What CPL receives
CPL receives your immutable Lichess account ID, current Lichess username, public account status, and Classical rating, performance, game-count, and activity evidence. It stores OAuth-attempt security records, immutable evidence snapshots, eligibility evaluations, document acceptances, registration, waiting history and seniority, timezone, and account status.
When features are used, CPL stores season seats, Team membership, schedules and proposed availability, Ready attendance, Lichess challenge and game identifiers, outcomes, standings inputs, discipline, replacement and movement records, Friendlies, community posts and read markers, moderation reports/actions, notifications, operational audits, and recovery provenance.
Contact messages, bug reports, and feedback store the authenticated CPL identity, submitted category and text, timestamps, handling status, and limited diagnostic context described below.
Why CPL uses it
This information is used to authenticate accounts, evaluate eligibility, operate registration and waiting, arrange and verify games, calculate and explain sporting records, provide Team and community access, send in-app notifications, protect league integrity, support players, diagnose bugs, and recover interrupted operations.
Lichess connection
You sign in through Lichess OAuth. CPL never receives your Lichess password. The access token used for ordinary login and eligibility refresh is not retained after that operation. If you separately authorize CPL to create and accept official games or Friendlies, CPL stores that scoped game-operation token until it expires or is revoked so the controlled Ready flow can work.
Public and limited information
Public competition pages may show your Lichess/display name, current or season rating where relevant, Division and group, Global Club/Team, fixtures, game links, results, standings, and historical sporting records. Content posted in a public community space is visible according to that space's access rules.
Scheduling details, eligibility evidence, waiting administration, sessions, game-operation credentials, support submissions, moderation records, and operational diagnostics are not public. Private Team Rooms are limited to current Team members and authorized moderation. Support submissions are available to the organizer.
Technical context
CPL stores a one-way hash of the application session token rather than the raw token in its database, plus session dates and the browser user-agent supplied at login. Bug reports may include the current route, a related match identifier when present in that route, browser user-agent, and deployed app commit. CPL does not automatically attach passwords, OAuth secrets, session cookies, private messages, arbitrary page content, or IP addresses to support submissions.
Services
CPL uses Lichess for chess identity and games, Convex for application data and backend processing, and Vercel for the web application. This notice does not make unsupported claims about hosting geography, certifications, processors, or international transfers.
Retention and requests
CPL has not adopted one fixed retention period for every record type. Sporting, consent, moderation, provenance, and audit records may need to remain so past competition and decisions stay explainable. Use Contact for an account, privacy, correction, access, or deletion request. The appropriate response may depend on whether a record is needed to preserve an authoritative competition history.
Review status
This Closed Beta notice describes current implementation but has not received independent legal review. Material changes to these practices will be published under a new Privacy Notice version and require renewed acceptance.