1. Definitions
- "ChessLead", "we", "our", "the platform" — the ChessLead chess-management service described in this policy, operated from Nairobi, Kenya.
- "Organisation" — a club, school, academy, or federation account on ChessLead (created by a Club Admin or School Admin).
- "Organisation Admin" — the Club Admin, School Admin, or Finance Admin user who administers an Organisation's account.
- "Member" — a Coach, Parent, or Player/Student associated with one or more Organisations, or a Vendor operating a marketplace store.
- "Player data" — records about a student/player, which may be a minor, managed by an Organisation and/or their parent or guardian.
- "Personal data" — any information relating to an identified or identifiable natural person, consistent with the definition in Kenya's Data Protection Act, 2019.
- "Processing" — any operation performed on personal data, including collection, storage, use, disclosure, or deletion.
2. Scope — what this policy covers
This policy applies to everyone who uses chesslead.org and the ChessLead application: Organisation Admins, Coaches, Parents/Guardians, Players/Students, Vendors, and visitors to our public pages. It covers data collected through the website, the dashboard application, our email and SMS notifications, and our public API documentation pages. It does not cover the practices of independent third-party websites we may link to (for example, an Organisation's own external website).
Because ChessLead is used by schools and clubs to manage records about minors, this policy pays particular attention to how Player data is handled — see Section 9.
3. Who we are
ChessLead is a cloud-based platform that helps chess clubs, schools, academies, coaches, and federations in Kenya manage organisations, players, parents, coaches, tournaments, finances, attendance, lesson plans, reports, and communication in one place.
ChessLead currently operates as an unincorporated platform based in Nairobi, Kenya. We have not yet completed formal company registration; this policy will be updated with our registered entity name, company number, and registered office address as soon as incorporation is complete. In the meantime, for any data-protection purpose, ChessLead should be treated as the data controller for personal data processed through the platform, reachable at [email protected].
4. Information we collect
We collect only the data needed to run the specific features you or your Organisation use. In practice, that includes:
Account & identity
- Full name, email address, phone number, and password (stored as a salted hash — we never see or store your plaintext password)
- If you sign in with Google, Microsoft, or Apple instead: the name, email address, and profile picture your provider shares with us — see Section 7
- Your role (Club Admin, School Admin, Coach, Parent, Finance Admin, Vendor, or Platform Admin)
- Optional profile fields depending on role: national ID/passport number, physical address, secondary phone, WhatsApp number, gender, date of birth
Organisation data
- Club or school name, type, county, description, and contact details
- Branding assets you choose to upload: logo, banner image, brand colours, invoice/document theme, digital signatures and stamps
- Registration and compliance documents you upload (e.g. certificates, insurance documents), and tax/payout details (KRA PIN, bank account or M-Pesa paybill number) used to invoice and pay your Organisation
Coach profiles
- Bio, FIDE ID and title, hourly rate (for marketplace/private-client listings), verification documents, and coaching credentials
- Arrival/check-in photos where an Organisation uses photo check-in for session attendance
Parent & guardian profiles
- Contact details, relationship to the player(s) they are linked to, notification and messaging preferences
- Billing and payment history for their account
Player / student data
- Full name, date of birth, gender, school/club affiliation, current rating and rating history
- Chess.com username, Lichess username, and FIDE ID, where provided
- Emergency contact names and phone numbers, and medical or allergy notes an Organisation records for safety purposes
- Attendance records, session history, coach reports, lesson plans, homework, and tournament registrations
- Photos, where an Organisation uploads a player photo or tournament media featuring the player
Financial data
- Invoices, receipts, and payment history generated on the platform
- M-Pesa phone number and M-Pesa receipt number for mobile-money payments (via Safaricom's Daraja API)
- For card payments: your name and email are passed to Stripe to create a customer record — ChessLead never receives or stores your card number; Stripe handles and stores card data directly
- Bank account and payout details Organisations provide for receiving payouts
Documents & uploads
- Files uploaded to the platform — club/school compliance documents, avatars, tournament media, marketplace product images — are stored in access-controlled cloud storage, with private documents (like compliance certificates or coach check-in photos) kept out of public reach
Technical & usage data
- IP address and approximate location (country/region), used for login security (detecting logins from unusual locations) and rate-limiting
- Browser type and device information, for troubleshooting and compatibility
- Session and authentication logs, and an internal audit trail of sensitive actions (e.g. changes to financial records or user roles)
- Support requests you send us, and your notification preferences
We do not collect or request any data beyond what these features require. Optional fields are clearly marked as optional in our forms, and several categories above (e.g. FIDE ID, national ID, medical notes) are only collected where a specific Organisation feature calls for them — not from every user.
5. How we use information
- Operating your account and Organisation — creating and maintaining profiles, memberships, and permissions
- Scheduling and running sessions — calendars, coach assignments, video-session links, QR check-in
- Tracking attendance — recording and reporting attendance for players, coaches, and Organisations
- Generating invoices and processing payments — via M-Pesa, Stripe, and bank transfer
- Communicating with parents and coaches — session reminders, progress reports, billing notices, and direct messages between Organisation members
- Supporting coaches — payroll, performance reviews, client management, and marketplace listings
- Managing tournaments — registrations, pairings, standings, and (where a club connects its own Lichess account) online tournament administration
- Improving the platform — diagnosing bugs, understanding which features are used, and prioritising fixes
- Providing customer support — responding to your questions and requests
- Maintaining security and preventing fraud — detecting suspicious logins, rate-limiting abusive requests, and auditing sensitive financial and administrative actions
- Meeting legal obligations — such as retaining financial records as required under Kenyan law
We do not use your data for advertising, and we do not build advertising profiles. ChessLead has no advertising or analytics-tracking integrations of any kind at the time of writing.
6. Data sharing
ChessLead does not sell personal data. We share data only in the following circumstances:
- Within your own Organisation — for example, a coach can see the players assigned to them, and a Parent can see their own linked children's attendance and reports. Access is role-based: a coach at one club cannot see another club's players, and access to sensitive fields (like national ID) is restricted to the roles that need them.
- With service providers who process data on our behalf, strictly to provide the platform (listed in full in Section 7 and below) — database and file storage, transactional email, SMS delivery, and payment processing.
- For authentication — if you choose to sign in with Google, Microsoft, or Apple, those providers confirm your identity to us; see Section 7.
- For payment processing — Stripe (card payments) and Safaricom (M-Pesa) process payment details directly; we share only what is necessary to initiate and confirm a transaction.
- For email and SMS delivery — Resend (email) and Africa's Talking (SMS) receive the recipient's address/number and message content solely to deliver that message.
- When legally required — if we are compelled by a valid court order, subpoena, or legal process, or to protect the rights, property, or safety of ChessLead, our users, or the public.
- With your consent — for any other purpose, only where you have specifically agreed.
Our full list of sub-processors, with what each one does and what data flows through it, is in Section 7 and the table below.
| Service | Purpose | Data shared |
|---|---|---|
| Supabase | Database, authentication, and file storage | All account data, application data, and uploaded files |
| Resend | Transactional email delivery | Recipient name, email address, and message content |
| Africa's Talking | SMS delivery | Recipient phone number and message content |
| Stripe | Card payments and subscriptions | Name, email, organisation reference; card details go directly to Stripe |
| Safaricom (M-Pesa Daraja API) | Mobile-money payments | Payer phone number, amount, and transaction reference |
| Upstash (Redis) | Rate-limiting login attempts | Email address/IP address as a short-lived rate-limit key, not profile data |
| Lichess.org | Optional club-initiated online tournaments | Only where a Club Admin connects their own Lichess account; tournament administration data only |
| Jitsi Meet | Live video coaching sessions | Display name and a session room identifier, for the duration of the call only |
| Cloudflare | Network security and content delivery (infrastructure only) | Standard web request metadata (IP, headers) in transit |
| Vercel | Application hosting (infrastructure only) | All traffic to chesslead.org passes through our hosting provider |
7. Google, Microsoft & Apple sign-in data
If you choose "Continue with Google" (or Microsoft/Apple) instead of creating a password, we receive only your name, email address, and profile picture from that provider, using the standard, non-sensitive openid email profile scopes. We do not request or receive access to your Gmail, Google Drive, Google Calendar, Google Contacts, or any other Google service or Sensitive/Restricted-scope data. This data is used solely to create and sign you into your ChessLead account, and is stored the same way as data from an ordinary email/password signup.
ChessLead's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We never sell or transfer this data to third parties, never use it for advertising, and never use it to assess creditworthiness or for lending. The only humans who can access it are ChessLead personnel providing you support, or as required for security or legal compliance.
8. Security
- Encryption in transit — every connection to ChessLead uses HTTPS/TLS; there is no unencrypted path to our servers
- Encryption at rest — our database and file storage (via Supabase/PostgreSQL) encrypt data at rest
- Password security — passwords are hashed (never stored or logged in plaintext) and must meet a minimum-strength policy
- Role-Based Access Control — what you can see and do depends strictly on your role (Club Admin, Coach, Parent, etc.)
- Row-Level Security & tenant isolation — our database enforces, at the database layer, that one Organisation's data (players, sessions, invoices, messages) cannot be read by another Organisation's users or accounts
- Sensitive-field restrictions — certain roles (for example, tournament arbiters) are automatically shown a restricted view that strips fields like national ID and phone numbers they don't need
- Audit logging — sensitive actions (financial changes, role/permission changes, data exports) are logged with who performed them and when
- Backups — the database is regularly backed up to guard against data loss
- Monitoring — we monitor for unusual login patterns (e.g. sign-ins from a new country) and rate-limit repeated failed login attempts
No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal data, we will notify affected users and the Office of the Data Protection Commissioner where required by Kenyan law.
9. Children's privacy
Many ChessLead users are students under 18. We built the platform around a specific principle: a child's ChessLead record is created and managed by an authorised adult — their school, their club, or their parent/guardian — not by the child signing up directly. Players do not have their own login or password on ChessLead; their data exists as a managed record linked to the adults responsible for them.
Under Section 33 of Kenya's Data Protection Act, 2019, processing a child's personal data requires consent from the child's parent or guardian, given in the child's best interest. In practice on ChessLead:
- Schools and clubs are responsible for ensuring they have the appropriate parental/guardian consent and legal basis before creating or uploading a player's record, exactly as they would for any other student record they hold offline.
- Parents and guardians who link to their child's record through ChessLead can see that child's attendance, ratings, reports, and billing, and can request correction or removal of that data through their Organisation or by contacting us directly.
- We collect only what specific features need (see Section 4) — we do not collect more data about a child than a school or club would ordinarily keep in its own records.
- We do not use children's data for advertising or marketing, and never share it outside an Organisation except as described in Section 6.
If you are a parent/guardian and believe a school or club has added your child's data without your consent, contact us at [email protected] and we will investigate and, where appropriate, remove the record.
10. International users & data transfers
ChessLead is built for Kenya's chess community, and the great majority of our users are in Kenya. The platform can be used by organisations anywhere, and some of our infrastructure providers (Supabase's hosting regions, Vercel, Cloudflare, Resend, Stripe) operate data centres outside Kenya. Where personal data is processed outside Kenya, we rely on our providers' own security certifications and contractual safeguards, and we take reasonable steps to ensure your data continues to receive a comparable level of protection to that described in this policy, consistent with the cross-border transfer requirements of the Data Protection Act, 2019.
11. Cookies & consent
ChessLead uses Cookiebot to manage cookie consent in accordance with GDPR and the ePrivacy Directive. A consent banner appears on your first visit; you can update your preferences at any time by clicking the “Cookie settings” link in the footer, or by clearing your cookies and revisiting the site.
Strictly necessary cookies (always active)
- Authentication cookie — keeps you signed in securely; set by Supabase Auth and required for the platform to function
- Sidebar preference — remembers whether your sidebar is expanded or collapsed; purely cosmetic, no personal data
- OAuth connection cookies (Club Admins only) — short-lived (10-minute) cookies used only while connecting a Lichess account, then discarded
- CookieConsent — set by Cookiebot to store your consent choices; expires after 12 months
Analytics & marketing cookies
ChessLead does not currently use any analytics, advertising, or cross-site tracking cookies. If we add any in the future, they will be listed in the declaration below, blocked by default, and only activated after you grant consent.
Full cookie declaration
The table below is automatically generated and kept up to date by Cookiebot:
12. Your rights
Under Kenya's Data Protection Act, 2019 (and equivalent principles we extend to all users regardless of location), you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Export your data in a machine-readable format
- Delete your data, subject to the retention exceptions in Section 13
- Object to or restrict certain processing
- Manage your communication preferences (e.g. notification settings in your account)
To exercise any of these rights, email [email protected] with your account email and what you'd like us to do. We aim to respond within 14 days. Parent accounts can also request deletion in-app from Settings → Privacy; other roles should currently email us and we will action the request directly — we are working on extending self-service deletion to every account type.
13. Data retention
- We retain your data for as long as your account is active and you or your Organisation continue to use the platform.
- If you request account deletion, we remove your personal data within 30 days, other than data we are required to keep — for example, financial and invoicing records, which Kenyan tax law requires organisations to retain for a statutory period.
- Backups containing deleted data are retained for a limited period as part of our disaster-recovery process, then age out and are overwritten.
- Organisations own their operational data. If a Club or School Admin's account is deleted but the Organisation continues operating under a new admin, the Organisation's records (players, sessions, invoices) are not deleted along with the departing admin's personal profile.
14. Changes to this policy
We may update this policy as ChessLead's features, integrations, or legal obligations change. If we make a material change to how we use previously collected data (for example, a new use of Google user data), we will notify you by email or an in-app notification and, where required, ask for your renewed consent before the change takes effect. Non-material changes (clarifications, formatting) may be made without advance notice; the "Last updated" date and version number at the top of this page always reflect the current version.
15. Contact information
Questions, requests, or complaints about this policy or your data:
- Support & privacy requests: [email protected]
- Platform: ChessLead
- Location: Nairobi, Kenya
- Website: chesslead.org
You may also lodge a complaint with Kenya's Office of the Data Protection Commissioner (ODPC) if you believe we have not handled your personal data in accordance with the Data Protection Act, 2019.
