PocketPairings
Log in
New privacy rules: player names are now shortened by default to first name and initial (“Ash K.”), Juniors and Seniors to initials. Have an account and want your full name next to your results? Switch it on in your profile. Show my full name

Privacy & Cookie Policy

Last updated October 2026.

Who we are

PocketPairings ("we", "us") provides tools for organising and following Pokémon TCG events. The data controller is José Pedro Valentim Oliveira, trading as Olivra Studio, Leenstraat 3, 3200 Aarschot, Belgium (enterprise number 1042.712.485) — see the legal notice. For any privacy question, contact us at jose@olivra.be.

What we collect

  • Account — your name, email address, and a securely hashed password (or your Discord id, nickname, avatar and email if you sign in with Discord), and when you agreed to the terms.
  • Player profile — your Play! Pokémon Player ID, name, and birth year (only the year — used to determine your age division). A parent or guardian can add their children as players they manage.
  • Event activity — registrations, the decklists you submit, pairings and results for events you take part in.
  • Players without an account — when an organizer publishes a tournament from their tournament software, the file has every player's name and Player ID. For a player without a PocketPairings account we keep only what we show: the first name and initial ("José O."), or initials only for Juniors and Seniors ("J. O."), the division and the results — plus a coded form of the Player ID (a keyed hash) so we recognise the same player at the next event. We do not keep their full name, their Player ID or anything else from the file.
  • Notifications — if you enable them, a web-push subscription for your browser/device.
  • Organizers — for tournament organizers, league/store details and the data needed to operate their events.
  • Supporters — if you link Patreon, your Patreon user id and membership status (tier and renewal date). We never see your payment details.
  • Technical — basic, aggregate usage such as page views; standard server logs, including IP addresses; and, for organizers, the data their desktop app sends us (including the IP address it was sent from).

How we use it & why

  • To run your account and let you register, submit decklists, and follow events — to perform our service to you (contract).
  • To show pairings, standings, and (after an event) published decklists — legitimate interest in running competitive events. You can turn off publishing your own lists in your profile settings; only the deck archetype is then shown, and the list itself stays with the organizer and the event's judges.
  • To show a player page and the leaderboard for players who want one — your choice, which you can change at any time in your profile.
  • To show your full name with your results — only if you ticked "Show my full name and results" (consent), which you can withdraw at any time in your profile. For a child, their parent or guardian has to agree as well.
  • To show the shortened name and results of players without an account, as their organizer published them — legitimate interest in publishing tournament results, kept to the minimum. Organizers confirm to us that their players were told; anyone can ask not to be named at all (see "Your rights").
  • To send transactional email (e.g. email verification, password resets, organizer setup) and, if enabled, pairing notifications — contract / your consent.
  • To keep the service secure and prevent abuse — legitimate interest.

We do not sell your personal data.

What is public

Event results are public: anyone can see an event's pairings and standings, with each player's name and division. Which name depends on the player:

  • An account that agreed to show its full name: the full name.
  • Everyone else in Masters: first name and initial ("José O.").
  • Everyone else in Juniors and Seniors: initials only ("J. O."). A child's full name needs their parent's or guardian's agreement and their own player page switched on.
  • Anyone who asked not to be named: "Player" with a number.

We never show a birth year, and never the Player ID of a player without an account. Players without an account have no player page and cannot be found by name. Minors' player pages are off unless they (or their parent) switch them on, and even then kept out of search engines; minors never appear on the leaderboard. Adults' player pages are on by default once they agreed to show their name, and can be switched off in the profile.

Cookies

Essential cookies keep you signed in and protect forms (session and CSRF cookies). The site can't function without them, so they don't require consent.

We do not currently use advertising or analytics cookies. If this changes, we'll update this policy and ask for your consent before any non-essential cookies are set.

Our fonts are served from our own server, so loading a page doesn't contact Google or any other font service. The store map loads its map tiles from OpenStreetMap, which receives your IP address while you view the map; no other page does.

Who we share data with

We use a small number of providers to run the service:

  • Hetzner — our hosting and infrastructure provider.
  • Resend — to deliver transactional email.
  • Discord — only if you choose to sign in with Discord.
  • Patreon — only if you link your Patreon account to become a supporter.
  • Stripe — payments for organizer modules: the store's billing details, never players' data.
  • Your browser's push service (Google, Mozilla, Apple or Microsoft, depending on your browser) — only if you turn on notifications; it delivers the notification text, such as your pairing.
  • OpenStreetMap Foundation — map tiles on the store map (see above).

International transfers

Our hosting is in the EU. Some of our providers — such as Resend, Discord, Patreon, Stripe and the push services — are based in the United States, and the OpenStreetMap Foundation in the United Kingdom, so using those features involves transferring some personal data outside the European Economic Area. Where that happens, the transfer is protected by appropriate safeguards, such as the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses; transfers to the United Kingdom are covered by the Commission's adequacy decision. You can request more detail at jose@olivra.be.

How long we keep it

  • Your account — until you delete it. When you do, your login, email, decks, teams, follows, notifications and devices are deleted straight away.
  • Event results — pairings, standings, match results and submitted lists are part of events other people played in too, so they are kept as the event's record after an account is deleted. The player is detached from the account, the birth year is erased, the player page goes private and lists are no longer published.
  • Notifications — about an event, until the event is over; others for two weeks.
  • Desktop-app data sent by organizers — a copy of each upload, with the same shortened names and coded IDs as above (never full names), for 90 days, to investigate problems. A record of each publish — event, who sent it, when, and a fingerprint of the file — is kept as long as the event.
  • Players without an account — the shortened name, division and results, as part of the events they played; see "Event results". If you ask not to be named, the shortened name is erased and only the coded ID stays, so your name does not come back at the next event.
  • Patreon notifications — 90 days after we've processed them.
  • Desktop-app logins — deleted after a year without use. Password-reset links expire after an hour.
  • Server logs — 14 days.

Your rights

Subject to applicable law (including the GDPR for EU/EEA users), you can request access to, correction of, or deletion of your personal data, receive it in a portable format, object to or restrict certain processing, and withdraw consent where we rely on it. You can download your data and delete your account yourself, under Account in your profile. Your name, birth year and list settings are under Player. No account, and your name came to us from an organizer's tournament software? You can ask us to stop showing your name; we answer within 30 days. For anything else, contact jose@olivra.be. You also have the right to complain to your local data protection authority — in Belgium, the Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), dataprotectionauthority.be.

Children

Pokémon events include Junior and Senior age divisions, so some participants are minors. In Belgium you can consent to an online service yourself from the age of 13, so:

  • Under 13 — a child does not get an account of their own. A parent or guardian adds them as a family member on their own account and manages their registrations, lists and settings. We don't accept a child under 13 as an account's own player.
  • Accounts from before family members existed — until July 2026 a parent could only link a child as the account's own player. Where that player is under 13, we pause the account and email its address to ask whether a parent or guardian holds it. Confirming turns the child into a family member and reopens the account; nothing is deleted in the meantime.
  • 13 and older — you can have your own account. Signing up asks for your date of birth to check this. We use it only for that check and don't store it.
  • Every minor gets the protections described under "What is public": initials only on event pages unless a parent or guardian agreed to the full name, no public player page unless switched on, kept out of search engines, never on the leaderboard. We never use a minor's data for advertising or profiling.

If you believe a child has given us data without appropriate consent, contact us and we will delete it.

For organizers

How the desktop app handles your tournament file, and what you confirm to us on the first publish: organizer FAQ.

Changes

We may update this policy; we'll revise the date above when we do. Questions? jose@olivra.be.