GPCLASH
Back to home

Legal

Privacy & Cookie Policy

This notice describes how we process the personal data of users of the GP Clash mobile app and website, the legal bases for doing so, and the rights you have under the GDPR.

Last updated: 2 June 2026

1. Introduction & scope

This Privacy & Cookie Policy describes how personal data of users (“you”, the “User”) is processed when you use the GP Clash mobile application (the “App”) and website (the “Website”), together the “Service”. GP Clash is an independent fantasy Formula 1 game.

We process personal data in accordance with Regulation (EU) 2016/679 (the “GDPR”), Legislative Decree 196/2003 (the Italian Privacy Code, as amended by Legislative Decree 101/2018), and the guidelines of the Italian Data Protection Authority (Garante). Please read this notice carefully before using the Service.

2. Data controller

The data controller is Cosimo Orlacchio, with registered office at Via G. Ocone - Ponte (BN) Italy, VAT / Tax code IT01836370625. Contact email: [email protected].

The data controller has not appointed a Data Protection Officer (DPO), as the conditions set out in Art. 37 GDPR do not apply. For any request relating to the processing of your personal data, you may contact the data controller at the email address above.

3. Personal data we collect

We collect the following categories of personal data.

3.1 Data you provide

Data you provide directly when creating an account and using the Service:

  • Registration data: email address and a securely hashed password (passwords are hashed with Argon2id and never stored in plaintext).
  • Sign-in via Apple or Google (optional): when you choose “Sign in with Apple” or “Google Sign-In”, we receive your name, email address and (for Google) profile picture from the provider.
  • Profile data: display name / nickname and preferred language (locale).
  • Support data: the content of support tickets and messages you send us, including the email address you provide.

3.2 Data collected automatically

Data collected automatically when you use the Service:

  • Usage data: how you interact with the Service (features used, in-game activity, session duration).
  • Device data: device model, operating system, App version, language, screen resolution.
  • Identifiers: internal user ID, device identifiers and advertising identifiers (IDFA on iOS, Google Advertising ID on Android) — the latter collected only with your prior consent.
  • Network data: IP address (from which an approximate city/region-level location may be derived).
  • Crash and diagnostic data: error logs, stack traces, and device state at the time of an error.
  • The App does not access your GPS location, contacts, camera, or microphone.

4. Purposes of processing & legal bases

We process your personal data for the purposes below, each with its legal basis under Art. 6 GDPR.

PurposeData processedLegal basis
Registration & authentication (email/password and Apple/Google Sign-In)Email, hashed password, name, profile picture, nicknameContract — Art. 6(1)(b)
Providing the game (leagues, auctions, line-ups, duels, standings)Profile data, usage and in-game activity dataContract — Art. 6(1)(b)
Payments & subscriptions (purchases via the App Store / Google Play)User ID, transaction dataContract — Art. 6(1)(b)
Personalised advertisingAdvertising identifiers (IDFA/GAID), usage data, device data, IPConsent — Art. 6(1)(a)
Non-personalised advertising (without consent for personalisation)Usage data, device dataLegitimate interest — Art. 6(1)(f) (financial sustainability of the free service)
Analytics & service improvementUsage data, device data, IP (anonymised)Legitimate interest — Art. 6(1)(f)
Crash reporting & debuggingError logs, device data, app stateLegitimate interest — Art. 6(1)(f) (stability and security)
Service push notifications (results, rounds, leagues)Device token, notification preferencesContract — Art. 6(1)(b)
Promotional push notificationsDevice tokenConsent — Art. 6(1)(a)
Security, fraud and cheating preventionAccount, usage and device dataLegitimate interest — Art. 6(1)(f)
Legal & tax obligations relating to transactionsTransaction dataLegal obligation — Art. 6(1)(c)

5. Third-party services & processors

We do not sell your personal data. We share it only with service providers (processors) acting on our behalf under data processing agreements, and with the authentication/store providers you choose to use. The actual SDKs integrated must be confirmed and kept accurate.

  • Authentication: Sign in with Apple (Apple Inc., USA) and Google Sign-In (Google LLC, USA) — name, email, profile picture.
  • Hosting & database: DigitalOcean (data hosted in the European Union) — account, profile and gameplay data.
  • Object storage: DigitalOcean Spaces (S3-compatible object storage, EU region) — user-uploaded media such as profile pictures.
  • Payments & subscriptions: Apple App Store and Google Play Store process all payments; we do not collect or store card or payment-instrument data. Subscription entitlements are managed by RevenueCat (RevenueCat, Inc., USA), which processes your purchase and transaction data and a pseudonymous app user ID.
  • Advertising: Google AdMob (Google LLC, USA) and Meta Audience Network (Meta Platforms Ireland Ltd.) — advertising identifiers, usage and device data; activated only after consent.
  • Analytics: Google Analytics for Firebase (Google LLC, USA) — usage and device data.
  • Crash reporting: Firebase Crashlytics (Google LLC, USA) — error logs and device data.
  • Push notifications: Firebase Cloud Messaging — FCM (Google LLC) — device push token.

6. International data transfers

Account, profile and gameplay data are hosted within the European Union (DigitalOcean, EU region) and are not transferred outside the EEA for hosting purposes.

Some providers above (e.g. Apple, Google, Meta and other advertising/analytics SDKs) are based in the United States. Such transfers rely on the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023) for certified providers, and on the European Commission’s Standard Contractual Clauses (Implementing Decision 2021/914) for the others. You may request details of the specific safeguards by contacting us.

7. Data retention

We keep personal data only as long as necessary for the purposes for which it was collected.

Data categoryRetention period
Account data (email, nickname, profile picture)For the life of the account; deleted on account closure.
In-game activity data (leagues, standings, scores)For the life of the account; deleted on account closure.
Transaction & billing data10 years from the transaction (Art. 2220 Italian Civil Code and tax law).
Analytics dataAggregated/anonymised; raw event data up to 14 months.
Crash reporting dataUp to 90 days from collection.
Advertising dataPer the respective providers’ policies; consent revocable at any time.
Push notification tokensUntil notifications are disabled or the account is closed.
Support ticketsUp to 24 months after the ticket is resolved.

8. Cookies & tracking technologies

Website: the Website uses only a strictly-necessary cookie that stores your language preference (NEXT_LOCALE). It has no login or session tokens, does not use profiling, third-party analytics, or advertising cookies, and self-hosts its fonts (no requests to third-party font services).

App: the App uses tracking SDKs for the purposes in Section 4. Before activating SDKs that collect data for personalised advertising, the App requests your explicit consent through the Google UMP consent module and, on iOS, Apple’s App Tracking Transparency (ATT) framework. You can change your consent preferences at any time in the App or device settings.

9. Push notifications

The App may send two types of push notification:

  • Service notifications — relating to gameplay (results, rounds, league updates), sent on the basis of the contract.
  • Promotional notifications — about news, offers or new features, sent only with your consent.

10. Your rights under the GDPR

Under Articles 15–22 GDPR, you have the right to:

  • Access (Art. 15) — confirmation of whether your data is processed and a copy of it.
  • Rectification (Art. 16) — correction of inaccurate or incomplete data.
  • Erasure (Art. 17, “right to be forgotten”).
  • Restriction of processing (Art. 18).
  • Data portability (Art. 20) — your data in a structured, machine-readable format.
  • Objection (Art. 21) — including, for direct-marketing processing, the right to have it cease immediately.
  • Not to be subject to solely automated decision-making (Art. 22).
  • Withdraw consent at any time (Art. 7(3)), without affecting prior lawful processing.

11. How to exercise your rights

You can export your personal data and permanently delete your account directly in the app (Settings → Account); these self-service tools satisfy your access, portability, and erasure rights. You can also exercise any of your rights by writing to [email protected]. We will respond within 30 days of receiving the request (extendable by a further 60 days for complex requests, with prior notice).

To revoke consent to personalised advertising you can also: on iOS, Settings → Privacy & Security → Tracking; on Android, Settings → Google → Ads → Delete advertising ID.

You also have the right to lodge a complaint with the Italian supervisory authority: Garante per la Protezione dei Dati Personali, Piazza Venezia 11, 00187 Roma — www.garanteprivacy.it, email [email protected], PEC [email protected].

12. Children

The Service is intended for users aged 14 years or older, in accordance with Art. 2-quinquies of Legislative Decree 196/2003. We do not knowingly collect personal data from minors under 14. If we become aware that we have collected such data without the consent of the holder of parental responsibility, we will promptly delete it. Parents or guardians may contact us at [email protected].

13. Nature of data provision

Providing registration data (email, or name/email via Apple/Google Sign-In) is necessary to create an account and use the Service; without it, the account cannot be created. Providing data for personalised advertising and promotional notifications is optional, and refusing it does not affect access to the Service.

14. Data security

We adopt appropriate technical and organisational measures to protect your data, including:

  • Encrypted communications via HTTPS/TLS.
  • Passwords hashed with Argon2id; data at rest protected by our hosting provider.
  • Access to personal data restricted to authorised personnel.
  • Secure authentication through trusted providers (Apple, Google).
  • Ongoing monitoring of security and stability.

15. Changes to this policy

We may update this notice from time to time. Changes are published on this page with an updated “last updated” date; for material changes we will notify you through the Service. Continued use after changes take effect constitutes acceptance of the updated notice.

16. Contact

Data controller: Cosimo Orlacchio — Via G. Ocone - Ponte (BN) Italy. Email: [email protected].

17. Definitions

  • Personal Data: any information relating to an identified or identifiable natural person.
  • User: the natural person who uses the Service.
  • Data Controller: the entity that determines the purposes and means of processing.
  • Data Processor: a party that processes personal data on behalf of the controller.
  • Service: the GP Clash App and Website.