PRIVACY POLICY
Draft
DRAFT — not legal advice. Must be reviewed by a qualified lawyer before public launch.
Last updated: [DATE]
The short version
- We only collect what the game needs: your email address, your password (stored only in scrambled, “hashed” form), your name, an optional nickname, your avatar, and what you do and post in your competitions.
- Other members only see your display name (for example “John D.”, or your nickname), your avatar and, if you are an admin, the Admin tag. Never your email address or full last name.
- Proof photos and comments are only visible to members of that competition. Proof photos are deleted automatically 30 days after the competition ends.
- No ads, no analytics, no tracking cookies, and we never sell your data.
- Our database and file storage are in Zurich, Switzerland. Some of our service providers are US companies, and some processing happens in Germany or elsewhere (see section 5).
- You can see, correct, download and delete your data. Just ask at [CONTACT EMAIL].
1. Who is responsible
The controller responsible for your personal data is:
Jarno Baumgartner
Switzerland
Email: [CONTACT EMAIL]
ToniChallenge is run by this private individual as a non-commercial side project (“we”, “us”).
- Data protection officer: [none appointed, CONFIRM that none is required].
- Representative in the EU (Art. 27 GDPR): [NAME AND ADDRESS OF EU REPRESENTATIVE, or delete this line if not required].
This policy is written to meet the information duties of the Swiss Federal Act on Data Protection (FADP) and, for users in the EU/EEA where it applies, the EU General Data Protection Regulation (GDPR). Legal bases below refer to the GDPR. Swiss law doesn’t require a legal basis for each processing activity, but we follow its processing principles in the same way.
2. What data we process, and why
2.1 Account data
- What: email address; password (stored only as a hash by our login provider, so nobody can read it); when you signed up, confirmed your email and last logged in; the page you signed up from (for example an invite link, so we can take you to the right competition after you confirm your email); and the date and time you confirmed you are 18 or older and accepted the Terms of Use.
- Why: to create and protect your account, log you in, send you service emails (such as the sign-up confirmation and password reset), and be able to show that you confirmed your age and accepted the terms.
- Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR); for the acceptance record, our legitimate interest in being able to prove it (Art. 6(1)(f) GDPR).
2.2 Profile data
- What: first name, last name, optional nickname, and avatar. Your avatar is either one of the ready-made characters, your initial, or your own photo (cropped to a square, made smaller and stripped of location data before upload). From your names we create your display name: “First name + initial of last name” (for example “John D.”), or your nickname if you set one.
- Why: so your group can see who is playing.
- Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR).
2.3 Competition and game data
- What:
- competitions you create: title word, tagline, start and end dates, your time zone (taken from your device, it sets when the competition starts and ends), chosen pack, challenge list, photo rules and rules text;
- memberships: your role (Owner, co-admin or participant), when you joined, and whether you left or were removed, when and by whom (we keep removals so that a removed person can’t rejoin through the invite link);
- completions: which challenge, when, the points, and the number you entered for per-unit challenges;
- tags: whom you tagged in a group challenge and who tagged you, including “Not me”;
- undos: who undid a completion, when, and the optional reason;
- invite links.
- Why: to run the game: challenge board, points, leaderboard, feed and results.
- Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR).
2.4 Content you post
- What: proof photos, comments, and custom challenges.
- Why: to show them to the members of the competition.
- Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR).
- Please don’t post sensitive information (for example about health, religion, political views or sex life) about yourself or others. [REVIEW: legal basis if photos reveal sensitive data.]
2.5 Reports and moderation
- What: when you report a photo or comment: what you reported, your reason, that you made the report, and when. When content is hidden, or an account suspended or a competition frozen: who did it, when, and the reason. We keep a log of our own moderation actions.
- Why: to keep ToniChallenge safe, handle reports, enforce our Terms of Use, and defend or pursue legal claims.
- Legal basis: our legitimate interest in a safe service (Art. 6(1)(f) GDPR); where the law requires us to act, a legal obligation (Art. 6(1)(c) GDPR).
2.6 Messages to us
- What: your email address and what you write to us.
- Why: to answer you and handle your request.
- Legal basis: our legitimate interest in answering (Art. 6(1)(f) GDPR), or our contract with you where your message is about your account (Art. 6(1)(b) GDPR).
2.7 Technical data
- What: when you visit the site, our hosting and database providers automatically process technical data needed to deliver it and keep it secure: IP address, date and time, the page or request, browser and device type, and error information. Our login provider also keeps security logs of sign-ins [CONFIRM contents, e.g. IP address].
- Why: to deliver the website, find errors, and detect and stop attacks.
- Legal basis: our legitimate interest in running a secure website (Art. 6(1)(f) GDPR).
2.8 Bot check [planned: Cloudflare Turnstile]
- What: when you sign up or reset your password, a bot check makes sure you are a human. The provider processes your IP address and technical browser and device information for this.
- Why: to prevent fake accounts, spam and abuse.
- Legal basis: our legitimate interest in preventing abuse (Art. 6(1)(f) GDPR).
2.9 What you must provide
You need to give us your email address, a password and your first and last name to create an account. Without them, you can’t use ToniChallenge. Everything else (nickname, own avatar photo, proof photos, comments) is up to you, unless a challenge requires a photo, in which case you can simply skip that challenge.
2.10 What we don’t do
- No advertising, no analytics, no tracking, and no profiling.
- We don’t sell or rent your data.
- We don’t send marketing emails, only emails needed for the service.
- We don’t make automated decisions about you that have legal or similarly significant effects.
3. Who can see your data
- The public: nothing about you. Competitions are invite-only and there are no public profiles.
- Members of a competition you are in: your display name, avatar and Admin tag; your completions, points and rank; the photos and comments you posted there; and tags. They never see your email address or full last name. [CONFIRM what remains visible to members after you leave or are removed.]
- Admins of that competition: the same as members, plus reports about content in their competition (including who made the report and the reason), hidden content, undo reasons, and who left or was removed. Admins also never see your email address or full last name.
- Us (the operator): we see reports and can act on content (hide it, suspend accounts, freeze competitions). For moderation, support and security, we can access account data, profiles, competitions and content. As the operator we also have technical access to the database, including email addresses. We only use this access to run and protect ToniChallenge.
- Outside ToniChallenge: members may share the end-of-competition results card (display names and scores [and avatars, CONFIRM], never proof photos) or take screenshots. We can’t control that.
- Service providers: see section 4.
- Authorities: only where the law requires it, or where it is needed to protect people or our rights (for example when reporting illegal content).
- A successor: if ToniChallenge is handed over to a new operator (for example an association or company set up to run it). We would tell you in advance.
4. Service providers (processors)
We use the following providers to run ToniChallenge. They process data on our behalf and according to our instructions, under data processing agreements [CONFIRM that each agreement is in place].
Supabase [LEGAL ENTITY]
Database, login, and storage of photos and avatars.
Company based in the USA.
Data stored in Zurich, Switzerland. [CONFIRM whether support or maintenance access from other countries is possible.]
Vercel [LEGAL ENTITY]
Website hosting and server functions.
Company based in the USA.
Server functions run in Frankfurt, Germany. Its content delivery network is global, so your request may pass through a server near you anywhere in the world.
Resend [LEGAL ENTITY]
Sending service emails (sign-up confirmation, password reset[, report notifications to the operator]).
Company based in the USA.
Region: [TO BE CONFIRMED].
Cloudflare [LEGAL ENTITY] [planned]
Bot check (Turnstile) on sign-up and password reset.
Company based in the USA.
Global network [CONFIRM].
We also use GitHub to store the website’s code. GitHub receives no user data.
5. Data outside Switzerland
- Your account, profile, game data and photos are stored in Switzerland.
- Some processing happens in Germany (Vercel’s server functions). The Swiss Federal Council recognises the EU/EEA as providing adequate data protection.
- Our providers are US companies, and some use global networks. Your data may therefore be processed in, or accessed from, the USA and other countries, for example through the global content delivery network or provider support.
- For these transfers we rely on: [PER PROVIDER, CONFIRM: certification under the Swiss-U.S. and EU-U.S. Data Privacy Framework, and/or the EU standard contractual clauses with the adaptations required under Swiss law]. You can ask us for a copy of these safeguards at [CONTACT EMAIL].
- Please be aware that authorities in the USA may, under US law, request access to data held by US companies.
6. How long we keep your data
Account and profile
As long as your account exists. After you delete it, removed within [X DAYS]. Backup copies are overwritten within [BACKUP RETENTION].
Your own avatar photo
Until you replace it (the old photo is then deleted) or delete your account.
Proof photos
Automatically deleted 30 days after the competition ends, or earlier when you delete your account. [CONFIRM what happens to a photo when a completion is undone.]
Comments, completions, tags and competition data
As long as the competition exists [RETENTION FOR ENDED COMPETITIONS, TO BE DECIDED, e.g. X months after the end]. Your completions are deleted when you delete your account. People you tagged keep their points. [CONFIRM what happens to your comments on group posts.]
Reports and moderation logs
[RETENTION, e.g. 12 months after the report is resolved], longer if needed for legal claims or by the authorities.
18+ and Terms acceptance record
As long as your account exists [+ PERIOD, if kept longer as evidence].
Emails to us
[RETENTION]
Technical logs at our providers
According to the providers’ settings [LOG RETENTION, CONFIRM].
We may keep data longer where the law requires it or where we need it to establish, exercise or defend legal claims.
7. Your rights
Under the FADP and, where it applies, the GDPR, you have the right to:
- access the personal data we hold about you;
- correct data that is wrong;
- delete your data;
- restrict processing (GDPR);
- object to processing based on our legitimate interests;
- data portability: receive the data you gave us in a common, machine-readable format;
- withdraw consent, where we rely on it (currently we don’t rely on consent for any processing).
How to use your rights
- Many things you can do yourself in the app: edit your profile, undo your own completions, leave competitions, and delete your account [in your profile settings, feature planned before launch].
- For everything else, email [CONTACT EMAIL]. To protect your data, we may ask you to confirm your identity, for example by writing from the email address of your account.
- It’s free. We reply within 30 days. In complex cases we may need longer where the law allows it, and we’ll tell you if so.
- Some rights have limits, for example where we need data to defend legal claims, or where other people’s rights are involved (such as a group photo someone else posted). We will explain if we can’t fully meet your request.
Right to complain
You can complain to a data protection authority:
- in Switzerland: the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, www.edoeb.admin.ch;
- in the EU/EEA: the data protection authority in the country where you live or work, or where you think the violation happened.
We’d appreciate the chance to sort things out first, so feel free to contact us.
8. If you appear in someone else’s photo
If you are shown in a photo on ToniChallenge and didn’t agree to it, contact us at [CONTACT EMAIL], even if you don’t have an account. Tell us which competition and photo it is, as far as you know. We will check and remove the photo where appropriate. Our users must only upload photos of people who agreed to it.
9. Cookies and similar technologies
We only use what is strictly necessary for the site to work:
Login session cookies (set by our login provider, names start with “sb-”)
Keep you logged in.
Until you log out or the session expires [SESSION DURATION, CONFIRM].
tc_recovery
Set when you open a password-reset link, so that only that link lets you set a new password.
15 minutes, or until used.
tc-install-banner-dismissed-at (local storage in your browser, not a cookie)
Remembers that you closed the “Add to home screen” hint. It stays on your device and is not sent to us.
30 days.
[Cloudflare Turnstile, planned]
[CONFIRM whether it stores anything in your browser, and for how long.]
No analytics, advertising or tracking cookies, and no social media plugins. Our fonts are stored on our own server, so your browser doesn’t contact Google to load them.
Because we only use strictly necessary technologies, we don’t show a cookie banner. You can delete cookies in your browser settings at any time; you will then be logged out.
10. How we protect your data
- All connections are encrypted (HTTPS).
- Passwords are stored only in hashed form by our login provider.
- Access rules are enforced directly in the database: members can only see the competitions they belong to.
- Photos are kept in private storage and shown only through short-lived links.
- Photos are made smaller and stripped of location data (GPS) before upload [currently on your device; additional cleaning on the server is planned].
- Only the operator has administrative access.
- A bot check protects sign-up and password reset [planned].
No system is completely secure. If a data breach happens, we will inform you and the authorities where the law requires it. Please use a strong password that you don’t use anywhere else.
11. Minimum age
ToniChallenge is only for people aged 18 or older. We rely on your confirmation at sign-up and don’t check ages. If you believe someone under 18 is using ToniChallenge, please tell us at [CONTACT EMAIL]. We will then close the account and delete its data.
12. Changes to this policy
We will update this policy when ToniChallenge changes, for example if we add “Continue with Google”, new providers or paid features. We will tell you about significant changes by email or on the site before they take effect. The date at the top shows when the policy was last changed.
13. Contact
Questions about your data? Email [CONTACT EMAIL]