Legal
Privacy & Cookie Policy
This notice describes how we process the personal data of users of the GP Clash mobile app and website, the legal bases for doing so, and the rights you have under the GDPR.
Last updated: 2 June 2026
1. Introduction & scope
This Privacy & Cookie Policy describes how personal data of users (“you”, the “User”) is processed when you use the GP Clash mobile application (the “App”) and website (the “Website”), together the “Service”. GP Clash is an independent fantasy Formula 1 game.
We process personal data in accordance with Regulation (EU) 2016/679 (the “GDPR”), Legislative Decree 196/2003 (the Italian Privacy Code, as amended by Legislative Decree 101/2018), and the guidelines of the Italian Data Protection Authority (Garante). Please read this notice carefully before using the Service.
2. Data controller
The data controller is Cosimo Orlacchio, with registered office at Via G. Ocone - Ponte (BN) Italy, VAT / Tax code IT01836370625. Contact email: [email protected].
The data controller has not appointed a Data Protection Officer (DPO), as the conditions set out in Art. 37 GDPR do not apply. For any request relating to the processing of your personal data, you may contact the data controller at the email address above.
3. Personal data we collect
We collect the following categories of personal data.
3.1 Data you provide
Data you provide directly when creating an account and using the Service:
- Registration data: email address and a securely hashed password (passwords are hashed with Argon2id and never stored in plaintext).
- Sign-in via Apple or Google (optional): when you choose “Sign in with Apple” or “Google Sign-In”, we receive your name, email address and (for Google) profile picture from the provider.
- Profile data: display name / nickname and preferred language (locale).
- Support data: the content of support tickets and messages you send us, including the email address you provide.
3.2 Data collected automatically
Data collected automatically when you use the Service:
- Usage data: how you interact with the Service (features used, in-game activity, session duration).
- Device data: device model, operating system, App version, language, screen resolution.
- Identifiers: internal user ID, device identifiers and advertising identifiers (IDFA on iOS, Google Advertising ID on Android) — the latter collected only with your prior consent.
- Network data: IP address (from which an approximate city/region-level location may be derived).
- Crash and diagnostic data: error logs, stack traces, and device state at the time of an error.
- The App does not access your GPS location, contacts, camera, or microphone.
4. Purposes of processing & legal bases
We process your personal data for the purposes below, each with its legal basis under Art. 6 GDPR.
| Purpose | Data processed | Legal basis |
|---|---|---|
| Registration & authentication (email/password and Apple/Google Sign-In) | Email, hashed password, name, profile picture, nickname | Contract — Art. 6(1)(b) |
| Providing the game (leagues, auctions, line-ups, duels, standings) | Profile data, usage and in-game activity data | Contract — Art. 6(1)(b) |
| Payments & subscriptions (purchases via the App Store / Google Play) | User ID, transaction data | Contract — Art. 6(1)(b) |
| Personalised advertising | Advertising identifiers (IDFA/GAID), usage data, device data, IP | Consent — Art. 6(1)(a) |
| Non-personalised advertising (without consent for personalisation) | Usage data, device data | Legitimate interest — Art. 6(1)(f) (financial sustainability of the free service) |
| Analytics & service improvement | Usage data, device data, IP (anonymised) | Legitimate interest — Art. 6(1)(f) |
| Crash reporting & debugging | Error logs, device data, app state | Legitimate interest — Art. 6(1)(f) (stability and security) |
| Service push notifications (results, rounds, leagues) | Device token, notification preferences | Contract — Art. 6(1)(b) |
| Promotional push notifications | Device token | Consent — Art. 6(1)(a) |
| Security, fraud and cheating prevention | Account, usage and device data | Legitimate interest — Art. 6(1)(f) |
| Legal & tax obligations relating to transactions | Transaction data | Legal obligation — Art. 6(1)(c) |
5. Third-party services & processors
We do not sell your personal data. We share it only with service providers (processors) acting on our behalf under data processing agreements, and with the authentication/store providers you choose to use. The actual SDKs integrated must be confirmed and kept accurate.
- Authentication: Sign in with Apple (Apple Inc., USA) and Google Sign-In (Google LLC, USA) — name, email, profile picture.
- Hosting & database: DigitalOcean (data hosted in the European Union) — account, profile and gameplay data.
- Object storage: DigitalOcean Spaces (S3-compatible object storage, EU region) — user-uploaded media such as profile pictures.
- Payments & subscriptions: Apple App Store and Google Play Store process all payments; we do not collect or store card or payment-instrument data. Subscription entitlements are managed by RevenueCat (RevenueCat, Inc., USA), which processes your purchase and transaction data and a pseudonymous app user ID.
- Advertising: Google AdMob (Google LLC, USA) and Meta Audience Network (Meta Platforms Ireland Ltd.) — advertising identifiers, usage and device data; activated only after consent.
- Analytics: Google Analytics for Firebase (Google LLC, USA) — usage and device data.
- Crash reporting: Firebase Crashlytics (Google LLC, USA) — error logs and device data.
- Push notifications: Firebase Cloud Messaging — FCM (Google LLC) — device push token.
6. International data transfers
Account, profile and gameplay data are hosted within the European Union (DigitalOcean, EU region) and are not transferred outside the EEA for hosting purposes.
Some providers above (e.g. Apple, Google, Meta and other advertising/analytics SDKs) are based in the United States. Such transfers rely on the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023) for certified providers, and on the European Commission’s Standard Contractual Clauses (Implementing Decision 2021/914) for the others. You may request details of the specific safeguards by contacting us.
7. Data retention
We keep personal data only as long as necessary for the purposes for which it was collected.
| Data category | Retention period |
|---|---|
| Account data (email, nickname, profile picture) | For the life of the account; deleted on account closure. |
| In-game activity data (leagues, standings, scores) | For the life of the account; deleted on account closure. |
| Transaction & billing data | 10 years from the transaction (Art. 2220 Italian Civil Code and tax law). |
| Analytics data | Aggregated/anonymised; raw event data up to 14 months. |
| Crash reporting data | Up to 90 days from collection. |
| Advertising data | Per the respective providers’ policies; consent revocable at any time. |
| Push notification tokens | Until notifications are disabled or the account is closed. |
| Support tickets | Up to 24 months after the ticket is resolved. |
8. Cookies & tracking technologies
Website: the Website uses only a strictly-necessary cookie that stores your language preference (NEXT_LOCALE). It has no login or session tokens, does not use profiling, third-party analytics, or advertising cookies, and self-hosts its fonts (no requests to third-party font services).
App: the App uses tracking SDKs for the purposes in Section 4. Before activating SDKs that collect data for personalised advertising, the App requests your explicit consent through the Google UMP consent module and, on iOS, Apple’s App Tracking Transparency (ATT) framework. You can change your consent preferences at any time in the App or device settings.
9. Push notifications
The App may send two types of push notification:
- Service notifications — relating to gameplay (results, rounds, league updates), sent on the basis of the contract.
- Promotional notifications — about news, offers or new features, sent only with your consent.
10. Your rights under the GDPR
Under Articles 15–22 GDPR, you have the right to:
- Access (Art. 15) — confirmation of whether your data is processed and a copy of it.
- Rectification (Art. 16) — correction of inaccurate or incomplete data.
- Erasure (Art. 17, “right to be forgotten”).
- Restriction of processing (Art. 18).
- Data portability (Art. 20) — your data in a structured, machine-readable format.
- Objection (Art. 21) — including, for direct-marketing processing, the right to have it cease immediately.
- Not to be subject to solely automated decision-making (Art. 22).
- Withdraw consent at any time (Art. 7(3)), without affecting prior lawful processing.
11. How to exercise your rights
You can export your personal data and permanently delete your account directly in the app (Settings → Account); these self-service tools satisfy your access, portability, and erasure rights. You can also exercise any of your rights by writing to [email protected]. We will respond within 30 days of receiving the request (extendable by a further 60 days for complex requests, with prior notice).
To revoke consent to personalised advertising you can also: on iOS, Settings → Privacy & Security → Tracking; on Android, Settings → Google → Ads → Delete advertising ID.
You also have the right to lodge a complaint with the Italian supervisory authority: Garante per la Protezione dei Dati Personali, Piazza Venezia 11, 00187 Roma — www.garanteprivacy.it, email [email protected], PEC [email protected].
12. Children
The Service is intended for users aged 14 years or older, in accordance with Art. 2-quinquies of Legislative Decree 196/2003. We do not knowingly collect personal data from minors under 14. If we become aware that we have collected such data without the consent of the holder of parental responsibility, we will promptly delete it. Parents or guardians may contact us at [email protected].
13. Nature of data provision
Providing registration data (email, or name/email via Apple/Google Sign-In) is necessary to create an account and use the Service; without it, the account cannot be created. Providing data for personalised advertising and promotional notifications is optional, and refusing it does not affect access to the Service.
14. Data security
We adopt appropriate technical and organisational measures to protect your data, including:
- Encrypted communications via HTTPS/TLS.
- Passwords hashed with Argon2id; data at rest protected by our hosting provider.
- Access to personal data restricted to authorised personnel.
- Secure authentication through trusted providers (Apple, Google).
- Ongoing monitoring of security and stability.
15. Changes to this policy
We may update this notice from time to time. Changes are published on this page with an updated “last updated” date; for material changes we will notify you through the Service. Continued use after changes take effect constitutes acceptance of the updated notice.
16. Contact
Data controller: Cosimo Orlacchio — Via G. Ocone - Ponte (BN) Italy. Email: [email protected].
17. Definitions
- Personal Data: any information relating to an identified or identifiable natural person.
- User: the natural person who uses the Service.
- Data Controller: the entity that determines the purposes and means of processing.
- Data Processor: a party that processes personal data on behalf of the controller.
- Service: the GP Clash App and Website.