What is public
Read this section carefully. Some of what UCA publishes is visible to anyone on the internet, signed in or not. This is the part people are most often surprised by, so it comes first.
- Your player page is public. Your gamertag is the page title. It also appears in the page's metadata and in an automatically generated share image.
- Your full gamertag history is public — every past and present gamertag we hold for you, with the dates each was active. Changing your gamertag does not hide the old one.
- Your player page also shows your profile address, primary position, player status, platform, current club, career statistics, your last 10 matches, and a "Discord connected" badge.
- Club pages are public — club name, tag, logo, description, colors, the manager's display name and avatar, and the roster.
- Our site search works without an account. Anyone, signed in or not, can search UCA and get back active players along with their gamertags and platforms.
Never public: your email address, your bio, and your Discord handle, Discord ID, global name, and Discord avatar. Those are visible only to you and to staff.
Signing in to browse the full player, team, match, and leaderboard directories does not make individual profiles private — anyone can still open your player page or club page directly, without an account.
If you are not comfortable with a gamertag appearing publicly and permanently, do not use one that identifies you off-platform. We would rather you knew this before signing up than found out afterward.
Information we collect
When you register
Registration asks for exactly three things: a display name (up to 80 characters), an email address, and a password. We do not ask for your date of birth, real name, phone number, postal address, country, platform, or gamertag at sign-up.
If you sign in with Discord
We request only the basic identity and email permissions. We store your Discord user ID, username, global name, avatar address, and the date you linked the account. We do not request access to your servers or your connected accounts.
Your player profile
Your gamertag is not collected at sign-up. It is added later — by you or by staff — as part of joining a club and playing recorded matches, and the gamertag recorded against your performances also comes back with the match data we import from EA. Over time your profile may include past gamertags, your profile address, primary position, player status, platform, a bio, an avatar, and your club membership.
Club applications
If you apply to bring a club into UCA, we collect the club name, tag and platform, your Discord username, club status, whether you play in other leagues and which, roster and availability answers, your management experience, why you want to join, and your acknowledgements of the rules and code of conduct. Some of these are free-text boxes — please do not put anything sensitive in them. Your identity comes from your signed-in session; the form never asks for your name or email. Staff may add private reviewer notes, which are never visible to applicants.
Competition data
Fixtures, results, per-player match statistics (including the EA gamertag recorded for a performance and EA's own anti-cheat indicator), who submitted a result and who approved it, standings, and roster history.
Disputes
A dispute is created automatically when two clubs submit conflicting scores for the same fixture. We store the description, staff notes, the outcome, and resolution notes. There is no in-app evidence uploader — any evidence you share with staff is sent through Discord and hosted wherever you host it.
Administrative records
Staff actions are logged: what was changed, the change itself, when, and by whom. For staff actions this log also records the acting administrator's email address. These logs do not record IP addresses or device information — those fields do not exist.
Technical data
We read the IP address on your connection only to rate-limit registration and password-recovery requests. We do not save it. It is held in memory for about a minute to count attempts, then discarded. It is never written to our database and never written to a log file. We do not collect user-agent strings and we do not fingerprint devices.
Where information comes from
- From you — registration, your profile, club applications, and uploads.
- From Discord — only if you choose Discord sign-in, and only the fields listed above.
- From the EA Pro Clubs API — UCA queries EA's Pro Clubs API from our servers to import match data. Your browser never contacts EA on our behalf; data flows inbound from EA to UCA. Imported results can be inaccurate or incomplete and are subject to administrative review. Staff can turn the import off platform-wide, but this is not a per-player setting — you cannot opt your own matches out of it.
- Automatically — the short-lived IP handling described above, and the cookies described below.
How we use it
- Create your account and sign you in.
- Run competitions: rosters, fixtures, official results, standings, statistics, and permanent competitive history — including continuity when a club folds, changes owner, or rebrands.
- Publish public player and club profiles.
- Review club applications and make admission decisions.
- Investigate disputes, enforce the rules, and keep an accountable record of administrative decisions.
- Prevent abuse — for example, rate-limiting sign-up attempts.
- Communicate with you through our Discord community.
What we do not do
Stated plainly, because it matters:
- We do not sell your data. Not to anyone, in any form.
- No advertising. No ad networks, no ad cookies, no tracking pixels.
- No analytics. No Google Analytics, no Vercel Analytics, no PostHog, no Plausible — none at all.
- No payments. No card processing, no subscriptions, no billing. We collect no financial information.
- No marketing email and no newsletter.
- No third-party tracking cookies, and no data written to your browser's local or session storage by UCA code.
- No session recording or replay of any kind.
Service providers
These are the only companies that handle UCA data. Each uses its own infrastructure suppliers, and we will update this list if we add a provider.
- Supabase — where your account, the database, and uploaded images live. Almost everything UCA stores is stored with them.
- Discord — optional sign-in, and our community and support server.
- EA Pro Clubs API — server-side match data queries.
- Vercel — hosting and infrastructure.
For completeness: error-monitoring software is included in our code but is switched off — no destination is configured, so nothing is sent anywhere.
Security
- Passwords and sessions are handled by our authentication provider. Signed-in users can change their own password and email address at /profile/settings.
- Self-service password reset by email is switched off. If you are locked out, contact staff on Discord — the "Forgot password?" link points there.
- Uploaded images are stripped of metadata. Every avatar and club logo is re-encoded, resized, and has its EXIF data — including any location tags your device wrote — removed.
No system is perfectly secure, and we cannot guarantee that a determined attacker will never succeed. If we become aware of a breach affecting your information, we will post notice in our Discord community.
How long we keep information
We want to be accurate here rather than reassuring.
- Competition records are kept indefinitely. Fixtures, results, statistics, disputes, and administrative decisions form the league's permanent competitive history. There is no retention limit on them.
- Nothing is currently deleted automatically. We have an internal policy for expiring older administrative logs, but no automated deletion is running today.
- "Deleting" a record in the app hides it rather than erasing it. Removal marks the record as deleted and takes it out of the interface; the underlying record, including any email address it holds, remains in the database.
- Your account record is never deleted. We do not delete the underlying authentication record, so the row holding your email address stays in our database — including after you ask us to close your account.
- If you stop playing, nothing is removed. There is no inactivity clean-up. Your public player page and match history stay online until you ask staff to close the account.
- Backups. Our provider takes daily backups retained for seven days. Information may persist in backups for a period after it is removed from the live system. Backups do not include uploaded files or authentication records.
Closing your account
There is no button for this. Message staff privately in our Discord community and a member of staff will handle it by hand. We cannot tell you how long it will take, and we do not commit to a completion time.
The full detail — including what we are building to improve this — is on Account Deletion. That page is the operational procedure; this policy is the statement of position.
Staff may delay or decline a closure request where your account holds manager, administrative, competition, dispute, or integrity obligations.
Your privacy choices
- Change your password and email address yourself at /profile/settings.
- Ask staff in Discord to correct anything on your profile that is wrong. Gamertag history is part of the competitive record, so we will not remove past gamertags simply because you no longer use them.
- Ask about, or request, closure of your account — see Account Deletion.
Everything other than the password and email change goes through our Discord community — message staff privately, saying what you want changed and which profile it concerns. We do not have an automated export tool, so there is no self-service "download my data" button; ask staff and we will discuss what we can provide.
Children
UCA is for people aged 13 and over. Registration by anyone under 13 is prohibited. We do not ask for your date of birth, so we rely on you being truthful and on reports from the community.
If we learn that an account belongs to someone under 13, we will close it. Because our systems do not currently support complete erasure, closure works as described above — some records, including the underlying account record, will remain in our database and in backups. A parent or guardian who believes a child under 13 has registered should contact us on Discord.
International processing
UCA is operated online, and our providers operate infrastructure in multiple countries. Your information may be processed in countries other than the one you live in, where data protection law may differ. We are confirming the specific hosting regions with our providers and will state them here once verified.
How this policy is accepted
We do not currently ask you to tick a box to accept this policy at sign-up, and we do not keep a record of anyone agreeing to it. We are being explicit about that rather than implying a consent record we do not hold.
Changes to this policy
We will update this page when our practices change, and we update the "last updated" date at the top when we do. If a change materially affects how we handle your information, we will announce it in our Discord community.
Contact
Questions about this policy, your information, or your account go to our official Discord. That is currently our only contact channel — we do not operate a support email address, though establishing one is on our pre-launch list.
Ultimate Clubs Association is an unincorporated organization, not a company. See also the Terms of Service and the Code of Conduct.
UCA is not affiliated with or endorsed by EA SPORTS. EA SPORTS FC is a trademark of Electronic Arts Inc.