Legal

Privacy Policy

Last updated 3 September 2026

This explains what ChessGOATs collects, why we hold it, who else sees it, and what you can make us do about it. We have tried to write it in plain language. Where it is dry, that is because the law requires precision rather than because we are hiding anything.

1. Who we are

ChessGOATs is operated by [COMPANY NAME] OÜ, a company registered in Estonia under registry code [REGISTRY CODE], with its registered office at [REGISTERED ADDRESS], Estonia. We are the data controller for the personal data described here.

Because we are established in the EU, the General Data Protection Regulation (GDPR) applies to everything below, wherever in the world you use the service from.

For anything in this policy, write to support@chessgoats.com.

2. What we collect

Account information. Your name, email address, and either a password (which we store only as a bcrypt hash — we cannot read it) or a link to your Google account. If you sign in with Google we also receive your Google profile picture and the fact that Google has verified your address.

Chess activity. Games you play on the platform, positions and analyses you save, opening repertoires you build, puzzle attempts, training progress, and course enrolments and lesson progress.

Files you upload. Anything you store in GOATbase — game databases, studies, and whatever else you put there — plus the folder structure and any sharing links you create.

Classroom data. If you use coaching features, the connections between coach and student, session records, and assignments.

Payment information. Your subscription status, plan, and purchase history. We never see or store your card details — those go directly to Stripe, who send us only a customer reference.

Connected accounts. If you connect Lichess or Chess.com, we store the access token (encrypted) or username needed to fetch your games from them. You can disconnect at any time.

Technical data. Server logs including IP address, and usage counts we keep to enforce plan limits.

3. Why we hold it, and on what legal basis

  • To provide the service — your account, your files, your games, your courses. Legal basis: performance of our contract with you.
  • To take payment and manage subscriptions. Legal basis: performance of our contract, and legal obligation for retaining transaction records.
  • To send service email — address confirmation, password resets, and notices about your account. Legal basis: performance of our contract. These are not marketing and cannot be unsubscribed from while you hold an account.
  • To keep the platform secure and stop abuse, fraud and automated attacks. Legal basis: our legitimate interest in running a service that works.
  • To fix and improve things using aggregate usage patterns. Legal basis: our legitimate interest in improving the product.

We do not sell your personal data, we do not share it with advertisers, and we do not build advertising profiles from it.

4. Who else processes it

We use a small number of service providers. Each acts on our instructions under a data processing agreement, and each receives only what it needs:

  • Railway — hosting and the database where your account and content live.
  • Stripe — payments and subscriptions. Stripe is the controller of your card data, not us.
  • Google — only if you choose to sign in with Google.
  • Resend — delivery of the emails we send you.
  • Cloudflare Stream — hosting and delivery of course videos.
  • Pusher — the realtime connection behind live games.
  • Lichess and Chess.com — only if you connect those accounts yourself.

Some of these are based outside the European Economic Area. Where that is the case, transfers are covered by the European Commission's Standard Contractual Clauses or an adequacy decision.

We will also disclose data where the law requires it — a valid court order or a legal obligation — and, if the business is ever sold or merged, to the acquiring party, who would be bound by this policy until they gave you notice of any change.

5. Cookies

We use cookies only to make the site work. There are no advertising or tracking cookies and no third-party analytics.

  • A session cookie that keeps you signed in. Without it you would have to log in on every page.
  • A language cookie remembering which of our 13 languages you chose.
  • Cookies set by Stripe during checkout, for fraud prevention.

Because these are strictly necessary to deliver a service you asked for, they do not require consent under the ePrivacy Directive. Blocking them in your browser will break sign-in.

6. How long we keep it

Your account data and content are kept for as long as your account exists. When you delete your account we remove your personal data and content within 30 days, except where we must keep something longer:

  • Payment and invoice records, which Estonian accounting law requires us to retain for seven years.
  • Security and abuse logs, kept for up to 12 months.
  • Anything we are under a legal obligation or active legal claim to preserve.

Content you shared with others — a shared GOATbase file, a forum post — may remain visible to those people after you leave unless you remove it first.

7. Your rights

Under GDPR you can ask us to:

  • Show you the personal data we hold about you.
  • Correct anything inaccurate.
  • Delete your data — the right to be forgotten.
  • Restrict or object to processing based on our legitimate interests.
  • Export your data in a portable, machine-readable format.
  • Withdraw consent where we relied on it.

Email support@chessgoats.com and we will respond within one month. There is no charge.

If you think we have handled your data badly, you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) or to the supervisory authority where you live.

8. Children

You must be at least 13 to hold a ChessGOATs account. If you are under 18, you may only use the service with the consent and supervision of a parent or guardian, who accepts our Terms of Service on your behalf.

We do not knowingly collect data from anyone under 13. If you believe a child under 13 has created an account, email us and we will delete it and their data promptly.

Where a coach uses our classroom features with students who are minors, the coach is responsible for obtaining the consent needed to enrol them.

9. Security

Passwords are stored as bcrypt hashes. Tokens for connected accounts are encrypted at rest. Email confirmation and password-reset links are stored only as hashes, are valid once, and expire — 24 hours for confirmation, one hour for a reset. All traffic is served over TLS.

No system is perfectly secure. If a breach ever affects your personal data and poses a risk to you, we will notify you and the Estonian Data Protection Inspectorate within 72 hours of becoming aware of it, as GDPR requires.

10. Changes to this policy

When we change this policy we will update the date at the top. If a change materially affects your rights, we will tell you by email or with a notice on the site before it takes effect.

Questions about this document? Email support@chessgoats.com.