FIGHTNEXUS

PRIVACY POLICY

Last updated: April 13, 2026

This Privacy Notice for FightNexus("we", "us", or "our") describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:

  • Visit our website or any website of ours that links to this Privacy Notice
  • Register and use FightNexus — a platform to connect combat sports fighters with event promoters in Indiana, making the process of matchmaking simple and effective
  • Engage with us in other related ways, including account management or event coordination

Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services. If you have questions, please contact us at admin@fightnexus.com.

SUMMARY OF KEY POINTS

What personal information do we process?

We collect information you provide during registration and profile setup, including name, contact details, fight records, and uploaded documents.

Do we process sensitive personal information?

No.

Do we collect information from third parties?

No.

How do we process your information?

To provide the platform, match fighters with events, verify credentials, and communicate with you.

Do we share personal information?

Only with AWS (our infrastructure provider) and, in limited ways, with promoters and admins within the platform.

How do we keep your information safe?

Through AWS-managed security, httpOnly cookies, presigned URLs, and role-based access controls.

What are your rights?

You may access, correct, or delete your data. In-app account deletion is available.

1.WHAT INFORMATION DO WE COLLECT?

Personal information you disclose to us

We collect personal information you voluntarily provide when you register, update your profile, upload documents, submit RSVPs, or contact us.

Fighter accounts may include:

  • First and last name
  • Email address and password (stored hashed via AWS Cognito)
  • Date of birth (age verification — must be 18+)
  • Gender
  • Phone number
  • Weight class, height, walkaround weight
  • Gym or club name
  • Fight record (wins, losses, draws, KOs)
  • Optional bio (up to 500 characters)
  • Optional social media handles (Instagram, Twitter)
  • Optional profile photo
  • Uploaded documents (PDFs and images — e.g., fight ID, medical clearance)

Promoter accounts may include:

  • Company/organization name
  • First and last name (contact person)
  • Email address and password (stored hashed via AWS Cognito)
  • Phone number
  • City and state
  • Indiana Gaming Commission (IGC) license number and LLC documentation
  • Optional bio, website, and social media handles

All users:

  • Account status (pending/active/suspended)
  • RSVP submission history
  • Account creation and update timestamps

Sensitive Information: We do not process sensitive personal information.

Information automatically collected

We automatically collect certain technical information when you visit or use the Services:

  • Log and Usage Data: IP address, browser type, device information, pages viewed, timestamps, and error reports
  • Session Data: Authentication tokens stored in HTTP-only cookies

2.HOW DO WE PROCESS YOUR INFORMATION?

We process your personal information to:

  • Facilitate account creation, authentication, and account management
  • Verify fighter eligibility (age, weight class) and promoter credentials (IGC licensing)
  • Match fighters with appropriate events and enable RSVP submissions
  • Allow promoters to review and respond to fighter applications
  • Send transactional emails (account approval/rejection, RSVP status updates, password resets, account deletion confirmations)
  • Enable admin review of pending accounts and uploaded documents
  • Maintain the security and operation of our platform
  • Comply with applicable sports regulation requirements

4.WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

We may share your information in the following situations:

  • AWS (Amazon Web Services): All data is stored and processed using AWS infrastructure — Cognito (authentication), DynamoDB (profiles and events), S3 (documents), and SES (email). AWS acts as a data processor under our direction.
  • Promoters: Fighter name, weight class, fight record, and RSVP notes are visible to promoters managing events you apply to.
  • Admins: FightNexus administrators can view user profiles and documents for account approval purposes.
  • Business Transfers: We may share or transfer your information in connection with a merger, sale of company assets, or acquisition of all or a portion of our business.
  • Other Users: Your public profile information (name, gym, fight record, weight class) is visible to promoters on the platform.

We do not sell personal information. We do not share data with advertisers, analytics providers, or data brokers.

5.WHAT IS OUR STANCE ON THIRD-PARTY WEBSITES?

Our Services may contain links to third-party websites (e.g., IGC event pages, social media profiles). We are not responsible for the safety or privacy practices of those websites. Any data you provide to third parties is not covered by this Privacy Notice. We encourage you to review the privacy policies of any third-party sites you visit.

6.DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?

We use essential session cookies only to maintain authentication:

CookiePurposeExpiry
fc_accessCognito access token for authentication1 hour
fc_refreshCognito refresh token to maintain session30 days

These cookies are HTTP-only and Secure, preventing JavaScript access. They are required for the platform to function and cannot be opted out of while using the Services.

We do not use advertising, analytics, or third-party tracking cookies.

7.HOW LONG DO WE KEEP YOUR INFORMATION?

We retain your personal information for as long as your account is active. Specific retention periods:

Data TypeRetention Period
Active account data (profiles, RSVPs, events)Indefinitely while your account exists
Access tokens1 hour
Refresh tokens30 days
Pending registration session data30 minutes
Account deletion verification codes10 minutes
Presigned document upload URLs5 minutes
Presigned document view URLs15 minutes

When you delete your account, all profile data, documents (S3 and DynamoDB records), RSVPs, events (promoters), and your Cognito authentication account are permanently and immediately deleted.

8.HOW DO WE KEEP YOUR INFORMATION SAFE?

We have implemented appropriate technical and organizational security measures:

  • Passwords are never stored by FightNexus — they are managed entirely by AWS Cognito with industry-standard hashing
  • Session tokens are stored in HTTP-only, Secure, SameSite=Lax cookies to prevent XSS and CSRF attacks
  • Documents are stored in AWS S3 with time-limited presigned URLs (no permanent public access)
  • File uploads are restricted to PDF, JPEG, and PNG content types
  • API inputs are validated with Zod schema validation on every endpoint
  • Data access is scoped by role — fighters, promoters, and admins can only access what is appropriate for their role

However, no electronic transmission over the internet can be guaranteed 100% secure. Transmission of personal information to and from our Services is at your own risk. You should only access the Services within a secure environment.

9.DO WE COLLECT INFORMATION FROM MINORS?

We do not knowingly collect, solicit data from, or market to children under 18 years of age. Fighter registration enforces an age requirement of 18 years or older at the time of sign-up.

By using the Services, you represent that you are at least 18 years of age. If we learn that personal information from a user under 18 has been collected, we will deactivate the account and delete the data. If you become aware of any such data, please contact us at admin@fightnexus.com.

10.WHAT ARE YOUR PRIVACY RIGHTS?

EEA, UK, Switzerland, and Canada residents

You have rights including:

  • Request access to and a copy of your personal information
  • Request rectification or erasure
  • Restrict the processing of your personal information
  • Data portability (where applicable)
  • Object to processing

To exercise these rights, contact us using the details in Section 14.

If you are in the EEA or UK and believe we are unlawfully processing your information, you have the right to complain to your Member State data protection authority or the UK ICO. Swiss residents may contact the Federal Data Protection and Information Commissioner.

Withdrawing consent

You may withdraw consent to optional data processing at any time by updating your profile or contacting us. This does not affect the lawfulness of processing before withdrawal.

Account information

You can review or update your profile at any time via your account settings. To delete your account, use the Danger Zone section of your profile page — this triggers a 6-digit email verification before permanent deletion.

11.CONTROLS FOR DO-NOT-TRACK FEATURES

Most web browsers include a Do-Not-Track ("DNT") feature. Because no uniform technology standard for recognizing and implementing DNT signals has been finalized, we do not currently respond to DNT signals. If a standard is adopted in the future, we will update this notice accordingly.

California law requires us to disclose our DNT response. We do not respond to DNT signals at this time.

12.DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?

If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, or Virginia, you may have the right to request access to, correct, or delete your personal information, and to withdraw consent to processing.

Categories of Personal Information Collected in the Past 12 Months

CategoryExamplesCollected
A. IdentifiersName, email, phone, IP address, account IDYES
B. Personal information (CA Records statute)Name, contact infoYES
C. Protected classification characteristicsGender, age/date of birthYES
D. Commercial informationTransaction/purchase historyNO
E. Biometric informationFingerprints, voiceprintsNO
F. Internet/network activityBrowsing history, ad interactionsNO
G. Geolocation dataDevice locationNO
H. Audio/visual informationImages (profile photo, uploaded documents)YES
I. Professional/employment informationGym affiliation, fight record, IGC licenseYES
J. Education informationStudent recordsNO
K. Inferences from personal dataProfiles or summariesNO
L. Sensitive personal informationNO

We retain Category H data (images and documents) for as long as your account is active.

We have not sold or shared personal information with third parties for commercial purposes and will not do so.

Your Rights

  • Right to know whether your personal data is being processed
  • Right to access your personal data
  • Right to correct inaccuracies
  • Right to request deletion
  • Right to obtain a copy of data you shared with us
  • Right to non-discrimination for exercising rights
  • Right to opt out of sale or sharing (we do not sell or share data)

How to Exercise Your Rights

Submit a request by emailing admin@fightnexus.com. We will verify your identity before processing requests. You may designate an authorized agent with written permission.

Appeals

If we decline your request, you may appeal by emailing admin@fightnexus.com. If your appeal is denied, you may submit a complaint to your state attorney general.

California "Shine The Light" Law

California residents may request information about disclosures to third parties for direct marketing once per year, free of charge. Contact us using the details in Section 14.

13.DO WE MAKE UPDATES TO THIS NOTICE?

Yes. We may update this Privacy Notice from time to time. The updated version will be indicated by an updated "Last Updated" date at the top. For material changes, we will notify you by prominently posting a notice or by sending you a direct notification. We encourage you to review this notice regularly.

14.HOW CAN YOU CONTACT US ABOUT THIS NOTICE?

If you have questions or comments about this notice, you may email us at admin@fightnexus.com.

15.HOW CAN YOU REVIEW, UPDATE, OR DELETE YOUR DATA?

Based on applicable laws, you may have the right to request access to, correct, or delete your personal information. The easiest way is to use your account settings or the in-app account deletion feature (Profile → Danger Zone). You may also email us at admin@fightnexus.com to submit a data subject access request.

↑ Back to top