Operator and data
Tokyo Metropolitan League (TML) staff process TML User ID; Roblox User ID, username, display name and public avatar; Discord User ID, username, display name and public avatar; team, position, league role, link status, permissions, sessions, match records and audit history. We do not collect your Roblox or Discord password.
Purposes
We use data for identity verification, account linking, roster and participant management, match operations, published statistics and abuse prevention. For linked Discord accounts, we check club roles and reflect membership in the site roster. Discord roles do not grant system administration permissions. Checks occur when pages or commands are accessed, so changes may take time to appear.
Visibility and providers
Player profiles, public Roblox information, club, position, league role and match statistics are public. Discord IDs and sessions are excluded from public profiles. Sites and its infrastructure providers host the service and data. Sign-in communicates with Roblox or Discord. We do not sell personal data.
Retention and unlinking
Linked identity data is retained until unlinking or account deletion. Sessions expire within seven days and authentication flows within ten minutes. Unlink through Account. The last sign-in provider cannot be unlinked; delete the account instead.
Deletion and retained records
Account deletion removes provider IDs, names, avatars, membership settings, sessions and grants. Internal IDs and match statistics remain to preserve competition history; audit records remain with personal fields removed. Historic public information may still allow identification; this is not a guarantee of complete anonymization. Contact staff for deletion requests or questions about retained history.
Protection
We use a server-side database, HttpOnly cookies, authorization checks and OAuth state validation. OAuth secrets are not published. Sign out on shared devices. Changes to this policy are published here.
