Skip to content

Privacy Policy

Effective date: June 14, 2026Last revised: July 26, 2026

This policy explains how Diffy eSports LLC (“Diffy,” “we,” “us”) collects, uses, shares, and protects your information on diffy.gg. It covers the handful of things you can do here: browse the site, apply to become a Diffy player, buy merch, or back a player by contributing to the Player Development Fund (our “Services”). There are no accounts or logins.

One thing this policy does not cover: if you apply and are accepted as a player, your actual development (the coaching, sessions, and support) happens off the website under a separate player agreement, which has its own privacy terms. This privacy policy is about the website and Services only.

To reach our privacy desk about anything on this page, email privacy@diffy.gg.

1. What we collect and why

We collect only what we need for the activities below (GDPR Art. 13/14):

  • When you apply to become a player: your email, optional Discord handle, public gamer tag, optional pronouns, main game, age range, optional social and streaming channels (with follower counts), and the free-text answers and links you submit. For an applicant under 18, we also require a parent or guardian attestation. The legal bases are your consent and our legitimate interest in reviewing applications.
  • When you pay (application fee or a contribution): your name, email, and card details, collected by Stripe on its hosted checkout (your card details go to Stripe, not to us). The legal basis is performance of a contract.
  • When you buy merch: your name, email, card details, and shipping address. Checkout and payment run on Shopify’s hosted checkout (your information goes to Shopify, not to us); your shipping details are then also shared with our fulfillment provider to ship the order. The legal basis is performance of a contract.
  • When you back a player (contribute to the Player Development Fund): your email, your country or region, how you’d like to appear on the Boost Board (a display name or “Anonymous”), and an optional company name (for an invoice). At Gold tier and above we also require a Discord username, so we can add you to your player’s private channel. The legal basis is performance of a contract and your consent.
  • When you browse: your IP address and device information reach our host and, only if something breaks, our error monitor. Analytics runs only after you accept analytics cookies. The legal basis is legitimate interest (security and operation) and, for analytics, your consent.

We do not collect more than this. Notably, the application form does not collect legal name, postal address, phone number, birthdate, school, or photo. We use the information only for the purposes above, and we do not send marketing email — every message we send is service-related, such as a parent or guardian notice, your welcome package, or a data-rights confirmation. We do not use it for automated decision-making that produces legal or similarly significant effects; a person, not an automated system, makes the decision on your application. We collect all of it directly from you, not from data brokers or other outside sources.

Providing this information is voluntary. If you leave out information a form marks as required, the desired Services cannot be performed — the application or purchase cannot go ahead.

2. Who we share your information with

To provide the Services, we rely on a few outside companies (“processors”). Each processor receives only what it needs to do its job, acts on our instructions, and is not permitted to use your information for its own purposes.

What it doesToolWhat is shared, and when
Payment processingStripeYour name, email, and card details on Stripe’s hosted checkout when you pay an application fee or contribute. Stripe collects card details directly through its own secure form; we never see or store the card number.
Storefront and fulfillmentShopifyBrowsing the shop sends your IP address to Shopify’s CDN. If you buy merch, checkout and payment run on Shopify (your card goes to Shopify’s checkout, not to us), and your name, email, and shipping address are passed to our print-and-ship fulfillment provider to ship the order. We will name that provider here once merch shipping is live.
Application and contribution databaseSanityStored here for our team to review: a player application (your answers, the links you submit, and, for an under-18 applicant, the parent or guardian attestation) or a contribution (a backer’s contact and listing details). Separately, images and video that Diffy hosts in Sanity are served from its content CDN, so your IP address and device reach it when you browse the site.
Hosting and serverlessNetlifyEvery request to the site and all stored data passes through Netlify, which serves the pages and runs the forms. It supplies the connection details of anyone using the site.
Error monitoringSentryReceives a technical error report only when something breaks. It carries the error details plus your browser and device type, and (like any site you load) it can include your IP address. We do not include request headers, cookies, the request body, or any name or account details, and we keep only what we need to fix the problem.
Rate-limiting and anti-abuseUpstashYour IP address is checked against a request-rate limit when you call the site’s API endpoints, to block abuse.
Link checkingAutomated link checkersWhen you submit a gameplay or profile link, the link itself is sent to outside services that confirm it is public and working. Only the link is sent, never your name or email.
Site analytics(only after consent)Google Analytics 4Runs only if you accept analytics cookies. It then sets the _ga and _ga_* cookies and reports your IP address, device, and page navigation. If you decline, nothing is sent.
Embedded videoYouTubeA privacy-enhanced (no-cookie) player. Browsing a page with a video sets no YouTube cookies; only clicking play loads the player and its cookies.
Email correspondenceGoogle Workspace (Gmail)We use email to send the parent or guardian notice, the welcome package, data-rights confirmations, and post-review correspondence. The site sends no confirmation email when you apply. Your confirmation is the Stripe receipt and the on-site confirmation page.
  • Our fonts are served from our own site (self-hosted); no font data is sent to Google.
  • We use no advertising trackers and no analytics tool other than Google Analytics 4.
  • We do not sell or share your personal information for cross-context behavioral advertising (tracking you across other sites and apps to target ads).

Beyond the website, once you are accepted, the program itself — coaching (including recorded sessions), scheduling, signed agreements, payouts, the community, and program-materials delivery — runs off-site under a separate participation agreement. With your consent, we may also share your highlights and progress with Player Development Fund contributors and publish them on Diffy’s own channels. The participation agreement discloses the specific tools used and the consents that apply.

One off-site processor is named here, because it holds access to a player’s own accounts rather than a copy of a file. Ayrshare, operated by Neverminds Solution, LLC in the United States, publishes to a player’s social channels on our instructions: it holds the connection to each channel the player links, receives the media and captions we publish for them, and keeps the resulting post history and channel status. We connect a channel only with the player’s agreement and, for a player under 18, their parent’s or guardian’s as well. Because Ayrshare holds those connections and we keep no copy of them, a player, parent, or guardian can ask our privacy desk to unlink a single channel or delete the whole profile. Ayrshare acts as our processor under a data-processing agreement that forms part of its terms, and that agreement names the eight sub-processors it uses.

3. International data transfers

Diffy and most of the processors above are in the United States. When you are in the EU or the UK, the personal data you give us is transferred to the United States, a country outside the EEA and the UK.

Where the law requires a safeguard for that transfer, we rely on the European Commission’s Standard Contractual Clauses with our processors (and, for the UK, the UK International Data Transfer Addendum or the equivalent UK safeguard). You can ask us for a copy of the relevant safeguard by emailing privacy@diffy.gg.

4. How long we keep your information

We keep personal data only as long as we need it, unless the law requires us to keep it longer. When a retention period ends, we securely delete the data or anonymize it — replacing the identifying parts with a one-way hash, so the business record survives but no one’s identity is exposed. Some content you agreed to publish — a player’s profile, a contributor’s quote — is different: we keep it while your consent to publish stands and remove it when you revoke that consent, as the published-profiles row below explains. We never delete financial records the law requires us to keep. The table below is generated from our retention manifest and reflects how long we actually keep each kind of data.

Kind of dataHow long we keep itThenLegal basis
Active applications and paid contributionsThe email and Discord handle on an application or a Player Development Fund contribution.Kept readable for 1 year after your time with Diffy ends.After that, the email and handle are replaced with a one-way hash; the game, tier, and timestamps are kept.Contract and legitimate interest (refunds, returning customers, disputes).
Children’s data (applicants under 18)A minor applicant’s own email and Discord handle, escalated to a tighter window.Kept while you’re active. A player still active at 18 moves onto the adult basis and is never hashed on their birthday. Once you leave, hashed at the earliest of your departure or the day you turn 18.The email and handle are replaced with a one-way hash; the game, tier, and timestamps are kept, the same as an adult applicant’s.GDPR Art. 8, COPPA, and the UK Children’s Code.
Rejected or unpaid applications (adults)Applications that did not proceed, kept for re-application context and fraud detection.Kept readable for 3 years from the rejection date.After 3 years, identifiers are hashed; aggregate fields are kept.Legitimate interest (re-application context, fraud-pattern detection).
Rejected applications (under 18)Under-18 applications that did not proceed, with a shorter window than the adult one.Kept for 90 days from the rejection date.After 90 days, identifiers are hashed; aggregate fields are kept.GDPR Art. 8, COPPA, and the UK Children’s Code.
Payment recordsStripe transaction records: customer ID, amount, currency, tax, and line items.Numeric and tax fields kept for 7 years; identifying fields hashed after 1 year.We never delete financial records the law requires us to keep; identifying parts are hashed first.Legal obligation (US tax / IRS 7-year retention).
Consent records and published profilesCookie-consent and opt-in records, plus the published showcase content people agreed to make public — a player’s profile (gamer tag, avatar, stats, quote, bio, links) and a contributor’s chosen Boost Board name or testimonial quote.Cookie-consent and opt-in records are kept up to 3 years after consent is withdrawn or expires. Published profiles and contributor quotes are kept for as long as you give us consent to publish them.Cookie-consent and opt-in records are deleted or anonymized at the 3-year mark. Published showcase content is removed when you revoke your consent (email privacy@diffy.gg). A former player who was a minor while with Diffy has their published profile removed no later than their 18th birthday; a player who is still active at 18 continues on our adult basis. We do not anonymize published showcase content on a timer.Your consent and agreement to publish (for showcase content); legitimate interest in the defensibility of the consent record itself.

For young players, retention follows their age. A minor who leaves the program before turning 18 has their own identifiers removed at that point. A player who is still active when they turn 18 moves onto our standard adult basis — we don’t delete an active player’s account on their birthday. Details shown on a published profile stay only while that profile is published, and come down when the profile does or when you ask us to remove it.

5. Children’s privacy

The only place we collect personal data about people under 18 is the player application. We treat it more carefully than adult personal data, in compliance with the EU/UK GDPR Art. 8, the US Children’s Online Privacy Protection Act (COPPA), and the UK Children’s Code (Age-Appropriate Design Code).

Falsifying an applicant’s age is prohibited and will result in immediate termination of the application.

  • Parental consent at collection. An application for an applicant under 18 must be completed, submitted, and paid for by a parent or legal guardian, who confirms this in a binding attestation. That card payment is our verifiable parental consent. For children under 13 it satisfies COPPA’s ‘monetary transaction’ verifiable-parental-consent method (16 CFR §312.5(b)(2)); we apply the same standard to every applicant under 18. We cannot accept an under-18 application without it.
  • What we collect from a child. The applicant’s email (the parent or guardian’s, or the player’s, as applicable), Discord handle (optional), public gamer tag, age range, and the answers and links they submit. We do not collect a child’s legal name, address, phone number, birthdate, school, or photo. The parent or guardian contact is the email used to pay the application fee on Stripe; we do not store a separate parent or guardian email.
  • Discord and age. Discord sets its own minimum age, which varies by country. A Discord handle is optional, and a player under the Discord age requirement for their country is never added to Discord under their own account. Any Discord contact for an underage player is through a parent or guardian’s own account.
  • Where a child’s data goes. A minor applicant’s submitted handle or links may be sent to the outside link-checking services to confirm a link is public and working (only the link, never a name or email). A minor’s IP and device reach our host always, and our error monitor only if something breaks; analytics runs only after analytics cookies are accepted.
  • Shorter retention. A minor applicant’s own identifiers are removed when their time with Diffy ends, or when they turn 18 if they leave before then; a player who is still active at 18 moves onto our adult basis. A rejected under-18 application is kept only 90 days.
  • Parental rights. A parent or guardian can review, delete, or refuse further collection of their child’s information at any time using the request form below (submitting the email they paid with) or by emailing privacy@diffy.gg. We never use a child’s information for marketing or re-engagement.

6. Your US state privacy rights

California (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect, to access and delete it, to correct it, and to limit the use of sensitive personal information. We do not collect sensitive personal information (as the CPRA defines it) through this website. You can exercise these rights using the request form below or by emailing privacy@diffy.gg. We will not discriminate against you for exercising them.

  • Do Not Sell or Share My Personal Information. We do not sell your personal information and we do not share it for cross-context behavioral advertising, so there is nothing to opt out of, but we honor the Global Privacy Control signal all the same (see below).
  • Categories we collect (12-month look-back). In CCPA terms, the personal information we collected, used, and disclosed in the prior 12 months falls into these categories: identifiers (name, email, Discord handle); internet or network activity (IP address and device and usage data; analytics only after you accept analytics cookies); commercial information (your purchases and contributions); financial information (payment-card data, collected by Stripe — we never store it); geolocation (your country or region, coarse only); and a protected classification (the age range you select). We disclose these only to the processors named above, for the business purposes described — we do not sell or share any of them, and we disclose them for no other purpose.
  • Financial incentives. We offer no financial incentive or price/service difference in exchange for your personal information.

If you live in another US state with a privacy law — such as Virginia, Colorado, Connecticut, Utah, Texas, or Oregon — you have these same core rights. Rather than track each state separately, we extend the full set of rights described in “Your rights and how to use them” below to everyone, wherever you live. If we decline a request, our decision email will explain your options, including any right to appeal or to contact your state Attorney General.

7. Global Privacy Control (GPC)

We honor the Global Privacy Control (GPC) signal. Because analytics on this site is strictly opt-in (Google Analytics loads only after you accept analytics cookies), a GPC signal means no analytics and no sale or sharing of your personal information unless you separately opt in. We do not sell or share personal information for cross-context behavioral advertising in any case.

8. Cookies and similar technologies

We use a small set of cookies and local-storage items. Analytics cookies load only after you accept them; you can change your choices any time on the cookie preferences page. The full list below is generated from our cookie inventory.

NameProviderPurposeDurationConsent
_gaGoogle AnalyticsHelps us count visitors without knowing who they are.2 yearsRequired
_ga_*Google AnalyticsHelps Google Analytics keep track of a single visit.2 yearsRequired
consent_stateDiffy (first-party)Remembers your cookie choice so we don’t ask again.1 yearNot required
cookie-consentDiffy (first-party)A second copy of your cookie choice, so every page applies it right away.1 yearNot required
cookie-consent-expDiffy (first-party)Remembers when your cookie choice expires, so we re-ask for consent about once a year.1 yearNot required
form-progress-*Diffy (first-party)Saves your partially completed application on this device, only if you turn on Save my progress.30 daysRequired
form-save-opt-in-*Diffy (first-party)Remembers whether you turned on Save my progress for a form.Until clearedNot required
shopify-cart-idDiffy (first-party)Remembers what’s in your shopping cart as you move around the site.30 daysNot required

9. Your rights and how to use them

Wherever you live, you can ask us for a copy of the personal data we hold about you, or request that we delete your personal data. We respond within 30 days of a request. For an unusually complex or high-volume request we may take longer where the law allows, and we’ll tell you why within the first 30 days. To protect your data, we confirm your identity by sending a one-time link to the email address you give us below. No action happens until you verify your identity. We answer the same way whether or not we hold any data for an address, so this form cannot be used to discover who has an account with us.

A parent or guardian acting for a child under 18 uses the same form with the email they paid the application fee with. Some records (payment records the law requires us to keep, and anything under an active legal hold) are retained even after a deletion request; we will tell you what we kept and why.

What would you like to do?

If the form is unavailable, or you would rather not use it, email privacy@diffy.gg and we will process your request manually within the same 30 days.

Your rights in detail

We extend the following rights to everyone, wherever you live. “Delete my data” on the form above is your right to erasure, and “Download my data” is your right to data portability; for the rest, email privacy@diffy.gg and we will handle your request within the same 30 days. The legal bases for our processing are described in “What we collect and why” above. You can:

  • Access: ask for a copy of the personal data we hold about you and how we use it (Art. 15).
  • Rectification: ask us to correct personal data that is wrong or incomplete (Art. 16).
  • Erasure: ask us to delete your personal data, via the “Delete my data” option on the form below (Art. 17).
  • Restriction: ask us to pause our use of your data while a question about it is resolved (Art. 18).
  • Portability: ask for a copy of the data you gave us in a portable format, via the “Download my data” option on the form below (Art. 20).
  • Objection: object to our use of your data where we rely on legitimate interest, and we will stop unless we have an overriding reason not to (Art. 21).
  • Withdraw consent: withdraw consent at any time where we rely on it (such as analytics cookies); this does not affect anything we did before you withdrew it.

If you are in the EU or the UK, you also have the right to lodge a complaint with your local data-protection supervisory authority. In the UK, that authority is the Information Commissioner’s Office (ICO). We would, of course, welcome the chance to address your concern first. Related provisions for EU and UK residents also appear in the International data transfers and EU and UK representative sections.

10. EU and UK representative

If you are in the EU or UK, GDPR Article 27 can require us to name a local representative you and regulators can contact about your data. We’ve appointed one for both the EU and the UK.

We’ve appointed Prighter Group, with its local partners, as our representative for both the European Union and the United Kingdom under Article 27 of the GDPR and Article 27 of the UK GDPR. If you’re in the EU or the UK, you can contact our representative — or raise a concern about how we handle your data — through the Prighter portal at app.prighter.com/portal/diffy. You can also reach our privacy desk directly at privacy@diffy.gg.

11. How we protect your information

We protect personal data with encryption in transit and at rest, strict access controls, a one-way hash for anonymized records, and short, encrypted backups. No system is perfectly secure, but we work to keep your information safe and to limit how long we hold it.

13. Changes to this policy

We may update this policy as the website changes. When we do, we revise the “Last revised” date above and, for material changes, give prominent notice on this page before they take effect — and, where the law requires, seek your consent before the change applies.

14. Contact us

For any privacy question or to exercise a right, email privacy@diffy.gg. Diffy eSports LLC is the controller of the personal data described in this policy.