1. Who we are
ChessBinder is operated by the ChessBinder team, operating from India (“ChessBinder”, “we”, “us”). We decide how and why your personal data is processed, which makes us the data fiduciary under India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and the data controller under the EU and UK General Data Protection Regulation (“GDPR”) where those laws apply to you.
You can reach us about anything in this policy — including access, correction, and deletion requests — through our contact form. Requests are handled by the ChessBinder Grievance Officer, who acts as our grievance officer for the purposes of the DPDP Act.
2. What this policy covers
This policy covers the ChessBinder website at chessbinder.com and every feature within it: studies, lessons and courses, daily puzzle challenges and the Grand Prix, leaderboards, live study boards, coach and academy tools, class scheduling and attendance, homework, and notifications. It does not cover third-party websites you reach by following a link from ChessBinder.
3. The personal data we collect
3.1 Data you give us
- Account details. Your name, a username, and an email address. Your password is never stored — we keep only a one-way bcrypt hash of it, which cannot be reversed back into your password.
- Profile details. An optional avatar image reference, and your preference about whether your published studies may be used in daily challenges.
- Content you create. Studies, positions, variations, move annotations and notes, lessons, courses, and anything else you type into ChessBinder.
- Messages. What you write in the contact form, including the email address you ask us to reply to.
3.2 Data created as you use the service
- Learning and practice activity. Puzzle and challenge attempts, the individual moves you played, whether they were correct, how long each attempt took, points scored, and your study practice history.
- Leaderboard and reward records. Scores, rankings, periods, and any prizes recorded against your account.
- Coaching and class records. Coach–learner relationships and invitations, class schedules and sessions, attendance marks, homework assignments and their status, and notifications sent to you.
- Account and security events. Sign-in timestamps, email verification and password reset tokens (which expire), and audit records of administrative actions taken on an account.
3.3 Technical data
- Anti-abuse fingerprints. To stop cheating and automated abuse of challenges and forms, we store hashed (irreversible) forms of your IP address and browser user-agent alongside challenge attempts, and use the same hashes for rate limiting. We do not keep your raw IP address in our database for these purposes.
- Diagnostics. Page paths, how long a page took to load, whether an action succeeded, and coarse browser, operating-system, and device categories (for example “Chrome”, “Android”, “mobile”). These are tied to a random identifier stored in your browser, not to your name.
- Server logs. Ordinary web-server and application logs needed to keep the service running and to investigate errors and security incidents.
3.4 What we do not collect
We do not collect payment card details, precise location, biometric data, government identifiers, or contacts from your device. We do not buy personal data about you from data brokers, and we do not run advertising on ChessBinder.
4. Why we use your data, and our legal basis
| Purpose | Legal basis |
|---|---|
| Creating and running your account; delivering studies, challenges, classes, and homework | Performance of a contract with you (GDPR Art. 6(1)(b)); processing for the specified purpose you provided your data for (DPDP Act s. 4 and 6) |
| Verifying your email address, resetting passwords, and keeping accounts secure | Contract and our legitimate interest in a secure service (GDPR Art. 6(1)(b), 6(1)(f)) |
| Preventing cheating, spam, and automated abuse | Legitimate interest in fair play and service integrity (GDPR Art. 6(1)(f)) |
| Publishing leaderboards and public content you chose to publish | Contract, and your choice to publish (GDPR Art. 6(1)(b), 6(1)(a)) |
| Fixing bugs, measuring performance, and improving the product | Legitimate interest in maintaining and improving the service (GDPR Art. 6(1)(f)) |
| Service emails you cannot opt out of while you hold an account (verification, password reset) | Contract (GDPR Art. 6(1)(b)) |
| Complying with law and responding to lawful requests | Legal obligation (GDPR Art. 6(1)(c)); legitimate use under DPDP Act s. 7 |
Where we rely on a legitimate interest, we have considered whether that interest is overridden by your rights, and we do not rely on legitimate interests for anything involving a child’s data.
5. What other people can see
Most of ChessBinder is private to you. The exceptions are deliberate and listed here:
- Your username appears on public leaderboards when you place on one, and next to content you publish. Your email address is never shown publicly.
- Content you publish — studies, lessons, or courses you choose to make public — is visible to anyone, including people who are not signed in.
- Your coach can see the learning data relevant to coaching you: your attendance, homework and its status, practice activity, and studies shared with them.
- People you share with can see studies and live boards you invite them to, and your username within them.
- Our administrators can access account data where necessary to operate the service, investigate abuse, or respond to your support request. Administrative actions are recorded in an audit log.
If you would prefer not to be identifiable on a leaderboard, choose a username that is not your real name. See the Children & Parents notice for our specific advice about usernames for children.
6. Who we share data with
We do not sell your personal data, we do not rent or trade it, and we do not share it with advertising networks or data brokers. We share it only with the following categories of recipient:
- Cloud hosting. A cloud infrastructure provider runs our servers and database and stores your data on our behalf, under a contract that lets them use it only to provide that service.
- Email delivery. An email delivery provider sends our service emails — verification messages, password resets, and notifications. It receives your email address and the contents of those messages, and nothing else.
- Legal and safety. Courts, regulators, or law enforcement where we are legally required to disclose, or where disclosure is necessary to protect the safety of a user — particularly a child.
- A successor. If the service is ever transferred to another operator, your data would transfer with it, and we would tell you before that happens so you can delete your account first.
These providers act as our processors: they may use your data only to provide their service to us, and never for their own purposes. If you want to know exactly which providers we use — a school or academy reviewing us before signing up often does — ask through the contact form and we will tell you.
7. Cookies and browser storage
ChessBinder uses no advertising cookies, no tracking pixels, and no cross-site tracking of any kind. We use only what the service needs to work:
- Session cookie. Set when you sign in so we know it is you on each page. It expires after 30 days, or sooner when you sign out.
- Security cookies. Short-lived cookies that protect sign-in and forms against cross-site request forgery.
- Local storage. A random diagnostics identifier, so we can tell one browsing session’s performance measurements from another. It contains no personal details, and clearing your browser storage removes it.
Our anti-bot check is a proof-of-work challenge computed inside your own browser. It does not profile you and sends no data to a third party.
8. Children
Children use ChessBinder, and their data is handled with extra care. Under the DPDP Act, anyone under 18 is a child; in the United States, COPPA applies to children under 13; in the EU and UK, GDPR Art. 8 applies below the local digital-consent age. We apply the strictest of these standards to every child account.
In short: child accounts are set up and supervised by a parent, guardian, or coach; we never show behavioural or targeted advertising to a child; we never track or profile a child for advertising; and we never sell a child’s data. The full explanation — what we collect about a child, who can see it, and how a parent exercises control — is in the Children & Parents notice, which forms part of this policy.
9. How long we keep data
- Account and content data — for as long as your account is open.
- After you delete your account — we delete or irreversibly anonymise your personal data within 30 days, except where we must keep something longer to comply with law or to resolve a dispute. Content you published publicly may be removed from public view immediately but persist in backups until they rotate.
- Backups — kept on a short rolling cycle for disaster recovery and overwritten automatically as newer backups replace them. Deleted data disappears from backups as that cycle completes.
- Security and audit records — kept for up to 12 months so we can investigate abuse.
- Verification and password-reset tokens — expire within minutes and are then invalid.
10. How we protect your data
Traffic is encrypted in transit with TLS. Passwords are stored only as bcrypt hashes. IP addresses and user-agents used for abuse prevention are stored hashed rather than in the clear. Access to production data is limited to administrators who need it, and administrative actions are logged. No system is perfectly secure, but if a breach affects your personal data we will notify you and the relevant regulator as the law requires — under the DPDP Act this includes notifying the Data Protection Board of India.
11. Where your data is processed
ChessBinder is operated from India, and our providers may process data in data centres outside your country. Where we transfer personal data out of the EEA or the UK, we rely on the European Commission’s standard contractual clauses or an equivalent safeguard offered by the provider.
12. Your rights
Whoever you are and wherever you live, you can ask us to show you the personal data we hold about you, correct it, or delete it. Contact us through the contact form and we will respond within 30 days. We may need to verify that the request really comes from you before we act on it.
- Under the DPDP Act (India): the right to access a summary of your data and the processing we do, to correction and completion, to erasure, to grievance redressal, and to nominate someone to exercise your rights if you die or become incapacitated. If we do not resolve your grievance, you may complain to the Data Protection Board of India.
- Under GDPR (EU/UK): access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interests, and withdrawal of consent at any time without affecting prior processing. You may also complain to your national supervisory authority.
- Under California law: the right to know what we collect and why, to delete it, to correct it, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use it for cross-context behavioural advertising.
A parent or guardian may exercise every one of these rights on behalf of their child. See the Children & Parents notice.
13. Changes to this policy
We will update this page when our practices change, and we will change the “last updated” date at the top. If a change materially affects how we use your personal data, or how we handle a child’s data, we will tell you by email or through a notice in the app before it takes effect.
14. Contact and grievances
Send any question, request, or complaint about privacy — including any grievance under the DPDP Act — through the contact form, addressed to the ChessBinder Grievance Officer. We read every message and will come back to you, and we resolve grievances within the time the law allows.