Privacy Policy for D1 Arena
Last Updated: January 19, 2026
SKILL-BASED ESPORTS PLATFORM - PRIVACY COMMITMENT
D1 Arena is a skill-based esports competition platform operating under Texas Penal Code §47.01. We are committed to protecting your privacy while providing legitimate skill-based tournament services.
Introduction
This Privacy Policy explains how we collect, use, and protect your data in compliance with:
- TDPSA - Texas Data Privacy and Security Act
- COPPA - Childrens Online Privacy Protection Act
- IRS Tax Reporting Requirements - Form 1099-K for payment processors
- Phone Number: For SMS verification and two-factor authentication
- Geographic Location: Country, state, and city for compliance with regional regulations and tournament eligibility
- Stream Key: Unique identifier for streaming authentication (encrypted and never shared)
- Known Locations: Trusted login locations for security verification
Information We Collect
Account Information
- Personal Info: Name, email, date of birth, contact details
- Account Credentials: Username and password (password stored using industry-standard hashing)
- Profile Data: Avatar, bio, social links, gaming preferences
Two-Factor Authentication (2FA) Data
- Authentication App: TOTP secret key (encrypted, used to generate verification codes)
- Recovery Codes: One-time backup codes (hashed and stored securely)
- 2FA Status: Whether 2FA is enabled on your account
- Authentication Logs: Timestamps of successful/failed 2FA attempts for security monitoring
Identity Verification Data
For users accessing wallet/payout features, identity verification is handled securely through Stripe Connect Express:
- Stripe Identity Verification: Government-issued ID (passport, driver's license, or state ID) is verified directly through Stripe's secure hosted flow - D1 Arena never stores your ID documents
- Selfie Verification: Photo matching is performed by Stripe during onboarding - deleted after verification
- Address Verification: Verified through Stripe's KYC process
- Verification Status: Synced from Stripe - pending, verified, or requires additional information
Important: All identity documents are submitted directly to Stripe through their secure, PCI-compliant hosted onboarding flow. D1 Arena does not receive, process, or store copies of your identity documents.
Tax Compliance Data (IRS Requirements)
For users receiving payouts, tax information is collected and managed securely through Stripe Connect Express:
- Social Security Number (SSN): Collected directly by Stripe during onboarding - D1 Arena never receives or stores your full SSN
- Tax Identification Number (TIN/EIN): For business entities, collected by Stripe
- W-9/W-8BEN Forms: Stripe collects and validates all required tax forms electronically
- 1099-K Tax Reporting: Stripe automatically generates and files 1099-K forms with the IRS for qualifying payouts
SSN/TIN Security: Your Social Security Number is collected and stored exclusively by Stripe in their PCI-DSS Level 1 compliant infrastructure. D1 Arena does not receive, store, or have access to your full SSN. Stripe handles all IRS tax reporting on your behalf, including Form 1099-K generation and filing.
Wallet & Financial Data
- Wallet PIN: 6-digit security PIN (hashed, never stored in plain text)
- Payment Info: Stripe Connect account ID
- Transaction History: Deposits, withdrawals, tournament winnings, subscription payments
- Payout Methods: Bank account details for ACH transfers (encrypted)
Tips & Donations Data
- Tip Transactions: Amount, recipient (streamer/team), timestamp, and payment method
- Tip Messages: Optional messages attached to tips (up to 200 characters)
- Display Preferences: Whether you chose to show or hide your name on tips
- Team Tip Splits: For team tips, records of how the tip was distributed among members
Platform Usage Data
- Membership Info: Subscription tier (Starter, PRO, or Ultimate) and billing history
- Usage Data: Game stats, preferences, tournament history
- Device Info: IP address, browser, operating system
- Streaming Data: VOD recordings, clips, stream analytics
- Stream Screenshots: Frames captured from live streams for game detection (processed in real-time, not stored)
- Clip Video Frames: Strategic frames extracted from clips for visual analysis and title generation
- Chat Context: Recent chat messages around clip creation time for context-aware titles
- User Corrections: When you edit AI-generated titles, we track the correction to improve future AI outputs
- Engagement Metrics: Views and interactions with AI-generated content to optimize suggestions
- AI Provider: AI processing is performed using xAI (Grok) API
- Data Sent: Only content data (images, text) is sent to AI services - no personal information, account details, or identifying data
- Data Retention: AI providers process data in real-time and do not retain your content beyond the processing session
- No Training: Your content is not used to train AI models
- We track AI-generated vs. user-edited content to improve future AI outputs
- Successful AI titles (based on engagement) inform better suggestions
- User corrections help the system learn game-specific terminology and preferences
- All AI features are optional - you can choose not to use them
- AI-generated content is always editable and replaceable
- Discord User ID: Unique identifier from Discord
- Discord Username: Your Discord display name
- Discord Avatar: Your Discord profile picture URL
- Discord Email: Email associated with your Discord account (if provided)
- OAuth Tokens: Encrypted access tokens for sending you notifications (never shared)
- Under 13: NOT permitted. We do NOT knowingly collect data from children under 13 (COPPA compliance)
- Ages 13-17: Parental/guardian consent required. Age-appropriate content only. Cannot access wallet features or receive payouts.
- Ages 18+: Full access to all tournaments, wallet features, and payouts (with identity verification)
- Account Security: 2FA verification, login protection, fraud prevention
- Identity Verification: Confirming user identity for wallet access and payouts
- Tax Compliance: IRS Form 1099-K reporting for payment processors
- Tournament Management: Registration, matchmaking, results
- Tip Processing: Processing tips to streamers and teams, calculating fee splits, and crediting wallets
- Tip Notifications: Notifying streamers of incoming tips and showing tip alerts during streams
- Prize Distribution: Secure payment processing to verified accounts
- Membership Services: Managing your Starter, PRO, or Ultimate subscription
- Communication: Updates, support, security alerts, notifications
- Legal Compliance: Texas law and skill-based competition verification
- Platform Improvement: Analytics and feature development
- Sell your personal information, including identity documents or SSN
- Rent your data to third parties
- Share data for marketing without consent
- Collect data from children under 13
- Store passwords, PINs, or 2FA recovery codes in plain text
- Display full SSN/TIN in any user interface (only last 4 digits shown)
- Stripe Connect Express: Primary payment processor - handles identity verification, SSN collection, tax form generation (1099-K), and payouts. Stripe is PCI-DSS Level 1 certified and SOC 2 compliant. View Stripe Privacy Policy
- Discord: When you link your Discord account, we use Discord's API to send you direct message notifications. We share only what's necessary to deliver notifications (your Discord User ID). View Discord Privacy Policy
- Note: All creator payouts are processed via Stripe Connect (as of January 2026).
- Tax Authorities: Stripe reports to the IRS on your behalf via Form 1099-K for qualifying payouts
- Legal Requirements: Court orders, law enforcement requests, subpoenas
- Platform Protection: Fraud prevention, terms enforcement
- SSL/TLS Encryption: All data encrypted in transit using TLS 1.3
- AES-256 Encryption: SSN, bank account numbers, and sensitive financial data encrypted at rest
- Password Hashing: Bcrypt with cost factor 12 for password storage
- PIN Security: Wallet PINs hashed using secure one-way algorithms
- 2FA Secrets: TOTP secrets encrypted, recovery codes hashed
- Role-Based Access: Limited personnel access to personal and financial data
- PII Access Logging: All access to sensitive data (SSN, ID documents) is logged and audited
- Admin 2FA Required: All administrative accounts require two-factor authentication
- Regular Audits: Security assessments and vulnerability testing
- PCI-DSS Compliance: Payment processing through compliant providers
- Secure Payments: We never store full credit card numbers
- Account Data: Retained while account is active, deleted upon request (subject to legal holds)
- Tax Records (SSN, W-9/W-8BEN): Stored and retained by Stripe per IRS requirements (7 years) - D1 Arena does not store this data
- Identity Documents: Processed by Stripe during verification - not stored by D1 Arena
- Stripe Connect Account: Your Stripe account persists independently; you can manage it via Stripe's dashboard
- Transaction History: Retained for 7 years for audit purposes; also available in your Stripe dashboard
- 2FA Data: Deleted immediately when 2FA is disabled or account is deleted
- Security Logs: Retained for 2 years for fraud prevention
- Chat Messages: Messages sent in stream chats are stored for moderation purposes and may be retained for up to 90 days
- Moderation Actions: Records of bans, timeouts, and warnings are retained for accountability
- Chat Filters: Custom banned word lists you create are stored to enforce your channel rules
- Commands Used: Chat commands (e.g., !ban, !poll, !predict) are logged for audit purposes
- Watch Time: We track time spent watching streams to award Channel Points
- Point Balances: Your Channel Points balance and transaction history are stored
- Reward Redemptions: Records of rewards you redeem are maintained
- Predictions & Polls: Your participation in predictions and polls is recorded
- Custom Emotes: Images you upload as channel emotes are stored on our servers
- Channel Panels: Panel content (images, text, links) you create is stored
- Stream Schedules: Your streaming schedule information is publicly displayed
- Raid/Host Logs: Records of raids and hosts you initiate or receive are logged
- Viewer Counts: Approximate viewer counts during raids are recorded
- StreamLabs/StreamElements: If you connect third-party alert services, they receive event data (new followers, subscribers, tips) according to their privacy policies
- Real-time Events: Follow, subscribe, and tip events are broadcast via WebSocket for alert integrations
- Access: View your personal data anytime via account settings
- Update: Correct inaccurate information (identity re-verification may be required)
- Delete: Request account and data deletion (subject to tax record retention requirements)
- Withdraw Consent: Opt out of optional data processing
- Portability: Request copy of your data in machine-readable format
- 2FA Management: Enable, disable, or reset 2FA at any time
- Security Alerts: Receive notifications of suspicious account activity
AI Data Processing
When you use AI-powered features, we process the following data:
Third-Party AI Services
AI Learning System
Discord Integration Data
When you connect your Discord account to D1 Arena:
Why We Collect This: To send you personalized direct message notifications about tournament reminders, match times, team invites, and prize payouts. You can disconnect your Discord account at any time from your Discord Settings page.
Age Requirements & Parental Consent
How We Use Your Data
Data Protection - We Do NOT
Data Sharing (Limited)
Security Measures
Encryption & Data Protection
Access Controls
Payment Security
Data Retention
Live Streaming & Chat Data
When you use our streaming and chat features, we collect and process the following data:
Chat Messages & Moderation
Channel Points & Engagement
Channel Customization
Raid & Host Activity
Data Sharing with Third Parties
Your Rights
Cookies & Tracking
We use essential cookies for Platform functionality including session management and 2FA verification. For detailed information, see our Cookie Policy. You can manage cookie preferences in your browser settings.
Third-Party Links
External links are not covered by this policy. Review third-party privacy policies separately.
Policy Updates
We may update this policy. Significant changes will be communicated via Platform notification or email. Material changes to how we handle SSN, identity documents, or 2FA data will require explicit re-consent.
Contact
Questions about privacy, identity verification, or data security? Contact us.
For data deletion requests or TDPSA rights: [email protected]
By using D1 Arena, you consent to this Privacy Policy and acknowledge our commitment to protecting your personal information, including identity documents and tax information, while operating a legitimate skill-based esports competition platform in compliance with Texas law.