1. Information We Collect
We collect information to provide, improve, and protect our services. The categories include:
-
Account Registration Data: When you register, we collect your full name, email address, date of birth, and a password. This information is essential to create and secure your account.
-
Usage Data: We automatically gather information about how you interact with Fantasy Skills Arena: pages you view, actions you take (team selections, points tracking), dates and times of your visits, session durations, and device type (desktop, mobile, tablet).
-
Device & Technical Data: Includes IP address, browser type and version, operating system, screen resolution, and your unique device identifiers (e.g., device fingerprinting) to help us diagnose technical issues and optimize performance.
-
Match Data & Player Statistics: To simulate fantasy scoring, we fetch real‐time sports data from third‐party sports data providers. While this is not “personal data,” we log match IDs, player IDs, and timestamped events to calculate your points.
-
Optional Feedback & Support Data: If you contact us via support tickets or feedback forms, we may collect additional personal data you choose to submit—such as screenshots, descriptions of bugs, or personal anecdotes.
2. How We Use Your Information
We use your data for the following purposes:
-
Account Creation & Management: To register you as a user, authenticate your logins, and manage your profile preferences.
-
Service Delivery: To fetch and display real-time match statistics, calculate fantasy points, generate leaderboards, and provide the core simulation experience.
-
Personalization: To tailor in-app tutorials, recommend tutorials or articles based on your experience level, and highlight trending players. We use usage patterns to show relevant tooltips and strategy suggestions.
-
Analytics & Improvement: We analyze aggregate usage data to identify popular features, detect bugs, and optimize UI/UX. This helps us improve stability, performance, and introduce new educational tools.
-
Security & Fraud Prevention: IP addresses and device data are used to prevent unauthorized access, detect suspicious activity, and implement rate limiting to avoid DDoS or scraping attacks.
-
Communications: Email notifications—such as password resets, account verification, system maintenance alerts, or updates to Terms/Privacy—are sent to your registered email. We may also send periodic newsletters or educational tips if you opt in.
3. Legal Basis for Processing
Under applicable privacy laws (e.g., GDPR for EU residents), we process your personal data on the following grounds:
- Consent: You explicitly consent to collection and use of your data for certain purposes (e.g., receiving marketing emails, personalized recommendations).
- Performance of Contract: Use of your data is necessary to provide the service you requested—account creation, login authentication, and real-time scoring.
- Legitimate Interests: We process usage analytics and security data to improve the platform and protect against fraud, provided these interests do not override your fundamental rights.
- Legal Compliance: We may process data to comply with legal obligations, such as responding to law enforcement requests or preventing underage use in restricted regions.
4. Sharing & Disclosure
We do not sell or rent your personal data. We share information only under the following circumstances:
-
Service Providers: Third‐party vendors who help us operate the platform—such as hosting providers (AWS), CDN services (Cloudflare), email delivery services (SendGrid), analytics providers (Google Analytics), and payment processors (for any optional future features)—receive only the minimal data necessary to perform their functions under strict confidentiality.
-
Sports Data Partners: We fetch real-time match and player data from sports data APIs. While we do not share your name or email with these partners, we provide them with your team selections in anonymized form for API calls.
-
Legal Obligations: We may disclose personal data if required by law, regulation, or a valid subpoena, court order, or governmental request. We will attempt to notify you unless prohibited by law.
-
Business Transfers: In the event of a merger, acquisition, bankruptcy, or asset sale, user data may be transferred to the new entity, provided that the new entity agrees to honor this Privacy Policy.
5. Cookies & Tracking Technologies
We use cookies, web beacons, and similar technologies to collect and store information. This helps us with:
-
Essential Cookies: Necessary for the website’s basic functionality: maintaining session state, authenticating users, and preventing CSRF attacks.
-
Performance Cookies: Used to gather anonymous data on page load times, user interactions, and overall site performance (e.g., Google Analytics, AOS animations).
-
Functional Cookies: Remember user preferences such as language selection, UI theme (dark/light), and tutorial completion status.
-
Third-Party Cookies: Some embedded content (e.g., YouTube highlights, social media buttons) may place cookies to track interactions outside our site. We recommend reviewing those providers’ cookie policies.
You can configure your browser to block or delete cookies. However, disabling certain cookies may impact your ability to use specific features (e.g., staying logged in, personalized tips).
6. Data Security
We implement a variety of security measures to protect your data:
-
Encryption: All data in transit is encrypted via HTTPS (TLS 1.2+). Sensitive data—such as passwords—are hashed with bcrypt before storage.
-
Access Controls: We restrict access to personal data to authorized personnel only, using role-based access control (RBAC).
-
Regular Audits: We conduct periodic security audits, vulnerability scanning, and penetration testing to identify and remediate potential threats.
-
Data Backups: We maintain routine, encrypted backups of critical data (user accounts, match logs) in geographically redundant data centers.
-
Incident Response: In the event of a data breach, we have an incident response plan to assess the impact, contain the breach, notify affected users, and remediate vulnerabilities within 72 hours.
7. Children’s Privacy
Our platform is intended for users aged 18 and above. We do not knowingly collect personal data from anyone under 18. If we learn that we have inadvertently collected data from a minor (anyone under 18), we will promptly delete that information. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately at support@fantasyskillsarena.com.
8. Third-Party Links
Our platform may contain links to external websites or services (for example, social media integrations, sports news sites, or analytics providers). These third-party sites have their own privacy policies and practices. We encourage you to read the privacy policies of any site you visit. We are not responsible for the content, security, or privacy practices of those external sites.
9. Your Rights & Choices
Depending on your jurisdiction, you may have the following rights concerning your personal data:
- Access: You can request a copy of the personal data we hold about you.
- Correction: If your data is incorrect or incomplete, you can request updates or corrections.
- Deletion: You can request that we delete your personal data, subject to legal obligations to retain certain information (e.g., transactional records for tax purposes).
- Objection or Restriction: You can object to or request a restriction on certain data processing activities (e.g., direct marketing, profiling).
- Data Portability: You can request an export of your personal data in a structured, machine-readable format (e.g., JSON or CSV).
- Withdraw Consent: If processing is based on your consent (e.g., newsletters), you can withdraw that consent at any time. Withdrawal does not affect processing that occurred before withdrawal.
To exercise any of these rights, please contact us at support@fantasyskillsarena.com. We will respond within 30 days, as required by applicable law.
10. International Data Transfers
Fantasy Skills Arena may store and process your personal data on servers located in India or other countries where we have service providers. When we transfer your data outside your country of residence, we use appropriate safeguards (e.g., contractual clauses, standard data protection clauses) to ensure that your data receives an adequate level of protection.
11. Data Retention
We retain your personal data for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required by law. Criteria we use to determine retention periods include:
- Duration of your account activity (we may delete inactive accounts after 24 months of non-use).
- Legal or regulatory obligations to retain certain records (e.g., tax or financial data).
- Dispute resolution—if a dispute arises, we may retain relevant data until the matter is resolved.
12. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. When we make material changes:
- We will update the “Last Updated” date at the top of this page.
- We may send you an email or display a prominent notice on the site before the changes become effective.
- Your continued use of Fantasy Skills Arena after any changes indicates your acceptance of the updated Privacy Policy.
13. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us at:
Email: support@fantasyskillsarena.com
Phone: +91 93119 82376
Mailing Address:
NIVOLA TECH ENERGY (OPC) PRIVATE LIMITED
123 Cricket Avenue,
Andheri East, Mumbai 400069,
Maharashtra, India