Privacy
Privacy Policy
In compliance with the General Data Protection Regulation (GDPR — EU 2016/679, arts. 13–14).
Data Controller
- Data controller: Armand Zireg (private individual), contact: armandzireg@gmail.com
- PrancingPika does not store passwords. Authentication is handled exclusively via third-party OAuth providers (Discord, Google).
- For any data-related request, contact: armandzireg@gmail.com — responses within 30 days.
Authentication
- Users authenticate exclusively via Discord OAuth or Google OAuth. No password is ever created or stored on PrancingPika.
- A user may link both a Discord account and a Google account to the same PrancingPika account.
- During authentication, Discord and Google receive data as part of their respective OAuth flows (user ID, email address, profile picture, depending on granted scopes). Users should refer to Discord's Privacy Policy and Google's Privacy Policy for how each provider handles this data.
- PrancingPika only retains the minimum identifiers necessary to maintain your account (see data table below).
Processing Purposes
- Account management: authenticating users via Discord/Google OAuth and identifying players in leaderboards.
- Service delivery: parsing combat log files and displaying DPS/HPS rankings.
- Security: connection logs to detect and prevent abuse.
- No behavioural profiling, no targeted advertising, no sale of data to any third party for commercial purposes.
- No automated decision-making or automated profiling with legal or similarly significant effects.
Data Collected — Summary
| Data | Legal basis | Retention |
|---|---|---|
| Discord user ID, username, avatar | Contract performance (authentication) | Duration of account |
| Google account ID, email, display name | Contract performance (authentication) | Duration of account |
| Combat log files (uploaded by user) | User consent | Not automatically deleted — periodically reviewed and deleted manually by the operator |
| Leaderboard scores and parsed results | Legitimate interest (site functionality) | Retained indefinitely unless a justified erasure request is submitted |
| Connection logs (IP address, timestamp) | Legitimate interest (security) | Minimum 6 months, maximum 1 year |
Cookies
- PrancingPika uses a single session cookie, strictly necessary for maintaining your authenticated session (NextAuth).
- This cookie is not persistent: it is deleted upon logout or when you close your browser.
- No tracking cookies, no third-party analytics (e.g. Google Analytics), no advertising pixels.
Third-Party Recipients
- OVH SAS (2 rue Kellermann, 59100 Roubaix, France) — hosting infrastructure only. OVH has no access to user data stored on the server.
- Discord Inc. — receives data during Discord OAuth authentication. Subject to Discord's Privacy Policy (discord.com/privacy).
- Google LLC — receives data during Google OAuth authentication. Subject to Google's Privacy Policy (policies.google.com/privacy).
- No data is sold to, shared with, or rented to any other third party.
Your Rights (GDPR arts. 15–21)
- Right of access (art. 15) — obtain a copy of your personal data.
- Right of rectification (art. 16) — correct inaccurate data.
- Right to erasure (art. 17) — request deletion of your data. For leaderboard scores, requests must include a brief justification; the operator may refuse requests that are manifestly unfounded or abusive.
- Right to data portability (art. 20) — receive your data in a structured, machine-readable format.
- Right to object (art. 21) — object to processing based on legitimate interest.
- Right to restriction (art. 18) — request temporary suspension of a processing activity.
- To exercise any of these rights, contact: armandzireg@gmail.com — response within 30 days.
Right to Lodge a Complaint
- If you believe your rights under GDPR are not being respected, you may lodge a complaint with the French supervisory authority, the Commission Nationale de l'Informatique et des Libertés (CNIL).
- Legal Notice
Last updated: March 2025