GlitchIt

Effective 2 August 2026

Privacy Policy

This policy explains how Spiri Francesco Pio handles personal data when you use GlitchIt.

1. Data we process

We process account and security data; profile and preference data; community, team, message, notification, and tournament activity; uploaded asset metadata; essential session data; and limited security signals. Passwords, session tokens, and recovery tokens are stored only in protected hashed or encrypted forms appropriate to their purpose.

2. Why we process it

We use data to provide accounts and requested features, operate teams and tournaments, deliver transactional email and realtime updates, prevent abuse, secure and troubleshoot the service, comply with law, and improve reliability. Depending on the activity, the legal basis is performance of our agreement, legitimate security/operational interests, consent, or legal obligation.

3. Riot account data

If you choose Riot Sign On, we may retain your Riot subject or PUUID, game name, tag line, linked provider, and verification timestamps. We use this data to display the linked identity, retrieve requested League profile/rank data, and establish tournament eligibility. Unlinking removes the stored link fields. We do not publish private custom-match history as a general player database.

4. Service providers and disclosures

We use vetted providers for hosting and databases (Railway), network/security and transactional email (Cloudflare), media storage (Cloudinary), commerce where used (Shopify), and Riot identity/game services. They receive only the data needed for their role. We may also disclose information when legally required or necessary to protect users and the service.

5. Retention

Account and feature data is kept while the account or related operation is active and then deleted or anonymized according to the applicable lifecycle. Pseudonymous risk signals expire after no more than 90 days. Security/audit records may be retained longer where necessary to investigate abuse, demonstrate authorization, or meet legal obligations.

6. Your choices and rights

You can update profile data, unlink Riot, and request access, correction, export, objection/restriction where applicable, or account deletion. Contact privacy@glitchit.net. We may verify identity before completing a sensitive request. You may also complain to your competent data-protection authority.

7. Cookies and security

GlitchIt uses essential session and security storage needed to sign you in and protect requests. We use layered access controls, least-privilege credentials, HTTPS, rate limits, audit trails, and tested recovery, but no online service can guarantee absolute security. Report security concerns to security@glitchit.net.

8. International processing and children

Providers may process data outside your country under lawful transfer safeguards. GlitchIt is not directed to children who cannot lawfully consent to the service in their country; a parent or guardian should contact us if a child supplied data improperly.

9. Changes and contact

We date material updates and provide additional notice where required. The data controller is Spiri Francesco Pio, Theodor-Körner-Straße 27, 69115 Heidelberg, Germany. Privacy questions and requests should be sent to privacy@glitchit.net.