CHESS OX

Privacy Policy — How We Collect · Use · Store · Protect · Share Your Personal Data

Version 2.0 | Effective: June 2026
PDPP Act 2023 (India) | IT Act 2000 | Consumer Protection Act 2019

Operated by Phoenix Brothers | Tamil Nadu, India | chessox.com

At a Glance

TopicSummary
What we collectName, email, username, IP address, device/browser info, gameplay data, subscription and payment info
Why we collect itTo operate your account, run tournaments, process payments, improve platform, send service communications
Who we share it withPayment processors, hosting providers, analytics tools, law enforcement when legally required. We never sell your data.
How long we keep itAccount data: 90 days after deletion. Transaction records: up to 7 years for legal/tax compliance.
Your rightsAccess, correct, erase, restrict, port your data. Opt out of marketing. Withdraw consent. File a complaint.
Minimum age13 years. Parental consent for 13-17. Cash prize features restricted to 18+.
CookiesEssential always on. Analytics and marketing only with explicit consent.
Contactcontact@chessox.com | Response within 48h | Resolution within 30 days

Legal Basis: Compliance with India's Digital Personal Data Protection (DPDP) Act, 2023; IT Act 2000 & IT Rules 2011; Consumer Protection Act 2019. EU/UK users also benefit from GDPR-aligned rights.

1 - Who We Are and How to Contact Us

Chessox.com is operated by Phoenix Brothers, Tamil Nadu, India. We are the Data Fiduciary under DPDP Act 2023.

Contact TypeDetails
Company NamePhoenix Brothers
PlatformChessox.com
Registered AddressTamil Nadu, India
General Supporthelp@chessox.com
Privacy and Data Requestscontact@chessox.com
Grievance Officerhelp@chessox.com | Response: 48 hours | Resolution: 30 days
Tournamentscontact@chessox.com
Websitehttps://www.chessox.com

Data Protection Contact: For all privacy requests (access, correction, deletion, complaints): contact@chessox.com. Acknowledged within 48h, full response within 30 days. Escalate to Grievance Officer at help@chessox.com if unresolved.

Section 2 - What Personal Data We Collect

2.1 Account Registration Data

Username, email address, hashed password, country (optional), date of birth (age verification).

2.2 Profile and Gameplay Data

Chess rating & history, games played, tournament participation, puzzle scores, friends/clan memberships, in-platform messages, chat history, profile picture/bio. Game records (PGN) stored permanently.

2.3 Subscription and Payment Data

Plan type, transaction IDs, billing history, renewal dates. We do NOT store full card numbers, CVV, or bank account details.

2.4 Technical and Device Data

IP address, browser/OS, device type, screen resolution, referring URL, pages visited, timestamps.

2.5 Communications Data

Support emails, survey responses, feedback — retained up to 2 years for quality assurance.

Data we do NOT collect: precise location, biometrics, health data, racial/ethnic origin, political/religious beliefs. No facial recognition. No data selling.

Section 3 - Why We Use Your Data (Legal Bases)

PurposeData UsedLegal Basis
Create and manage accountRegistration, profile dataContract
Provide gameplay & tournamentsGameplay, rating dataContract
Process subscription paymentsPayment, subscription dataContract
Communicate about your accountEmail, account dataContract / Legal obligation
Detect cheating & fraudGameplay, IP, device dataLegitimate interest / Legal obligation
Platform security & abuse preventionIP, technical dataLegitimate interest
Improve platform performanceTechnical, anonymised gameplayLegitimate interest
Send marketing communicationsEmail, nameConsent (opt-in)
Comply with legal obligationsAll relevant dataLegal obligation
Tax & financial record-keepingPayment/transaction dataLegal obligation (Income Tax Act)

Section 4 - Cookies and Tracking Technologies

Cookie TypePurposeCan Be Disabled?
Essential / FunctionalLogin sessions, authentication, security tokens, languageNo (platform won't work)
AnalyticsUsage stats, feature performance, error tracking (anonymised)Yes – via Cookie Settings
Marketing / PersonalisationPromotional content preferences (explicit consent)Yes – Cookie Settings or opt-out
Third-PartyPayment provider scripts, analytics SDKsPartially (essential payment scripts cannot be disabled)

Managing preferences: Cookie consent banner on first visit; update via Cookie Settings in footer or browser settings. Consent stored for 12 months.

Section 5 - How Long We Keep Your Data

Data CategoryRetention PeriodReason
Account registration dataDuration of account + 90 days after deletionService provision
Game records (PGN)Indefinitely (anonymised after deletion)Platform archive & statistics
Chat and messages2 yearsDispute resolution
Payment transactions7 yearsIncome Tax Act 1961 (India)
Support communications2 yearsQuality assurance
IP and access logs90 daysSecurity monitoring
Anti-cheat investigation data5 yearsPlatform integrity
Marketing consent records3 years from last consentDPDP Act compliance
Deleted account data90 days in backup, then purgedRecovery window

Account Deletion: Within 90 days, identifiable data removed from active systems. Transaction/tax records retained for 7 years as required by law, but not used for marketing.

Section 6 - Who We Share Your Data With

RecipientWhat We ShareWhy
Payment Processors (Razorpay, UPI)Transaction ID, subscription plan, amountProcess payments & prize disbursements
Cloud Hosting ProviderEncrypted user data, game recordsHosting & data storage
Analytics ProviderAnonymised usage data, page viewsPerformance monitoring & improvement

6.1 International Data Transfers

Operated from India. If accessing outside India, data may be transferred to India. Appropriate safeguards (standard contractual clauses) applied for cross-border transfers.

Section 7 - Children's Privacy

Minimum age: 13 years. Users under 13 not permitted; accounts discovered will be suspended and data deleted within 48h.

Ages 13-17: Require verifiable parental consent. Restricted from independent premium subscriptions, cash prize tournaments. No marketing profiling without explicit parental consent.

Parental access: Parents/guardians may request access/correction/deletion of child's data via contact@chessox.com with proof of relationship.

Section 8 - How We Protect Your Data

Encryption: TLS 1.2+ in transit; bcrypt hashing for passwords.
Access controls: Need-to-know basis, confidentiality obligations.
Payment security: PCI-DSS compliant providers; Chess OX never stores card details.
Incident response: Data breach notification within 72 hours to affected users and authority.
Your responsibility: Use strong unique password; enable 2FA; contact help@chessox.com if compromised.

Section 9 - Your Data Rights (PDPP Act & GDPR aligned)

Access Request summary of data, purposes, third-party recipients. Free of charge within 30 days.
Correction Update inaccurate/incomplete data via Account Settings or contact@chessox.com.
Erasure Request deletion of personal data; processed within 90 days (subject to legal retention).
Restrict processing While accuracy or lawfulness is disputed.
Data portability Receive your data in structured machine-readable format (JSON/CSV).
Withdraw consent Unsubscribe from marketing, update cookie settings, or email.
Object Object to processing based on legitimate interests.
Complain To Grievance Officer first, then Data Protection Board of India or CDRC.

EU/UK users: Benefit from GDPR/UK GDPR rights, including right to lodge complaint with ICO or local supervisory authority.

Section 10 - Marketing Communications

Consent-based marketing: Only send promotional emails with explicit opt-in. Opt out anytime via Unsubscribe link, Account Settings, or email contact@chessox.com (subject "Unsubscribe").

Transactional communications (cannot opt out while active): registration, subscription confirmations, renewal notices, payment receipts, security alerts, policy updates.

Section 11 - Third-Party Links and Services

Links to external sites (social media, payment portals) are subject to their own privacy policies; Chess OX not responsible.

Section 12 - India PDPP Act 2023 Compliance Statement

Data Fiduciary: Phoenix Brothers ensures lawfulness, fairness, transparency. Consent management: free, specific, informed consent for marketing/cookies. Data Principal rights: fully facilitated. Grievance redressal: Grievance Officer at help@chessox.com (ack 48h, resolution 30d). Data processor obligations: contractually enforced security measures.

Section 13 - Changes to This Privacy Policy

Material changes: email notification + platform notice 14 days in advance. Minor changes: website update without advance notice. Previous versions available on request.

Section 14 - Contact Us and How to Complain

Contact PurposeDetails
General Privacy Questionscontact@chessox.com - response within 48h
Data Access / Correction / Erasurecontact@chessox.com - resolution within 30 days
Unsubscribe from Marketingcontact@chessox.com with subject "Unsubscribe"
Grievance Officer (escalation)help@chessox.com - resolution within 30 days
Data Breach Reportcontact@chessox.com (priority response)
Postal AddressPhoenix Brothers, Tamil Nadu, India

Escalation Path:
Step 1: contact@chessox.com (48h response, 30d resolution)
Step 2: Grievance Officer at help@chessox.com
Step 3: Data Protection Board of India (once operational), National Consumer Helpline 1800-11-4000, or CDRC under Consumer Protection Act 2019. EU/UK users may contact local supervisory authority (e.g., ICO).