● LEGAL

Privacy Policy

Effective date: 2026-05-08

1. Who we are

DotaScore is an independent editorial site covering the Dota 2 professional scene. This Privacy Policy describes what personal information we collect, how we use it, who we share it with, and the controls you have. By using DotaScore you agree to the practices described here. If you do not agree, please do not use the service.

2. Information we collect

  • Account data (Steam OpenID). When you sign in we receive your public Steam ID and persona name from Valve's OpenID provider. We do not receive your Steam password and we do not log into your Steam account.
  • Preferences. Teams and players you follow, notification opt-ins, and similar UI preferences are stored against your DotaScore account so the experience stays consistent across sessions.
  • Session cookies. A secure, httpOnly cookie named dw_session holds a short-lived JSON Web Token used to authenticate you. A second short-lived cookie carries an OpenID anti-CSRF nonce during the sign-in handshake.
  • Network metadata. Standard server access logs (IP address, user agent, request path, response code, timestamp) are retained for security audit and abuse mitigation. Authenticated administrative actions additionally log the actor and IP for the audit trail required by the brief.
  • User-submitted content. If you submit a tip via the public tip intake (BE-30) or comment on an article, the submission is stored along with a timestamp and the originating IP for moderation and abuse review.

DotaScore does not knowingly collect data from anyone under 13. If you believe a minor has provided information, contact us and we will delete it.

3. How we use your information

  • To authenticate you and keep you signed in across page loads.
  • To personalise the experience (the teams / players you follow, notification opt-ins).
  • To run security controls (rate limits, anti-CSRF nonce verification, abuse detection) and produce the audit trail required for tournament-data integrity.
  • To compute aggregate, non-identifying analytics about site usage so we can prioritise improvements. We do not sell or share these analytics with third-party advertisers.

We do not use your information for behavioural advertising. We do not buy or sell personal information.

4. Third-party data sources and processors

DotaScore pulls public Dota 2 esports data from third parties. None of these calls include your personal information; we identify ourselves with a contact-bearing User-Agent and respect the documented rate limits.

  • Valve Steam Web API + Steam OpenID — authentication and live match data. Subject to Valve's own privacy practices.
  • OpenDota — historical match analytics. Read-only, public data.
  • STRATZ — additional match analytics. Read-only, public data.
  • Liquipedia — tournament metadata and editorial content (CC-BY-SA 3.0). Read-only.

Hosting and infrastructure providers (the operator of our database, web servers, and CDN) act as data processors and are bound by their own contractual obligations.

5. Cookies

  • dw_session — first-party, httpOnly, Secure, SameSite=Lax. Carries the authentication JWT. Cleared when you sign out.
  • dw_oid_state (or equivalent) — first-party, httpOnly, single-use, Secure. Carries the anti-CSRF nonce during the Steam OpenID handshake. Cleared automatically after callback.

We do not use third-party advertising or analytics cookies. Where we add a cookie banner for EU/UK visitors, you may opt out of any non-essential cookies; the two cookies above are essential to the service.

6. Your rights

Depending on where you live (notably EU/UK under GDPR / UK GDPR, and Russia under §152-FZ), you have rights to access, correct, delete, restrict, port, or object to processing of your personal information.

  • Access & portability. Sign in and visit /me to see what we hold against your account.
  • Deletion. The same page exposes a self-serve account-deletion action. We honour requests within a reasonable time (typically immediately for account / preferences; 30 days for residual log data).

7. Retention

  • Account data & preferences. Until you delete your account.
  • Session cookies. Until you sign out, or the JWT expires (≤7 days).
  • Audit logs & security logs. Up to 90 days unless required for an ongoing investigation or by law.
  • Live match snapshots and event log. 7 days after the match ends, per engineering retention policy.
  • User-submitted content (tips, comments). Until you delete it or request deletion. Moderated removals are kept in a small audit row for abuse review.

8. International transfers

DotaScore's infrastructure may be hosted outside your country. When we transfer personal information across borders we rely on standard safeguards (standard contractual clauses or equivalent) where required by law.

9. Security

We follow industry-standard security practices: encrypted transport (TLS), modern password hashing for staff accounts, short-lived JWTs in httpOnly cookies, parameter binding everywhere (no string-concatenated SQL), rate limits on sensitive endpoints, a strict Content-Security-Policy on the public site, and an audit log on administrative actions. No system is perfectly secure.

10. Changes to this policy

We may update this Privacy Policy. Material changes will be reflected by a new effective date at the top of this page; we will additionally surface a notice for signed-in users where the change affects how their data is handled.

Privacy Policy · DotaScore