Who is responsible
- Operator / controller
- [TO COMPLETE: full legal name]
- Tax identification (NIF)
- [TO COMPLETE: NIF]
- Address
- [TO COMPLETE: full legal contact address]
- Country of establishment
- Spain
- Contact
- [TO COMPLETE: contact email]
What this version records
- Visits and presence: a random browser-session identifier, first and latest visit times and whether that session has a confirmed paid attack. These power the visit counter and active-player count. They do not establish the number of unique people.
- Prelaunch support: a random browser identifier and selected side. Selecting the same side again does not add another supporter. Switching sides changes the stored choice.
- Public activity: support events contain a side, time and relevant side changes. Confirmed attack events contain the side, pixel count, time and change in territory. Browser identifiers and payment details are not displayed in the relay. The short reactions are generated by the site, not written by visitors.
- Purchases, when enabled: order and payment references, side, amount, pixel count, time, status and any refund reference. The final attack is identified in the battle record and linked privately to its order. This does not publish the payer’s identity. The payment provider handles payment details. The battle database does not store card numbers.
- Abuse prevention: short-lived request counts use your support identifier and a daily changing, keyed hash of your network address. The application does not store the raw address in these counts. Limits expire within an hour; expired records are removed on subsequent protected requests. This reduces automated submissions but does not verify unique people.
- Technical requests and enquiries: hosting providers may process connection information such as IP addresses and request logs. Contacting the operator provides the information you include in your message.
There are no visitor accounts, nicknames, public message submissions or advertising trackers added by the application. Random identifiers can still be personal data; they are not a promise of complete anonymity. The Archive contains authored fiction, not recovered private visitor conversations.
Purposes and legal bases
Support identifiers enable the team choice requested by the visitor. Order information is needed to fulfil purchases, resolve payment problems and meet applicable record-keeping obligations. Technical security data protects the service; enquiries are used to respond to the sender.
[TO COMPLETE: Confirm the legal basis for each purpose, including the requested free support service, the legitimate-interest assessment for security, and the legal obligations for payment records. Decide and implement consent or a verified exemption for visit measurement before publication.]
Cookies and browser storage
pixel-supporter — first-party cookie
Set when you choose a team. Contains a random identifier used to remember one choice for this browser. It is inaccessible to page scripts. It lasts up to one year, or until the scheduled launch if that comes first, and is renewed when you choose a side. Previously issued cookies retain their expiry until your next choice. Choosing a side does not buy pixels. Clearing this cookie or using another browser creates a separate support identity.
pixel-visit — session storage
Created when the battle page opens. Identifies a browser session for the visit counter and presence updates. It normally lasts for the tab session, subject to browser session restoration. A corresponding server record remains after browser storage is cleared.
pixel-pending-receipt — session storage
Temporarily remembers a checkout reference so a pending confirmation can resume after a reload. Removed when the payment reaches a final state, or when the tab session ends.
pixel-player-proof — session storage
Saved after a confirmed attack to associate active presence with a paid attack. Contains a checkout reference. It normally lasts for the tab session, subject to browser session restoration. It is not a card number.
You can clear or block site storage using your browser settings. Doing so can reset your saved team choice or session recognition. Clearing browser storage does not automatically delete server records.
[TO COMPLETE: The current local preview starts visit measurement on page load. It does not yet provide a consent preference control. Audit this measurement and any payment-provider storage before deciding whether a consent control is required; do not describe all storage as exempt by default.]
Providers and international processing
The application is built for Cloudflare hosting and database storage. Stripe is the intended payment provider; payments are not enabled. Their final contractual roles, processing locations and arrangements have not yet been confirmed for this project.
[TO COMPLETE: List the contracted hosting, payment and email providers, their roles and any processing outside the EEA, including the applicable transfer safeguards and how to obtain information about them.]
Retention
Browser-storage lifetimes are described above. Expiration of the support cookie does not erase the server-side choice. The local implementation currently has no scheduled deletion for visit, supporter, event or order records.
[TO COMPLETE: Set and implement server retention periods for each category, including backups and logs. Keep financial records for the confirmed statutory periods; remove or anonymise other identifiers when no longer needed. Then replace this draft paragraph with the actual periods or criteria.]
Your rights
You may request access, correction, erasure, restriction or portability where applicable, and object to processing on the relevant grounds. Where processing uses consent, you may withdraw it without affecting earlier lawful processing. Contact the controller above. Requests may require proportionate verification; do not send card details or identity-document copies in an initial enquiry.
You may complain to the Spanish Data Protection Agency (AEPD) or your competent supervisory authority. The site does not make automated decisions with legal or similarly significant effects about visitors.