1. Who we are and who this policy covers
eSportzCraazy.in is owned and operated by Catalyst Web Trendz Pvt. Ltd., D 29, 2nd Floor, Greater Kailash Enclave 2, Greater Kailash, New Delhi – 110048. For the purposes of the Digital Personal Data Protection Act, 2023 (the "DPDP Act") we are the Data Fiduciary for personal data processed through this website, our tournament platform, our store and our community channels. You are the Data Principal.
This policy applies to everyone who visits the site, creates an account, registers a squad or organisation, enters a tournament, claims a prize, buys merchandise, watches or chats on a stream, subscribes to The Respawn, or contacts our support desk. It does not apply to independent platforms we link to or broadcast on — game clients, publisher accounts, Discord, YouTube, Twitch and payment gateways each operate under their own privacy policies, which you should read separately.
We are also an intermediary for user-generated content under the Information Technology Act, 2000 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and we publish the grievance mechanism those Rules require in section 18 below.
2. What we collect
We group everything we hold into eight buckets. You can use large parts of the site — reading news, browsing brackets, watching a public stream — without giving us any of it.
2.1 Account and identity data
Your display name, gamer tag, email address, mobile number, password (stored only as a salted hash), date of birth or age bracket, city and state, preferred titles, avatar selection and the timestamps of your account activity. Where you claim a cash prize we additionally collect the KYC data described in section 2.4.
2.2 Team, roster and competitive data
Organisation or squad name, region, logo you upload, the roster you register (each player's gamer tag, role, substitute status and in-game user ID), captain and manager contact details, roster-change requests, ranked tier or rank proof you submit for eligibility, and your match history, placements, points, K/D and rating on our ladders.
2.3 In-game identifiers
The in-game IDs, UIDs, Riot IDs, Steam IDs, activision IDs, EA IDs or equivalent handles you supply so that lobbies can be created and results verified. We store the identifier itself and, where the publisher's public API permits, the display name and region attached to it. We do not collect your game account password and will never ask for it.
2.4 Entry, prize and tax data
Tournament entries and withdrawals, entry-fee payment references, prize allocations, and — only where you win a cash prize — your legal name, PAN, date of birth, bank account or UPI handle, address proof and a signed prize-receipt declaration. This is collected because we are required to deduct tax at source and to file the corresponding returns under the Income-tax Act, 1961.
2.5 Order and payment data
For store purchases: the items ordered, order value, GST invoice details, delivery name, address and phone number, and the payment reference returned by our gateway. Card numbers, UPI PINs, CVVs and net-banking credentials are never transmitted to or stored on our servers — the payment is captured on the gateway's own hosted page and we receive only a tokenised reference and a success or failure status.
2.6 Stream and chat activity
If you chat, react, vote in a poll, post a clip or comment on a VOD, we record the message content, the channel, the timestamp, reports filed by or against you, and moderation actions taken. Public chat is public by design and is visible to everyone watching.
2.7 Device and anti-cheat telemetry
Device type, operating system and version, browser, screen resolution, approximate city-level location derived from IP address, connection latency to our Mumbai, Chennai and Delhi servers, and — for competitive lobbies only — the integrity signals described in section 9.
2.8 Enquiry and support data
The name, email, phone number, team name, gamer tag, game, platform and message you submit through our forms, plus the correspondence that follows and any evidence you attach to a dispute or appeal.
We do not ask for, and ask you not to send us, Aadhaar numbers, health information, biometric data, caste or religion, or any other sensitive category of data through the site or through chat. If you send it to us unsolicited, we will delete it.
3. Why we collect it — purpose limitation
Under section 6 of the DPDP Act we may process your personal data only for the specific purposes you were told about when it was collected. Those purposes are:
- Running your account — authentication, password recovery, account security and support.
- Operating competitions — verifying eligibility, seeding brackets, creating lobbies, recording results, resolving disputes and publishing standings.
- Paying prizes — identity verification, tax deduction and remittance, and audit records.
- Fulfilling store orders — taking payment, raising a GST invoice, shipping, returns and refunds.
- Protecting competitive integrity — detecting cheating, smurfing, account sharing, multi-accounting and match manipulation.
- Keeping the platform safe — abuse reports, moderation, fraud prevention and security logging.
- Improving the product — aggregate analytics on which events, titles and streams people actually use.
- Communicating with you — service messages, match reminders and, only with your consent, marketing.
- Meeting legal obligations — record-keeping under the IT Act, 2000, tax law, GST law and any lawful order.
We do not use your data for any new purpose without first giving you a fresh notice and, where the law requires it, obtaining fresh consent.
4. Notice, consent and withdrawal
Where we rely on consent, it is collected through a clear affirmative action — ticking a box, pressing Accept on the cookie banner, or submitting a registration form after reading the notice attached to it. Each consent is recorded with a timestamp and the version of this policy in force at the time. Consent is never bundled: declining marketing does not stop you from entering a tournament.
Where consent is not the basis, we rely on the certain legitimate uses permitted by section 7 of the DPDP Act — for example, processing data you voluntarily provided for a purpose you have not objected to, responding to an email you sent us, complying with a legal obligation, or acting in an emergency involving a threat to life or safety at a LAN venue.
You may withdraw consent at any time, and with the same ease with which it was given, from Account → Privacy & Consent or by writing to the Grievance Officer. Withdrawal does not affect the lawfulness of processing carried out before it. Please note that withdrawing consent for competitive-integrity processing means we can no longer allow you into ranked lobbies or prize-bearing events, because we would not be able to verify a fair result.
5. Cookies and local storage
We use a small number of cookies and browser local-storage entries. The consent banner blocks the analytics class before it is set; strictly necessary entries cannot be switched off because the site will not function without them.
Cookies and local storage used by eSportzCraazy, with their class, purpose and lifetime
| Name |
Class |
Purpose |
Lifetime |
| esz-session |
Strictly necessary |
Keeps you signed in to the arena and protects the session against tampering. |
Session |
| esz-csrf |
Strictly necessary |
Cross-site request forgery token on every form submission. |
Session |
| esz-cookie-consent |
Strictly necessary |
Stores your own accept or decline choice so we stop asking. |
12 months |
| esz-titles |
Preference |
Remembers your favourite titles and the last platform filter you used. |
12 months |
| esz-region |
Preference |
Remembers your preferred server region so latency estimates are accurate. |
6 months |
| esz-metrics |
Analytics |
First-party, aggregate measurement of pages read, streams watched and brackets opened. |
13 months |
| esz-stream-qos |
Analytics |
Playback quality, buffering events and bitrate, used to fix streaming problems. |
30 days |
We do not run third-party advertising trackers, ad-network pixels or cross-site behavioural profiling on eSportzCraazy. You can clear all of the above from your browser settings at any time.
6. Tournament entries, organisers and publishers
Competitive esports cannot be run anonymously. When you enter an event, some of your data necessarily becomes visible or is passed on:
- Published publicly — gamer tag, team name, region, seed, results, placements, points and ladder position. These appear on brackets, leaderboards and broadcast graphics, and may be indexed by search engines.
- Shared with co-organisers and venue partners — for LAN legs, the captain's name and phone number, roster gamer tags and accreditation details are shared with the venue and event-operations partner purely for access control and match logistics.
- Shared with game publishers — where a title's rules require a licensed or sanctioned event, we share the roster's in-game IDs and event details with the publisher or its authorised regional partner so that lobbies, custom rooms or tournament codes can be issued. What the publisher then does with that data is governed by the publisher's own privacy policy.
- Shared with the integrity panel — match logs, replays, demo files and reports where a dispute or an integrity investigation is opened.
We do not sell roster data to scouts, agencies or brands. Where a sponsor or a scouting partner asks for player contact details, we ask you first and pass nothing on without your specific consent.
7. Payments, the store and logistics
Entry fees and store purchases are processed by an RBI-authorised payment gateway. You are taken to the gateway's hosted page to enter card, UPI or net-banking details; we receive back only a transaction reference, the amount, the instrument type (for example "UPI" or "credit card"), the last four digits where the gateway supplies them, and a success or failure result. We store that reference for reconciliation, refunds and audit.
For physical merchandise we pass your delivery name, address, PIN code and phone number to our courier partner so that the parcel can be delivered and so that the courier can call you if the address cannot be found. Couriers receive nothing else — not your email, not your gamer tag, not your order history.
GST invoices, payment evidence and prize-payout records are retained for eight financial years as required by tax and companies law, and are not deleted on an erasure request while that obligation subsists.
8. Streams, chat and community content
Live chat, clip submissions, VOD comments, poll votes and Discord activity linked to your eSportzCraazy account are recorded so that moderation, reports and appeals can work. Chat is retained for 90 days in a searchable form and then reduced to moderation outcomes only.
If you appear on a broadcast — as a player on the observer feed, a caster, an interviewee or an audience member at a LAN venue — that footage is published as part of the event and may be re-used in highlight reels and archives. Signage at every venue states this, and player agreements cover it explicitly. If you are recognisable in footage and want it reviewed, write to the Grievance Officer.
Anything you post publicly is content you have chosen to publish. Deleting your account removes your profile and unlinks your posts, but we cannot recall copies that other viewers, clipping bots or third-party platforms have already made.
9. Anti-cheat and device telemetry
Prize-bearing lobbies use integrity checks. Depending on the title, these may include: hardware and device fingerprints used to detect one person playing on several accounts; IP and session overlap between accounts; input-timing and aim-trace statistics derived from match replays; the publisher's own anti-cheat verdicts where the publisher shares them with tournament organisers; and screen or webcam monitoring during an online final, which is always announced in the event rules in advance and is optional to enter that event, not to use the site.
Integrity telemetry is processed only to protect fair competition. It is never used for advertising, never sold, never used to build a general behavioural profile, and is accessible only to the small integrity team. Raw telemetry is deleted 180 days after the event closes; where it is evidence in an open case or an appeal, it is retained until the case, and any appeal window, is over.
If an automated integrity signal leads to a suspension, you are entitled to be told the category of the finding and to appeal to a human reviewer under section 12 of our Terms & Conditions. No competitive ban is issued on an automated decision alone.
10. Analytics and measurement
We measure the platform so we can decide which titles to add, which qualifiers to run and where to place servers. Analytics are aggregate: we look at how many people opened the Vortex Cup bracket versus the Cyber Clash bracket, not at what any named individual does. IP addresses used for city-level geolocation are truncated before storage and are not retained in raw form beyond 30 days.
Declining analytics from the cookie banner does not degrade anything. Brackets, streams, the store and the ladders all work identically without them.
11. Newsletters and marketing
The Respawn goes out at 8:00 AM IST daily. To send it we store your email address, subscription date, the titles you follow and delivery telemetry (delivered, bounced, opened, unsubscribed). Open and click data is used only to fix deliverability and to remove addresses that have stopped engaging.
Every edition carries a one-click unsubscribe link. Unsubscribing takes effect immediately; your address is deleted within 30 days and retained only on a short suppression list so we do not accidentally re-add you. We never rent, sell or trade the subscriber list. Transactional messages — match reminders, lobby codes, order and prize updates, security alerts — are not marketing and continue after you unsubscribe, because you need them.
12. Players under 18
Competitive gaming attracts a young audience and we treat that as a design constraint, not a footnote. Under section 9 of the DPDP Act, a child is anyone under 18 years of age, and their data may be processed only with verifiable consent from a parent or lawful guardian.
12.1 Age gating
Every account asks for date of birth at sign-up. Accounts recording an age under 18 are flagged as a child account and are placed in a restricted mode until a guardian completes verification. Age is not stored as a free-text claim alone — where a minor enters a prize-bearing event, we require documentary age proof as part of eligibility checks.
12.2 Verifiable parental consent
Before a child account can be activated we obtain consent from a parent or lawful guardian through a consent form signed by the guardian, verified against a government-issued identity document that establishes the guardian is an adult, and confirmed through a one-time code sent to the guardian's own email and mobile number. Consent records are stored with a timestamp and the guardian's verification reference. A guardian may withdraw consent at any time, which closes the child account.
12.3 No tracking or targeted advertising directed at children
We do not carry out behavioural monitoring or tracking of child accounts, and we do not serve targeted or interest-based advertising to them, as prohibited by section 9(3) of the DPDP Act. Analytics for child accounts are limited to what is strictly necessary to keep the service running and safe. No child's data is used to build a profile, to train a recommendation model or to be passed to a sponsor.
12.4 Restrictions on minors and cash prizes
Minors may compete in designated youth and open-qualifier events, but they may not receive cash prizes directly. Where a squad containing a minor wins prize money, the minor's share is paid only into a bank account held by, or jointly with, the verified parent or guardian, against a guardian-signed receipt and the guardian's PAN for tax purposes. Some events are marked 18+ only in their rules; those are closed to minors entirely, including as substitutes.
12.5 Safeguards inside the community
Child accounts default to restricted chat, cannot receive direct messages from unconnected adults, cannot appear on paid creator programmes, and cannot list a contact number publicly. If we learn that a child account was created without guardian consent, we suspend it and delete the data within 30 days unless consent is completed in that window. To report an underage account, write to the Grievance Officer.
13. Who we share data with
We share personal data only with the following categories of recipient, each under a written contract that limits them to processing on our documented instructions:
- Hosting, CDN and email-delivery providers operating our servers and transactional mail.
- Payment gateway and banking partners, for entry fees, store payments, refunds and prize remittance.
- Courier and logistics partners, for merchandise delivery only.
- Tournament co-organisers, venue operators and referees, for the specific event you entered.
- Game publishers and their authorised regional partners, where a sanctioned or licensed event requires it.
- Broadcast and production partners, for the observer feed and the archive of that broadcast.
- Chartered accountants, auditors and legal advisers, where required for statutory compliance.
- Law enforcement, courts and regulators, where we are obliged to disclose under the Information Technology Act, 2000, the Bharatiya Nagarik Suraksha Sanhita, or a valid order.
We do not sell personal data. We do not share your data with data brokers, and we do not permit any partner to re-use it for their own marketing.
14. Cross-border transfers
Our primary infrastructure is hosted in India. A limited number of processors — error monitoring, transactional email, and some publisher tournament systems — process data outside India. Under section 16 of the DPDP Act we transfer personal data only to countries not restricted by the Central Government by notification, and only under contractual safeguards that impose the same standards of confidentiality, security and purpose limitation that apply here.
If the Central Government restricts a country to which one of our processors transfers data, we will migrate or terminate that processing and update this policy.
15. How long we keep data
We keep personal data only for as long as the purpose lasts, and then delete or irreversibly anonymise it. In practice:
Retention periods applied by eSportzCraazy to each category of personal data
| Data |
Retention |
Why |
| Raw IP logs | 30 days | Security and abuse investigation |
| Analytics events | 13 months | Season-on-season comparison |
| Live chat messages | 90 days | Moderation, reports and appeals |
| Anti-cheat telemetry | 180 days | Integrity review window |
| Match results, standings and ladder history | Indefinite | Permanent competitive record |
| Open account | While active | Running your account |
| Closed account | 30 days | Recoverable window, then erased |
| Support and enquiry records | 24 months | Repeat-issue handling |
| Competitive ban records | 5 years | Recognising repeat offenders |
| Invoices, GST records, prize and TDS evidence | 8 years | Mandatory under tax law |
Anonymised aggregate statistics — for example "63 per cent of BGMI entrants play on a sub-₹20,000 handset" — are not personal data and may be kept indefinitely.
16. Security and breach notification
We apply reasonable security safeguards as required by section 8(5) of the DPDP Act and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011: TLS on every connection, passwords stored only as salted hashes, role-based access limited to staff who need it, separate production and test environments, encrypted backups, logged administrative access, annual access reviews and vulnerability testing before each season opens.
No system is perfectly secure. If a personal data breach occurs, we will notify the Data Protection Board of India and every affected Data Principal without delay in the form and manner prescribed under the DPDP Act and its rules, and we will separately report the incident to CERT-In within six hours of becoming aware of it, as required by the CERT-In Directions of 28 April 2022. Our notice to you will describe what happened, the categories of data involved, the likely consequences, what we have done, and what you should do — for example changing a reused password.
Please help us: use a unique password, turn on two-factor authentication in Account → Security, and never share your account with a teammate. Account sharing is also a competitive-integrity offence under our Terms.
17. Your rights as a Data Principal
Under Chapter III of the DPDP Act you have the right to:
- Access — obtain a summary of the personal data we hold about you, how it is processed, and the identities of the other Data Fiduciaries and processors it has been shared with.
- Correction and completion — have inaccurate or misleading data corrected, incomplete data completed, and outdated data updated.
- Erasure — have your data erased where it is no longer needed for the purpose it was collected for and no law requires us to keep it.
- Withdraw consent — as easily as you gave it, at any time.
- Nominate — nominate another individual to exercise your rights in the event of your death or incapacity.
- Grievance redressal — a readily available mechanism, set out in section 18.
How to exercise them. Most of it is self-service: Account → Privacy & Consent lets you download your data, correct your profile, manage consents and request deletion. For anything else, email the Grievance Officer from the address registered on your account, stating the right you are exercising. We may ask a security question to confirm it is really you — we will never ask for your password or a payment credential to verify identity.
We respond to rights requests within 30 days and never charge for the first request in any 12-month period. If you are not satisfied with our response, you may complain to the Data Protection Board of India. Please note that filing a false or frivolous complaint may attract a penalty under the DPDP Act.
18. Grievance Officer and complaints
In accordance with section 13 of the DPDP Act, 2023 and Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the following officer handles privacy grievances, data-rights requests and complaints about content on this platform.
Grievance Officer & Data Protection Contact
- Officer: The Grievance Officer, eSportzCraazy — the named individual holding this office must be inserted here before this policy is published.
- Company: Catalyst Web Trendz Pvt. Ltd.
- Address: D 29, 2nd Floor, Greater Kailash Enclave 2, Greater Kailash, New Delhi – 110048
- Email: info@catalystwebtrendz.com
- Phone / WhatsApp: +91-9953590779 · wa.me/919953590779
- Hours: Monday–Friday, 10:00 AM – 7:00 PM IST
Timelines we commit to
- We acknowledge every complaint within 24 hours of receipt and issue you a ticket reference.
- We resolve the complaint and communicate the outcome within 15 days of receipt.
- Requests to remove content that exposes a person in an intimate or impersonated form are actioned within 24 hours, as the Intermediary Guidelines require.
- Data-rights requests under section 17 are answered within 30 days.
If you remain dissatisfied, you may escalate to the Grievance Appellate Committee constituted under the Intermediary Guidelines, or to the Data Protection Board of India for data-protection matters.
19. Changes to this policy
We update this policy when the law changes, when we add a feature that processes data differently, or when a processor changes. The version number and the "last updated" date at the top of this page always reflect the current text. Material changes — a new purpose, a new category of recipient, a change to retention — are announced by email to registered accounts and by a banner on the site at least 7 days before they take effect, and where the change requires it we will ask for fresh consent.
Superseded versions are archived and a copy of any earlier version can be requested from the Grievance Officer.