2026-08-25
2026-08-25
This document is published in the eight languages of the site. Every edition is equally binding; none of them governs the others.
You can read this site without an account. Our own analytics are self-hosted and cookieless, there are no advertising tags, and nothing is sold or handed to a data broker. We also use Google Analytics to see where visitors come from: it sets a cookie, and in the EEA and the UK it does not run until you say yes. What we hold beyond that is what an account and a subscription need — your email address, the record that you accepted the terms, the days the account was used, and what our payment provider tells us about your subscription.
Everything below says which field, why we have it, how long it stays, and who else sees it. To read, correct, export or delete what we hold, write to one address and a person answers.
1Who is responsible, and how to reach them
cs2pickside.com is an independently run service, operated by the owner of this website, who decides what personal data is collected here and why — the "controller", in the language of the GDPR.
For anything in this policy — a question, a correction, a copy of your data, a deletion — write to [email protected]. It reaches a person, and the answer comes from the same address.
This policy covers the site and every subdomain of it. It forms part of our Terms of Service.
2What we hold, and why
Reading the site asks nothing of you: no account, no name, no form to fill in. What the servers note by themselves is the last group below, and that group applies to everyone; everything before it applies once you create an account, subscribe, write to us, or take the newsletter.
Your account:
- your email address, and a second one while a change of address is waiting to be confirmed;
- your password as an argon2id hash — never the password itself, which we cannot read or recover;
- the language you use the site in, so an email arrives in it;
- when you accepted the terms, which version you accepted, and in which language edition it was shown to you — the record that answers a payment dispute;
- when the account was created, when it last signed in, whether the email is confirmed, and the country the sign-up came from, derived from the connection and stored as a country code only;
- counters that lock an account after repeated failed sign-ins, so a password cannot be guessed at leisure.
Your sessions and the record of use:
- one row per signed-in session: a hash of the session token (never the token), the IP address and browser it was created from, and when it was last used;
- one row per day the account was used, with the address it was used from. This is kept as evidence: we defend chargebacks ourselves, and "the service was used on these days" is what a bank asks for. It is deleted after 400 days;
- security events — failed sign-ins, lockouts, refused registrations — kept for 365 days so a pattern of abuse can be seen and explained.
Your subscription:
- what our payment provider tells us: the subscription and payment identifiers, its status, the dates, the amounts, and the country of the payment method;
- your card details are handled by the provider and its processors and never reach us — we could not show them to you if you asked.
What you send us:
- emails to support, their attachments, and our replies, kept with the thread so a later question has its history;
- a newsletter subscription: the address, its language and its confirmation state, until you unsubscribe;
- notes an operator writes about an account while handling a request.
What the servers record on their own:
- application logs and traces for requests, including the IP address and what was asked for, kept for a short operational window and used to run and debug the service;
- one row each time somebody arrives here from somewhere else: the site or search that sent you, as its domain and never the full address you came from; the page you landed on; any campaign tags carried in the link; the country the connection is placed in; and your address as a hash rather than the address itself. It is kept for 90 days;
- a log of the emails we sent you and what happened to them, so a "you never told me" can be answered;
- page analytics — see the section on cookies and analytics below.
That hash is what keeps an arrival countable without keeping it identifiable. It is made from your address together with a random value that lives for one day and is then thrown away, so the same address gives a different hash tomorrow and, once that value is gone, no hash can be turned back into an address. If you create an account, that day’s hash is written beside the sign-up as well — the one thread that ever ties an arrival to a person, and it goes when the account does.
3The legal basis for each of those
Where the GDPR or a comparable law applies to you, we rely on:
- performance of our contract with you — the account, the subscription, the emails a subscription has to send;
- our legitimate interests — keeping the service secure, stopping abuse of free trials and country restrictions, defending a payment dispute, and knowing how people find the site and which pages they use, counted without being identified;
- a legal obligation — records of payments and of the acceptance of the terms, which tax law and the time limits on a dispute require us to keep;
- your consent — the newsletter, which you confirm by clicking a link, and which you can withdraw in one click from any issue.
Where we rely on a legitimate interest, you may object: write to us and say so, and we will either stop or explain why the interest overrides in your case.
5Who else processes it
We do not sell personal data, and we do not share it for anyone else’s marketing. The services below process it on our instructions so that the site can work:
- Whop — payments and subscriptions, as merchant of record. It holds the payment details we never see, and tells us the state of your subscription.
- Resend — sending our email and receiving what you send to support.
- Cloudflare — the network in front of the site: the tunnel that carries requests, the anti-bot challenge on the sign-in and sign-up forms, and a page-performance measurement. It processes connection data such as your IP address in doing so.
- Hetzner — the servers themselves, in Germany, where the database and the backups live.
- Google — the analytics that tell us where visitors come from, described in the section on cookies. It receives nothing where consent has not been given.
Our forecasts are produced with the help of a language model, and no personal data is sent to it: the questions it is asked are about matches, teams and tournaments.
We disclose personal data outside that list only where the law requires it, or where it is necessary to establish or defend a legal claim — a chargeback is the everyday example, and the Terms of Service say exactly what a bank is shown.
6Where it is kept
The database and its backups are in Germany. Backups are encrypted, and a copy is held offsite with a storage provider, also encrypted.
Some of the services above are based outside the EU. Where personal data reaches them it travels on the transfer terms their own agreements provide — the European Commission’s standard contractual clauses in the usual case, and for Google its certification under the EU-US Data Privacy Framework, which the Commission has found to provide adequate protection.
7How long it stays
We keep each thing for as long as the reason for having it lasts:
- the account and its email address: until you ask us to erase it;
- sessions: until they expire, and then they are swept away;
- the record of days an account was used: 400 days;
- security events: 365 days;
- the record of arrivals on the site: 90 days;
- payments, and the record that the terms were accepted: for as long as tax law and the time limit on a payment dispute require, which outlasts the account itself;
- support threads: while they are useful to answer a later question;
- the newsletter: until you unsubscribe;
- server logs and traces: a short operational window, measured in days.
8Your rights, and how to use them
You can ask us to show you what we hold, correct it, give you a copy you can take elsewhere, delete it, restrict what we do with it, or object to a use we base on a legitimate interest. Where we rely on consent, you can withdraw it at any time without affecting what was done before.
Write to [email protected] from the address on the account. We answer within one month, which is the period the GDPR allows, and usually much sooner. We do not charge for this.
Erasure means the identifying details are overwritten and the account can no longer be signed in to. An arrival carrying the same hash as your sign-up is erased with it, and a copy of your data includes that arrival — it is the only one we can show is yours. Erasure does not remove the records we are required to keep — the payments and the acceptance of the terms — which stay under the legal obligation above, detached from a name.
If you think we have handled your data badly, tell us first — we would rather fix it. You also have the right to complain to the data protection authority of the country you live in.
9How it is protected
Passwords are stored as argon2id hashes. Session tokens are random and stored only as hashes, so a copy of the database does not let anyone sign in as you. Every connection is HTTPS, and the site declares strict transport security and a content security policy.
Sign-in and registration are rate-limited and protected by an anti-bot challenge, an account locks itself after repeated failed attempts, and the admin console is reachable only to accounts holding that role.
Backups run daily, are encrypted, and are restore-tested on a schedule — a backup nobody has restored is a hope, not a backup.
No system is perfect. If a breach ever affects your data and the law requires it, we will tell you and the authority within the time the law allows.
10Age
The site is for adults: you must be at least 18 to hold an account, and we do not knowingly collect data from anyone younger. If we find that an account belongs to someone under 18 we close it and delete what we hold, refunding the most recent payment.
11Changes to this policy
We may change this policy — because the service changes, or the law does. The version in force and the date it took effect are printed at the top of this page.
A change that materially affects how we use data we already hold is announced by email to the address on your account before it takes effect, so that a change of use never arrives unannounced.
Questions about any of it: [email protected].