of the account, and erased with it.
- App sessions (installation identifier, device label, platform, last activity): one record per sign-in of the app, kept while that session can still be used. A session ends when you sign out, when you end it from the device list, or after 60 days without the app being opened. Thirty days after a session has ended its record is erased — long enough to answer "my phone signed itself out last week, what happened", short enough that spent records do not accumulate. One exception, and it is in your favour: while a device still has a live session we keep its oldest record, whatever its age, because that is the date the device list shows you as "first seen", and pruning it would silently rewrite that date to thirty days ago. The security events themselves (a sign-in, a device revoked, a token replayed) live in the audit logs above, under the same 12 months.
- Push notification token: kept while the installation is registered. It stops being used the moment that installation has no live session — a phone you signed out of, or lost and revoked, receives nothing further even though the token is still on file. It is erased when you turn notifications off in the app, when Google tells us the token is dead, and when your account is deleted.
- Installation identifier on the phone itself: it survives signing out, on purpose — that is what keeps the same phone as one entry in your device list rather than a new one every time you sign in — and it is destroyed when you uninstall the app.
5. Your Rights (GDPR Art. 15-22)
You have the right to:
- Access the personal data we hold about you (Art. 15).
- Rectification of inaccurate or incomplete data (Art. 16).
- Erasure ("right to be forgotten") subject to legal retention obligations (Art. 17).
- Restriction of processing in specific cases (Art. 18).
- Data portability in a structured, machine-readable format (Art. 20). When you download your data, IP addresses in the audit history are masked to /24 (IPv4) or /64 (IPv6) for data minimization — only the network prefix is retained, not the full host address.
- Objection to processing based on legitimate interest (Art. 21).
- Not to be subject to automated decisions with legal or similarly significant effect (Art. 22). We do not perform such automated decisions on the platform.
6. How to Exercise Your Rights
You can exercise any of the rights above by:
- Sending an email to privacy@meetplaynow.com, or
- Using the privacy controls available in /dashboard/privacy when logged in.
We will reply within 30 days. If we cannot honor a request (e.g. erasure conflicts with fiscal retention), we will explain the reason in writing.
You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or with your local supervisory authority.
7. Local Law, and the Country Integrations
Everything in this document applies to you wherever you play. But data protection law is not the same everywhere, and a policy that pretends otherwise ends up saying a number that is right in one country and wrong in the next. So we do not rewrite this text per market: what a local law changes is published as a country integration — a short document, one per market that needs one, printed directly under this one on /privacy, saying only what is different. Read the integration for the country your account belongs to together with everything above. Where the two differ, the integration governs, and only for the players it names.
Age. You may hold an account once you have reached the age of majority of the country your account belongs to. That is 18 by default and higher where local law puts it higher; the integration for that country states its number, and section 2 of the Terms states the rule itself. We operate no parental-consent route anywhere. We have no way to reach a parent, to verify that they are one, or to record what they agreed to, and a half-built version of that would be worse than not admitting the minor — so an account whose date of birth is below the threshold is refused at registration, not created and then restricted.
This is a different line from the one in section 10, and the two are kept apart on purpose. Section 10 stops a photo of a person under 18 from being published outside the platform, and that number is 18 in every country, including the ones whose age of majority is higher: it asks whether someone is a child, which is not the same question as whether they can enter into a contract.
8. Cookies
We use cookies and similar technologies. Details are in our Cookie Policy. Strictly necessary cookies are always active; preference, analytics, marketing cookies, and the chatbot toggle are loaded only with your consent.
9. Chatbot Service (Khun Somtum)
MeetPlayNow offers an optional AI chatbot named Khun Somtum to help you navigate the platform, answer questions about tournaments, sports, rules, and onboarding. You can use it in any language (with first-class support for English and Thai).
Activation. The chatbot is opt-in. It is loaded only after you grant the "Khun Somtum chatbot" consent in our cookie banner or in your /dashboard/privacy settings. If consent is withheld or revoked, the widget is not loaded and no conversation data is sent to our chatbot infrastructure.
Data we process for the chatbot.
- The text of messages you send and receive.
- The locale you use during the conversation.
- A non-persistent session identifier (random UUID) for anonymous visitors, or your account user ID if you are logged in. We use it to keep the messages of one conversation together, and to find that conversation again if you ask us about it.
Where the chatbot runs. Conversations are processed by our self-hosted automation pipeline (n8n) running on EU infrastructure. The pipeline forwards messages to a third-party large-language-model (LLM) provider for response generation. Message content is sent to the LLM provider for the sole purpose of generating a reply. We do not allow the provider to train its models on your messages.
Retention. We keep no separate archive of chatbot conversations. The chatbot's working memory holds only the last few messages of an exchange and is lost when the conversation ends. The one durable copy is the execution record that our automation platform (n8n) writes each time the chatbot answers: it contains the messages of that exchange, it lives on the server that runs the platform, our administrators can read it, and the platform deletes it automatically once it is more than 14 days old. Operational backups of that server may hold a copy for longer; we use them only to restore the service. Because a conversation is filed under a session identifier and not under your name, we can delete one earlier only if we can identify it: write to privacy@meetplaynow.com telling us when you spoke to the chatbot and, for an anonymous session, roughly what you asked.
Rate limits. The chatbot widget stops an anonymous conversation after 5 messages and invites you to sign in. This is a limit applied in your browser, to hold down cost and casual abuse in ordinary use. It is not a security control: it is not enforced on our server, and starting a fresh browser session resets it. We state it this way rather than describe it as a protection it is not. It counts nothing about you on our side, and it is not a profiling mechanism.
No automated decisions. The chatbot does not take any decision that has legal or similarly significant effects on you (no account suspensions, no payments, no eligibility decisions). If a chatbot suggestion conflicts with the official tournament rules or the platform terms, the official rules and terms prevail.
Withdrawal of consent. You can revoke chatbot consent at any time from the cookie banner or /dashboard/privacy. Revocation hides the widget on next page load and stops new data collection. The execution records of past conversations are deleted on the 14-day cycle described above, or earlier on request where we can identify them.
Legal basis. Your consent (GDPR Art. 6(1)(a)). Where a local law names the equivalent basis differently, its integration says which one — see section 7.
10. Match Photos
After a match you can upload photos of it. What we may do with them is set out in full in section 10 of our Terms of Service; this section describes the data protection side of the same thing.
What we process. The image file, the faces and other identifiable features it contains, the match and tournament it is attached to, the account that uploaded it, the timestamp, and the technical metadata carried by the file. Where the file carries a GPS location, we strip it before the photo is stored.
Two consents, recorded separately. Uploading is not consenting. We ask you two questions and we record the answers as two distinct entries in our consent ledger, each with the text you accepted, its version, the date, your IP address and your browser's user agent:
- `photo_use_platform` — display of the photo on MeetPlayNow.
- `photo_use_marketing` — publication on our social media accounts and use in advertising and promotional material, online and printed.
They are separate because withdrawing them does not have the same effect, and because you must be free to allow one without the other. Refusing either has no consequence for your account, your matches or your ranking.
Other people in the photo. When you upload, you declare to us that every identifiable person in the photo has agreed with you to the uses you are authorising. That declaration is our basis for processing their image, and it is recorded with the consent. If someone shown in a photo tells us they did not agree, we take the photo down — write to privacy@meetplaynow.com. You do not need an account with us to make that request, and we will not ask you to justify it.
People under 18. A photo of a person under 18 is never published outside the platform, whatever consent is on record. This is why date of birth is collected (section 2). An account whose date of birth we do not hold is treated as being under 18 for this purpose.
Withdrawal, and its limits. You can withdraw either consent at any time in /dashboard/privacy or at privacy@meetplaynow.com. We then stop all new use, and remove the photo from the platform and from the social channels we control, within 30 days. We cannot retrieve copies that third parties have already downloaded, re-shared, screenshotted or indexed, nor printed material already distributed. This limit is inherent to publication outside our own systems; we state it plainly so that the second consent is an informed one.
Recipients. Photos published under `photo_use_marketing` are, by definition, transmitted to the social media platforms we post them on, each of which acts as an independent controller for what happens on its own service, under its own terms, including any transfer outside the EU/EEA. Photos under `photo_use_platform` alone are not sent to them.
Legal basis. Your consent (GDPR Art. 6(1)(a)), asked and recorded once for each of the two uses.
11. The MeetPlayNow Mobile App
MeetPlayNow is also an Android app. Everything above applies to it exactly as it applies to the website — same account, same data, same rights. This section covers only what is different because the app runs on a phone.
Your installation identifier. When you first sign in from the app we mint a random identifier for that installation and the app keeps it in the phone's encrypted keystore. It travels with every sign-in. It exists so that your phone is one thing to us rather than a stranger every time: it is what makes the device list show one entry per phone, what lets you end the session on a lost phone without ending the others, and what makes a stolen session token detectable when someone tries to reuse it. It is not an advertising identifier, we do not read your phone's hardware identifiers (no Android ID, no IMEI, no serial number), and it means nothing to any app but ours. It survives signing out — that is the point of it — and it is destroyed when you uninstall.
What we store next to it. A device label, the platform (`android`), and when the session was last used. The label the app sends today is a fixed string, "MeetPlayNow Android": we do not read your phone's model or its name. If that changes, this section changes with it.
Push notifications. If you allow the app to send you notifications, Google Play services on your phone issue a registration token — an address for that one installation — and the app hands it to us so we know where to deliver. The token is not a name and not an account; it is a destination, and Google replaces it on its own schedule, so the app reports the new one and it overwrites the old on the same record.
- What a push actually contains. The title and the text are fixed sentences we wrote in advance — "A score was entered", "You have a new message". No message text, no player names, no scores, no tournament names ever travel inside a notification. What travels beside it is a handful of identifiers so that tapping the notification opens the right screen. A lock screen is a public surface, and this is why yours stays uninformative to whoever is looking at it.
- What we never push. Anything promotional. Not because we choose restraint today, but because we hold no consent that would make it lawful, and the four notification switches in the app govern service messages only.
- Turning it off. Android asks you before the first notification and you can refuse; you can also switch categories off inside the app, or withdraw the permission in your phone's settings at any time. Refusing costs you nothing in the service — everything a push announces is in the app anyway.
- Where it goes. Delivery is performed by Google (Firebase Cloud Messaging), in the United States — see section 12.
Camera and photos. The app asks for the camera only at the moment you tap "Take a photo", never when a screen opens, and it keeps working if you refuse. Choosing an existing photo asks for nothing at all: it goes through Android's own photo picker, which hands the app the single image you selected — we never request access to your photo library, because asking for the whole library in order to read one file is not a trade we are willing to offer you. What happens to a match photo after that is section 10.
Your clipboard. There is exactly one clipboard read in the app, and it is on the screen where you join a tournament with an invite code. When that screen opens, the app looks at the clipboard once to see whether what you copied is shaped like an invite code; if it is, the field is filled in for you and the screen says so. If it is not, nothing is kept and nothing leaves the phone. We never read your clipboard anywhere else, never in the background, and the contents are never sent to us.
Unlocking the app with a fingerprint or your face. You can ask the app to require your fingerprint, your face or your device PIN before it opens. If you do, the only thing stored is your preference that this is on — kept on the phone, not on our servers. The check itself is performed entirely by Android against data held in your phone's secure hardware: no fingerprint, no face, no biometric template of any kind is ever sent to us, and we could not read one if we tried. This is a lock on the app for whoever is holding your phone; it is not a second password on your account, and it is not a condition of anything.
Signing in with Google. If you use "Sign in with Google", the sign-in happens on Google's own pages and Google is told that you are signing in to MeetPlayNow. What comes back to us is a signed assertion containing your email address, which we use to find or create your account. We never see your Google password. You can use an email address and a password instead, and nothing in the service depends on the choice.
Paying in the app. Card payments in the app are handled by Stripe's own component, exactly as on the website: your card details are entered into Stripe and never pass through our systems. See section 12.
Where you are signed in. The app shows you every installation with a live session — its label, when it first signed in and when it was last used — under Settings → Security, and lets you end any of them, including the one you are holding. Ending a session there also stops that phone receiving notifications.
What the app does not do. There is no analytics SDK, no crash-reporting SDK, no advertising SDK and no third-party tracker of any kind in the app. It does not ask for your location, your contacts, your microphone, your calendar, your files or your call history, and it does not read them.
Legal basis. Contract performance (GDPR Art. 6(1)(b)) for the session, the installation identifier and service notifications; legitimate interest (Art. 6(1)(f)) for the device list and the detection of a reused session token. The camera, the photo you pick, the clipboard read and the biometric lock are each an action you take, and Android asks for its own permission where one is required.
12. International Data Transfers
Personal data is hosted in the European Union. Our hosting provider is Contabo GmbH (Munich, Germany), and the servers holding the database, the uploaded files and the application itself are located in the European Union; the current data centre is in France. Estonia is where our company is registered (section 1) — it is not where the servers are, and the two are stated separately here on purpose. If you play in a country outside the EU/EEA, your data reaches the servers named here by leaving it, and what your own law calls that transfer is in your country's integration (section 7).
We do not transfer data outside the EU/EEA except for:
- Stripe, Inc. (United States), our payment processor. Transfers are covered by Standard Contractual Clauses (SCC) and the EU-U.S. Data Privacy Framework (DPF).
- Google LLC (United States), for two things, both described in section 11. Firebase Cloud Messaging delivers push notifications to the app: what Google receives is your installation's registration token and the fixed title and text of the notification, never the content of a message, a name or a score. Google Sign-In, only if you choose it, tells Google that you are signing in to MeetPlayNow. Transfers are covered by Standard Contractual Clauses (SCC) and the EU-U.S. Data Privacy Framework (DPF).
- Chatbot LLM provider (see section 9) when chatbot consent is granted. Where the provider is located outside the EU/EEA, transfers are covered by appropriate safeguards (Standard Contractual Clauses or equivalent).
13. Security
We apply industry-standard safeguards: TLS in transit, hashed passwords, principle of least privilege, audit logging, and regular review of access rights.
14. Updates to This Policy
We may update this Privacy Policy. Material changes will be notified by email or in-app notice; the current version is always available at /privacy. The previous versions remain accessible on request via privacy@meetplaynow.com.
15. Contact
For any privacy-related question or request: privacy@meetplaynow.com.