MATCHUPENGINE
Matchup Engine

Legal

Privacy Policy

Version 2026-08-21 · Effective from 21 August 2026

1. Overview

This Privacy Policy explains how Mitchell John Fuller, a sole trader trading as Matchup Engine (ABN 15 729 771 132) ("Matchup Engine", "we", "us" or "our"), collects, holds, uses, and discloses personal information.

We collect the information needed to operate accounts, deliver and support the product, process payments, protect the service, and understand how it is used. We do not sell personal information or provide account information to bookmakers or advertising networks for their independent marketing.

2. Information we collect

Account and authentication information: When you create or use an account, we collect your email address, Matchup Engine account identifier, account creation and sign-in information, and the authentication method or provider needed to operate the account. Authentication is managed by Supabase. We do not store your password in plain text.

Legal acknowledgements: We record the time and version of your age confirmation and acceptance of the Terms and this Privacy Policy.

Purchase and access information: For a Round Pass or other paid product, we record the account, access type, competition, season and round or game covered, entitlement status, relevant access dates, amount and currency, payment status, refund or dispute status, discount code if used, and limited Stripe customer, PaymentIntent, checkout, and event identifiers. We do not receive or store your card number, CVV, or full payment details.

Optional support payments: If you make a voluntary support payment, Stripe processes the amount, currency, payment status, receipt email, and payment identifiers. If you add an optional supporter note, that note is stored in Stripe payment metadata. Do not put card details, passwords, or sensitive personal information in the note. A support payment does not create product access.

Product and Challenge information: We may store your member number, optional display name, leaderboard visibility choice, Challenge picks, results, streaks, ranks, and related history. We may also record product-interest preferences that you deliberately select, such as an expression of interest in a future membership.

Usage and technical information: We collect page and feature interactions, page path, referring page or URL, event time, browser user-agent, account identifier if signed in, anonymous visitor and browser-session identifiers, and a salted one-way hash of the IP address for first-party analytics, rate limiting, security, debugging, fraud prevention, and product improvement. Hosting and security providers may also process normal request information, including the raw IP address, in their infrastructure logs.

Website analytics: We use Vercel Web Analytics for aggregated page-view and limited custom-event reporting. Depending on configuration, it may process the page or route, referrer, time, broad device and browser categories, and approximate geographic information. Our custom events use product context such as round, game, and signed-in status, not card details or account email.

Outbound bookmaker-link information: If you choose to open a bookmaker link, we may record the operator, source page or component, round, game, player or market context, displayed odds, target URL, referrer path, campaign parameters, time, session or anonymous identifier, account identifier if signed in, hashed IP address, user agent, and deduplication or rate-limit information.

Legacy profile information: Matchup Engine previously offered an experimental profile-card editor. The feature is retired and those profiles are not publicly displayed, but previously supplied display names, handles, club themes, descriptions, avatar images, and website links may still be held. You can request deletion or delete your account.

Communications: If you contact us, we collect the contact details, message, and information needed to respond and keep a record of the request or complaint.

3. How we collect and use information

We collect information directly when you sign up, sign in, make a choice in the product, enter checkout, make a payment, or contact us; automatically when your browser uses the site; and from service providers when they return authentication, payment, refund, dispute, security, or delivery status.

We use relevant information to:

  • create, authenticate, secure, and support accounts
  • record legal acknowledgements and age confirmation
  • provide public, account-gated, and paid product features
  • process and reconcile payments and grant, verify, refund, suspend, or revoke associated access
  • operate Challenge identities, picks, and leaderboards
  • remember product-interest choices you make
  • measure product use, improve user experience and reliability, and diagnose errors
  • operate and measure outbound links and prevent duplicate or abusive click activity
  • prevent fraud, misuse, attacks, and unauthorised access
  • meet accounting, legal, audit, and dispute-resolution needs
  • respond to support, account, payment, and privacy requests

We do not use account or payment information for behavioural advertising and do not sell personal information.

4. Payments and Stripe

Stripe processes Round Pass purchases and optional support payments. Card or wallet details are provided directly to Stripe and handled under Stripe's own security standards and privacy policy. We do not receive or store your card number, CVV, or full payment details.

We provide Stripe with the email address and account identifier needed to maintain a customer record, process and reconcile payment, issue a receipt, and associate successful payment with the correct access. We also provide the product and round being purchased, amount, currency, attempt and payment identifiers, and relevant discount information. Stripe returns payment, refund, dispute, and event status to us.

5. Authentication, storage, and security

Supabase manages authentication and the primary application database. If you choose Google sign-in, Google and Supabase process the authentication request, and we receive the identity and basic provider information needed to sign you in. Different email addresses or sign-in methods can result in different Matchup Engine accounts if the authentication service does not link them.

Login and signup may use Cloudflare Turnstile to distinguish genuine requests from automated abuse. Cloudflare may process browser, device, network, and interaction signals for that purpose.

We use access controls, restricted operator systems, authentication, rate limiting, and service-provider security features appropriate to the current product. No internet service can guarantee absolute security. Please use a secure account and tell us if you suspect unauthorised access.

6. Cookies and similar technologies

We use first-party cookies and similar browser storage for authentication, security, core site operation, analytics continuity, and remembering limited choices. Supabase authentication cookies keep you signed in and have provider-managed lifetimes.

  • an anonymous visitor identifier may remain for up to one year
  • an analytics session identifier expires after about 30 minutes of inactivity and is refreshed while you browse

Vercel Web Analytics does not require third-party analytics cookies. We do not currently use advertising cookies, tracking pixels, or behavioural advertising tools. Blocking essential cookies may prevent sign-in or other site functions from working correctly.

7. Third-party services and overseas processing

The principal services that may process information are:

  • Supabase — authentication, database, and file storage
  • Stripe — payment processing, receipts, refunds, and payment disputes
  • Vercel — website hosting, edge delivery, logs, and aggregate Web Analytics
  • Google — optional Google sign-in and limited font delivery on some pages
  • Cloudflare — Turnstile abuse prevention and private operator access
  • Render — hosting for the private operator API
  • Discord — limited private operational and payment status alerts containing system identifiers and status information, not card details or passwords
  • Licensed Australian wagering operators — only when you choose to open an outbound bookmaker link

When you follow an external link, the destination receives normal browser request information and any parameters present in the link. We do not intentionally send your Matchup Engine password, card details, or account email to bookmakers.

Information may be processed in Australia and overseas. Based on our current services, the United States is a likely overseas processing location. Some providers operate global infrastructure or use subprocessors in multiple countries, so information may also be processed elsewhere depending on the service used, routing, and support. Provider locations can change; you may contact us for current information about material overseas processing.

7A. Challenge leaderboard information

The Challenge leaderboard is available to signed-in users. If you enable display-name visibility, your chosen display name—or otherwise your member number—and associated Challenge results, rank, or streak may be visible to other signed-in Challenge users. You can change your display name or visibility setting from the Account page, subject to rules and retention needed to preserve completed competition records.

8. Data retention and account deletion

We retain information for as long as reasonably needed to provide and secure the service, maintain accurate access and transaction records, meet accounting and legal obligations, resolve disputes, and prevent fraud or misuse. Different records have different retention periods.

Account and entitlement information is generally held while the account remains active. Transaction and accounting records are generally retained for at least five years, and longer where required for tax, legal, chargeback, dispute, or audit purposes. Stripe may retain its own customer and payment records under its policies and legal obligations.

Usage, security, reliability, and audit records may be retained after an account is deleted where reasonably needed for the purposes above. Some of those records use an account identifier rather than an email. We may delete or de-identify identifiers when no longer needed, but account deletion does not require us to erase records we must or may lawfully retain.

Deleting your account removes the authentication account and attached product access, and removes associated legacy profile images where technically practicable. It does not transfer paid access, erase Stripe's payment records, or automatically create a refund.

9. Access, correction, deletion, and complaints

You may contact us to request access to, correction of, or deletion of personal information associated with you. We may need to verify your identity and may decline or limit a request where permitted or required by law.

We will acknowledge a privacy complaint, investigate the relevant circumstances, and provide a response within a reasonable timeframe. If you remain dissatisfied and the Privacy Act applies to the matter, you may have the right to contact the Office of the Australian Information Commissioner.

10. Changes to this policy

We may update this Privacy Policy as the product or our practices change. The version and effective date appear at the top. Material changes may require renewed acceptance before you continue using account-gated parts of the service.

11. Contact

The privacy contact is Mitchell John Fuller trading as Matchup Engine (ABN 15 729 771 132). For questions, requests, or complaints, email support@matchupengine.com.