Privacy
Last updated: 12 August 2026
What this covers
This page describes what College Deadlock collects across two places: this website (collegedeadlock.com), which is public and read-only, and the tournament portal at app.collegedeadlock.com, where players sign in, build teams and play their matches. Almost everything personal we hold comes from the portal.
Browsing this site
We don’t run analytics, advertising pixels or third-party trackers on this site today, and we don’t sell anything you do here. The only thing we keep in your browser is a single local storage entry recording that you dismissed the cookie notice, so it doesn’t reappear on every page. If we ever add analytics, it will be the aggregate, non-identifying kind, and this page will be updated before it ships.
Signing in to the portal sets one cookie, cdl_session. It is signed, HTTP-only, and holds your account id and an expiry — nothing else. It exists to keep you signed in; clearing it signs you out.
The contact form
The contact page asks for your name, your email address and your message. We email all three to the league inbox and set your address as the reply-to, so a human can write back. Contact messages are not written to our database. We rate-limit submissions per network address to keep spam out; that check lives in memory and is not stored.
Your account and player profile
Registering to compete creates an account in the portal. Depending on what you fill in, that record can hold:
- your email address and a hashed password (we store the bcrypt hash, never the password itself), plus the date you confirmed the address, accepted the terms and last signed in;
- your display name, in-game name, pronouns, nationality, a short bio and any profile links you add;
- the school you compete for, and a school email address where one is on file;
- your linked Steam and Discord accounts, and a phone number if you give one to staff;
- your email preferences: whether you opted in to promotional mail, and whether you want pre-match reminders.
Playing generates the rest: team memberships and roles, roster changes, match schedules, scores, check-ins, disputes, and any strikes or bans. Actions taken by tournament staff are written to an audit log so decisions can be reviewed. Some player records predate this site and were imported from the league’s earlier registration systems; those may carry a few extra fields, such as a real name, that only staff can see.
Discord and Steam
Linking Discord uses OAuth with the identify scope only. We receive your Discord user id and username, and store the id. We deliberately do not request your Discord email address, and you cannot sign in with Discord — linking attaches a Discord identity to an account you already have.
Linking Steam stores your Steam ID so rosters and match reports can be tied to the right account. If a lookup key is configured, we call Steam’s public Web API to resolve the profile you entered. We also derive a link to your public Statlocker match history from that Steam ID.
Images you upload
Team logos and match screenshots are stored in an Amazon S3 bucket whose objects are readable by anyone holding the URL. Treat anything you upload as public, and don’t put personal information in a screenshot you wouldn’t want shared.
What we publish
Player pages on this site show your display name, in-game name, your roles, the teams you play for and your match record. Team pages show the team name, tag, logo, school and roster, alongside schedules, scores and standings. Other profile fields — your bio, your links, your Steam and Statlocker URLs — are stored but not published here today. Your email address, school email and phone number are never shown publicly.
Email we send
Transactional mail goes out through Amazon SES: address verification codes, password resets, team invitations and other notifications, and pre-match reminders. Occasional operational announcements — schedule changes, rule updates — go to confirmed addresses. Promotional mail goes only to people who ticked the opt-in. Match reminders can be turned off in your portal settings; announcements about an event you entered are part of running the competition and aren’t opt-out.
Our Discord bot
The league runs a Discord bot that assigns team roles and opens match threads. When a roster changes, a match is scheduled, or an event starts or ends, the site sends the bot a signed message so it can keep Discord in step. The only personal identifier in those messages is your Discord user id and your role on the team — no email address, no real name, no contact details.
The same bot reads a token-authenticated API for rosters and results. That API can return Discord ids; it is built never to return email addresses or contact records.
Third-party services
We use Amazon Web Services for hosting, the database, file storage and outbound email; Discord for account linking and our community server; and Steam’s public API for account lookups. Pages that embed a live stream load that player directly from Twitch, and links to YouTube or other platforms take you to services with their own privacy policies. We don’t sell or rent your information, and we don’t share it with anyone outside running the league.
Keeping and deleting data
Results, rosters and standings are the competitive record of the league and we keep them. Enrollment documents are a deliberate exception: they are sent to staff over Discord modmail rather than uploaded here, and are deleted once eligibility has been confirmed, as set out in the rulebook. You can edit or clear most profile fields yourself in your portal settings, unlink Discord at any time, and ask us to delete your account — staff can remove it, though matches you already played remain part of the historical record.
Questions
Reach out through the contact page or our Discord modmail. If any of this changes, we’ll update this page and the date at the top of it.