← RISE 11

Data protection

Privacy Notice

This Notice explains, in plain language, how RISE 11 handles personal data across player, guardian, professional, organization, messaging, scouting, safety, web, and mobile services.

Effective
1 September 2026
Published version
2026-09-01

1. Who is responsible

MerchNique Technologies Private Limited, Bhagat Singh Marg, Durgapur, West Bengal, India, operates RISE 11 and is the data fiduciary or controller for the processing described here. In some organization workspaces, a club, academy, or scouting organization may also determine why it creates reports, assessments, rosters, or other professional records and may have its own privacy responsibilities.

Privacy questions and rights requests can be sent to privacy@merchnique.com. Account support is available at support@merchnique.cloud.

2. Scope

This Notice applies to the RISE 11 website, installable web app, mobile app, APIs, email and push delivery, direct uploads, professional workspaces, and support and safety operations. It does not control an independent third-party site you visit or an organization's separate systems.

3. Personal data we handle

  • Account and identity: name, email, password hash, date of birth, age status, roles, verification status, account state, and policy acceptance.
  • Player and football profile: public name, location at the precision you choose, playing position, dominant foot, physical and career details, team history, skills, achievements, XP, goals, and profile preferences.
  • Evidence and media: videos, thumbnails, captions, upload metadata, external video identifiers, processing and moderation states, and private verification evidence.
  • Professional and organization records: club, academy, coach and scout profiles; memberships; invitations; rosters; training attendance; match records; assessments; shortlists; pipelines; saved searches; reports; notes; commercial plan and entitlement state.
  • Social and communications: follows, likes, comments, shares, blocks, conversations, messages, attachments, read status, notifications, and communication preferences.
  • Guardian and child-safety records: guardian relationships, invitation status, consent scopes, revocation history, age transition state, safety restrictions, and related audit events.
  • Trust, safety, and compliance: reports, evidence references, moderation decisions, suspension reasons, appeals, professional verification decisions, administrator actions, and append-only audit records.
  • Security and device data: session and refresh-family identifiers, IP address, user agent, device and push-subscription data, login and lockout events, multi-factor state, recovery-code hashes, request identifiers, and security telemetry.
  • Service and diagnostics: bounded request and failure metrics, queue state, delivery outcomes, storage and processing state, backup status, and privacy-safe operational logs.
  • Support and rights requests: correspondence, request status, identity confirmation, data-export state, grievance details, and records needed to resolve the request.

We do not ask for full payment-card numbers. If paid services are added, an approved payment provider will process card details and RISE 11 will retain only necessary transaction, entitlement, invoice, tax, refund, or reconciliation records.

4. Where data comes from

Data comes from you; a guardian; an authorized club, academy, coach, scout, or organization member; other users who interact with you; devices and browsers used to access the service; service providers acting for us; and safety or legal authorities where permitted. We may derive visibility, eligibility, ranking, recommendation, risk, entitlement, achievement, and moderation state from these records.

5. Why we use personal data

  • create accounts, authenticate users, manage sessions, and recover access;
  • provide player profiles, discovery, development, teams, evidence media, scouting, messaging, and organization features;
  • apply age, role, guardian, block, privacy, membership, and entitlement controls;
  • verify professionals and organizations and protect the integrity of sporting records;
  • deliver essential security, account, invitation, operational, and preference-based notifications;
  • detect abuse, fraud, grooming, illegal content, account compromise, and service attacks;
  • investigate reports, enforce policies, preserve evidence, and respond to emergencies or lawful requests;
  • operate backups, disaster recovery, monitoring, diagnostics, support, and service improvement;
  • maintain legal acceptance, audit, accounting, grievance, and compliance records; and
  • respond to access, correction, erasure, export, deactivation, appeal, and grievance requests.

6. Legal grounds

Depending on the feature and applicable law, we process data to perform our service agreement; with specific consent; for legitimate uses or legitimate interests such as service security, safeguarding, fraud prevention, and improvement; to comply with legal obligations; to protect vital interests; and to establish, exercise, or defend legal claims.

Where processing depends on consent, you may withdraw it through the relevant control or by contacting us. Withdrawal does not make earlier processing unlawful and may disable features that require the data.

7. Children and guardian controls

RISE 11 uses date of birth and server-enforced age state to restrict professional roles and sensitive discovery, media, messaging, challenge, and quest features. Where required, a verified adult guardian controls separate participation, public-profile, public-media, and messaging permissions and can change or revoke them.

We do not knowingly use a child's data for behavioral advertising, sell it, or permit profiling that is prohibited by applicable child-data law. Safety and legal obligations may require us to preserve or disclose evidence even after a guardian revokes ordinary feature consent.

8. Visibility and professional records

Public profile and evidence fields are displayed only when the account, age, guardian permissions, moderation state, privacy setting, and blocks permit it. Private object keys, precise credentials, email, date of birth, internal moderation fields, and private locations are not part of public profile responses.

Scouts, coaches, clubs, and academies may create assessments, shortlists, reports, and internal notes. Access is restricted by current role, verification, organization membership, assignment, player relationship, consent, and block state. Ask the relevant organization about records for which it independently determines the purpose.

9. When data is shared

  • With users you choose or features you use, according to visibility, team, conversation, organization, and guardian controls.
  • With service providers for hosting, private object storage, email, push delivery, security, backups, and approved media processing, under instructions and access restrictions appropriate to their function.
  • With authorities or safety organizations when required by law or reasonably necessary to address imminent harm, exploitation, fraud, security incidents, or legal claims.
  • During a corporate transaction, subject to confidentiality, lawful notice, and continued protection of the data.

We do not sell personal data. We do not share private player, message, scouting, guardian, or verification data for third-party advertising.

10. International processing

RISE 11 is operated from India and may use providers or authorized recipients in other countries. Where data is transferred, we use contractual, technical, organizational, localization, or other safeguards required by applicable law and respect any government restrictions on transfers from India.

11. Retention and deletion

We retain data only as long as needed for the purposes above, considering account status, feature use, safety, disputes, statutory duties, limitation periods, organization obligations, and secure backup cycles. Security, acceptance, moderation, and safeguarding evidence may be retained longer than ordinary profile data where necessary and lawful.

  • Upload and playback links expire after a short configured period.
  • Unfinished staging uploads are automatically expired on a bounded schedule.
  • Verification and recovery credentials expire, are one-time, and are erased from delivery records after terminal use or failure.
  • Expired privacy-export objects and temporary generation files are scheduled for deletion.
  • Backups follow a protected recovery schedule and age out through controlled retention maintenance.

Account deactivation immediately revokes sessions and ordinary visibility. Irreversible deletion is completed subject to lawful retention, legal hold, safeguarding, counterparty rights, and backup expiry requirements.

12. Security

Measures include hashed passwords and refresh tokens, multi-factor authentication, encrypted sensitive credentials, sender-locked TLS email, private object storage, signed short-lived URLs, role and organization authorization, guardian controls, malware and moderation gates, rate limits, audit trails, monitoring, encrypted backups, and tested restore procedures. No system is risk-free; report suspected compromise promptly.

13. Cookies, devices, and notifications

The web service uses strictly necessary cookies for authentication, session continuity, security, and request protection. It does not require third-party advertising cookies. See the Cookie Notice. Push notifications are optional and require browser or device permission; they can be disabled in RISE 11 settings and device settings.

14. Rankings and automated processing

RISE 11 may calculate search order, suggested players, achievements, XP, eligibility, spam or abuse risk, and entitlement state using rules and platform activity. These tools support discovery and safety; they do not make a binding employment, selection, contract, or similarly significant legal decision for a club or player. Authorized people remain responsible for professional decisions and moderation appeals are available where appropriate.

15. Your rights and choices

Subject to applicable law, you may:

  • access information about personal data and request a portable export;
  • correct inaccurate profile or account information;
  • request erasure, deactivate the account, or withdraw consent;
  • change profile visibility, notification choices, blocks, and guardian scopes;
  • object to or restrict certain processing where the law provides;
  • nominate another person to exercise rights where applicable; and
  • raise a grievance and complain to the competent data-protection authority.

Use account settings where available or email privacy@merchnique.com. We may verify identity and authority before acting. We will explain if a request is limited by another person's rights, safety obligations, legal hold, or another lawful exception.

16. Grievances and contact

Grievance Officer: Ronnie Thomas, Founder & CEO, MerchNique Technologies Private Limited, Bhagat Singh Marg, Durgapur, West Bengal, India. Email grievance@merchnique.com. Include the account email, a clear description, relevant references, and the outcome requested. Do not email passwords, recovery codes, private keys, or illegal content.

17. Updates to this Notice

We publish a stable version and effective date. Material changes may be presented in the service and require renewed acceptance. Earlier versions and acceptance records may be retained where needed to show which notice applied.