Privacy Policy

Last updated: 18 June 2026

1. About this policy

TribePicks ("we", "us", "our") is operated by 11outof10 Pty Ltd. (ACN 637 629 219). This Privacy Policy explains how we collect, use, store and disclose your personal information when you use the TribePicksweb application (the "Service"). It is prepared in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

By registering for or using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.

2. Information we collect

We collect the following personal information when you register and use the Service:

  • Account information: email address, display name, password (stored as a one-way hash — we never store your plain-text password)
  • Profile information: country, timezone, favourite World Cup team, profile photo (optional)
  • Usage data: match predictions you submit, points earned, leaderboard rankings, tribe membership
  • Organisation data: the organisation you belong to, any tribe you join
  • Technical data: browser type, IP address, and session data collected automatically by our hosting and authentication provider

We do not collect payment card information directly. Payments (where applicable) are processed by a third-party payment processor and we receive only a payment reference.

3. How we use your information

We use the information we collect to:

  • Create and manage your account
  • Display your predictions, points and rankings on leaderboards visible to other players
  • Enable tribe and organisation features, including chat and announcements
  • Send transactional emails (account verification, password reset) — these are not marketing emails
  • Administer paid organisation subscriptions
  • Improve and maintain the Service
  • Comply with our legal obligations

We will not use your personal information for direct marketing without your explicit consent, and we will not sell your personal information to any third party.

4. Leaderboard visibility

Your display name, total points, and tribe/organisation name are visible to other registered users on the leaderboard. Your email address, country, timezone and favourite team are never displayed publicly. If you do not want your display name shown on leaderboards, you may delete your account at any time (see section 8).

5. Disclosure to third parties

We use the following third-party service providers who may process your data on our behalf:

  • Supabase Inc. — database, authentication and file storage. Data is stored on servers in the United States (or Australia if applicable). Supabase is SOC 2 Type II certified.
  • Vercel Inc. — web hosting and deployment. Servers are located in the United States.
  • Resend Inc. — transactional email delivery.
  • Google LLC — advertising via Google AdSense. Google may set cookies and use device identifiers to serve and measure ads (see section 6). Premium subscribers are not shown advertisements.

Prize draws & sponsors. Some challenges (such as the Bracket Challenge) are run with a sponsor who provides the prize. If you enter a sponsored challenge and tick the consent box, we share the entry details you provide — which may include your name, postcode, phone number and email — with that sponsor so they can administer the draw and may contact you about their products or services. Entering a sponsored challenge is optional, and you can ask us or the sponsor to stop contacting you at any time.

Other than the sponsor disclosure described above, we do not disclose your personal information to any other third parties except where required by Australian law or a court order.

By using the Service you acknowledge that your data may be transferred to and stored in countries outside Australia, including the United States, which may have different data protection laws. We take reasonable steps to ensure these providers handle your data securely.

6. Cookies and advertising

We use cookies and local storage to keep you signed in and manage your session. These are essential to the Service.

Parts of the Service display advertisements served by Google AdSense (a service of Google LLC). To deliver, measure and — where permitted — personalise these ads, Google and its partners may set and read cookies and similar device identifiers in your browser. This information is collected and processed by Google under its own privacy policy; we do not receive or store it.

  • You can review and control how Google uses data for ads, and opt out of personalised advertising, via Google Ad Center and Google's How Google uses information from sites that use its services.
  • If you are in the European Economic Area, the United Kingdom, or Switzerland, we present a Google-certified consent message before any non-essential or advertising cookies are set, and we honour your choice.
  • Premium subscribers are not shown advertisements.

Other than the advertising described above, we do not use third-party analytics or tracking pixels that identify individual users, and we do not sell your personal information.

7. Data retention

We retain your personal information for as long as your account is active. Prediction history and leaderboard data may be retained in aggregate (de-identified) form after account deletion to maintain historical tournament records. Identifiable data is deleted within 30 days of an account deletion request.

8. Your rights

Under the Australian Privacy Principles you have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate or out-of-date personal information
  • Delete your account and associated personal data
  • Complain about how we have handled your personal information

Delete your account

You can permanently delete your account and all associated personal data directly from the Settings page. This is immediate and cannot be undone. Your predictions, points, and tribe membership will be permanently removed from all leaderboards.

To exercise any other rights, or to make a complaint, contact us at privacy@tribepicks.com. We will respond within 30 days.

If you are not satisfied with our response to a complaint, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).

9. Security

We take reasonable steps to protect your personal information from misuse, loss, and unauthorised access. Measures include encrypted storage, hashed passwords, row-level security on all database tables, HTTPS-only access, and authentication via industry-standard JWT tokens. No internet transmission is completely secure, however, and we cannot guarantee the security of information transmitted to the Service.

10. Children

The Service is not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us immediately at privacy@tribepicks.com.

11. Changes to this policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes by email or by a prominent notice on the Service. The "Last updated" date at the top of this page will always reflect the most recent version. Continued use of the Service after changes are posted constitutes acceptance of the updated policy.

12. Contact us

For any privacy-related questions, access requests, or complaints, contact us at:

11outof10 Pty Ltd. (ACN 637 629 219)

Email: privacy@tribepicks.com

This privacy policy was prepared with reference to the Privacy Act 1988 (Cth) and the Australian Privacy Principles. TribePicks is an unofficial fan competition and is not affiliated with or endorsed by FIFA, the FIFA World Cup™, or any associated national football federation.