Privacy notice (POPIA)
Responsible party: Stolen Youth Organization (Pty) Ltd (2023/589555/07), South Africa. Information officer: privacy@stolenyouth.co.za. Last updated 9 October 2026.
Draft pending legal review.
What we collect
Account: email, handle, display name, date of birth, main platform, province and city (optional), avatar, bio, favourite games, social handles (optional), and sign-in records.
Gaming: the gaming IDs you link (PSN, Xbox, EA, Steam, etc.), match reports, result screenshots, and the statistics we derive from them.
Payments and payouts: wallet transactions; for withdrawals, your legal name, a one-way hash of your ID or passport number (we never store the number itself), ID document and selfie photos, and your bank account. Account numbers are encrypted (AES-256) and only the last 4 digits are shown.
Why we use it
To run tournaments and match you with opponents, verify results (including automated and AI checks of your screenshots), prevent fraud and enforce fair play, pay prizes, meet legal obligations (including FICA-style identity checks and tax records), and, if you opt in, send you tournament news.
Who we share it with
Your opponents see your handle and linked gaming IDs so you can play. Your public profile shows your handle, avatar, stats and anything you add to it. We use service providers to run the platform: PayFast (deposits), Anthropic (AI screenshot checks; images are sent for analysis and not used to train models), our hosting and email providers, and SY-IAM for Stolen Youth staff sign-in. We share information with authorities only where the law requires it.
How long we keep it
Account and match data while your account is open. Financial and identity-verification records for 5 years after your last transaction, as required by law. Screenshots for 12 months after the tournament ends unless they're needed for a dispute.
Your rights
You can ask to access, correct or delete your personal information, object to processing, or withdraw marketing consent, by emailing our information officer. You may also complain to the Information Regulator (inforegulator.org.za).
Security
Passwords are hashed, sensitive identifiers are hashed or encrypted, staff access to identity documents and bank details is restricted and logged, and all traffic uses HTTPS.