MATCOMMAND TOURNAMENT PRIVACY POLICY Effective: August 27, 2026 This policy describes the verified data behavior of MatCommand Tournament V14.13. It applies to the local Tournament application, Tournament Cloud publishing, and private Athlete ID matching. MatCommand Tournament is designed for tournament directors and youth organizations. Tournament operators decide what athlete information they enter and whether an event is published online. 1. INFORMATION PROCESSED MatCommand can process tournament and minor athlete information including wrestler name, team or club, division, actual weight, assigned weight class, seed, record, skill, Grapevine rating, local roster identifier, MatCommandAthleteId, optional birth date, bout assignments, scores, results, and tournament audit or recovery information. Birth dates and Grapevine ratings are not part of the public Tournament Cloud projection. A tournament operator should collect only the information needed to run the event. 2. INFORMATION THAT REMAINS LOCAL The complete tournament save is authoritative and remains on the Director computer unless the operator exports, copies, backs up, or publishes information. Local saves, autosaves, recovery points, result journals, exports, and full-event backups can contain the complete roster and optional birth dates and ratings. The installed application stores tournament data under the current Windows user's LocalAppData MatCommand Tournament folder. The portable package stores tournament data in its MCTournament_Data folder beside the portable application. Files exported or copied by the operator remain wherever the operator places them. Local scoring stations, displays, and parent-finder pages can receive event information over the operator's local network. Local network use is not Tournament Cloud publication. 3. LICENSING, PURCHASE, AND UPDATE REQUESTS Online activation sends the license key, product and plan details needed for activation, and a versioned one-way SHA-256 License Device ID derived from the Windows MachineGuid. The raw MachineGuid is not transmitted. The returned activation token is encrypted for the current Windows user with Windows Data Protection API (DPAPI). PayPal purchase and license-delivery workflows process the organization or customer name, contact name, purchase email, transaction identifiers, and license information needed to fulfill and support the purchase. Update checks transmit the installed product version and ordinary network request information needed to retrieve update information. 4. PRIVATE ATHLETE ID MATCHING When an active online license is available, MatCommand can use a private authenticated preparation session before public publication. The application may transmit a local wrestler identifier, wrestler name, team, division, assigned weight class, an existing MatCommandAthleteId, and an optional birth date over HTTPS. An optional birth date is used in memory with the wrestler name to generate a keyed HMAC identity value for exact matching. The raw birth date is not written to the permanent Cloud athlete record, public event state, event entry, or identity-review record. The keyed identity value can be retained to recognize the same athlete later. Private preparation does not create a public viewer URL. Permanent Cloud athlete records can retain a MatCommandAthleteId, athlete name, event-specific name, team, division, assigned weight class, linked events, verified bout results, aggregate win and loss information, identity keys, and administrative correction or audit records. These records support repeat-event matching and verified records. 5. TOURNAMENT CLOUD PUBLICATION Tournament information is published only after the Director explicitly chooses Publish Online. The public viewer can display the tournament name, date, location, status, format, active mats, wrestler names, teams, divisions, assigned weight classes, seeds, bracket or bout assignments, scores, results, and match status. A linked tournament athlete can also provide access to the athlete's public MatCommandAthleteId page and verified record. The public projection does not include birth dates, Grapevine ratings, local recovery files, Director logs, licensing keys, payment details, or complete private tournament state. The Director can end a Cloud event. Ending changes the event to stopped and ends live publishing. It does not delete the public event snapshot, permanent Athlete ID record, linked event entries, verified bout results, or Cloud audit information. 6. RETENTION Local tournament files remain until the tournament operator deletes them from the Director computer, portable folder, backups, exports, or other storage locations under the operator's control. Cloud event snapshots and permanent athlete records do not currently have an automatic deletion period. They remain until MatCommand performs an authorized correction or deletion. MatCommand does not promise that Cloud data is automatically removed when an event ends. Session credentials and live publishing state are used to authenticate and operate active Cloud sessions. Expiration of a session credential stops its use but does not itself delete the event or permanent athlete record. 7. CORRECTION AND DELETION REQUESTS There is no public self-service deletion control in V14.13. A tournament operator, parent or guardian, athlete, or other authorized person can request a correction or deletion by contacting MatCommand at MatCommand@outlook.com. Include enough information to identify the event or Athlete ID and explain the requested change. Do not send a minor athlete's full birth date unless MatCommand specifically requests it through a secure process. MatCommand may need to verify the requester's authority and may preserve limited records when needed to protect tournament integrity, resolve disputes, prevent fraud, maintain licensing or transaction records, or comply with applicable obligations. This policy does not promise a specific completion time or guarantee that every record can be deleted without affecting verified tournament history. 8. SECURITY MatCommand uses HTTPS for Cloud requests, signed and scoped Cloud session tokens, allow-listed public tournament projections, a keyed HMAC for private birth-date matching, and Windows DPAPI for the local activation token. No security method eliminates all risk. Tournament operators must protect the Director computer, local network, exported files, backups, license keys, Director PINs, and public links. 9. TOURNAMENT OPERATOR RESPONSIBILITIES The tournament operator is responsible for having authority to collect and use minor athlete information, providing any notices or obtaining any permissions required for the event, limiting access to staff who need it, verifying public information before publication, responding to parent or athlete questions, securing local and exported files, and asking MatCommand to correct or remove Cloud information when appropriate. Do not publish optional information merely because the software can store it. Birth dates and Grapevine ratings should remain private and should be entered only when needed. 10. CONTACT AND POLICY STATUS Privacy questions and correction or deletion requests: MatCommand@outlook.com This policy describes current product behavior and is not a legal-compliance certification. MatCommand has adopted this policy for the current release. Tournament operators remain responsible for complying with the laws, league rules, school policies, and organizational requirements that apply to their events and their handling of minor athlete information.