Turnierplan.eu

Privacy Policy

Last updated: 30 July 2026

This Privacy Policy explains how personal data is processed when visiting and using Turnierplan.eu. Even when the website is used for information only, technically necessary connection and usage data is generated, in particular IP addresses, server and page-view data, session data and consent settings.

1. Controller

Markus Müller, trading as Pixel33 Software
Platform: Turnierplan.eu
An den Gleisen 5
92224 Amberg
Germany
Email: info@turnierplan.eu
Website: www.turnierplan.eu

2. Roles concerning tournament and participant data

Markus Müller, trading as Pixel33 Software, is the controller for account-holder data, the website, billing, security and its own usage analysis.

Where a tournament organiser enters data concerning teams, participants, coaches, referees or other persons, the organiser normally determines the purposes and content of the processing and is the controller for that processing. Pixel33 Software generally processes this data as a processor under Article 28 GDPR.

The organiser must have an appropriate legal basis and inform data subjects in accordance with Articles 13 or 14 GDPR. This applies in particular to names, images and other data relating to minors in youth tournaments. Before publication, the organiser must determine whether and to what extent publication is lawful.

The central data processing agreement is available at Pixel33 Data Processing Agreement.

3. Hosting, connection data and server logs

The platform is hosted by STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. When the website is accessed, the IP address, date and time, requested resource, HTTP status, transferred data volume, referrer, browser and operating system may be processed.

The purposes are delivery, stability, error analysis and protection against misuse. The legal basis is Article 6(1)(f) GDPR, based on our legitimate interest in secure and reliable operation. Where processing is necessary to provide a contract, Article 6(1)(b) GDPR also applies. A processing agreement under Article 28 GDPR is in place with STRATO.

4. User accounts and authentication

For registration and account use, we process username, email address, password stored only as a hash, activation status, account and subscription data, login times and technical security data. Activation, login, automatic login and password reset also require activation, login and time-limited reset tokens.

The purposes are account creation, authentication, performance of the contract and prevention of misuse. The legal bases are Article 6(1)(b) and (f) GDPR. Activation, security and reset emails are necessary for the requested account function and are not advertising.

Guest use is available where a function does not require an account. Connection, session and page-view data and any tournament data entered by the guest are nevertheless processed.

5. Tournament platform and public content

Depending on the functions used, we process tournament names, organisers, locations, times, modes, fields, rules and settings; teams, participant names and contact details, group assignments, logos and images; schedules, fixtures, results, tables, tournament status, live timers and tickers; sponsor details, sponsor logos, websites and uploads; as well as QR codes, PDFs, widgets, external tournament links and external result reports.

Processing is carried out to provide the selected platform functions under Article 6(1)(b) GDPR or, for third-party data, on the organiser's behalf under Article 28 GDPR.

Live, tournament and event pages marked public can be accessed worldwide without logging in. Spectators, recipients of shared links and search engines may access, save or index this content. Organisers should therefore publish only data that is necessary and lawfully approved for this purpose.

6. Internal visitor analytics

For internal reach measurement and technical optimisation, we store in our own database the IP address, session ID, user or administrator ID where logged in, page and time of access, request method, referrer, browser language, user agent and UTM parameters. The requested URL may also contain campaign identifiers such as gad_source, fbclid or rdt_cid. Page views may be linked to a registered user after login.

The purposes are reach measurement, campaign attribution, error analysis, platform improvement and abuse detection. Where information is stored on or read from the user's device, this takes place only with consent under section 25(1) TDDDG and Article 6(1)(a) GDPR. Security analysis may be based on Article 6(1)(f) GDPR. Consent can be withdrawn at any time through the cookie settings.

7. Cookies, local storage and consent management

  • PHPSESSID: necessary session cookie, generally retained until the browser session ends.
  • remember_token: optional necessary cookie for “stay signed in”, retained for 30 days; Secure, HttpOnly and SameSite=Lax.
  • Google CMP (FCCDCF / FCNEC): stores the consent decision and IAB TCF string in cookies or browser storage.

Cookies and other device storage that are not strictly necessary are activated only after consent. This also applies to first-party analytics technology. The legal bases are section 25(1) TDDDG for device access and Article 6(1)(a) GDPR for subsequent processing.

Stripe is used only in connection with a payment process deliberately opened by the user. Google reCAPTCHA protects selected forms against automated misuse. Neither service is classified across the board as essential for every page view; its legal basis depends on the function requested.

Settings can be changed or withdrawn at any time by selecting Open cookie settings. Withdrawal does not affect the lawfulness of earlier processing.

8. Google services

We may use Google Analytics for reach measurement, Google Ads including conversion measurement and Google AdSense to display advertising. These services are activated only after the relevant consent. Google reCAPTCHA is used on protected forms to identify automated access.

The primary provider in the EEA is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Processing by Google LLC and other recipients in the United States cannot be ruled out. Transfers are governed by Articles 44 et seq. GDPR, in particular an adequacy decision or appropriate safeguards.

Depending on the service and consent, IP address, device and browser data, pages visited, interactions, referrers, campaign and advertising identifiers and Google cookies may be processed. Cookie names and retention periods can change and are therefore displayed for each service in the consent dialogue.

9. Payments and subscriptions

Payments are processed through Stripe. In the EEA, Stripe Payments Europe, Limited and Stripe Technology Europe, Limited, both in Dublin, Ireland, may be involved. Depending on the payment method, contact details, customer and contract IDs, amount, currency, payment status, IP and device data and the necessary payment details are processed. We generally do not receive full card or account details.

The legal bases are Article 6(1)(b) GDPR for the contract and payment and Article 6(1)(c) and (f) GDPR for legal obligations, fraud prevention and claims management.

If other methods such as PayPal, Klarna or Amazon Pay are available in Stripe Checkout, data is also transmitted to the selected payment service. Availability depends on country, currency, amount and the current Stripe configuration. The selected payment provider's privacy information also applies.

10. Communications, support and bug reports

For contact, support, withdrawal or bug reports, we process the submitted contact, contract and content data, technical details, attachments and processing history. The purpose is to handle the request, correct errors and document the process under Article 6(1)(b), (c) or (f) GDPR.

For withdrawals and cancellations we process, in particular, name, email address, postal address, order or contract data, time, subscription and processing status. Receipt of a withdrawal and completed subscription cancellation are confirmed automatically by email.

Withdrawal: withdrawal form and information. A subscription can be cancelled in the logged-in area under My account.

11. Recipients and international transfers

Recipients may include STRATO GmbH as host, Google Ireland Limited for the Google services described above, participating Stripe companies and selected payment services, email service providers, and authorities or legal advisers where required. Service providers are bound under Article 28 GDPR where necessary.

Transfers outside the EEA take place only under Articles 44 et seq. GDPR, in particular on the basis of an adequacy decision, standard contractual clauses and any required additional safeguards.

12. Retention and deletion

We retain data only for as long as necessary for its purpose, performance of the contract, security or statutory obligations. It is then deleted or anonymised unless a retention obligation or the defence of legal claims requires otherwise.

  • User accounts and contract data: until account deletion or the end of the contract and any subsequent statutory or contractual period.
  • Active tournaments, participant data and public pages: until deletion by the organiser or account deletion; tournaments marked as deleted may initially remain blocked or archived.
  • Uploads, logos, PDFs and QR codes: generally until deletion of the associated tournament or account and completion of technical cleanup cycles.
  • Password reset links: until expiry, normally one hour, or successful use.
  • Web login tokens: 30 days or until logout or withdrawal.
  • Hosting server logs: according to the retention periods applicable to the STRATO hosting product.
  • Our application, security and billing logs: generally up to 300 days; longer where required to resolve a specific security, legal or billing matter.
  • Raw internal analytics data: no longer than 13 months; campaign and aggregated statistics may then continue without direct personal reference.
  • Support, contact and bug reports: generally up to 24 months after closure, longer if contract or litigation records require it.
  • Consent records: generally up to 24 months after the last evidential need.
  • Backups: until scheduled overwriting in the applicable backup cycle.
  • Accounting records and invoices: generally eight years; commercial correspondence six years; books, records and financial statements ten years.

Statutory periods generally begin at the end of the calendar year. Different periods may apply where claims are asserted, a legal duty exists or the specific processing ceases to be necessary sooner.

13. Deleting accounts and tournaments

Organisers can delete tournaments using the designated function. Deletion first blocks public and regular access; final removal from production data, files and backups follows the deletion cycles above. Account deletion can be requested through the account functions or by emailing info@turnierplan.eu. Billing and evidence records that must be retained by law remain restricted.

14. Data-subject rights

Subject to the statutory conditions, data subjects have rights of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18), portability (Article 20) and objection (Article 21).

Consent may be withdrawn at any time for the future, especially via cookie settings or email. Where processing is based on Article 6(1)(f) GDPR, an objection may be made for reasons arising from the particular situation. There is an unconditional right to object to direct marketing.

Requests concerning participant data should first be addressed to the relevant tournament organiser as controller. Pixel33 Software assists the organiser in handling data-subject requests.

15. Right to complain

Data subjects may lodge a complaint with a data protection supervisory authority, in particular:

Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18, 91522 Ansbach, Germany
Phone: +49 981 180093-0
Fax: +49 981 180093-800
Email: poststelle@lda.bayern.de
Website: www.lda.bayern.de

16. Data security and amendments

We use appropriate technical and organisational measures, including encrypted transmission, access controls, password hashing and security and recovery procedures. This Policy will be amended where functions, providers or legal requirements change.

Ahrefs Web Analytics

We use Ahrefs Web Analytics for anonymised audience measurement. The service is loaded only if you have consented to analytics storage in Google privacy settings or if the EU consent requirement does not apply to your location.

According to Ahrefs, Web Analytics does not use cookies or persistent identifiers by default. Data processed includes the requested URL, referrer, user agent and browser language. The IP address is used to determine country and city and is then discarded. You can withdraw your consent at any time via “Cookie settings”.

Ahrefs privacy information