Privacy Policy
Last updated: 2026/06/27
1. Controller / Who we are
CycloDraft is operated by Willem Aarts (“we”, “us”).
Contact: cyclodraft@gmail.com
Location: NL
2. Scope
This Privacy Policy explains how we collect, use, and share personal data when you use CycloDraft (the “Service”), whether accessed through our website or our mobile application distributed through the Apple App Store and Google Play Store.
3. Data we collect
- Account data: username, email address, password (stored as a secure hash incl. salt, not in plain text).
- Gameplay data: teams you submit, rider collection, pack openings, scores, rankings, and related in-game actions.
- Technical data: IP address, device/browser type, device model, operating system version, app version (when using the mobile app), timestamps, and server-level access logs (retained by our infrastructure provider for security and troubleshooting).
- Performance logs: request path, HTTP method, response time, database query count, and browser/device type (derived from user-agent string). No IP address and no account identifier is stored in these application-level logs. Retained for 90 days. Legal basis: legitimate interest (service performance monitoring and debugging).
- Analytics data (when cookies are accepted): page views, session and interaction data, approximate location, device and browser information.
4. Why we process data (purposes)
- To provide the Service and maintain your account.
- To operate core gameplay (teams, scoring, rewards, and leaderboards).
- To secure the Service, prevent abuse, and debug issues.
- To understand usage patterns and improve the Service (analytics, only with consent where required).
5. Legal bases (EEA/UK GDPR)
- Contract: to provide the Service you request (account + gameplay).
- Legitimate interests: security, fraud prevention, and service improvement (non-intrusive, necessary processing).
- Consent: for analytics cookies and similar technologies (e.g., Google Analytics), where required by law.
6. Cookies and similar technologies
We use cookies and/or similar technologies for:
- Strictly necessary functions (e.g., login/session and security). These do not require consent in the EU/EEA.
- Analytics (Google Analytics). In the EU/EEA, we enable analytics only after you provide consent via our cookie banner.
You can change or withdraw analytics consent at any time via the Cookie Settings link in the footer of every page, or by clearing cookies in your browser.
7. Sharing of data
We do not sell personal data.
We share data with service providers only as needed to operate the Service, including:
- Linode (Akamai Technologies, Inc.) — our hosting and infrastructure provider. The application runs on Ubuntu/Nginx/Gunicorn servers. All application data is stored and processed on these servers.
- Google Analytics (Google LLC) (analytics, subject to your consent where required).
8. International transfers
Some providers (such as Google) may process data outside your country, including outside the EU/EEA. Where required, we rely on appropriate safeguards (e.g., Standard Contractual Clauses) offered by providers.
9. Retention
- Account + gameplay data: retained while your account is active. You can delete your account from the My Account page. After requesting deletion, there is a 14-day grace period during which you can cancel. After the grace period, all account and gameplay data is permanently deleted.
- Security logs: retained for a limited period for security and troubleshooting.
- Analytics data: retained per our Google Analytics retention settings.
10. Your rights
Depending on your location, you may have rights to access, correct, delete, or restrict processing of your personal data, and to withdraw consent (for analytics). You can delete your account directly from the My Account page. For other requests, contact: cyclodraft@gmail.com. We will respond within 30 days.
If you are in the EU/EEA, you have the right to lodge a complaint with your national data protection authority. For users in the Netherlands: Autoriteit Persoonsgegevens (AP).
11. Security
We apply reasonable technical and organizational measures to protect personal data (e.g., hashed passwords and access controls). No method of transmission or storage is 100% secure.
12. Children
The Service is not intended for children under 16 years of age (the minimum age for digital services under Dutch law). If you believe a child provided personal data, contact us and we will take appropriate steps.
13. Changes
We may update this policy from time to time. The “Last updated” date reflects the latest version. Your continued use of the Service means you acknowledge the updated policy.