Privacy Policy

Swing to Smash — Privacy Policy

Version 1.0

Document Information

Version: 1.0 Operator / Data controller: the organizer of the badminton tournament(s) and event(s) run through this website, who also operates the Service (the "Organizer", "we", "us", "our"). The Organizer can be reached via the tournament website (see Contact below). Service: the Swing to Smash application at swingtosmash.com (the "Service") and the associated badminton tournament(s) and event(s) (the "Event").

1. What We Collect

  • Account & profile — your name, email address, gender (used only to determine discipline eligibility for Men's / Women's / Mixed doubles), preferred language, and an optional avatar photo you upload.
  • Sign-in — you sign in with Google, Microsoft, or Apple. We receive your basic profile (name, email, provider account identifier) from the provider. We never see or store your password.
  • Registration & teams — the teams you create or join, your discipline, and the name and email of a partner you enter when inviting them (see "Partner invitations" below).
  • Tournament data — check-in status, match assignments, scores, results, standings, and placements.
  • Waiver records — when you accept the Terms & Liability Waiver we record your typed legal name, your drawn signature (image), the signed PDF, and acceptance metadata: version accepted, date/time, IP address, and browser user-agent (DESIGN.md §11.2).
  • Payment reconciliation — if the Event charges a registration fee, it is paid by manual e-transfer outside the Service. We record only whether your payment was received and reconciled. We do not collect or process card numbers or bank credentials.
  • Technical data — server logs (IP address, user-agent, timestamps) used for security, abuse prevention, and rate limiting.

2. Why We Use It

  • To operate the Event: registration, team building, scheduling, check-in, live scoring, standings, and brackets.
  • To publish the public tournament portal (see "What is public" below).
  • To send transactional email necessary to run the Event (see "Email" below).
  • To create and retain the legally required record of your waiver acceptance.
  • To keep the Service secure: authentication, role checks, rate limiting, and abuse detection.
  • To remember your preferences (language, theme).

We do not sell your personal data, and we do not use it for advertising.

3. Partner Invitations

When you register a team, you may enter your partner's name and email so we can invite them. We use that information only to send the invitation and connect them to your team, we identify you as the sender in the message, and we do not send them marketing. Invitations are rate-limited to prevent abuse.

4. Cookies & Local Storage

We use only what the Service needs to function — no advertising or third-party analytics cookies:

  • Session cookie — set by our sign-in system (Auth.js) to keep you signed in. Essential.
  • Locale cookie — remembers your language choice (English / 简体中文).
  • Theme preference — your light/dark choice, stored in your browser's local storage.

5. What Is Public

The tournament portal is public so players and spectators can follow the Event. It shows your name, avatar (if uploaded), team, discipline, group, schedule, match scores, standings, and placements — including a per-player page listing your matches and results.

Your email address, waiver records, payment status, and any data beyond the above are never shown publicly.

6. Email

We send email via Azure Communication Services from our own domain. Messages are transactional: partner invitations, registration confirmations, schedule and result notifications, staff-role claim links, and your signed waiver PDF. Event announcements from the organizer include an unsubscribe option; essential transactional messages do not, because the Service cannot operate without them.

7. Where Your Data Lives

The Service runs on Microsoft Azure: the application on Azure App Service, structured data in Azure Database for PostgreSQL, and files in Azure Blob Storage. Avatar photos and signature images live in private storage containers, accessible only through the application. Signed waiver PDFs are archived in a write-once (WORM) immutable container with versioning, so a signed record cannot be altered or deleted during its retention period. Admin access to archived waivers uses short-lived, authorized links — never public URLs.

8. Retention

  • Account & tournament data — kept while your account is active and for 2 years afterwards, then deleted or anonymized.
  • Signed waiver PDFs and acceptance records — retained for 10 years in immutable storage, even if you delete your account, because they are a legal record of the release you signed.
  • Server logs — retained for 90 days.

9. Your Rights — Export & Deletion

You may at any time:

  • Request a copy of the personal data we hold about you (export).
  • Correct your profile information in the app.
  • Request deletion of your account and data.

Deletion is a soft-delete followed by a purge under the retention schedule above. Two limits apply: signed waiver records are retained for the legally required period, and if you are on a team in an event that is under way, published match results may be anonymized rather than erased so the tournament record stays coherent — an admin will coordinate this with you. Depending on where you live, you may have additional rights (access, portability, objection, complaint to a supervisory authority). To exercise any right, contact us using the details below.

10. Sharing

We share personal data only with:

  • Service providers — Microsoft Azure (hosting, database, storage, email delivery), acting on our instructions.
  • Sign-in providers — Google, Microsoft, or Apple, when you use them to sign in, per their own privacy policies.
  • Authorities — if required by law, or to protect the safety of participants or the integrity of the Service.

We never sell personal data or share it for advertising.

11. Minors

The Service is intended for adults. A participant under the age of majority in their jurisdiction may only participate with a parent or legal guardian's consent and signature per the Terms & Liability Waiver. We do not knowingly collect personal data from children without such consent; contact us to have it removed.

12. Changes to this Policy

We may update this policy. We will update the version above, and for material changes we will notify you in the app or by email.

13. Contact

Questions, export requests, or deletion requests: contact the Organizer via the tournament website.