dinkFlow

Data Processing Addendum

Last updated September 14, 2026

For organizers — clubs, leagues, and others who run events on DinkFlow. This addendum is part of our Terms of Service and explains how we handle your participants’ personal data on your behalf.

1. Scope and how this DPA applies

This Data Processing Addendum (“DPA”) is part of the agreement between DinkFlow (“DinkFlow,” “we,” “us”) and the organizer that accepts it (“Organizer,” “you”) under our Terms of Service. It applies whenever we process Participant Data on your behalf while providing the Service.

You accept this DPA when you set up your organization on DinkFlow. If you accept on behalf of a club, league, company, or other organization, you confirm that you are authorized to bind it. If this DPA and the Terms conflict on a data protection matter, this DPA controls.

2. Definitions

  • Participant Data — personal data about players, partners, invitees, scorekeepers, and other participants that is submitted to, collected through, or generated by the Service for your events: for example names, contact details, eligibility details (such as gender and DUPR rating), registrations, teams, payment status, schedules, scores, and results.
  • Data Protection Laws — privacy and data protection laws that apply to the processing, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”), other U.S. state privacy laws, and, where applicable, the EU and UK General Data Protection Regulation (“GDPR”).
  • Processing — any operation on personal data, such as collecting, storing, using, disclosing, or deleting it.
  • Subprocessor — a third party we engage to process Participant Data on your behalf.
  • Security Incident — a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Participant Data.
  • “Controller,” “processor,” “business,” “service provider,” “sell,” “share,” and “data subject” have the meanings given in Data Protection Laws.

3. Roles of the parties

For Participant Data, you are the controller (a “business” under the CCPA) and DinkFlow is your processor (a “service provider” under the CCPA).

DinkFlow is an independent controller of personal data it processes for its own purposes, as described in our Privacy Policy — for example, operating player and organizer accounts (which a person can use across many organizers’ events), securing the Service and preventing fraud, billing organizers, meeting legal obligations, and improving the Service using de-identified or aggregated information. This DPA does not apply to that processing.

4. Processing on your instructions

We process Participant Data only to provide the Service to you and on your documented instructions. Your instructions are the Terms, this DPA, and the actions you take in the Service — for example, publishing a tournament, opening registration, generating brackets, emailing schedules, or exporting results. We will tell you if we believe an instruction violates Data Protection Laws, and we may decline to follow it.

Details of the processing

  • Subject matter and duration: providing the Service, for as long as you use it, plus the return and deletion period below.
  • Nature and purpose: hosting event pages and registration, checking eligibility, matching partners, scheduling, scoring, collecting entry fees, sending event communications, and publishing brackets and results.
  • Data subjects: players, partners and invitees, scorekeepers, and other event participants.
  • Personal data: names; email addresses; phone numbers, if provided; eligibility details such as gender, DUPR rating, and confirmation of the minimum age; registrations; team and partner information; payment status; schedules; scores; and results.
  • Sensitive data: the Service is not designed for sensitive personal data (such as health information), and you should not submit it.

5. Your responsibilities

As controller, you are responsible for:

  • having a lawful basis for, and giving participants any notices and obtaining any consents required for, the Participant Data you submit or collect through the Service;
  • submitting only Participant Data you are entitled to use — including rosters you import and invitations you send — and keeping it accurate and limited to what your events need;
  • not registering or submitting data about anyone under 13, and following any additional rules for minors at your events;
  • any Participant Data you export from the Service. For example, the DUPR match export is a file you download and upload to DUPR yourself — DinkFlow does not send data to DUPR, and your sharing with DUPR or other third parties is governed by your arrangements with them;
  • handling questions and complaints about your own events and practices.

6. Our commitments as your service provider

With respect to Participant Data, DinkFlow will not:

  • sell or share it;
  • retain, use, or disclose it for any purpose other than the business purposes of providing the Service described in this DPA, or as otherwise permitted by the CCPA;
  • retain, use, or disclose it outside our direct business relationship with you; or
  • combine it with personal data we receive from or on behalf of others, or collect from our own interactions with a person, except as permitted by the CCPA.

We will comply with our obligations under the CCPA and provide the same level of privacy protection it requires, and we will notify you if we determine we can no longer meet those obligations. You may take reasonable and appropriate steps to stop and remediate any unauthorized use of Participant Data. We certify that we understand these restrictions and will comply with them.

7. Confidentiality

We ensure that anyone we authorize to process Participant Data is bound by appropriate confidentiality obligations and accesses it only as needed to provide, support, or secure the Service.

8. Security

We maintain reasonable technical and organizational measures designed to protect Participant Data, appropriate to the risk. These include encryption in transit, access controls that limit who and what can reach the database, hosting with established infrastructure providers, and periodic review of access settings. We may update these measures as long as the overall level of protection is not reduced.

9. Subprocessors

You authorize DinkFlow to engage the Subprocessors below. We require each to protect Participant Data under written terms at least as protective as this DPA, and we remain responsible for their performance.

SubprocessorPurposeLocation
SupabaseDatabase hosting and authenticationUnited States (AWS us-east-1)
VercelApplication hosting and deliveryUnited States, with a global content delivery network
StripePayment processing for entry feesUnited States
ResendTransactional email deliveryUnited States

Before any SMS features launch, we expect to add Twilio for text message delivery.

We will update this list and notify organizers by email at least 14 days before a new Subprocessor begins processing Participant Data. If you object on reasonable data protection grounds, tell us within that period. If we cannot reasonably address your objection, you may stop using the affected part of the Service or close your organizer account.

10. Help with participant requests

If a participant asks to access, correct, delete, or otherwise exercise their rights over Participant Data, we will provide reasonable assistance, taking into account the nature of the processing, so you can respond. Players can also download or delete their own DinkFlow account data themselves from their account. If we receive a request that relates to your events, we will refer the person to you or, where we are the controller of the data concerned, respond ourselves.

11. Security incidents

We will notify you without undue delay, and in any event within 72 hours, after confirming a Security Incident affecting your Participant Data. Our notice will describe, to the extent known, what happened, the categories of data and participants affected, the likely consequences, and the steps we are taking. We will provide updates as more becomes known and reasonably cooperate with your own notification obligations. Notifying you is not an admission of fault or liability.

12. Other assistance

Taking into account the nature of the processing and the information available to us, we will provide reasonable information and assistance to help you meet your obligations under Data Protection Laws, including data protection impact assessments and consultations with regulators that relate to the Service.

13. International transfers

Participant Data is processed in the United States. Where Participant Data protected by the GDPR, UK GDPR, or Swiss data protection law is transferred to a country without an adequate level of protection, the EU Standard Contractual Clauses (Module Two: controller to processor) are incorporated into this DPA by reference — together with the UK International Data Transfer Addendum or Swiss amendments where applicable — with you as data exporter and DinkFlow as data importer.

14. Return and deletion

While you use the Service, you can view and export available event information, such as the DUPR match export. When you close your organizer account, you may ask us within 30 days for a copy of your event Participant Data in a commonly used format.

Within 90 days after your organizer account closes, we will delete or de-identify the Participant Data we hold on your behalf, except for: (a) competition history that we retain only in de-identified form, or that belongs to players’ own accounts; (b) data we must keep to comply with law or resolve disputes; and (c) copies in routine backups, which remain protected until they are deleted on their normal schedule.

15. Audits and information

On written request, no more than once a year (or more often if a regulator requires it or after a Security Incident), we will provide information reasonably necessary to demonstrate our compliance with this DPA, such as responses to a reasonable security questionnaire. Any on-site audit requires reasonable advance notice, is limited to what Data Protection Laws require, is at your expense, and is subject to confidentiality.

16. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Terms, except where Data Protection Laws do not allow such limits.

17. Term and changes

This DPA applies for as long as DinkFlow processes Participant Data on your behalf. We may update it to reflect changes in law or in the Service. We will post the new version with its date, notify organizers of material changes, and ask you to accept a new version where required.

18. Contact

Questions about this DPA, or a data protection request relating to your events: hello@dinkflow.app.