Logo
LATEST DONORS:
← Back to the homepage

Privacy Policy

Effective from March 18, 2026  ·  Controller: efootball.cz

1. Who we are

efootball.cz is operated by the eFootball CZ/SK community. The site serves as a platform for organizing online football competitions. For any questions, contact us via Discord.

2. What data we process and why

We only process data necessary to run the platform:

DataPurposeLegal basis
Discord ID, username, avatarLogin and identification in competitionsConsent (OAuth login)
Match results, ELO rating, karma pointsManaging competitions and leaderboardsContract performance (competition participation)
Pages visited, visit time, referrerOur own anonymous traffic analyticsLegitimate interest
Session ID (stored in sessionStorage)Linking pageviews into a single sessionLegitimate interest
IP address (anonymized), User agentSecurity, bot protectionLegitimate interest
FCM token (optional, for push notifications)Sending match notificationsConsent

3. Analytics – no tracking cookies

Our site runs our own anonymous analytics without using tracking or analytics cookies. Specifically:

  • A session ID is generated randomly and stored in sessionStorage — it disappears when you close the tab.
  • We don't track you across sessions or across other websites.
  • We don't pass data to any third parties (Google Analytics, Meta Pixel, etc.).
  • Visit data is stored on Supabase servers in the EU (Frankfurt).

Note: for login we use secure session tokens stored in the browser, required to keep you signed in (see sections 4 and 8). These tokens are not used for tracking or analytics.

4. Login via Discord

We sign you in using Discord OAuth 2.0. We only receive your public profile from Discord (ID, name, avatar). We never see or store your Discord account password. Your login session is managed by Supabase Auth through secure session tokens stored in your browser.

5. Sharing data with third parties

We don't sell or rent your data. We only share data with these necessary service providers:

  • Supabase — database and authentication (EU, Frankfurt)
  • Discord — OAuth login and optional notifications
  • Firebase / Google FCM — push notifications (only if you've given consent)
  • Cloudflare Turnstile — bot protection for forms

6. How long we keep data

  • Account and in-game data — for as long as your account exists, plus 1 year after deletion.
  • Analytics data (pageviews) — a maximum of 12 months, then automatically removed.
  • Session ID — expires when you close the tab (sessionStorage).
  • FCM tokens — until consent is withdrawn or you unsubscribe from notifications.

7. Your rights (GDPR)

As a data subject, you have the following rights:

  • Access — find out what data we hold about you.
  • Rectification — correct inaccurate data.
  • Erasure — request deletion of your account and data.
  • Portability — get your data in a machine-readable format.
  • Objection — object to processing based on legitimate interest.

Submit a request via Discord. We'll handle it within 30 days. You also have the right to lodge a complaint with the Czech Office for Personal Data Protection (ÚOOÚ).

8. Security

Login sessions are managed using secure session tokens stored in the browser (inaccessible via JavaScript) — these tokens are used solely for authentication, not tracking. All communication takes place over HTTPS. Database access is governed by Row Level Security (RLS) policies in Supabase.

9. Changes to this policy

We reserve the right to update this policy. The date of the last change is shown in the page header. We'll notify you via Discord about any material changes.

Have questions about your privacy? Message us on Discord