This Privacy Policy describes how [●] ("CompeteUp," the "Company," "we," "us," or "our"), as data controller, collects, uses, discloses, retains, and protects personal data in connection with the CompeteUp mobile application (the "App"), the websites at competeup.net, and all related services (collectively, the "Service"), and explains the rights available to you and how to exercise them.
This Privacy Policy is incorporated into and forms part of our Terms of Service. Where the processing of your personal data requires consent under applicable law, we will request that consent separately; otherwise, the legal bases identified in Section 4 apply.
1.Controller and Contact Information
Controller: [●] (legal entity), [●] (registered address)
Privacy inquiries and data-subject requests: privacy@competeup.net
General support: support@competeup.net
2.Personal Data We Collect
2.1 Data you provide to us
| Category | Data | Context |
|---|---|---|
| Account data | Email address; username; display name; password (stored exclusively as a salted cryptographic hash — we cannot read your password) | Required to create an account |
| Optional contact data | Phone number | Optional |
| Profile content | Profile photograph; cover photograph; biographical text | Optional; visible to other users |
| Communications | Messages to other users; friend requests; challenge invitations; reports you submit; correspondence with support | Generated through use |
| Commercial data | Subscription tier and status; purchase and gift history; gift-recipient email addresses | Generated upon purchase |
2.2 Data received from third-party sign-in providers
If you elect to sign in with Google, Apple, or Facebook, we receive from the relevant provider your name, email address, and a unique account identifier. We do not receive your password for those services. The provider's own privacy policy governs its independent processing.
2.3 Data collected automatically
| Category | Data |
|---|---|
| Gameplay data | Matches played; answers and scores; results; win/loss/tie records; experience points; level; streaks; coin and gem balances; achievements; tournament participation; leaderboard standings |
| Device and connection data | Device model; operating-system version; App version; language and time-zone settings; IP address; session and connection events |
| Notification data | Push-notification device token; notification delivery events |
| Diagnostics data | Crash reports; stack traces; error and performance telemetry; sampled visual session replays (Section 6) |
| Safety and integrity data | Automated content-moderation results for messages and profile content; enforcement and restriction history |
2.4 Data we do not collect
We do not collect precise geolocation data. We do not integrate third-party advertising SDKs, do not serve targeted advertising, and do not sell personal data or "share" it for cross-context behavioral advertising (as those terms are defined in the California Consumer Privacy Act, as amended). We do not knowingly collect personal data from children under the age of thirteen (Section 11).
3.Sources of Personal Data
We collect personal data: (a) directly from you; (b) automatically from your device and your use of the Service; (c) from third-party sign-in providers you choose to use (Section 2.2); and (d) from our payment processor in connection with your purchases (Section 5).
4.Purposes and Legal Bases of Processing
| Purpose | Principal data categories | Legal basis (GDPR / UK GDPR) |
|---|---|---|
| Operating the Service: account management, matchmaking, gameplay, scoring, leaderboards, tournaments, messaging, friends, and challenges | Account, profile, gameplay, communications | Art. 6(1)(b) — performance of a contract |
| Processing subscriptions, gifts, and payments; issuing receipts | Commercial data; email address | Art. 6(1)(b); Art. 6(1)(c) — retention of transaction records required by tax and accounting law |
| Account security: email verification, password reset, authentication, session management | Account data; verification codes; device data | Art. 6(1)(b); Art. 6(1)(f) — our legitimate interest in securing accounts |
| Delivering push notifications you have enabled | Notification data; account data | Art. 6(1)(b); consent, where required — withdrawable at any time in App or device settings |
| Safety and integrity: automated and human content moderation, anti-cheat and fraud detection, enforcement of our Terms of Service, prevention of ban evasion | Communications; safety and integrity data; gameplay and device data | Art. 6(1)(f) — our legitimate interest, and that of our users, in a safe and fair service; Art. 6(1)(c) where disclosure or action is legally required |
| Diagnostics: detecting, reproducing, and repairing crashes, errors, and performance defects (Section 6) | Diagnostics data | Art. 6(1)(f) — our legitimate interest in providing a stable, secure service |
| Legal compliance, establishment and defense of legal claims, and responses to lawful requests | Any relevant category | Art. 6(1)(c); Art. 6(1)(f) |
We do not engage in automated decision-making that produces legal or similarly significant effects concerning you. Moderation and anti-cheat determinations are subject to the review and appeal mechanisms described in our Terms of Service.
5.Payment Processing (Stripe)
Payments are processed by Stripe, Inc. and its affiliates ("Stripe"). When you make a purchase:
- Your payment-card credentials are transmitted directly from your device to Stripe and are processed exclusively by Stripe. We never receive, transmit, or store full card numbers or card-security codes.
- We receive from Stripe, and retain, the data necessary to administer your purchase: transaction identifiers, payment status, card brand and final four digits, subscription status, and related billing metadata. We use this data for order fulfillment, receipts, customer support, fraud prevention, and compliance with tax and accounting obligations.
- Stripe processes payment data as our processor and, for certain regulatory, security, and fraud-prevention purposes, as an independent controller under its own privacy policy, available at stripe.com/privacy.
Where a purchase is made through Apple's App Store or Google Play, the transaction is processed by the relevant platform under its own terms and privacy policy, and we receive only transaction confirmation and entitlement data.
6.Diagnostics and Crash Reporting (Sentry)
We use Functional Software, Inc. d/b/a Sentry ("Sentry"; privacy policy at sentry.io/privacy) to detect, diagnose, and remediate errors, crashes, and performance defects in the Service:
- Crash and error reports comprise stack traces, error messages, App version, operating-system and device-model information, and relevant technical state at the time of the error, associated with a pseudonymous identifier and, where you are signed in, your user identifier, so that we can investigate problems you report to us.
- Session replay captures, for a limited sample of sessions and for sessions in which an error occurs, a visual reconstruction of in-App screens and interactions preceding the issue. Session replays are used exclusively for debugging and quality assurance. They are not used for marketing, advertising, or profiling.
- Sentry processes diagnostics data as our processor pursuant to a data-processing agreement. Diagnostics data is retained for ninety (90) days and deleted automatically thereafter.
7.Disclosure of Personal Data
We do not sell personal data, and we do not disclose personal data to any third party for that party's own marketing or advertising purposes. We disclose personal data only as follows.
7.1 Processors
We engage the following categories of service providers, each bound by contract to process personal data only on our documented instructions and to protect it appropriately:
| Recipient | Function | Data concerned |
|---|---|---|
| Stripe, Inc. | Payment processing (Section 5) | Commercial and billing data |
| Functional Software, Inc. (Sentry) | Crash reporting and diagnostics (Section 6) | Diagnostics data |
| Cloudflare, Inc. | Content delivery, network security, and object storage of profile and cover photographs | Profile content; technical data |
[●] — application hosting provider | Hosting of application servers and databases | All Service data |
[●] — transactional email provider | Delivery of verification codes, receipts, and account email | Email address; message content |
| Expo; Apple (APNs); Google (FCM) | Push-notification delivery | Notification data |
7.2 Other users of the Service
Your username, display name, profile photograph, cover photograph, biographical text, level, and gameplay statistics are visible to other users as an inherent feature of a multiplayer game. Messages you send are visible to their recipients. Your email address, phone number, and purchase history are never displayed to other users. The App provides controls over who may message and challenge you.
7.3 Sign-in providers
If you use third-party sign-in, the relevant provider necessarily learns that you use the Service.
7.4 Legal, protective, and corporate disclosures
We may disclose personal data: (a) to comply with applicable law, regulation, legal process, or an enforceable governmental request; (b) to enforce our Terms of Service and to investigate actual or suspected fraud, cheating, security incidents, or violations; (c) where necessary to protect the rights, property, or safety of the Company, our users, or the public; and (d) in connection with, or during negotiations of, a merger, acquisition, financing, reorganization, or sale of some or all of our assets, in which case the acquiring entity will be bound by this Privacy Policy or terms materially no less protective, and you will be notified of any successor.
8.International Data Transfers
We and our processors may process personal data in the United States and in other countries whose data-protection laws may differ from those of your jurisdiction. Where personal data of individuals in the EU, EEA, UK, or Switzerland is transferred to a country not recognized as providing adequate protection, we implement appropriate safeguards, namely: certification of the recipient under the EU–U.S. Data Privacy Framework (and its UK and Swiss extensions), where applicable, and/or the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), together with supplementary measures where required. A copy of the relevant safeguards may be requested at privacy@competeup.net.
9.Data Retention
We retain personal data only as long as necessary for the purposes described in this Policy, in accordance with the following schedule:
| Data | Retention period |
|---|---|
| Account, profile, gameplay, and communications data | Duration of the account; deleted or irreversibly anonymized within thirty (30) days after verified account deletion, subject to the exceptions below |
| Enforcement records of banned accounts | Retained in minimized form for so long as necessary to enforce the ban and prevent ban evasion |
| Commercial and transaction records | The period required by applicable tax, accounting, and financial-reporting law |
| Email verification and password-reset codes | Expire automatically within minutes to hours of issuance |
| Diagnostics data (Sentry) | Ninety (90) days |
| Backup media | Rolling backup cycle of [●] days; deleted data ages out of backups automatically |
| Data subject to legal hold | Until the relevant dispute, investigation, or obligation is resolved |
10.Your Rights
10.1 Rights available. Subject to applicable law — including the GDPR, the UK GDPR, and the California Consumer Privacy Act as amended ("CCPA") — you may have the right to: access your personal data and obtain a copy in a portable format; rectify inaccurate or incomplete data; erase your data; restrict or object to processing, including any processing based on legitimate interests; withdraw any consent at any time (without affecting prior processing); and be free from discrimination for exercising any of these rights.
10.2 How to exercise. You may exercise applicable rights: (a) directly in the App — by editing your profile, removing photographs, managing who may message or challenge you, and managing notifications; or (b) by submitting a request to privacy@competeup.net. We will verify each request — ordinarily by correspondence through the email address associated with your account — and respond within the period required by applicable law (one month under the GDPR; forty-five days under the CCPA; in each case extendable where the law permits). You may designate an authorized agent to act on your behalf where applicable law allows; we will require evidence of the agent's authority.
10.3 Account deletion. You may request deletion of your account and associated personal data at any time through the means described in Section 10.2. Deletion is subject to the retention exceptions set out in Section 9.
10.4 Limitations. These rights are subject to the exemptions and limitations of applicable law. In particular, we may retain transaction records required by tax and accounting law, and the minimized data necessary to enforce account bans, to establish or defend legal claims, and to maintain the security and integrity of the Service.
10.5 Complaints. If you are in the EU, EEA, or UK, you have the right to lodge a complaint with the supervisory authority of your habitual residence, place of work, or the place of the alleged infringement. We would welcome the opportunity to address your concerns first at privacy@competeup.net.
10.6 California disclosures. In the preceding twelve months we have collected the categories of personal information described in Section 2 — identifiers; customer-records information; commercial information; internet or other electronic-network activity; audio-visual information (photographs you upload); and inferences limited to in-game statistics — for the purposes stated in Section 4, and have disclosed them for business purposes to the service providers identified in Section 7.1. We have not sold or shared personal information within the meaning of the CCPA, and we have no actual knowledge of selling or sharing the personal information of consumers under sixteen years of age. Because we do not sell or share personal information or engage in cross-context behavioral advertising, opt-out preference signals (such as Global Privacy Control) do not alter our processing.
11.Children
The Service is not directed to children under thirteen (13) years of age — or, where higher, the applicable minimum age of digital consent (up to sixteen (16) in certain EU member states) — and we do not knowingly collect personal data from any child below the applicable age. If we obtain actual knowledge that we have collected personal data from a child below the applicable age without legally valid consent, we will delete that data promptly. A parent or guardian who believes that a child has provided personal data to us may contact privacy@competeup.net.
12.Security
We maintain technical and organizational measures appropriate to the nature and risk of the data we process, including: encryption of data in transit (TLS/HTTPS and WSS); salted cryptographic hashing of passwords; logical access controls and least-privilege restrictions on production systems; isolation of payment processing such that card credentials never reach our systems (Section 5); automated content-moderation and abuse-detection systems; and continuous error and security monitoring. No security program eliminates all risk, and we cannot guarantee absolute security; you are responsible for maintaining the confidentiality of your credentials. In the event of a personal-data breach giving rise to a legal notification obligation, we will notify the competent authority and affected individuals as and when required by applicable law.
13.Communications Preferences
- Push notifications may be managed at any time in the App's settings and at the operating-system level.
- Service email (verification codes, receipts, security notices) is integral to the operation of the Service. Should we introduce marketing email, it will be sent only as permitted by applicable law and will include functioning unsubscribe mechanisms.
14.Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The current version will always be available at competeup.net/privacy, identified by its effective date. We will provide reasonable advance notice of material changes through the Service or by email. Amendments do not apply retroactively to previously collected data except as permitted by applicable law.
15.Contact
[●] (legal entity)
[●] (registered address)
Privacy inquiries and data-subject requests: privacy@competeup.net
General support: support@competeup.net