1. About this notice
BracketOps is a tournament management app used by Play! Pokémon tournament organisers and competitors. This notice explains what personal information we hold, why, who can see it, and how you can get it corrected or removed.
BracketOps is operated by Tian, who is responsible for the information described here. Play! Pokémon organisers who run events on it, including Play NZ, are partners using the app — they are not its operator.
BracketOps is independent. It is not affiliated with, endorsed by, or operated by The Pokémon Company International, Inc. Any information you give directly to Pokémon — for example through your Pokémon Trainer Club account, or results your organiser reports to Pokémon after an event — is handled under Pokémon's own privacy notice, not this one.
2. Two ways your information reaches us
This matters, because most competitors never create a BracketOps account.
- You sign in and register. You create an account, complete your profile, and sign up for events yourself.
- Your organiser imports you. Organisers run events in Tournament Operations Manager (TOM) and upload the resulting tournament file to BracketOps so pairings and standings can be shown live. That file contains every competitor entered in the event. If you played in an event that used BracketOps, we hold information about you even if you have never used this site.
Your organiser decides which events to run and publish. We operate the platform that stores and displays that information for them.
3. What we hold
| Information | Where it comes from |
|---|---|
| Name, email address, profile picture | Google sign-in |
| Preferred/nickname, Play! Pokémon Player ID, year of birth | Entered by you when completing your profile |
| Name and Player ID of every competitor in an event | The tournament file your organiser uploads from TOM |
| Age division, registration status, pairings, table numbers, match results, win/loss/tie record, standings | Generated as the event runs |
| Deck lists and team lists, where the event requires them | Submitted by you |
| Photos of paper deck lists handed in at an event, and the list typed up from them | Photographed by event staff; the card names are read by Google's Gemini API |
| Penalties and deck checks recorded by judges, including notes | Entered by event staff |
| A history of each registration: when you registered, joined or left the waitlist, were given or offered a seat, or withdrew, and any change the organiser made, such as seating or removing you | Recorded as you register and as the organiser manages the event |
| Registration payment records: whether a payment was confirmed and whether that came from the payment provider or the organiser, the provider's payment reference, when you told us you had paid, and when a payment failed or arrived after your held seat was released | Your organiser's payment provider, your organiser, and you |
| Inbox: notices BracketOps creates about your registrations, events you run or judge, your account and your requests; announcements from BracketOps admins; requests you send to the admins and their replies | Created by BracketOps as those things happen, and written by you |
We do not store your full date of birth. Only a year of birth is kept, and only when you enter it yourself, because age division rules depend on it. The tournament file uploaded from TOM also carries only a year of birth for each player (TOM writes a fixed placeholder for the month and day); it is kept unchanged for the seven days described under How long we keep it.
We do not handle card or bank details. Registration payments happen on your organiser's payment provider's own pages. From the provider we receive whether a payment succeeded or failed, with its payment reference. We also record when you tell us you have paid and when your organiser marks a payment as received.
When you link a Player ID that has played at BracketOps events, we check the name on your account against the name recorded for it, and if they differ an organiser or admin checks your Play! Pokémon ID in person; we record who checked it and at which event.
Paper deck lists. At some events, staff photograph paper deck lists so the list can be checked in BracketOps. The photo is sent to Google's Gemini API to read the card names. Under Google's paid API terms, the photo is not used to train Google's models, and Google keeps it only for a limited period for abuse detection. The name and Player ID written on the sheet are only compared with the player the photo is filed under; they are not stored. We keep the photo until the event is completed or cancelled, and at the latest 14 days after the event date, then delete it. The typed-up list is kept like any other deck list. Players cannot view the photo; the event's organiser, its judges and BracketOps admins can, while the event runs.
4. What is shown publicly
A tournament's page can be opened by anyone with the link, without signing in. On that page we show competitors' names, age divisions, pairings, table numbers, match results and standings. This is how competitors and spectators follow a live event, and Play! Pokémon's tournament rules permit organisers to publish tournament details.
Deck lists, team lists, penalties and deck checks are not shown publicly. They are visible only to you, to the organiser of that event, and to judges assigned to it. Email addresses and years of birth are not shown publicly either. Your email address is visible only to you and to BracketOps admins. Your year of birth is visible only to you and to BracketOps admins; when you enter an event, its organiser also receives it inside the tournament file they export to TOM, which uses it to place you in an age division.
Player IDs are not shown on public pages. They are visible to the player, to the organiser and judges of an event the player is in, and to BracketOps admins. An organiser can look someone up only by typing their complete Player ID, to add them to an event or make them a judge; this shows the organiser only that person's first name and last initial, and a partial or wrong ID shows nothing. If an organiser sets up a registration webhook, it also receives registrants' Player IDs.
Registration history and payment records are not shown publicly or to judges. The organiser of that event sees them to manage the roster, and you see your own registration status and the updates about it.
No other user or organiser can see your inbox, and admins don't browse it; we look at delivery records only to answer a request or fix a problem. Admins read your requests and reply as a team. Registration notices go to the account that held the Player ID at the time, and your inbox never shows anything from before your Player ID was linked to your account. If an admin removes a Player ID from your account, notices about that Player ID are removed from your inbox.
5. Competitors under 18
Junior and Senior divisions are, by definition, made up of children. If you are registering as a minor, or on behalf of one, please be aware that the competitor's name, division and results will appear on a publicly accessible page as described above.
There is no private messaging in BracketOps. Admin replies to requests in your inbox only answer requests you started, and we check those replies for links and contact details.
A parent or guardian can ask us to remove a child's information, or to show only a shortened form of their name, using the contact details in section 9. We will act on those requests.
6. Where your information is stored
BracketOps runs on third-party infrastructure, which means your information is stored on servers outside New Zealand:
- Supabase — database, sign-in and file storage, hosted in India (ap-south-1)
- Vercel — application hosting and content delivery, United States and global edge locations
- Google — sign-in, and the Gemini API that reads photographed paper deck lists (section 3)
- Payment providers — where an organiser charges an entry fee
We do not sell your information, and we do not share it for advertising.
7. How long we keep it
The tournament file uploaded from TOM, unchanged, is available to the organiser for seven days after its last upload — long enough to report the results to Play! Pokémon — and is then deleted by a daily automatic clean-up, normally within a day.
Photos of paper deck lists are deleted when the event is completed or cancelled, and at the latest 14 days after the event date. The list typed up from a photo is kept like any other deck list.
The record of a Player ID you enter, and of any check of it, is kept for as long as your account exists if that Player ID is linked to your account, and otherwise until 180 days after the request was closed.
Results, standings, past events and each event's roster (including withdrawn or cancelled registrations) are kept so that event history remains available, and so is a record of payment provider notifications for a registration. The log of registration changes is deleted 180 days after each change was recorded, and the payment links issued for held seats 180 days after they were closed. If you would rather your information were removed, ask us and we will remove it.
Inbox notices are deleted 60 days after they were created, or when you delete them. Open requests are kept until they are closed; a request waiting for your reply closes after 30 days. Closed requests are deleted 60 days after they are closed. Deleting your account deletes your inbox and your requests with it.
8. Your rights
Under the New Zealand Privacy Act 2020 — and, if you are in the UK or EU, under the GDPR — you can ask us to:
- tell you what information we hold about you, and give you a copy
- correct anything that is wrong
- remove your information, or reduce what is shown publicly
A copy includes your inbox and the requests you have sent. You can also delete any notice in your inbox yourself, at any time, and it is gone for good.
You can also complain to the Office of the Privacy Commissioner if you are not satisfied with how we have handled your request.
9. Contact
For any privacy question or request, email bracketops.privacy@gmail.com. For questions about a specific event — including having your details removed from that event's public page — contacting the organiser who ran it is usually fastest, but you can always come to us instead. This applies whether or not you have a BracketOps account.
10. Changes
If we change how we handle personal information we will update this page and the date at the top. Material changes affecting what is published will be announced in the app.