PODIUM · BFT MENA
Privacy Policy
Last updated: 17 September 2026
The short version
PODIUM is the competition platform of BFT MENA. We collect only what running the competition needs: account and registration details, registration fee records, exercise scores and results, and the minimum security data required to protect sign-ins. No advertising, no trackers, no analytics, no data selling — the website and the mobile apps run entirely on our own infrastructure and talk to no third-party service.
Who runs this service
The PODIUM platform (this website and its mobile applications) is operated by BFT MENA. For any privacy question or request, contact us at admin@bftmiddleeast.com.
Accounts and sign-in
Accounts are created and invited by the organizing team — there is no open registration. For each account we store the email address, an optional display name, the role (staff or competitor), and the language preference.
There are two ways to sign in, and both are internal to PODIUM:
- Credentials issued by the organizer. Passwords are stored only as salted hashes — never in plain text.
- A one-time code (OTP) sent by email to the account’s own address. Codes are stored hashed, expire within minutes, and each code works once.
We offer no social logins — no Sign in with Apple, Google, or any other provider — so nothing about you is ever shared with a login provider, because none is used.
Sign-in security data
For every sign-in attempt we keep the time, the IP address, and a one-way hash (HMAC-SHA256) of device characteristics. Recognized devices are listed on a “trusted devices” screen with their browser, operating system and device type, and can be revoked by the account owner at any time. These records exist solely to protect accounts from unauthorized access. They are never used for profiling, advertising, or marketing.
Competition data, and what is public
Registration records can include names, email addresses, phone numbers, dates of birth, competition categories and studio membership. We use these details to organize participation and manage registrations. Registration fees may apply. Fee records include amounts, currencies, payment status and payment references; we do not store payment card details.
The service records the competition itself: studios, series, waves, teams, competitor names, scores and results. Published results are public by design — that is the product. The public results board (and the mobile applications) show team and competitor names, ranks and scores for competitions that the organizer has finished and published.
Exercise scores record what teams achieved during competition training and compare participating teams. They are fitness competition results; the service does not collect clinical records or provide medical advice. Contact details, dates of birth and fee records are not published on the public results board.
Staff may enter operational notes and announcements. We retain sign-in activity, staff action logs and announcement read receipts to operate the platform, deliver updates and protect accounts.
What we never do
- We show no advertising and do not sell personal data.
- We run no analytics, tracking scripts, or third-party CDNs. The site is fully self-contained.
- We do not sell, rent, or share personal data with any third party.
- Emails are operational only: invitations, password resets, and sign-in codes.
Retention and deletion
You can delete your account yourself, at any time, from Account → Delete account inside the app. No request and no approval: the account is closed immediately, you are signed out on every device, every trusted browser is revoked, and you can no longer sign in.
What a deletion does not erase is the record of competitions already run. Scores, placings and the published results of an event you competed in belong to that event and to everyone else who competed in it, and are kept as part of its result. The same is true of the administrative audit log, which exists so that decisions taken about accounts remain answerable. These records are retained for as long as the organizer keeps the competition on record.
Account data is otherwise kept while the account is active. To access or correct your personal data, or to ask about anything retained after a deletion, contact the organizing team or write to us at the address above, and we will action the request.
Security
Traffic is encrypted in transit (TLS). Passwords and one-time codes are stored only as hashes. Sign-in attempts and staff actions are logged and auditable. Access to production systems is limited to the platform operators.
Changes to this policy
If we change this policy, the updated version will be published on this page with a new date. Material changes will also be announced inside the app.
