Privacy Policy
Last updated: June 2026
OpenLadder is a free tennis ladder. We only collect the data we need to run it. No ads, no analytics tracking, no selling your information — ever. This page explains exactly what we collect, why, and what you can do about it.
1. What we collect
- Account info you give us: first name, last name, email address, password (stored only as a bcrypt hash — we never see the plain text), and gender.
- Optional profile fields: phone number, birth date, and tennis-style preferences (dominant hand, favorite shot, etc.).
- Match data you create: ladders you join, proposals you post or accept, match scores you report, disputes you file.
- Messages you send us: feedback form submissions and email correspondence with support.
- Security telemetry: a one-way hash of your IP address and your browser user-agent on failed logins, password-reset requests, and new signups — used to detect attacks. We never store your raw IP. See section 6 for details.
2. How we use it
- To run your account — let you sign in, post proposals, accept matches, and track your standings.
- To send transactional emails — email verification, match-related notifications (proposal accepted, score reported, match cancelled), and password-reset links.
- To compute and display public ladder standings.
- To respond to feedback, disputes, and support requests.
- To detect and respond to suspicious activity on the platform.
We do not use your data for advertising. We do not run behavioral analytics (no Google Analytics, no Mixpanel, no tracking pixels). We do not sell or rent your information to anyone.
3. What's visible publicly
OpenLadder is a public ladder. Anyone visiting the site (logged in or not) can see:
- Your first name, last name, and player slug (e.g.
/player/piyush-jain). - The ladders you've joined, your match history, scores, points, and standings.
- Any tennis-style fields you've filled in (dominant hand, favorite shot, etc.) — these are optional.
Your email and phone number are only visible to opponents you've matched with — so you can coordinate. Your birth date is never shown.
4. Who we share it with
We use three vendors to run the platform. That's the full list:
- Vercel — hosts the application code. Every request to OpenLadder is served from their infrastructure.
- Neon — hosts the Postgres database where account data, matches, and standings are stored.
- Brevo — delivers all transactional emails (verification, match notifications, password resets).
We may also disclose information if legally required (subpoena, court order) or if necessary to investigate fraud, abuse, or violations of our Terms. We'll push back on overly broad requests and notify you when we're legally able to.
5. Cookies
OpenLadder sets two cookies. Both are first-party (only readable by us) and neither tracks you across other sites:
- Session cookie — keeps you signed in. Cleared when you sign out or when the session expires.
- Theme cookie — remembers whether you chose light or dark mode.
No advertising cookies. No third-party analytics cookies. No cross-site tracking. You can clear them anytime in your browser settings; the only consequence is you'll be signed out and your theme will reset to default.
6. Security telemetry
To detect attacks (credential stuffing, signup spam, email enumeration), we record three categories of events:
- Failed login attempts
- Password-reset requests
- New account registrations
For each event we store the timestamp, the email address attempted, a truncated user-agent string, and a one-way SHA-256 hash of your IP address (salted with a server-only secret). We never store your raw IP address. The hash lets us group attacks from the same source without being able to reverse it back to an IP.
7. Data retention & backups
- Account data and match history are kept for as long as your account exists. Deleting your account removes them (see section 8).
- The database is backed up off-platform every night and retained for 30 days. Backups are encrypted at rest by the backup provider.
- Email delivery logs are kept by Brevo per their own retention policy.
8. Your rights
- View & correct — your profile page and account settings let you update any field you provided.
- Delete your account — email support@playopenladder.com from the address on the account and we'll delete it within 14 days. Your past match scores stay on the public standings (we don't rewrite history), but your profile, contact info, and login credentials are removed.
- Export your data — email support with the same request and we'll send you a JSON dump of your account data and match history.
- Withdraw consent — you can stop using the platform at any time. Combined with deletion above, this fully removes you from the system.
9. Age requirement
OpenLadder is intended for players aged 18 and older. By creating an account you confirm you are at least 18 years old. We don't knowingly collect information from anyone under 18. If you believe an under-age account has been registered, contact us at support@playopenladder.comand we'll remove it promptly.
10. International users
OpenLadder is operated from the United States and our servers (Vercel, Neon, Brevo) are based in the U.S. and EU. If you access the platform from outside these regions, your data will be transferred to and processed in these locations. By using OpenLadder you consent to this transfer.
11. Changes & contact
If we change this policy materially, we'll update the "Last updated" date at the top and announce the change on the What's New page. Continued use of OpenLadder after a change constitutes acceptance.
Questions, data requests, or anything else privacy-related: support@playopenladder.com.