Last updated: 8 October 2026

Privacy Policy

This policy explains how ASH Esports collects and uses personal data when you use our website, dashboard, recruitment forms, Discord-connected features, and team tools.

Data We Collect

If you create stream rank boxes, we store each box's name, appearance settings, linked Riot account, session start, latest ranked statistics, a hashed access key and an encrypted copy of that key so you can copy the same OBS link again from your dashboard. ASH Team layouts also store your chosen team ID and share your site alias and that team's name and logo through the OBS link. If no alias is set, your Riot game name is displayed instead. Only active memberships can be selected; leaving the selected team switches the overlay to the ASH Esports logo. Anyone with your OBS link can view that account's Riot ID, region, rank and session match statistics, including fields hidden in your chosen design. The link works without signing in. You can revoke it by generating a replacement, or delete the box in your dashboard. Unlinking the Riot account or deleting your ASH account also removes all its boxes. Each box has its own link; replacing or deleting one does not revoke your other boxes' links. Settings remain until then. Sessions are calculated automatically from ranked games in the last 24 hours, with a three-hour break separating sessions. A new session does not change your OBS link or erase the underlying match history used by other League features. Overlay pages do not load our analytics. Broadcast recordings and copies made by viewers remain outside our control. Contact the existing privacy contact for access or correction; include your linked account, but never send your OBS access link.

Team managers and coaches can set daily or weekly Solo/Duo practice quotas. We calculate progress from stored matches across linked Riot accounts and show it to you and your team managers and coaches. Staff can record an individual target or an exclusion from a daily or weekly quota, visible to you and authorised team staff. Excluded players have no requirement or quota notifications for that quota until included again. We store the exclusion and its creation time, without collecting a reason, until staff remove it or the associated membership, quota, team or account is deleted. If team staff enable Discord notifications, the bot shares quota progress in their selected team-category channel, mentioning your linked Discord account or using your site username. People with access to that channel can see these posts. Delivery records are retained for 35 days and then cleared by the scheduled cleanup; account or team deletion also removes the associated delivery records. Discord messages remain subject to the server's moderation and retention practices; contact staff for correction or removal.

When you sign in with Discord, we may receive and store your Discord account ID, username, display name, email address, avatar, OAuth tokens, and related sign-in metadata needed to operate your account.

When you use team and recruitment features, we may collect application answers, game preferences, Riot IDs, Ubisoft usernames and platforms, game-connection verification status and reviewer identity, rank snapshots, Rainbow Six Siege ranked history and operator performance returned by R6 Data, team memberships, roles, availability, practice days, champion pools, coaching notes, match bookings, scrims, results, uploaded avatars or logos, reviewer notes, and dashboard activity created through the service.

If you choose to import a custom game with the League Companion, we store game identifiers and timing, Riot IDs or PUUIDs where available, teams, champions, builds, spells, runes, performance statistics, objectives, result information, replay metadata, and the selected replay file. League Client credentials and local file paths remain on your computer.

If you create or use a team invitation or member referral, we store the link creator, intended team where applicable, creation and expiry or revocation times, the account that used the link, and the claim time. Secret link tokens are stored as one-way hashes rather than readable URLs.

Our hosting provider processes request and security information needed to deliver and protect the service. Vercel Web Analytics records aggregated page-view information such as the page, referrer, approximate location, browser, operating system, and device type. ASH redacts query strings and dynamic user or team identifiers before analytics events are sent.

Purposes and Lawful Bases

We use personal data to provide the website and dashboard, authenticate users, manage teams and staff access, process recruitment applications, match and verify game connections, run coaching and availability tools, publish results and roster information, protect the service, investigate issues, and communicate with players, applicants, staff, and community members. Invitation and referral records are used to grant the requested team access, attribute genuine new-member referrals, prevent self-referral or duplicate credit, and provide account holders with referral history.

Depending on the activity, we rely on performance of a contract or steps requested before entering one, our legitimate interests in operating and securing the organisation and its competitions, consent where you have a genuine choice, and compliance with legal obligations. Where we rely on legitimate interests, we balance those interests against the effect on the people concerned. You may object to that processing.

We do not use the website to make decisions about you based solely on automated processing that produce legal or similarly significant effects. Recruitment and roster decisions are made by authorised people.

Merchandise Orders

When you arrange an order offline, ASH administrators can record its items, prices, payment status and tracking information against your registered account. It appears in your protected order history. This record does not initiate a payment or send a new order to our checkout provider. It follows the same one-year retention period. Administrators may enable optional Discord updates at your request if your account has Discord linked; you can turn them off on your order page.

ASH staff can add fulfilment updates, carrier names, tracking numbers and tracking links after speaking with production. These are visible to the customer through their protected order page. We retain the update history and the editing staff member's internal identifier with the order for accountability, for the same one-year order retention period. Deleting the order also deletes this history. Optional Discord messages link to the updated order without including the tracking number or free-text update.

When you request a merchandise checkout, ASH sends your name, email address, selected products, sizes, and any optional printed names to our payment and distribution provider to create the order you requested. Payment is handled through Stripe checkout, which collects your delivery address there. ASH does not receive your card details or delivery address. Product images are loaded from our provider, which receives the ordinary network information needed to deliver those images.

Your bag, including sizes and printed names, is stored in this browser tab for up to 24 hours to let you return from checkout. If you choose “Remember my bag”, it is instead saved on this device for up to seven days after your last basket change. A checkout reference helps you resume an order; contact details and private recovery codes are not stored in the saved bag. Uncheck the option to return to tab-only storage, or use “Clear saved bag” to remove it. Confirmed payment clears the matching purchased bag, preserving a newer bag you have started. Expired saved bags are removed the next time the store reads them. ASH stores order references, selected items and printed names, totals, payment and production status, and order dates for one year from checkout. Buyer name and email are encrypted separately and retained with the order for one year to support fulfilment and customer service. Authorised staff see your linked Discord display name and profile contact link where available, otherwise your buyer name and email contact link. Addresses and card details are not included in the staff order view. A separate checkout retry payload lasts up to 30 days and is removed sooner when ASH confirms payment. The daily maintenance job deletes expired records in bounded batches. Our payment and distribution provider retains its own records under its policies.

Signed-in checkout saves the order to that account unless you choose guest checkout. Guest orders use a necessary secure browser cookie for 30 days and a private recovery code, stored by ASH as a one-way hash. Keep the recovery link safe: anyone holding it can access the guest order and save it to an account. Recovering on another browser replaces the previous browser access for that order. Saving a guest order to an account requires sign-in and existing guest access; it revokes guest recovery access. We do not link orders merely because email addresses match. Deleting an ASH account deletes its linked ASH order records; supplier records are handled separately. These references are not a public order lookup. ASH processes the checkout and tracking details to take steps you request towards your purchase, and uses hashed network identifiers in shared rate-limit records to protect the checkout from abuse. Expired rate-limit records are removed when an administrator runs the existing security-record cleanup; this cleanup is not currently automatic.

Our payment and distribution provider and its payment services retain their own order records. Contact an ASH administrator for order questions, corrections or rights requests, including coordination with those providers. Do not enter sensitive information in a printed name.

Discord order messages are optional. We use the Discord account verified through sign-in or explicit account linking, never a typed username. Messages include your order reference, payment and production status, product names, sizes, prices, product images, order total, and a link requiring account sign-in; they exclude your contact details, address, printed names, card details and guest recovery code. Enable or disable updates on each order page. Pending messages are cancelled when you turn updates off, and recipients are checked against your current linked Discord before delivery. A message already being sent cannot be recalled. Delivery records, including the Discord recipient ID, are removed after 30 days by daily maintenance; deleting the order also deletes these records. Messages already delivered remain subject to Discord and your own message history controls. Automatic status checks stop on final fulfilment/cancellation/refund or after 90 days; manual tracking remains available for the order retention period.

Payment and distribution for the ASH Esports store are provided by Hackin Sportswear.

Public Profiles

Unofficial League of Legends flex teams are excluded from public team listings and team membership displays on profiles. Their memberships still support private team dashboards and Discord roles and channels.

A member profile may publicly show an alias or name, country, avatar, biography, quote, organisation or game role, team membership, verified game connections and ranks, Rainbow Six Siege ranked and operator statistics, Twitch channel, and achievements. Rainbow Six statistics are published only while the linked identity is staff verified and the member is on an active non-tryout Rainbow Six roster. Exact age and free-form location are not returned by the public profile API and are shown on the profile page only to the profile owner or an authorised moderator.

Public visibility is used to present current ASH rosters, staff, competitive history, and achievements. Ask an ASH administrator to correct or remove optional public profile information. Some minimal historical result or hall-of-fame information may be retained where ASH has a documented overriding reason, but each request is assessed individually.

Discord Usage

Official broadcast requests store match details and the Discord identifiers of requesters, applicants, reviewers, website editors and approved crew in our website database to organise streams and track fair team coverage. We also retain the latest website editor and change time to help administrators review corrections. Denial reasons and reviewer details are retained with the request, sent to the requester by Discord direct message, and logged in broadcast-requests. If direct messages are unavailable, the bot tags the requester in that channel with the reason. Please avoid sensitive information in these reasons. Approved crew are mentioned in the Discord schedule. The public website shows only confirmed matchups, leagues and start times. Closed records are reviewed for deletion after two years; contact us using the privacy details below for access, correction or deletion requests.

We use Discord OAuth scopes for identity, email, and guild joining. Where our Discord bot is configured, it may add you to the ASH Esports Discord server, create or remove team roles and channels, send direct messages about relevant team, recruitment, or event activity, and post or update result messages through webhooks.

Messages or profile information you share in Discord may be visible to other Discord users according to the server, channel, role, and Discord settings in place. Discord processes data under its own privacy policy, and ASH Esports cannot control Discord's independent handling of data.

Sharing and Processors

Player rank lookups send the entered Riot ID and region to Riot Games and OP.GG to retrieve public ranked statistics. Lookup results are displayed in your browser and are not saved to an ASH player profile. We use hashed network identifiers and request counters to limit lookup abuse. Hosting providers may process request URLs in operational logs; these URLs can include the entered Riot ID.

For ranked match-count requests made through an authorised API integration, we temporarily save the Riot account identifier (PUUID), split dates, match counts and counting progress in our database so interrupted requests can resume. Progress is scoped to the integration's API key. We do not store individual match IDs or raw API credentials in these progress records or return the PUUID in count results.

We share data only where needed to run ASH Esports services. This may include Discord, Riot Games APIs, R6 Data for Rainbow Six Siege profile matching and statistics, Twitch, Vercel hosting, Vercel Analytics, Vercel Blob storage, database providers, configured webhook or form integrations, and authorised ASH staff or team managers. A successful Riot or R6 Data lookup confirms that an identity exists; it does not by itself prove ownership. Where automatic League icon verification is unavailable, an authorised administrator must complete a separate ownership check before marking a connection verified.

We do not sell personal data. Some roster, event entry, tournament team, Riot ID, verified Ubisoft profile, game statistics, result, hall of fame, avatar, and team information may be shown publicly where it forms part of ASH Esports community or competition activity.

Normal Uploaded Matches imports are restricted to authorised members of the selected team. Imports deliberately sent to Timmy's test sandbox are kept out of that production vault, but their unlisted analysis pages, including player statistics and the game summary, can be viewed by any signed-in ASH user who receives the link. Replay files use long random public Vercel Blob URLs; the analysis page does not publish that URL.

International Transfers

Some providers and their sub-processors may process data outside the UK or European Economic Area, including in the United States. ASH must use an applicable adequacy decision or contractual safeguards such as approved data-protection clauses where the law requires them. You can ask for information about the safeguard relevant to your data.

Retention

Saved API match-count progress expires after 24 hours without a progress update or a saved retry and is deleted by the next daily cleanup. A lookup that keeps making progress or saving retries can continue until it finishes. Completed results are reused for up to one minute before a new request starts a fresh count; deleting the integration's API key also deletes its saved progress.

We keep personal data only while it is needed for the purpose described, to resolve a dispute, protect the service, preserve proportionate competition records, or meet a legal obligation. The period depends on the record and the person's relationship with ASH.

ASH is formalising concrete deletion periods for accounts and OAuth tokens, unsuccessful recruitment applications, reviewer and coaching notes, availability, event registrations and evidence, logs, analytics, public profiles, and backups. Until those periods are approved and automated, records are subject to manual review and deletion requests. This is an operational limitation, not permission to keep data indefinitely.

League replay records carry a 180-day expiry. ASH must run the configured deletion process to remove the corresponding Blob object; deleting a database record alone does not remove an object from Blob storage.

Rainbow Six profile statistics are cached in our database for up to 30 days after their last successful refresh. The scheduled cleanup removes expired entries and entries for players who no longer qualify for a public Rainbow Six profile. Deleting an ASH account also deletes its cached statistics.

Your Data Rights

You can update some profile information in the dashboard. You can also disconnect from ASH community spaces by leaving Discord or contacting ASH staff about access changes. Removing data may affect your ability to use team tools, recruitment, or dashboard features.

Depending on where you live and the lawful basis involved, you may have rights to be informed, access, correct, delete, restrict, object to processing, receive portable data, withdraw consent, and complain to a regulator. California residents may also have applicable rights to know, correct, delete, opt out, limit certain sensitive-data uses, and receive equal service. ASH does not sell personal data.

Contact an ASH Esports administrator to make a request. We will verify that the request concerns your data, search relevant systems and processors, and explain any lawful exception. UK residents may complain to the Information Commissioner's Office. You may also complain to the data-protection authority where you live or work.

Cookies and External Media

Authentication uses cookies that are necessary to sign you in, keep the session secure, and return you to the requested page. Vercel Web Analytics is configured without advertising cookies and uses a daily, non-cross-site visitor hash for aggregated measurement.

The Twitch player is blocked until you choose “Load Twitch player”. Loading it connects your browser directly to Twitch, which may use cookies or similar technologies under Twitch's own policy. ASH stores that player choice in your browser so it can honour it on later visits. Clearing site storage resets the choice. ASH does not currently use advertising or cross-site tracking pixels.

Security

We use access controls, authentication, role-based permissions, provider-managed hosting, and operational safeguards to protect personal data. No online service is perfectly secure, so you should keep your Discord account secure and report suspected account misuse or data issues promptly.

Children

Account profile ages are restricted to 13 or over, but age entry alone is not a verified parental-consent mechanism. ASH Esports is intended for people who are old enough to use Discord, Riot services, and the relevant games and competitions in their region. If ASH learns that a child was registered below an applicable age threshold without the authorization the law requires, the account and associated processing must be reviewed promptly. Contact ASH staff if you believe this has happened.

Controller and Contact

ASH Esports determines why and how the processing described in this policy takes place and acts as the data controller for it. For privacy questions, objections, or rights requests, contact an ASH Esports administrator through the ASH Discord server or the channel where you normally communicate with ASH staff. ASH must publish its accountable legal identity and a monitored privacy address before treating this notice as production-complete.

We may update this policy as our services or legal obligations change. The updated version applies from the date shown at the top, and material changes should be brought to affected users' attention.