01

Who we are

Tourney Master by Shockwave9999 is a tournament-operations Discord bot plus this companion web dashboard. Together they run competitive events end to end: brackets, match scheduling with judge/recorder staffing, attendance and salary sheets, result declaration with score proof, channel transcripts, and moderation. This notice explains what the bot and dashboard collect about you, why each item is needed, and the choices you have. By using either you agree to this notice.

02

Discord access and membership

You must remain a member of the official Carnival Gaming Discord server to use this dashboard. During sign-in we may add you to that server automatically so membership can be verified on every visit. If you leave the server, dashboard access is suspended until you rejoin. Membership is checked with Discord using the permissions you granted during login.

  • We request identify guilds guilds.join scopes during Discord login.
  • We only add you to the official server; we never remove you from any other server.
  • We read the list of servers where you hold Discord Administrator permission to build your server list.
03

Account information

When you sign in with Discord we receive the account details Discord provides for the login: your Discord user ID, username, display name, and avatar when available. Your Discord password is never shared with us. Direct messages you send to the bot itself are read only to operate the support inbox described below — we never read your private DMs with other users.

04

Login history

Each sign-in stores a dated entry with device, browser, operating system, locale, screen size, and user agent to help dashboard owners review account activity.

  • Login history is visible to you on the Login History page and to the dashboard owner for security review.
05

Bot and tournament data

Only what tournaments need to run, stored in our MongoDB: your Discord user ID wherever you take part (staff assignments, match captains, team sheets, moderation entries, policy receipts); your current username on attendance and salary sheets so past records stay readable; and tournament data (scores, links, schedules, settings). When you use a bot feature, the related content is used just for that feature — a command you type, a DM you send to the bot (forwarded to the staff support channel), a text you ask to translate, or a match channel you played in (saved as a transcript file in that server's own channels for dispute evidence). Command records keep only the command name, user, channel, and server with message text removed, and expire automatically (see retention). Your data is never profiled and never used to train models. Tournament data is shown in the dashboard only to administrators of the affected server. Attendance and tournament records belong to each server's own organisers — they enter this data, and they have complete control over what they feed us: organisers can delete a match record with /attendance delete and remove a whole tournament with /tournament delete (or the Delete button on the dashboard tournament page).

06

Dashboard-generated data

The dashboard stores your saved tournaments, notification preferences, game profile used by the bot's /profile command, advertisement listings you publish with their analytics, and an audit trail of dashboard changes (who changed what, when, and in which server) for accountability.

07

Cookies and session storage

We use a single first-party session cookie (tourneymaster.sid) to keep you signed in and to protect forms against cross-site request forgery. After you accept this notice a signed policy receipt cookie (tourneymaster.policy) remembers your acceptance. Both cookies are HTTP-only and expire with your session or after one year respectively. We do not use advertising or third-party tracking cookies.

08

Third-party services

Tourney Master works with a small set of processors to deliver its features:

  • Discord (authentication, membership checks, bot operations) — subject to the Discord privacy policy.
  • Challonge (bracket data for tournaments you connect) — API keys are stored for the servers you manage.
  • Google Sheets (attendance report links shared by tournament organizers).
  • YouTube (tutorial metadata fetched for the Guide; videos embed via youtube-nocookie.com).
  • Translation provider (receives only the exact text you asked to translate, nothing else).
09

Data retention

Command logs are kept for about 30 days and then deleted automatically, and temporary log files are overwritten on rotation. Transcripts and forwarded DMs live only as messages and files inside that server's own Discord channels, under its administrators control. Sessions expire after eight hours of inactivity, login history is kept while your account is active, and tournament, attendance, schedule, and audit data is kept while the server uses the bot — removed with the tournament or server when an administrator deletes it.

10

Encryption and security

Stored data is encrypted at rest by our MongoDB hosting and in transit via TLS. Secrets (bot token, OAuth secret, session secret) live in environment variables, never in code, and are scoped per service. @mentions are sanitized before any log forwarding. Server data is only visible to the dashboard owner and the administrators of the affected server. Advertisement moderators only see the listings submitted for moderation, and blocked accounts lose all dashboard access.

11

What we never do

We never receive your Discord password or payment details, never sell or share your content beyond operating the feature that produced it, and never use your content to train models or for profiling. We don't track your online status.

12

Your choices and deletion

Self-serve and instant: /profile delete (with a confirm-button prompt) permanently deletes your game profile on the spot. Everything else: DM the bot owner (shockwave9999) or ask in the support server at https://discord.gg/DX46SJBqqX (also linked in /bot about) and we remove your attendance records, team-sheet entries, blacklist entries, command-log rows, and policy receipts from MongoDB. There is no passive tracking to opt out of — not using the content features above means no message content is processed. You can also leave the official server to suspend dashboard access, review your login history on the Login History page, or log out to end your session immediately.

13

Changes to this notice

When this notice changes materially we ask you to accept the updated notice before you can continue. Last updated September 12, 2026.

14

Contact

Questions about this notice or your data: ask in the official Carnival Gaming Discord server (https://discord.gg/DX46SJBqqX), in the support server at https://discord.gg/DX46SJBqqX, or DM shockwave9999.