Privacy Policy
OfficialWC26 — Effective March 16, 2026
1. Overview
This Privacy Policy describes how OfficialWC26 ("we," "us," or "our") collects, uses, shares, and protects personal information when you use the OfficialWC26 website ("Site") and services ("Services"). By using the Site, you consent to the practices described in this policy.
This policy applies to all users of the Site, including bracket participants, visitors, and referral recipients.
2. Information We Collect
Information you provide directly:
- Full name (first and last)
- Email address
- Password (stored using industry-standard hashing — we never store plain-text passwords)
- Contest bracket predictions and submissions
- Referral codes you share or use
Information collected via Google OAuth:
- If you sign in with Google, we receive your name, email address, and profile identifier from Google. We do not receive or store your Google password.
Information collected automatically:
- IP address
- Browser type and version
- Device type and operating system
- Pages visited, timestamps, and referral URLs
- Session and authentication tokens (stored locally in your browser)
Payment information:
- Payment card details are collected and processed directly by Stripe, Inc. We do not have access to, receive, or store your full credit card number, CVV, or billing address. We may receive a transaction confirmation, last four digits of your card, and payment status from Stripe.
3. How We Use Your Information
We use collected information for the following purposes:
- Create and manage your user account
- Process and validate contest entries
- Calculate scores, rankings, and leaderboard positions
- Process payments and issue refunds (if applicable)
- Distribute prizes and issue required tax documentation
- Communicate contest updates, winner announcements, and service notifications
- Administer the referral program and promotional codes
- Prevent fraud, detect abuse, and enforce our Terms of Service
- Improve the Site, troubleshoot issues, and analyze usage patterns
We will never sell, rent, or trade your personal information to third parties for marketing purposes.
4. Third-Party Services
We use the following third-party services that may process your data in accordance with their own privacy policies:
- Stripe, Inc. — Payment processing. Stripe Privacy Policy
- Supabase, Inc. — Authentication, database hosting, and backend infrastructure. Supabase Privacy Policy
- Vercel, Inc. — Website hosting and content delivery. Vercel Privacy Policy
- Google LLC — Google OAuth authentication and Google Analytics for usage analytics. Google Privacy Policy
We only share the minimum information necessary for these services to function (e.g., email for authentication, payment amount for processing).
5. Cookies & Tracking Technologies
The Site uses cookies and similar technologies for the following purposes:
- Essential cookies: Authentication tokens, session management, and language preferences stored in your browser's local storage
- Analytics cookies: Google Analytics collects anonymized usage data to help us understand how visitors use the Site. This includes pages visited, time spent, and general geographic location
You may disable cookies through your browser settings, but doing so may impair the functionality of the Site.
6. Data Security
We implement reasonable administrative, technical, and physical safeguards to protect your personal information, including:
- Encrypted data transmission via HTTPS/TLS
- Password hashing using industry-standard algorithms (provided by Supabase Auth)
- Row-level security policies on database tables restricting data access to authorized users
- Server-side API keys stored securely as environment variables, never exposed to clients
However, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security of your data.
7. Data Retention
We retain your personal data for the following periods:
- Account data: Retained for the duration of the contest and up to 12 months after the final prize distribution to fulfill legal and tax obligations
- Bracket and scoring data: Retained for the duration of the contest and for record-keeping purposes
- Payment records: Retained as required by applicable tax and financial regulations
After the retention period, personal data will be deleted or anonymized unless retention is required by law.
8. Data Breach Notification
In the event of a data breach that compromises your personal information, we will:
- Notify affected users via email within 72 hours of discovering the breach
- Describe the nature of the breach and the types of data involved
- Outline the steps we are taking to address the breach and mitigate harm
- Report the breach to relevant authorities as required by applicable law
9. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data, subject to legal retention requirements
- Portability: Request your data in a portable, machine-readable format
To exercise any of these rights, contact us at info@officialwc26.com. We will respond within 30 days.
Google Account Access: If you signed in with Google OAuth, you can revoke OfficialWC26's access to your Google account at any time by visiting your Google Account Permissions page. Revoking access will not delete your OfficialWC26 account or submitted entries.
Note: Deleting your account during an active contest does not entitle you to a refund of entry fees and may result in forfeiture of any pending prizes.
10. California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights
We do not sell personal information as defined by the CCPA. We do not use or share sensitive personal information for purposes other than those permitted by the CCPA.
To submit a CCPA request, email info@officialwc26.com with the subject line "CCPA Request."
11. Children's Privacy
The Site and Services are not directed at individuals under the age of 18. We do not knowingly collect personal information from anyone under 18 years of age. If we become aware that we have inadvertently collected data from a minor, we will promptly delete that information. If you believe a minor has provided us with personal data, please contact us immediately at info@officialwc26.com.
12. International Users
The Site is operated from the United States. If you access the Site from outside the United States, your data may be transferred to and processed in the United States, where data protection laws may differ from those in your country. By using the Site, you consent to such transfer and processing.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on the Site. The "Effective" date at the top of this page indicates when the policy was last revised. Your continued use of the Site after any changes constitutes your acceptance of the updated policy.
14. Contact
For questions or concerns about this Privacy Policy, or to exercise your data rights, contact us at:
We will respond to all privacy-related inquiries within 30 days.