Privacy Policy
Last updated: May 12, 2026
This Privacy Policy describes how BRKT (“we”, “us”, or “our”) collects, uses, discloses, and protects information when you use our websites, apps, and related services (collectively, the “Service”), operated in connection with the domain brkt.games and related BRKT properties.
By using the Service, you agree to this Privacy Policy. If you do not agree, please do not use the Service.
1. Who we are
The data controller for personal data processed through the Service is the operator of BRKT /brkt.games. For privacy requests, contact hello@brkt.games.
2. What we collect
Depending on how you use the Service, we may process:
- Account and authentication data — email address, name or display name, profile image (if you choose one), authentication provider identifiers, and security-related data when you sign in or create an account. This is processed by our authentication vendor, Clerk, on our behalf.
- Bracket and league data — league names, invites, picks, scores, standings, messages you post in the product, and similar content you submit.
- Payment-related data — when you pay for a paid league tier, our payment processor (Stripe) collects payment method details and billing information. We do not store full payment card numbers on our servers; Stripe processes card data according to its own policies and certifications.
- Technical and usage data — IP address, browser type and version, device type, operating system, referring URLs, pages viewed, approximate location derived from IP, timestamps, and similar diagnostics. We use this to operate, secure, and improve the Service.
- Support communications — information you send when you contact support or reply to emails from us.
3. How we use personal data
We use personal data to:
- Provide, maintain, and improve the Service;
- Create and manage your account;
- Process payments and fulfill purchases;
- Send service-related messages (e.g. security notices, receipts, product updates);
- Detect, prevent, and address fraud, abuse, and security issues;
- Comply with legal obligations and enforce our terms.
4. Legal bases (EEA, UK, and similar jurisdictions)
Where GDPR or UK GDPR applies, we rely on one or more of the following legal bases:
| Purpose | Legal basis |
|---|---|
| Providing the Service, accounts, leagues, picks | Performance of a contract; legitimate interests (service delivery) |
| Payments and tax documentation | Performance of a contract; legal obligation |
| Security, fraud prevention, abuse detection | Legitimate interests; legal obligation |
| Product analytics that do not require consent under local law | Legitimate interests (where applicable) |
| Non-essential cookies or similar technologies, where required | Consent |
5. Sharing and subprocessors
We share personal data with vendors that help us run the Service (“processors” or “subprocessors”). Categories include:
- Clerk — authentication, user management, and related security features.
- Stripe — payment processing, fraud prevention, and (where enabled) tax calculation and compliance (e.g. VAT/GST).
- Vercel — hosting and edge delivery of the web application.
- Sanity — content management for marketing or editorial content where configured.
- Email and infrastructure providers — sending transactional email and operating our backend APIs and databases as configured in our environment.
We may also disclose information if required by law, legal process, or governmental request, or to protect the rights, property, or safety of our users, the public, or us.
We do not sell your personal information for money. Where U.S. state laws use the term “sell” or “share” in a broader sense (e.g. certain digital advertising), we aim to disclose that below and offer opt-out rights where required.
6. International transfers
We may process and store information in the United States and other countries where we or our vendors operate. Those countries may have different data protection laws than your own. When we transfer personal data from the EEA, UK, or Switzerland to countries not deemed adequate, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (and UK Addendum where applicable), unless another lawful transfer mechanism applies.
7. Retention
We retain personal data only as long as needed for the purposes described above, including:
- Account data — for as long as your account is active and a reasonable period afterward for backup, dispute resolution, and legal compliance.
- League and picks data — for the life of the league and tournament-related retention as needed for standings, integrity, and user expectations, unless deletion is requested earlier where feasible.
- Payment records — as required by tax, accounting, and payment network rules (often several years).
- Security logs — for a limited period consistent with security needs and legal obligations.
8. Security
We use administrative, technical, and organizational measures designed to protect personal data. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, or restrict processing of your personal data, to data portability, to object to certain processing, and to withdraw consent where processing is based on consent. You may also have the right to lodge a complaint with a supervisory authority.
To exercise these rights, contact hello@brkt.games. We may need to verify your request. Some rights may be limited (for example, where we must retain data for legal reasons).
10. California (CCPA / CPRA)
If you are a California resident, you may have the right to know what personal information we collect, use, and disclose; to request deletion; to correct inaccurate information; and to opt out of certain types of sharing that may be considered “selling” or “sharing” under California law. We do not knowingly sell personal information of minors under 16 without affirmative authorization as required by law.
To submit a request, email hello@brkt.games with “California privacy request” in the subject line. We will not discriminate against you for exercising these rights.
11. Canada (PIPEDA and provincial laws)
Canadian users may request access to or correction of their personal information, and may have additional rights under applicable provincial privacy laws. Contact us at the email above.
12. Brazil (LGPD)
If you are in Brazil, you may have rights under the Lei Geral de Proteção de Dados, including confirmation of processing, access, correction, anonymization, portability, deletion of unnecessary data, and information about subprocessors and transfers. Contact hello@brkt.games.
13. Australia
If you are in Australia, you may have rights under the Privacy Act 1988 (Cth), including to access and correct personal information and to complain to the Office of the Australian Information Commissioner (OAIC). Contact us first at hello@brkt.games.
14. Cookies and similar technologies
We and our vendors use cookies and similar technologies for authentication, session management, security, payment processing, and (where we enable them) analytics or preference storage.
Essential cookies are typically needed to log you in, keep you signed in, route traffic securely, and prevent fraud. Where required by law, we will obtain consent before using non-essential cookies (for example, certain analytics or advertising cookies).
You can control cookies through your browser settings. Blocking essential cookies may prevent parts of the Service from working.
15. Children
The Service is not directed to children under 13 (or under 16 where a higher age applies under local law for consent-based processing). We do not knowingly collect personal information from children in violation of applicable law. If you believe we have collected such information, contact us and we will take appropriate steps to delete it.
16. Third-party links
The Service may link to third-party sites or services. Their privacy practices are governed by their own policies; we are not responsible for them.
17. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and update the “Last updated” date. If changes are material, we will provide additional notice as required by law.
18. Contact
Questions about this Privacy Policy: hello@brkt.games.