Privacy Policy

Last updated: February 25, 2026

PokerOps Privacy Policy

This Privacy Policy explains how PokerOps ("PokerOps," "we," "our," or "us") collects, uses, stores, and discloses personal information when organizations and their users access our poker tournament management platform, related websites, APIs, and integrations (collectively, the "Service").

PokerOps is a multi-tenant software platform for tournament operations. This policy applies to Organization owners, administrators, team members, and, where relevant, player information entered into the Service by organizations.

If you do not agree with this Privacy Policy, do not use the Service.

1. Introduction and Scope

1.1 Who this policy covers. This policy applies to personal information processed by PokerOps in connection with the Service, including account holders, invited users, and player-related records submitted by organizations.

1.2 Controller and processor roles. For player data entered by organizations (for example, player registration records), organizations generally act as data controllers and PokerOps acts as a processor on their behalf. PokerOps may act as an independent controller for limited purposes such as account security, fraud prevention, legal compliance, service analytics, and billing administration.

1.3 Regional legal context. Data protection rights vary by jurisdiction. Where mandatory laws grant additional rights, those rights apply.

1.4 Service nature. PokerOps provides operational software for tournament management. We do not operate gaming venues and do not determine each organization's legal obligations for player screening, licensing, tax reporting, or lawful event operations.

2. Information We Collect

We collect information in several categories.

2.1 Account and organization information

When an Organization creates and uses PokerOps, we may collect:

2.2 Player data managed by organizations

Organizations may enter player records into the Service. Depending on configuration and local legal requirements, such records may include:

This player data is submitted by and controlled by each Organization, subject to that Organization's lawful basis and obligations.

2.3 Device and session information

To operate and secure the Service, we may collect:

2.4 Usage and technical logs

We collect operational telemetry and logs such as:

2.5 Communications data

If you contact support or receive system notices, we process communication metadata and message content necessary to respond, troubleshoot, and document support outcomes.

3. How We Use Information

We use collected information for the following purposes:

3.1 Service delivery. To provide core product functions, including authentication, organization-scoped access, player registration workflows, tournament configuration, and operational tools.

3.2 Authentication and access control. To support magic-link sign-in and session management, verify user identity, and enforce role-based permissions.

3.3 Tournament operations. To enable organizations to run tournaments, assign tables, maintain blind structures, and monitor event progress.

3.4 Messaging workflows. Where enabled by an Organization, to facilitate messaging-related functions, including WhatsApp workflows and related operational notifications.

3.5 Security and abuse prevention. To detect suspicious behavior, prevent unauthorized access, investigate misuse, and protect platform integrity.

3.6 Service maintenance and improvement. To debug errors, monitor reliability, improve user experience, and plan platform enhancements.

3.7 Legal and contractual compliance. To satisfy legal obligations, enforce our Terms, resolve disputes, and maintain records.

4. Multi-Tenant Data Isolation

4.1 Organization boundaries. PokerOps uses tenant-based data isolation so each organization's records are logically separated from other organizations.

4.2 Access scoping. User sessions are scoped to the active organization and permissions assigned by that organization. Cross-organization data access is not available through ordinary Service operation.

4.3 Security architecture. We apply access controls and platform safeguards designed to reduce risk of unauthorized tenant-to-tenant access.

4.4 No absolute guarantee. While we implement security controls and validation layers, no online system is immune to risk. We continuously improve safeguards as threats evolve.

5. Data Sharing and Disclosure

We do not sell personal information to third parties for independent marketing purposes.

5.1 Service providers. We may share information with trusted vendors that process data on our behalf under contractual controls, including cloud hosting, infrastructure operations, and communication delivery.

5.2 Cloud hosting and region. Service data is hosted using AWS infrastructure in the il-central-1 region (Israel), subject to operational and legal requirements.

5.3 Email delivery. We use AWS SES for transactional email delivery such as authentication links and account notices.

5.4 Messaging integrations. If an Organization enables WhatsApp-related functionality, relevant operational data may be processed through messaging components, including Baileys-based integration flows under that Organization's configuration.

5.5 Legal disclosures. We may disclose data when required by law, subpoena, court order, regulatory request, or when necessary to protect rights, safety, and platform security.

5.6 Business transfers. In a merger, acquisition, restructuring, or asset sale, information may be transferred as part of the transaction, subject to applicable legal protections.

6. Data Retention

6.1 Account data retention. We retain account and organization data while the account remains active and as needed for legitimate business, legal, and security purposes.

6.2 Post-termination handling. Upon account termination, we may retain certain data for limited periods required for legal compliance, dispute resolution, fraud prevention, backup integrity, and enforcement of agreements.

6.3 Player data lifecycle. Player records are primarily managed by each Organization as controller. Organizations are responsible for defining retention practices aligned with legal obligations.

6.4 Deletion requests. We support deletion workflows consistent with our role and technical constraints. Some records may be retained in immutable logs or backups for limited periods.

7. Security Measures

7.1 Transport security. Data is encrypted in transit using HTTPS/TLS.

7.2 Authentication controls. Access uses session-based authentication with magic-link flows and organization-aware session scoping.

7.3 Authorization model. We apply role-based access controls designed to limit access according to assigned permissions.

7.4 Operational safeguards. We maintain logging, monitoring, and incident response practices intended to detect and address abnormal behavior.

7.5 Shared responsibility. Security also depends on customer behavior, including credential handling, device control, and timely offboarding of users.

7.6 No absolute security guarantee. No method of transmission or storage is fully secure. We cannot guarantee complete security but take commercially reasonable steps to protect data.

8. Your Rights and Choices

Depending on your jurisdiction and our role (controller vs processor), you may have rights such as:

8.1 How to exercise rights. Submit requests to support@pokero.ps with sufficient detail to verify identity and scope.

8.2 Organization-managed data. For player data submitted by an Organization, you may need to contact that Organization directly first because it controls those records.

8.3 Future export capabilities. We may provide additional self-service export tools over time. Availability can vary by plan and rollout stage.

8.4 Response timing. We aim to respond within legally required timelines and may request additional information for verification.

9. Cookies and Similar Technologies

9.1 Session cookies only. The Service uses cookies and similar storage primarily for authentication, session continuity, and security.

9.2 No tracking ads cookies. We do not use third-party advertising cookies for behavioral ad targeting in the core Service.

9.3 No third-party analytics cookies by default. The platform does not rely on third-party analytics cookies for user tracking in standard operation.

9.4 Browser controls. You can configure your browser to block cookies, but doing so may prevent login flows or degrade Service functionality.

10. Children's Privacy

10.1 Not directed to children. The Service is not directed to children under 18.

10.2 No knowing collection from minors under 18. We do not knowingly provide accounts directly to children under 18. Organizations using the Service are responsible for lawful participant handling under local rules.

10.3 Removal requests. If you believe personal information of a child under 18 was provided improperly, contact support@pokero.ps and we will investigate and take appropriate action.

11. International Data Location and Transfers

11.1 Primary hosting region. Data is primarily hosted in AWS il-central-1 (Israel).

11.2 Operational access. Authorized personnel and processors may access data as necessary for support, maintenance, and legal compliance, subject to contractual and security controls.

11.3 Cross-border considerations. Where cross-border processing occurs, we apply reasonable safeguards appropriate to our operations and legal obligations.

12. Changes to This Privacy Policy

12.1 Policy updates. We may update this Privacy Policy to reflect legal, technical, or business developments.

12.2 Notice. For material updates, we will provide at least thirty (30) days notice by email or in-product communication before changes become effective, unless immediate change is required for legal or security reasons.

12.3 Continued use. Continued use of the Service after the effective date of an updated policy indicates acceptance of the revised terms.

13. Contact Us

For privacy questions, rights requests, or concerns:

Please include your name, organization (if applicable), account email, and a clear description of your request so we can respond effectively.

14. Additional Legal Notes

14.1 No legal advice. This policy is provided for transparency regarding data handling and does not constitute legal advice to organizations using PokerOps.

14.2 Conflict with agreements. If you have a separate signed agreement with PokerOps that includes data processing terms, that agreement may govern where it conflicts with this policy for the covered subject matter.

14.3 Language. The English version of this Privacy Policy controls unless another version is explicitly designated as controlling.

By using PokerOps, you acknowledge that you have read and understood this Privacy Policy.