1. Who is responsible for your data
The hosted service at pongladder.com is operated by Victor Pero, a private individual in Sweden, who is the data controller for the personal data described here. Questions and requests can be sent to the address at the bottom of this page.
This policy covers the hosted service only. Someone who runs their own copy of the open-source software is the controller for that copy, and this policy does not describe it.
2. What data is stored
Pong Ladder stores what it needs to run a ladder and to keep your account secure. Nothing here is bought from a third party or collected for advertising.
The application database holds:
- Account details: your name, username, email address, chosen interface language, whether the address has been verified and when, and the date the account was created and last changed.
- Sign-in credentials: for a password account, a bcrypt hash of your password — never the password itself — and when it was last changed. For Google sign-in, the identifier Google uses for you, the tokens the sign-in returned, the granted scope, and the profile picture URL Google supplies.
- Organization membership: which organizations you belong to, your role and status in each, your display name there, your team, how you joined, and when you were admitted or reviewed.
- Play data: which seasons you have joined, your ladder position and points, challenges you have sent or received, and match results with the games won by each player.
- Session records: for each active sign-in, a session token, its expiry, and the IP address and browser user agent the session was created from.
- Security records: hashed, expiring email-verification and password-reset tokens, hashed invitation tokens, a record of which invitation you redeemed and when, and an administrative audit trail of membership and organization changes — who changed whose role or status, and when.
3. Why the data is processed
Account details, membership, and play data are processed to provide the service you asked for: to sign you in, to place you on a ladder, to run challenges, and to show standings and statistics to your organization.
Session records, hashed tokens, and the audit trail are processed for the legitimate interest of keeping accounts and organizations secure — detecting misuse, letting an administrator see who changed what, and making sure an invitation or a reset link cannot be reused.
The service does not profile you, does not make automated decisions with legal effect about you, and does not use your data for advertising.
4. Google Sign-In
Where Google Sign-In is enabled, Pong Ladder requests only the identity scopes openid, email, and profile. It receives your email address, whether Google has verified it, your name, and your profile picture URL, and uses them to create or match your account.
Pong Ladder does not request access to your Gmail mailbox, your contacts, your calendar, your files, or any other Google data, and it cannot read or send mail on your behalf. A Google account is only linked to a Pong Ladder account with the same email address.
You can revoke Pong Ladder's access at any time from your Google account's third-party access settings. Doing so stops future Google sign-ins but does not by itself delete the Pong Ladder account.
5. Email
The service sends transactional email only: address verification, password reset, a notice when a password reset is requested for an account that signs in with Google, and a notification when another player challenges you. There is no marketing email and no newsletter.
Delivery goes over SMTP through an email provider — in the hosted service, Resend. The provider processes your email address and the message content in order to deliver it, and keeps its own delivery logs.
7. Local storage and request metadata
Your browser's local storage keeps one value: the version of the application you last saw, so the What's new indicator is not shown again. It never leaves your browser.
To limit abuse of sign-in, verification, and reset requests, the service counts recent attempts per IP address in memory. Those counters are short-lived and are not written to the database.
8. Who can see your data
Inside an organization you have joined, other members can see your name or display name, your ladder position and points, your team, your challenges, and your match history and statistics. That is the purpose of a ladder.
Organization administrators additionally see membership status and role, and the audit trail of changes they and other administrators have made.
Data is scoped per organization: members of one organization do not see the ladders, players, or results of another. Your email address is not shown to other members.
Your data is not sold, and it is not shared with anyone else except the service providers below or where the law requires it.
9. Service providers
Running the service requires a few providers, each processing data only to deliver their part of it: a hosting provider that runs the application, a managed PostgreSQL database that stores it, and an email provider, Resend, that delivers transactional messages.
Where a provider processes data outside the EU/EEA, that transfer relies on the safeguards in the provider's own data processing terms. The current list of providers can be requested at the contact address below.
10. Retention and deletion
Account, membership, and play data is kept while your account exists, because a ladder position and a season history are only meaningful over time.
Short-lived records expire on their own: verification and password-reset tokens expire and are consumed or replaced, a password reset clears every other session, and sessions expire after seven days.
Being removed from an organization marks the membership as removed rather than erasing it, and recorded matches stay in the ladder's history. A match result belongs to two players, so removing one player's side of it would misstate the other's record.
The application has no self-service account deletion yet. Ask at the contact address below and your account and personal data will be deleted, with match history anonymized where it has to be kept for the other player's record.
11. Your rights
Under the GDPR you have the right to access the personal data held about you, to have inaccurate data corrected, to have data erased, to restrict or object to processing, and to receive your data in a portable form.
Some of this you can do yourself: your name, display name, language, email address, and password are editable from your account page. For anything else, write to the address below. A request is answered without undue delay and within one month.
If you believe your data is handled incorrectly, you can complain to the Swedish Authority for Privacy Protection (IMY), or to the supervisory authority in the EU country where you live.
12. Changes to this policy
This policy is updated when the service changes what it stores or how. The effective date at the top of this page shows when the current wording took effect, and a substantive change is announced in the application's What's new page.
13. Contact
Privacy questions and requests about your data can be sent to the address below.