Your data. Your dashboard.
A short summary of what Tourney Master uses to run and protect your Carnival Gaming experience.
- Discord access You must remain in the official Carnival Gaming server. We may add you during login so the dashboard can verify access.
- Account information We receive your Discord ID, name, avatar when Discord provides it, administrator server list, and a dated sign-in history.
- Bot and tournament data We keep your ID, username on sheets, and tournament data needed to run events. Content you send is used only for the feature you used. Logs expire after about 30 days.
- Protected information Encrypted at rest and over TLS. We never receive your password or payment details, never sell your content, never train models on it, and don't track your online status.
Who we are
Tourney Master by Shockwave9999 is a tournament-operations Discord bot plus this companion web dashboard. Together they run competitive events end to end: brackets, match scheduling with judge/recorder staffing, attendance and salary sheets, result declaration with score proof, channel transcripts, and moderation. This notice explains what the bot and dashboard collect about you, why each item is needed, and the choices you have. By using either you agree to this notice.
Discord access and membership
You must remain a member of the official Carnival Gaming Discord server to use this dashboard. During sign-in we may add you to that server automatically so membership can be verified on every visit. If you leave the server, dashboard access is suspended until you rejoin. Membership is checked with Discord using the permissions you granted during login.
- We request
identify guilds guilds.joinscopes during Discord login. - We only add you to the official server; we never remove you from any other server.
- We read the list of servers where you hold Discord Administrator permission to build your server list.
Account information
When you sign in with Discord we receive the account details Discord provides for the login: your Discord user ID, username, display name, and avatar when available. Your Discord password is never shared with us. Direct messages you send to the bot itself are read only to operate the support inbox described below — we never read your private DMs with other users.
Login history
Each sign-in stores a dated entry with device, browser, operating system, locale, screen size, and user agent to help dashboard owners review account activity.
- Login history is visible to you on the Login History page and to the dashboard owner for security review.
Bot and tournament data
Only what tournaments need to run, stored in our MongoDB: your Discord user ID wherever you take part (staff assignments, match captains, team sheets, moderation entries, policy receipts); your current username on attendance and salary sheets so past records stay readable; and tournament data (scores, links, schedules, settings). When you use a bot feature, the related content is used just for that feature — a command you type, a DM you send to the bot (forwarded to the staff support channel), a text you ask to translate, or a match channel you played in (saved as a transcript file in that server's own channels for dispute evidence). Command records keep only the command name, user, channel, and server with message text removed, and expire automatically (see retention). Your data is never profiled and never used to train models. Tournament data is shown in the dashboard only to administrators of the affected server. Attendance and tournament records belong to each server's own organisers — they enter this data, and they have complete control over what they feed us: organisers can delete a match record with /attendance delete and remove a whole tournament with /tournament delete (or the Delete button on the dashboard tournament page).
Dashboard-generated data
The dashboard stores your saved tournaments, notification preferences, game profile used by the bot's /profile command, advertisement listings you publish with their analytics, and an audit trail of dashboard changes (who changed what, when, and in which server) for accountability.
Cookies and session storage
We use a single first-party session cookie (tourneymaster.sid) to keep you signed in and to protect forms against cross-site request forgery. After you accept this notice a signed policy receipt cookie (tourneymaster.policy) remembers your acceptance. Both cookies are HTTP-only and expire with your session or after one year respectively. We do not use advertising or third-party tracking cookies.
Third-party services
Tourney Master works with a small set of processors to deliver its features:
- Discord (authentication, membership checks, bot operations) — subject to the Discord privacy policy.
- Challonge (bracket data for tournaments you connect) — API keys are stored for the servers you manage.
- Google Sheets (attendance report links shared by tournament organizers).
- YouTube (tutorial metadata fetched for the Guide; videos embed via youtube-nocookie.com).
- Translation provider (receives only the exact text you asked to translate, nothing else).
Data retention
Command logs are kept for about 30 days and then deleted automatically, and temporary log files are overwritten on rotation. Transcripts and forwarded DMs live only as messages and files inside that server's own Discord channels, under its administrators control. Sessions expire after eight hours of inactivity, login history is kept while your account is active, and tournament, attendance, schedule, and audit data is kept while the server uses the bot — removed with the tournament or server when an administrator deletes it.
Encryption and security
Stored data is encrypted at rest by our MongoDB hosting and in transit via TLS. Secrets (bot token, OAuth secret, session secret) live in environment variables, never in code, and are scoped per service. @mentions are sanitized before any log forwarding. Server data is only visible to the dashboard owner and the administrators of the affected server. Advertisement moderators only see the listings submitted for moderation, and blocked accounts lose all dashboard access.
What we never do
We never receive your Discord password or payment details, never sell or share your content beyond operating the feature that produced it, and never use your content to train models or for profiling. We don't track your online status.
Your choices and deletion
Self-serve and instant: /profile delete (with a confirm-button prompt) permanently deletes your game profile on the spot. Everything else: DM the bot owner (shockwave9999) or ask in the support server at https://discord.gg/DX46SJBqqX (also linked in /bot about) and we remove your attendance records, team-sheet entries, blacklist entries, command-log rows, and policy receipts from MongoDB. There is no passive tracking to opt out of — not using the content features above means no message content is processed. You can also leave the official server to suspend dashboard access, review your login history on the Login History page, or log out to end your session immediately.
Changes to this notice
When this notice changes materially we ask you to accept the updated notice before you can continue. Last updated September 12, 2026.
Contact
Questions about this notice or your data: ask in the official Carnival Gaming Discord server (https://discord.gg/DX46SJBqqX), in the support server at https://discord.gg/DX46SJBqqX, or DM shockwave9999.
