Legal
Privacy Policy
Last updated: 2026-05-05
This page explains what personal information Rook Ready collects, how we use it, who we share it with, and the rights you have over it. If you only read one section, read Your rights.
1. Who we are
Rook Ready ("we", "us") provides chess-club management software at rookready.com. This Privacy Policy explains what personal information we collect when you use the service, how we use it, and the rights you have over it.
For privacy questions or to exercise any of the rights described below, email support@rookready.com.
2. Information we collect
We collect only what we need to run a club-management product:
- Account information — name, email address, password (hashed), and the clubs you create or join.
- Member records — names, dates of birth (optional), contact emails, role within the club, and any custom fields the club admin chooses to track. Admins are responsible for getting consent from members before entering this data.
- Event and registration data — RSVPs, attendance, and any registration-form responses you submit.
- Billing data — handled by Stripe. We never see card numbers; we receive only a customer ID, subscription status, and invoice metadata. Stripe's privacy policy applies to the payment data they process on our behalf.
- Usage data — pages visited, features used, browser and device information. Used in aggregate to improve the product. We use PostHog for product analytics; it can be disabled by enabling Do Not Track in your browser.
- Email delivery data — when we send an announcement or transactional email on a club's behalf, our delivery provider records bounce / open / click events so admins can see whether the message landed.
3. How we use your information
We use the data above to provide, secure, and improve the service. Specifically:
- To authenticate you and keep your account safe.
- To deliver the announcements, RSVPs, and notifications you and your club have asked for.
- To process payments through Stripe.
- To monitor uptime, debug errors, and improve the product.
- To contact you about your account or important service changes.
We do not sell personal information, and we do not run third-party advertising on the service.
4. Sharing your information
We share data only with the providers we use to run the service ("subprocessors"):
- Stripe — payment processing.
- Hetzner and DigitalOcean — application hosting and storage.
- Sentry — error reporting.
- PostHog — product analytics.
- Email delivery provider — sends transactional and announcement email on behalf of clubs you belong to.
Each subprocessor is contractually limited to processing data on our behalf for the purposes listed above. We will also share data when required by law (court order, subpoena), to protect the rights or safety of users, or if Rook Ready is acquired (in which case we will notify you before your data is transferred).
5. How long we keep your information
Your account and the clubs you administer remain in our system for as long as the account is active. You can delete your account at any time from Settings → Account → Delete account. When you delete an account:
- Your user record is removed within 30 days.
- If you were the sole admin of a club, the club and its member data are queued for deletion; we will email co-admins first if any exist.
- During the 30-day window the deletion can be undone via the link included in the deletion-confirmation email. After 30 days the data is removed permanently.
- Backups are rotated out within 90 days.
- Anonymized usage analytics may be retained for product improvement.
6. Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct it if it's wrong.
- Delete it (the "right to be forgotten" / GDPR Article 17 / CCPA right to delete).
- Receive a copy of it in a portable format.
- Object to or restrict certain processing.
- Withdraw consent at any time.
Email support@rookready.com to exercise any of these. We respond within 30 days.
7. Children
Many chess clubs include junior players. Rook Ready is intended for use by club administrators (adults) on behalf of their members. Where a member is under the age of 13 (or the equivalent age in your jurisdiction), the club admin and the child's parent or guardian are responsible for collecting and providing only the data necessary for participation. We do not knowingly create direct accounts for children under 13 without verifiable parent or guardian consent.
8. Security
We take reasonable technical and organizational measures to protect your data: encryption in transit (TLS), encrypted storage at the database level, password hashing with bcrypt, scoped access for staff, and audit logs on sensitive actions. No system is perfectly secure, but we will notify you and applicable regulators in line with the law if a breach affects your personal information.
9. International transfers
Our infrastructure is hosted in the United States. If you access the service from outside the US, your information will be transferred to and processed in the US. We rely on Standard Contractual Clauses (or the equivalent) with our subprocessors to make transfers from the EEA / UK lawful.
10. Changes to this policy
We will revise this Privacy Policy as the product evolves and as the law requires. The "Last updated" date at the top reflects the most recent change. For material changes we will email account holders at least 14 days before the change takes effect.