- Home
- Legal
- Privacy Policy
Privacy Policy
CricLane handles four quite different kinds of personal data — a player profile, a squad registration, a child’s trial booking and a shop order. This policy describes each one separately instead of hiding them all behind a single paragraph.
1. Who we are and who this policy covers
CricLane.in is owned and operated by Catalyst Web Trendz Pvt. Ltd., D 29, 2nd Floor, Greater Kailash Enclave 2, Greater Kailash, New Delhi – 110048. For the purposes of the Digital Personal Data Protection Act, 2023 (the “DPDP Act”) we are the Data Fiduciary for personal data processed through this website, the CricLane scorer app and our newsletter. If you are the individual the data is about, you are the Data Principal.
This policy applies to everyone who uses CricLane: players and club officials with a profile, captains registering a team, parents booking an academy trial, coaches and academies listed in our directory, organisers running a tournament, shoppers buying merchandise, newsletter subscribers, and casual visitors who only ever look at a scorecard. It is published as an electronic record under section 4 of the Information Technology Act, 2000 and does not require a signature.
It does not cover what an academy, coach or tournament organiser does with your data on their own systems after you engage them directly. Those organisations are independent Data Fiduciaries for their own processing and run their own policies. Where we pass data to them we say so in section 8.
2. What personal data we collect
We collect only what a cricket platform actually needs. We group it into seven categories.
Account and player profile data
Name, mobile number, email address, city, password (stored only as a salted hash), date of birth or age band, playing role, batting and bowling style, club affiliation and any profile photo you choose from our built-in avatar set. Your public player profile shows your name, city, club, role and match statistics by design — that is the point of a profile. Your mobile number, email and date of birth are never shown publicly.
Tournament and team registration data
Team name, home ground, the captain’s and manager’s contact details, the squad list with each player’s name, age and role, age-proof reference numbers where an age-group event requires them, jersey sizes, and the organiser’s eligibility declarations. For age-group trophies the organiser may ask for a school or board certificate reference; we transmit it to the organiser and do not retain a copy of the document itself.
Academy trial and coaching enquiry data
The trainee’s first name and age, the preferred centre, batch and date, and the parent’s or guardian’s name, phone number and email where the trainee is under eighteen. Any medical or injury note you volunteer so that the academy can supervise safely is treated as sensitive and shared only with that academy.
Order and delivery data
Items ordered, size, quantity, price paid, order and invoice number, GSTIN if you supply one, delivery address, recipient name and phone number, courier tracking reference, and any return or refund correspondence.
Payment data
Payments are processed entirely by a PCI-DSS compliant payment gateway. We never see, receive or store your full card number, CVV, UPI PIN or net-banking credentials. What we receive back from the gateway and store is the transaction reference, the payment method type (for example “UPI” or “Visa ending 4242”), the amount, the currency, the timestamp and the success or failure status.
Device, log and analytics data
IP address, device type, operating system, browser, screen size, referring link, pages viewed, scroll depth, approximate city derived from IP, and crash or error reports. Raw IP addresses are truncated before they enter analytics storage.
Communications and scoring data
Contact-form submissions (name, organisation, email, phone, city, subject and message), newsletter subscription and delivery telemetry for The Stump Mic, WhatsApp and email correspondence with our desk, and the ball-by-ball entries a club official records through the scorer app together with the scorer’s identity.
We do not ask for, and request that you never send us, government identity numbers, bank account numbers, caste or religion, biometric data, or health records beyond the brief injury note described above.
3. Why we process it — purposes and lawful basis
Under section 4 of the DPDP Act, personal data may be processed only for a lawful purpose, either with your consent or for a “certain legitimate use”. Purpose limitation is real for us: data collected for one of the purposes below is not quietly reused for another.
| What we do with it | Data used | Lawful basis |
|---|---|---|
| Create and run your player or club profile | Account, profile, scoring | Consent |
| Register a team and pass the entry to the organiser | Registration, squad | Consent · performance of the service you asked for |
| Book an academy trial and confirm the slot | Trial, parent or guardian contact | Consent (parental consent where the trainee is a child) |
| Take an order, take payment, ship it and handle returns | Order, delivery, payment reference | Performance of the contract you entered into |
| Publish scorecards, tables and rankings | Scoring, profile | Consent · voluntary provision for a stated purpose |
| Send The Stump Mic and service notices | Email, preferences | Consent (marketing) · legitimate use (service notices) |
| Measure which pages help and fix what breaks | Device, log, analytics | Consent for non-essential analytics |
| Prevent fraud, abuse, scraping and account takeover | Log, device, account | Certain legitimate uses, section 7 DPDP Act |
| Keep invoices, GST records and statutory books | Order, invoice, payment | Compliance with law |
| Answer a grievance or a legal or court order | Whatever is relevant | Compliance with law |
4. Consent, withdrawal and Consent Managers
Where we rely on consent, it is asked for through a clear affirmative action — ticking a box, pressing Accept on the cookie banner, or submitting a form under a notice that says what the data will be used for. Consent is recorded with a timestamp and the version of the notice you saw. Silence, a pre-ticked box and continued scrolling are not consent, and we do not treat them as consent.
Withdrawing consent is as easy as giving it. You can withdraw from your account settings, by pressing Decline in the cookie banner, by using the one-click unsubscribe link in every edition of The Stump Mic, or by emailing info@catalystwebtrendz.com. Withdrawal takes effect immediately for future processing and does not affect the lawfulness of anything done before it. Where withdrawal makes a service impossible — for example, we cannot ship an order without a delivery address — we will tell you that consequence clearly rather than silently degrading the service.
The DPDP Act allows you to give, manage, review and withdraw consent through a Consent Manager registered with the Data Protection Board of India. CricLane will accept and act on instructions received through any Consent Manager once the Board’s registration framework is operational, on the same timelines as a request made directly to us. Until then, please use the routes above.
5. Children, academies and verifiable parental consent
This section matters more on CricLane than on most websites, because a large part of what we do — academy listings, coaching batches, age-group trophies, junior trials — is aimed at children. We treat it accordingly.
A child means anyone under eighteen years of age. Under section 9 of the DPDP Act we process a child’s personal data only after obtaining verifiable consent from a parent or lawful guardian.
How verifiable parental consent works here
- A player profile or academy trial booking for anyone under eighteen must be created by a parent or guardian from their own CricLane account, not by the child.
- The parent or guardian confirms the relationship, and the consent is verified by a one-time password sent to the adult’s registered mobile number and a confirmation email. Both are logged with a timestamp and the notice version.
- For age-group tournaments, the registering club official warrants that a parent or guardian has consented for every minor in the squad, and the consent record must be produced on request.
- A parent or guardian may withdraw consent at any time; we then delete the child’s profile and cancel any pending bookings, usually within seven working days.
What we never do with a child’s data
- No tracking or behavioural monitoring of children. Analytics, interest profiling and behavioural cookies are disabled on any account we identify as belonging to a child.
- No targeted advertising directed at children. We do not run advertising to child accounts at all, and we do not build advertising audience segments from a child’s data.
- No public display of a minor’s mobile number, email address, school, home address or exact date of birth. Age-group scorecards show a first name, surname initial, club and age band only.
- No processing likely to have a detrimental effect on the wellbeing of a child, as prohibited by section 9(2) of the DPDP Act.
Coaches and academy staff receive a trainee’s details only after the parent confirms the booking, and only what they need to supervise the session safely. If you believe a child’s data has reached us without proper parental consent, write to the Grievance Officer and we will verify and erase it, ordinarily within seven working days.
7. Payments, orders and the CricLane shop
The CricLane shop sells cricket merchandise; that is the only place we take money for ourselves. Tournament entry fees are paid to the organiser, never to CricLane — we do not hold entry fees, prize money or user stakes at any time.
Checkout is handled by a PCI-DSS Level 1 compliant payment gateway operating under Reserve Bank of India rules. Card details are tokenised at the gateway under the RBI card-on-file tokenisation framework; the token is meaningless outside that gateway and cannot be used to reconstruct your card number. We keep the transaction reference, amount and status so that we can issue an invoice, process a refund and satisfy a tax audit.
As required by the Consumer Protection (E-Commerce) Rules, 2020, the shop displays the total landed price inclusive of GST before you pay, the country of origin of each product, the expected delivery window, the seller’s legal name and the return and refund route, all before you are asked to confirm the order. Refunds are made to the original payment instrument.
9. Cross-border transfer
Our production databases and backups for CricLane are hosted in India. A small number of our processors — principally transactional email delivery and error monitoring — operate servers outside India. Under section 16 of the DPDP Act we transfer personal data only to countries that the Central Government has not restricted by notification, and only under a written contract imposing confidentiality, purpose limitation, security obligations and a right of audit.
Where a sectoral law imposes a stricter localisation requirement than the DPDP Act — for example the Reserve Bank of India’s payment-data storage directions — the stricter requirement is what we follow, and the relevant payment data stays in India.
10. How long we keep data
Data is kept only as long as its purpose lasts, or as long as a law requires, whichever is longer. Once the period ends the data is deleted or irreversibly anonymised. Aggregate anonymous statistics — for example “63% of Sunday matches in Pune start after 8:00 AM” — are not personal data and may be kept indefinitely.
| Category | Retention | Why |
|---|---|---|
| Raw IP and server access logs | 30 days | Security and abuse investigation |
| Analytics events | 13 months | Year-on-year comparison |
| Player and club account | Life of account + 30 days | Recovery window after deletion |
| Tournament and squad registration | 3 years | Eligibility disputes and age-fraud complaints |
| Academy trial bookings | 12 months | Follow-up and complaint handling |
| Parental consent records for a child | Life of account + 3 years | Proof of consent under the DPDP Act |
| Order, invoice, GST and payment records | 8 years | Companies Act, 2013 and GST record-keeping |
| Contact-form enquiries | 24 months | Continuity of correspondence |
| Grievance and moderation records | 24 months | Recognising repeat conduct |
| Newsletter subscription | Until you unsubscribe + 30 days | Suppression list, so we do not re-add you |
| Published scorecards and statistics | Indefinite | Historical record; name suppressed on request |
11. Security safeguards
We apply reasonable security safeguards to prevent a personal data breach, as required by section 8(5) of the DPDP Act and by the reasonable-security-practices standard under section 43A of the Information Technology Act, 2000. In practice that means: TLS encryption in transit on every page; encryption at rest for account and order databases; passwords stored only as salted hashes and never recoverable in plain text; one-time-password verification for account and parental-consent flows; role-based access limited to named staff, logged and reviewed quarterly; segregated production and development environments; rate limiting and bot detection on registration, login and scraping-prone endpoints; daily encrypted backups tested by restore; and contractual security obligations on every processor.
No system is perfect, and we do not claim otherwise. If you find a vulnerability, please report it to info@catalystwebtrendz.com rather than publishing it; we will acknowledge within two working days and will not pursue a good-faith researcher who gives us reasonable time to fix the issue.
12. Personal data breach notification
If a personal data breach occurs, we will notify the Data Protection Board of India and every affected Data Principal without delay, in the form and manner prescribed under section 8(6) of the DPDP Act. Our notice to you will describe, in plain language, the nature and extent of the breach, when and where it happened, the likely consequences, the safeguards and remedial measures we have implemented, what you should do to protect yourself, and how to contact us for more information.
We notify regardless of whether the breach is likely to cause you harm — the DPDP Act sets no harm threshold — and we do so even where the breach occurred at one of our processors. We maintain an internal breach register and conduct a post-incident review of every reportable event.
13. Your rights as a Data Principal and how to exercise them
As a Data Principal you have the following rights in respect of personal data processed on the basis of your consent or a certain legitimate use.
- Right to access — a summary of the personal data we process, the processing activities undertaken, and the identities of the other Data Fiduciaries and processors with whom it has been shared, together with a description of what was shared (section 11).
- Right to correction, completion, updating and erasure — have inaccurate or misleading data corrected, incomplete data completed, and data erased where it is no longer needed for the purpose it was collected for and no law requires us to keep it (section 12).
- Right to nominate — nominate another individual to exercise these rights on your behalf if you die or become incapacitated (section 14).
- Right to grievance redressal — a readily available route to complain to us, which you must use before approaching the Data Protection Board (section 13).
- Right to withdraw consent — at any time, as easily as you gave it, as described in section 4.
How to exercise them
Most things can be done yourself: edit your profile, change your privacy settings, hide your surname from public scorecards, unsubscribe from the newsletter, or delete your account from Account Settings (deletion is confirmed by email and completed within thirty days). For everything else, email the Grievance Officer at info@catalystwebtrendz.com from the address registered on your account, or use the contact form. We may ask one verification question to be sure it is you — we will never ask for a password or a payment credential.
We acknowledge every request within 24 hours and complete it within 15 days. There is no fee. You also have a corresponding duty under section 15 of the DPDP Act not to file a false or frivolous complaint and not to furnish false particulars.
14. Rankings, profiling and automated processing
CricLane publishes batting, bowling and all-rounder rankings, a club form index and win-probability figures. These are statistical models built from published match data. They do not use your device data, your browsing behaviour or your purchases, they produce no decision with a legal or similarly significant effect on you, and they are not used to price anything differently for different people.
We do not sell audience segments, we do not run behavioural advertising anywhere on CricLane, and we never profile a user identified as a child. If your name appears in a public ranking or scorecard and you would prefer it did not, write to us and we will suppress it to initials while keeping the match record intact.
15. Third-party sites, academies and organisers
CricLane links to academy websites, organiser pages, ground booking services, governing-body sites and video platforms. Once you follow a link you are on somebody else’s site, under their privacy policy and their security practices. We do not control them and a link is not an endorsement.
Academies, coaches and organisers listed in our directory are independent businesses. When you contact one directly — by phone, WhatsApp or at their premises — that conversation and anything you give them is governed by their policy, not ours. We do require every listed partner to contract with us to handle CricLane-sourced enquiry data lawfully, use it only to respond to that enquiry, and delete it on request.
16. Changes to this policy
We update this policy when the law changes, when the DPDP Rules are notified in final form, or when we change what we do with data. Material changes are announced on the site and in The Stump Mic at least fourteen days before they take effect, and where the change requires fresh consent we will ask for it rather than assume it. The “last updated” date at the top of this page always reflects the version currently in force, and superseded versions are available on request.
This policy is governed by the laws of India. Any dispute arising from it is subject to the exclusive jurisdiction of the competent courts at New Delhi, without prejudice to your right to approach the Data Protection Board of India or a consumer forum.
Questions about your data?
Rights requests, consent withdrawals, complaints about how we have handled personal data, and reports of a child’s data reaching us without parental consent all go to the same place.
Grievance Officer, CricLane — a named officer of Catalyst Web Trendz Pvt. Ltd., appointed under Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and section 13 of the Digital Personal Data Protection Act, 2023.
To be appointed and named before publication
- Catalyst Web Trendz Pvt. Ltd., D 29, 2nd Floor, Greater Kailash Enclave 2, Greater Kailash, New Delhi – 110048
- Email: info@catalystwebtrendz.com (write “Grievance” in the subject line)
- Phone and WhatsApp: +91-9953590779 · wa.me/919953590779
- Hours: Monday–Friday, 10:00 AM – 7:00 PM IST
We acknowledge every complaint within 24 hours and resolve it within 15 days of receipt, as required by the Intermediary Guidelines. Complaints about the removal or non-removal of content are decided within the same window; requests to take down content that exposes a private area of the body, or is in the nature of impersonation, are actioned within 24 hours of a valid complaint. If you are not satisfied with our response you may approach the Data Protection Board of India (for personal-data grievances) or the appropriate authority under the Consumer Protection Act, 2019.
Contact the CricLane deskThe rest of the paperwork
Disclaimer
Ask us anything about your data
One email starts the clock. We acknowledge within 24 hours and resolve within 15 days, and usually a great deal faster.