← Beydeck

Trust & Privacy

This page is maintained by Defined Ops, the team behind Beydeck, to answer common security and privacy questions about the app. It describes app-visible controls and current practices — it is editable project content, not an independent certification.

Shared responsibility. Beydeck runs on the Lovable platform, which provides hosting, the authentication service, and the managed Postgres database. Defined Ops, as the app owner, is responsible for the app's data handling, configuration, and operational practices described below. You (the user) are responsible for protecting your account credentials and the information you choose to enter into the app.

Access & authentication

  • Accounts are created through Beydeck's sign-in page (email/password or Google).
  • Sessions are managed by the platform's authentication service; passwords are never stored by Beydeck directly.
  • App functionality is gated by role — blader, judge, organizer, event staff — and enforced server-side on every request, not only in the UI.
  • Tournament organizers can invite judges and event staff; only they can promote other users into staff roles.

What data we collect

Beydeck collects only what's needed to run a tournament:

  • Account: email, display name, optional Beyblade handle.
  • Tournament activity: registrations, check-in state, match results, combos you submit, and badges you earn.
  • Optional uploads: photos of Beyblade parts you contribute to the shared catalog.
  • Contact form submissions: name, email, organization, and message when you reach out to us.

We do not sell your personal data. We do not run advertising on Beydeck.

How your data is protected

  • Database access is restricted by row-level security so a user can only read or change rows they're entitled to.
  • Privileged actions (recording match results, creating tournaments, editing the parts catalog) are restricted to the assigned judge, organizer, or event staff role.
  • Uploaded part photos live in a private storage bucket and are served through short-lived signed URLs.
  • Traffic between your browser and Beydeck is encrypted in transit (HTTPS).

Subprocessors & integrations

Beydeck relies on a small set of service providers:

  • Lovable — application hosting, authentication, managed Postgres database, and file storage.
  • Google — optional sign-in provider, if you choose to use it.
  • Stripe — payment processing for paid tournament tiers. Card details are entered directly into Stripe's hosted checkout and are never stored by Beydeck.
  • MailerLite — early-access waitlist email delivery.

Retention, deletion & your data

  • Tournament records (matches, results, standings) are retained so completed events remain viewable in history.
  • You can edit your profile from your dashboard at any time.
  • To request account deletion or a copy of your data, email the address below. We will respond within a reasonable timeframe.

Contact, incidents & vulnerability reports

For privacy requests, account deletion, or to report a security issue you've found in Beydeck, email hello@definedops.com. Please include enough detail for us to reproduce the issue and avoid testing against other users' data.

Compliance

Beydeck is an independent product currently in beta. It is not certified against SOC 2, ISO 27001, HIPAA, PCI DSS, or any other compliance framework, and this page should not be read as a statement of compliance. For questions about specific regulatory requirements before running a large event, please contact us.

This page describes Beydeck's current app-visible controls and may be updated as the product evolves. Last reviewed by the Beydeck team.