Home About Platform Solutions Categories Resources Success Stories Pricing FAQs Contact
Request Demo
Legal

Privacy Policy

We hold registration data for lakhs of students, athletes and employees. This page explains in plain language what we collect, why, how long we keep it, and what you can ask us to do about it.

Last updated 21 July 2026 · Applies to www.sportzcontests.com and the SportzContest organiser and participant apps.

SportzContest is operated by Catalyst Web Trendz Pvt. Ltd., a company registered in India with its head office at D 29, 2nd Floor, Greater Kailash Enclave 2, Greater Kailash, New Delhi – 110048. In this policy, "we", "us" and "SportzContest" mean that company. "You" means anyone who visits our website, registers for an event, or runs an event on our platform.

This policy is issued in compliance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000 and the rules made under them. Where we act as a Data Fiduciary we decide the purpose of processing. Where an organiser uses our platform to collect entries, that organiser is the Data Fiduciary and we act as their Data Processor. Section 4 explains which is which.

1. Scope of this policy

This policy covers personal data processed through our marketing website, the organiser dashboard, the participant registration flow, the volunteer scanner app, our WhatsApp and email notification systems, and any support conversation you have with us. It does not cover the websites of payment gateways, sponsors or third-party event partners that you may be redirected to; those carry their own policies and we say so clearly at the point of hand-off.

2. Data we collect

We collect only what an event genuinely needs to run. Broadly, that falls into six buckets.

  • Identity and contact data — name, date of birth or age group, gender where the event has gendered categories, email address, mobile number, and the institution or team you represent.
  • Organiser and account data — the name, designation, official email and phone number of the person administering an event, plus organisation details such as PAN, GSTIN, registered address and bank account for settlement.
  • Event participation data — entries, categories, seedings, check-in timestamps, scores, judge ratings, rankings, disqualifications, medal and certificate records.
  • Uploaded documents — where an organiser requires them, items such as school ID cards, age-proof documents, medical fitness declarations or consent letters. These are stored encrypted and are visible only to the organiser who asked for them.
  • Transaction data — amount, currency, date, invoice number, GST details, payment method type and the gateway's transaction reference. We do not store your full card number, CVV or UPI PIN at any point.
  • Technical and usage data — IP address, device and browser type, approximate city-level location, pages viewed, and the actions taken inside the dashboard. This is used for security, fraud prevention and product improvement.

We do not knowingly collect caste, religion, political affiliation, biometric templates or health data beyond a simple fitness declaration where an organiser requires one for a physical event.

3. Data of children and students

A very large share of our events are school competitions, so this section matters. Under the DPDP Act, a "child" is anyone under eighteen years of age.

  • Where a school, college or club registers its own students, we rely on that institution to have obtained verifiable parental or guardian consent under its existing admission and activity-consent framework, and to have recorded it. Our organiser agreement makes this an explicit obligation.
  • Where a parent or guardian registers a child directly on a public event page, we collect an express consent declaration from the adult, along with their name and contact number, before the entry is accepted.
  • We do not run behavioural advertising, tracking or profiling against any record flagged as belonging to a child, and we do not send marketing messages to a minor's contact details.
  • Photographs, videos and results involving minors are published only when the organiser has switched on public results for that event and has confirmed it holds media consent. Any parent may ask for a child's name to be masked on a public leaderboard by writing to our Grievance Officer.

4. Who is responsible for your data

When you visit our website, subscribe to our newsletter or contact our sales team, SportzContest is the Data Fiduciary and decides how that data is used.

When you register for an event run by a school, college, company or federation, that organiser is the Data Fiduciary. They decide what fields to ask for, who on their committee can see the entries, and how long the event data lives. We process that data on their documented instructions as a Data Processor, and we do not use it for our own marketing. If you want your entry deleted from a specific event, the fastest route is to contact that organiser; we will also help if you write to us and cannot reach them.

5. Why we process your data — lawful basis

We process personal data on one of three bases recognised under the DPDP Act and Indian contract law.

  • Consent — for marketing emails, the Contest Digest newsletter, WhatsApp promotional messages, optional analytics cookies, and any publication of your name or photograph beyond the results themselves. Consent is asked for separately and can be withdrawn at any time.
  • Performance of a contract — for creating your account, taking your entry, processing your payment, issuing your QR pass and certificate, and providing support. Without this data we simply cannot run the event you signed up for.
  • Legitimate uses and legal obligation — for fraud prevention, platform security, maintaining audit trails of scoring decisions, retaining tax invoices under the GST law, and responding to lawful requests from courts or government agencies.

6. How we use your data

Specifically, we use personal data to create and administer accounts; to accept and validate entries; to collect fees and issue GST-compliant invoices; to generate QR passes and verify them at the gate; to record scores and publish results and leaderboards; to generate certificates carrying a verification code; to send transactional notifications by email, SMS and WhatsApp about your event; to provide customer support; to produce aggregated, de-identified analytics about platform usage; and to detect duplicate entries, vote manipulation and payment fraud.

We do not sell personal data. We do not rent contact lists to sponsors. Where a sponsor receives a report about an event, it contains aggregate figures — turnout, age-band distribution, city spread — not individual records, unless a participant has separately opted in to hearing from that sponsor.

7. Payments and sharing with payment partners

Card, UPI, netbanking and wallet transactions are handled by RBI-authorised payment aggregators and payment gateways engaged by us. In line with the Reserve Bank of India's guidelines on the regulation of payment aggregators and payment gateways, and its card-on-file tokenisation norms, card data never touches our servers — it is collected directly by the aggregator on a PCI-DSS compliant page and, where you choose to save a card, stored only as a network token.

We share with the aggregator the minimum needed to process a transaction: the amount, the order reference, and your name, email and mobile number for receipt and dispute purposes. Settlement to an organiser's bank account is made against the organiser's verified KYC record. Chargeback and dispute handling follows the aggregator's process and the card networks' rules, and may require us to share transaction evidence with the acquiring bank.

8. Other parties we share data with

  • Event organisers — the institution running the event you entered, for the fields they configured.
  • Communication providers — our email, SMS and WhatsApp Business API partners, who receive your contact details solely to deliver the message.
  • Cloud infrastructure providers — our hosting, backup and error-monitoring vendors, under contracts that restrict them to processing on our instructions.
  • Professional advisers and auditors — lawyers, chartered accountants and security auditors, bound by confidentiality.
  • Law enforcement and regulators — where we are legally required to disclose, and only to the extent required. Where the law permits us to tell you about such a request, we will.
  • An acquirer — if the business is merged or acquired, data may transfer to the successor entity, which will remain bound by this policy or a materially equivalent one.

9. Where your data is stored

Primary databases, uploaded documents and backups are hosted in Indian data centre regions (Mumbai and Hyderabad) operated by our cloud provider, with encrypted backups replicated within India. A small number of support and analytics tools we use may process limited technical data outside India; where that happens, transfers are made only to countries not restricted by the Central Government under the DPDP Act, and are covered by contractual safeguards. Organisers on Championship plans may request full data residency within India across every sub-processor, and we will confirm that in writing.

10. How long we keep data

  • Event and participation records — for the duration of the organiser's account plus 24 months, so that certificates remain verifiable and results can be re-published on request.
  • Uploaded age and identity documents — deleted 90 days after the event concludes, unless the organiser has a documented reason to retain them for a dispute.
  • Financial records and tax invoices — eight financial years, as required under Indian tax and companies legislation.
  • Marketing contact data — until you unsubscribe, and for 30 days thereafter to honour the suppression list.
  • Server and security logs — 180 days, in line with Indian cyber-security directions.

When a retention period ends, data is deleted or irreversibly anonymised. Aggregate statistics that cannot identify anyone may be kept indefinitely.

11. Cookies and similar technologies

We use a small number of cookies. Strictly necessary cookies keep you logged in, protect against cross-site request forgery, and remember your cookie choice; these cannot be switched off because the platform will not work without them. Analytics cookies help us understand which features organisers actually use, and are set only after you accept them on the banner. We do not run third-party advertising or retargeting cookies on this site.

You can change your choice at any time by clearing site data in your browser, which will bring the consent banner back. Blocking all cookies in your browser will prevent login and registration from working.

12. Security

Data is encrypted in transit using TLS 1.2 or above and at rest using AES-256. Access to production systems is restricted by role, requires multi-factor authentication, and is logged. Organiser dashboards support role-based permissions so a scorer cannot see payment details and a volunteer cannot export participant lists. We run vulnerability scans continuously and an independent penetration test annually.

No system is perfectly secure. If a personal data breach occurs, we will notify the Data Protection Board of India and every affected person in the manner and within the timelines prescribed under the DPDP Act, describing what happened, what data was involved and what you should do.

13. Your rights

Subject to verification of your identity, you may:

  • Ask for a summary of the personal data we hold about you and the parties it has been shared with.
  • Ask us to correct data that is inaccurate, or complete data that is incomplete — for example a misspelt name on a certificate.
  • Ask us to erase data that is no longer needed for the purpose it was collected for, unless retention is required by law.
  • Withdraw consent for marketing or optional processing, as easily as you gave it.
  • Nominate another person to exercise these rights on your behalf in the event of your death or incapacity.
  • Register a grievance with us and, if unsatisfied, escalate to the Data Protection Board of India.

Write to info@catalystwebtrendz.com. We acknowledge requests within 48 hours and respond substantively within 30 days. There is no charge for a reasonable request.

14. Grievance Officer and updates to this policy

In accordance with the Information Technology Act, 2000 and the rules under it, the details of our Grievance Officer are:

The Grievance Officer
SportzContest, Catalyst Web Trendz Pvt. Ltd.
D 29, 2nd Floor, Greater Kailash Enclave 2, Greater Kailash, New Delhi – 110048
Email: info@catalystwebtrendz.com · Phone: +91 99535 90779
Hours: Monday to Friday, 10:00 a.m. to 7:00 p.m. IST

We review this policy at least once a year. If we make a material change — a new category of data, a new purpose, or a new class of recipient — we will notify account holders by email at least 15 days before it takes effect and update the "last updated" date above. Continuing to use the platform after that date means you accept the revised policy. Any dispute arising from this policy is subject to Indian law and to the exclusive jurisdiction of the courts at New Delhi, Delhi.

Questions about this policy?

Write to our privacy desk and a real person will answer — not a template. Schools and colleges are welcome to ask for our DPDP compliance note and sub-processor list for their internal records.

Legal centre

The rest of the fine print

Privacy Policy

You are here. What we collect, why, and the rights you hold under the DPDP Act, 2023.

Terms of Service

Account rules, organiser and participant roles, fees, refunds and how disputes are settled.

Disclaimer

Where our responsibility ends and the organiser's begins — listings, results and external links.