Privacy Policy
Last updated: 13 June 2026
This Privacy Policy explains how Elite World Cup 2026 ("the App", "we", "us") handles personal information. The App is operated by an individual, NZN (nznofficial.com) — not an incorporated company (the "Operator"). It is a soccer match‑prediction and mini‑game companion for the 2026 World Cup. This policy uses the EU/UK GDPR as the baseline and includes a dedicated California (CCPA/CPRA) section. It applies to all users worldwide.
In short: We only store what we need to sign you in and to keep your own predictions and game scores. We do not store passwords, profile you, advertise to you, or sell/share your personal information.
1. Who is responsible
The data controller is the Operator, NZN. We rely on two processors: Supabase (authentication + database hosting) and Google (solely as an identity provider when you choose "Sign in with Google").
2. What we collect
- Authentication identifiers: your email address; for Google sign‑in, the Google account identifier/email returned by OAuth; a Supabase‑generated user ID.
- Profile: a display name you choose and an optional favorite team.
- User‑generated content: your match predictions and penalty mini‑game results (high score, longest streak).
- Technical/operational: standard request metadata (e.g. IP address) processed transiently for security and rate‑limiting — never used to build advertising or behavioural profiles.
We do not collect or store passwords. Sign‑in is handled by Supabase Auth via Google OAuth or an email magic link. We do not collect special‑category data, precise geolocation, or payment information; the App is free and processes no payments.
3. How we use it
Only to authenticate you, to store and display your own predictions/profile/scores, to operate the global leaderboards (your display name, favorite‑team flag, and scores are shown publicly — choose a name you are comfortable showing), and to keep the service secure. No profiling, targeted advertising, or resale.
4. Legal bases (GDPR)
Contract (providing the account/features you request); legitimate interests (security and abuse prevention); and consent (e.g. initiating Google OAuth or requesting a magic link), which you can withdraw by deleting your account.
5. Who we share with
We do not sell, rent, or share your personal information. Data is disclosed only to Supabase (privacy policy) as our processor, and to Google (privacy policy) only if you use Google sign‑in. We may disclose data where required by law. Transfers outside your country rely on appropriate safeguards provided by our processor.
6. Your rights (GDPR)
Subject to law, you may access, rectify, erase, port, restrict, or object to processing, and withdraw consent. Use the in‑app controls (edit profile, delete account) or contact us. We aim to respond within 30 days, and you may complain to your local data protection authority.
7. California rights (CCPA/CPRA)
California residents may know/access, delete, and correct personal information, and opt out of its "sale" or "sharing." We do not sell or share personal information as defined by the CCPA/CPRA and have not done so in the past 12 months, so no "Do Not Sell or Share" link is required; you may still contact us with any request. We will not discriminate against you for exercising your rights. Categories collected: identifiers, transient network activity (IP), and user‑generated content — disclosed only to the providers in Section 5.
8. Data deletion
Delete your account anytime from Profile → Delete account → confirm. This removes your Supabase Auth user, which cascades the deletion of your profile, all predictions, and mini‑game scores. Deletion is immediate and irreversible; public leaderboard entries disappear with the underlying rows. If you can no longer sign in, email us from your account address and we will verify and process the request. Residual encrypted backup copies are overwritten on our processor's normal rotation.
9. Retention
We retain account data for the lifetime of your account; it is removed on deletion (Section 8). Transient security/operational metadata is short‑lived and not part of your profile.
10. Security
Authentication is delegated to Supabase Auth (we never handle passwords); database access is protected by Row Level Security so the public key cannot read/write other users' private rows; privileged keys live only in server‑side environment variables; and requests are rate‑limited. No system is 100% secure.
11. Children
The App is not directed to children; you must be at least 16. (GDPR sets digital‑consent age between 13–16 by member state; COPPA applies under 13 in the US. We adopt 16 as a conservative floor.)
12. Contact
Operator: NZN (Attn: Chomp Entertainment) — please submit privacy requests via nznofficial.com.
13. Changes
We may update this policy; material changes update the "Last updated" date and, where appropriate, an in‑app notice.
See also our Terms of Service.
This document is a template, not legal advice. Have it reviewed by a qualified lawyer before launch.