Privacy Policy
Last updated: June 1, 2025
1. Introduction
The Chess Master Club (TCMC, we, us, or our) is committed to protecting your personal data and respecting your privacy. This Privacy Policy describes how we collect, use, store, and protect your information when you use our Service at thechessmasterclub.com. We are fully compliant with the General Data Protection Regulation (GDPR) (EU) 2016/679 and applicable national data protection laws. By using the Service, you acknowledge that you have read and understood this Privacy Policy.
2. Data We Collect
We collect the following categories of personal data. Account data: your name, email address, and password (stored as a secure cryptographic hash โ we never store plaintext passwords). Purchase data: transaction history and purchase records; payment card details are processed exclusively by Stripe and are never stored on our servers. Usage data: chess openings viewed and unlocked, drill sessions completed, exam scores, daily streak counts, and your overall learning progress. Technical data: your IP address, browser type and version, operating system, device type, and locale or language preference. We collect only the data necessary to provide and improve the Service.
3. How We Use Your Data
We use your personal data to: provide the Service by authenticating your account, unlocking purchased openings, and tracking your learning progress; send transactional emails including welcome messages, purchase confirmations, password resets, and exam notifications; and improve the product by analyzing anonymized, aggregated usage patterns to understand how users engage with the Service.
๐ We do NOT sell your personal data to third parties, advertisers, or data brokers โ ever.
4. Legal Basis for Processing (GDPR)
We process your personal data on the following legal bases under GDPR Article 6. Contract performance (Art. 6(1)(b)): processing your account data and purchase records is necessary to fulfill our contractual obligation to provide the Service you signed up for. Legitimate interest (Art. 6(1)(f)): we analyze anonymized, aggregated usage data to improve the Service โ this interest does not override your fundamental rights and freedoms. Consent (Art. 6(1)(a)): if you opt in to marketing or promotional emails, we process your contact details on the basis of your freely given, explicit consent, which you may withdraw at any time without affecting prior processing.
5. Data Retention
We retain your account data โ including name, email, and usage history โ for as long as your account is active. Following account deletion, we retain personal data for an additional 2 years to address any outstanding legal matters, after which it is securely deleted or anonymized. Purchase records and transaction data are retained for 7 years from the date of purchase to comply with applicable tax and accounting legal requirements. Analytics data is retained only in anonymized, aggregated form and may be kept indefinitely for product improvement.
6. Your Rights (GDPR)
Under the GDPR, you have the following rights regarding your personal data. Right of access: you may request a copy of all personal data we hold about you. Right to rectification: you may request that we correct inaccurate or incomplete data. Right to erasure: you may request deletion of your data (right to be forgotten), subject to our legal retention obligations. Right to data portability: you may request your data in a structured, machine-readable format such as JSON or CSV. Right to object: you may object to processing based on our legitimate interests. Right to withdraw consent: where processing is based on consent, you may withdraw it at any time. To exercise any of these rights, please email us at hello@thechessmasterclub.com. We will respond within 30 days.
8. Third-Party Services
We use the following carefully selected service providers to operate the Service. Supabase: our database and authentication infrastructure, hosted in the EU region, with a Data Processing Agreement (DPA) in place. Stripe: payment processing; Stripe is PCI DSS Level 1 certified and handles all payment card data โ we never receive or store your card details. Resend: transactional email delivery for welcome emails, purchase receipts, and password resets. PostHog: product analytics configured for EU-region data processing with anonymization enabled. Each provider processes your data only as necessary and under appropriate data protection agreements.
9. Data Transfers
All personal data is processed and stored within the European Union or European Economic Area (EU/EEA) wherever possible. Where data must be transferred outside the EU/EEA โ for example, to international service providers โ we ensure that appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, or equivalent mechanisms recognized under GDPR. We do not transfer your data to countries that lack an adequate level of data protection without such safeguards in place.
10. Childrenโs Privacy
The Service is not directed at and is not intended for use by children under the age of 13. We do not knowingly collect personal data from children under 13. If we discover that we have inadvertently collected data from a child under 13, we will take immediate steps to delete that data from our systems. If you are a parent or guardian and believe that we may have collected data from your child, please contact us immediately at hello@thechessmasterclub.com.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by sending an email to your registered address and by posting the updated Policy on this page with a new date. Minor changes that do not materially affect your rights may be made without separate notification. We encourage you to review this Policy periodically to stay informed.
12. Contact & Data Protection
For privacy-related questions, data subject access requests, or any concerns about how we handle your personal data, please contact us at:
The Chess Master Club
hello@thechessmasterclub.comWe respond to all privacy inquiries within 30 days.