PiltoverArchive
  • News
  • Events
  • Proxies
Become anArchivist

On this page

  1. 1. Introduction
  2. 2. Data Collection
  3. 3. Cookies
  4. 4. Advertising
  5. 5. Data Sharing
  6. 6. Third Countries
  7. 7. US Privacy Rights
  8. 8. Affiliate Links
  9. 9. Data Retention
  10. 10. Your Rights
  11. 11. Data Security
  12. 12. Changes

Legal

Piltover Archive Privacy Policy

How we collect, use, and protect your personal data.

Last updated: July 31, 2026

1. Introduction and Data Controller Information

Welcome to Piltover Archive.

This Privacy Policy explains how Piltover Archive (a project of STGMNN Labs UG (haftungsbeschränkt), "we," "us," or "our") collects, uses, processes, and protects your personal data when you use our website, located at https://piltoverarchive.com(the "Service"). We are committed to protecting your privacy and handling your data in accordance with the General Data Protection Regulation (GDPR) and German data protection laws.

Data Controller:

  • STGMNN Labs UG (haftungsbeschränkt)
  • Maria-Goeppert-Straße 1, 23562 Lübeck, Germany
  • Managing Director: Jan Stegemann
  • Registered with the Local Court (Amtsgericht) Lübeck, Commercial Register HRB 27403 HL
  • E-mail: privacy@piltoverarchive.com

For our full legal contact details, please see our Imprint.

Data Protection Officer (DPO):

We are not legally required to appoint a Data Protection Officer at this time. Should this become legally required in the future, we will update this Policy accordingly and publish the DPO's contact details.

2. Data Collection and Processing

We only collect and process personal data that is necessary for providing our services and for purposes explicitly stated in this policy, based on a valid legal basis.

a) Account Registration and Login (Authentication)

Data Collected: Username, e-mail address, password (handled by our authentication provider Clerk; we never store plain-text passwords), profile data from social sign-in providers you choose to use, IP address upon registration/login, session data, and user preferences.

Purpose: To create and manage user accounts, enable secure login, provide access to deck building tools, remember user sessions, and personalize your experience.

Legal Basis: Performance of a contract (Art. 6(1) lit. b GDPR). This data is essential for us to provide you with the core functionalities of our service. Without this data, we cannot provide you with a user account or access to the deck building features.

b) Deck Building and Content Creation

Data Collected: Deck data (e.g., card lists, names, descriptions), user-generated content, associated metadata (e.g., creation date, last modified date).

Purpose: To enable you to create, store, manage, and optionally share your decks on our platform.

Legal Basis: Performance of a contract (Art. 6(1) lit. b GDPR). This data is integral to the service you sign up for.

c) Communication with Us (Contact Form/E-mail)

Data Collected: Your name, e-mail address, and the content of your message.

Purpose: To respond to your inquiries, support requests, and feedback.

Legal Basis: Legitimate interest (Art. 6(1) lit. f GDPR) in effectively communicating with our users and providing support. Where your inquiry relates to an existing account or contractual relationship, the primary legal basis is Art. 6(1) lit. b GDPR.

d) Website Analytics (Google Analytics 4)

Data Collected: Usage data, such as pages visited, time spent on pages, referral sources, device information (e.g., browser type, operating system), approximate location (derived from IP address before storage), and pseudonymous user identifiers stored in cookies. We have configured Google Analytics 4 with IP anonymization enabled and Google Consent Mode v2.

Purpose:To understand how our website is used, identify popular content, and improve our website's performance and user experience.

Legal Basis: Your explicit consent (Art. 6(1) lit. a GDPR). Google Analytics is loaded with consent denied by default and only activated after you opt in via our cookie banner.

e) Server Log Files and Operational Telemetry

Data Collected: IP address, browser type and version, operating system, referrer URL, hostname of the accessing computer, time of the server request, and aggregated performance metrics, error events, and distributed traces collected through Sentry (Functional Software, Inc., EU region — Frankfurt, Germany).

Purpose: For technical security purposes, such as identifying and mitigating cyber-attacks, ensuring the stability and operational integrity of our systems, and diagnosing errors.

Legal Basis: Legitimate interest (Art. 6(1) lit. f GDPR) in maintaining the security and functionality of our website.

f) Embedded Third-Party Content (YouTube, Social Media)

Data Collected: When you interact with embedded content (e.g., YouTube videos in articles, Twitter/X, Bluesky, Instagram or Discord embeds), the respective providers may receive your IP address, browser identifiers, and information about the page you are viewing.

Purpose: To enrich editorial content with relevant videos and social posts.

Legal Basis: Legitimate interest (Art. 6(1) lit. f GDPR). Where embeds set non-essential cookies, they are loaded only after you grant analytics consent via our cookie banner.

g) Sentry Error Monitoring (Crash Reporting)

Data Collected:Unhandled JavaScript errors and exceptions in your browser, including the error message, the URL where it occurred, the browser type and version, your IP address (used by Sentry to derive coarse country-level location, then dropped), a pseudonymous user identifier and username (only when you are signed in via Clerk — never your email address), and recent navigation events ("breadcrumbs") preceding the error. We apply automated scrubbing to remove sensitive headers, tokens, and credential-shaped values before transmission.

Purpose: To identify and fix crashes and regressions before they affect more users. Without error monitoring we cannot reliably detect production failures.

Legal Basis: Legitimate interest (Art. 6(1) lit. f GDPR) in maintaining the security and stability of our service. We have weighed this interest against your rights and determined that minimal-scope error capture (with extensive scrubbing) is the least intrusive means to keep the service working. You may object to this processing under Art. 21 GDPR by contacting us.

h) Sentry Telemetry — Performance, Session Replay, and Logs (Optional Analytics)

Data Collected:Navigation timing, request durations, business-event log entries, and — only when an error occurs during a consenting session — a "session replay" recording of approximately the last 60 seconds of your interaction with the page where the error happened. Replay recordings capture DOM mutation events and network request metadata, not screenshots or video. The values you type into form fields (e.g. passwords, search queries, email addresses) are masked by default; rendered content such as deck names, card names, and button labels is recorded so we can reproduce the issue you encountered. A session identifier is stored in your browser's sessionStorage for the duration of a session and cleared on tab close.

Automated Decision-Making / Profiling (Art. 22 GDPR): None of this data is used to make automated decisions about you or to profile you within the meaning of Art. 22 GDPR. Replays are reviewed only on demand by our engineers when diagnosing a specific bug report.

Purpose: To understand real-world performance, diagnose user-visible issues in context, and detect regressions earlier.

Legal Basis: Your explicit consent (Art. 6(1) lit. a GDPR). Sentry telemetry beyond error capture is only collected after you opt in via our cookie banner. When you withdraw analytics consent, replay recording stops immediately, the session identifier is removed from your browser, and no further performance traces or logs are submitted.

i) Consent Records (Audit Log)

Data Collected: Your consent is collected through our consent management platform, CookieYes, which stores your choices and keeps its own record of consent. When you accept, reject, or change your cookie preferences, we additionally record the event in our own consent audit log: a hashed identifier of your IP address, your country (from the Cloudflare cf-ipcountry header), a hashed user-agent, the consent version, the categories you selected, and a timestamp.

Purpose: To demonstrate that valid consent was obtained, as required by Art. 7(1) GDPR, in case of complaints or supervisory authority audits.

Legal Basis: Compliance with a legal obligation (Art. 6(1) lit. c GDPR) and our legitimate interest (Art. 6(1) lit. f GDPR) in being able to defend our compliance posture.

Retention: Consent log entries are retained for three (3) years after the event, after which they are deleted. The hashing salt is never recoverable, so the IP and user-agent values cannot be reversed even before deletion.

3. Cookies and Other Technologies

Our website uses cookies and similar technologies. Cookies are small text files that are stored on your device (computer, tablet, smartphone) when you visit our website. They help us to provide you with a functional and user-friendly experience. We use CookieYes (CookieYes Limited, United Kingdom) as our consent management platform to present our cookie banner and to obtain and record your consent choices.

a) Strictly Necessary Cookies

Examples:

  • Authentication (Clerk): __client_uat, __session, __clerk_db_jwt — keep you logged in, valid for the session.
  • Cookie consent record: cookieyes-consent — set by our consent management platform CookieYes to store your cookie choices so the banner is not shown on every visit. Retained for up to 12 months.
  • Bot management (Cloudflare): __cf_bm — set by our edge provider Cloudflare to distinguish humans from bots, valid for 30 minutes after each request. This cookie is set automatically by Cloudflare on every request and cannot be disabled without breaking site security.

Purpose: These cookies are essential for the basic functionality and security of our website. Without them, core features like logging in, creating decks, maintaining a user session, or protecting the site against attacks would not work.

Legal Basis: Performance of a contract (Art. 6(1) lit. b GDPR) and our legitimate interest (Art. 6(1) lit. f GDPR) in providing a functional and secure website. These cookies are necessary for the service to operate and do not require your explicit consent prior to being set.

b) Analytics Cookies and Storage (Google Analytics 4 + Sentry)

Examples:

  • Google Analytics 4: _ga (13 months), _ga_* (13 months), _gid (24 hours), _gat (1 minute), _dc_gtm_* (1 minute) — measure aggregated website usage.
  • Sentry (Functional Software, Inc.):A session identifier stored in your browser's sessionStorage under a sentryReplaySession_* key — used to correlate session replay segments when an error occurs. Cleared on tab close and when you withdraw analytics consent. No tracking cookies are set.

Purpose: As described in Sections 2d and 2h, to understand website usage patterns, monitor real-world performance, and improve our services.

Legal Basis: Your explicit consent (Art. 6(1) lit. a GDPR). These cookies and storage entries are only placed if you opt in via our cookie banner. When you withdraw consent we delete the existing values (Art. 17 GDPR).

c) Functional Cookies

Examples:

  • piltover_gallery_settings, piltover_library_sort, piltover_deck_panel_settings, piltover_image_export_settings, piltover_image_export_bg_image, piltover_binder_filter, piltover_external_link_warning_dismissed — each stores a single UI preference (gallery layout, sort order, dismissal of the external-play warning, etc.) for up to 12 months.

Purpose:Remember the UI preferences you have explicitly set so you don't have to reconfigure them on every visit.

Legal Basis:Your explicit consent (Art. 6(1) lit. a GDPR), opted in via our cookie banner under the "Functional" category. When you withdraw consent, we delete the existing values (Art. 17 GDPR).

d) Advertising and Consent-Signalling Cookies and Storage (IAB TCF)

Examples:

  • euconsent-v2— the IAB Europe Transparency & Consent Framework (TCF) consent string (the "TC string"), written by our consent management platform to record, in a standardised format, the advertising purposes and vendors you have consented to. Retained for up to 12 months.
  • Cookies and similar identifiers set by our advertising vendors (see Section 4) to deliver, frequency-cap, and measure advertising. These are only set after you consent to the corresponding purposes.

Purpose: To record your advertising consent choices in the IAB TCF format and to deliver and measure advertising as described in Section 4.

Legal Basis:Your explicit consent (Art. 6(1) lit. a GDPR) for the processing, and § 25(1) TDDDG for the storage of and access to information on your device. These entries are only set if you opt in to advertising via our cookie banner. When you withdraw consent, we delete the existing values (Art. 17 GDPR).

Managing Cookies:

You can manage your cookie preferences at any time by clicking the "Your Privacy Choices" link in the footer of our website. You can also configure your browser to refuse all cookies or to indicate when a cookie is being sent. If you block strictly necessary cookies, core features of the Service may not function properly.

4. Advertising

We display advertising on parts of our website, including personalized (interest-based) advertising. Advertising is not shown to members of our paid ad-free tier (see below), and it is personalized only where you have given consent. If you do not consent, you can still use the website in full and are shown only non-personalized (contextual) advertising.

a) How our advertising is operated

Our advertising is operated for us by Metafy, Inc. (USA) through a Rev.iq / Google Ad Manager"Multiple Customer Management" (MCM) setup. In this arrangement Metafy operates the ad stack on our site and is declared as the publisher of record for our domain, and the Google Ad Manager account used is Rev.iq's. We (STGMNN Labs UG) operate the website on which the advertising is shown.

b) Data processed for advertising

Data Collected: Online identifiers stored in or read from cookies and similar technologies, your IP address, the IAB TCF consent string, information about the ads shown to you and your interactions with them, approximate location derived from your IP address, and device and browser information.

Purpose: To display advertising; to personalize advertising to your likely interests where you consent; to limit how often you see the same ad; to measure ad performance; and to detect fraud and invalid traffic.

Legal Basis: Your explicit consent (Art. 6(1) lit. a GDPR) for personalized advertising and the associated processing, obtained through our consent banner. The storage of and access to information on your device for these purposes is based on § 25(1) TDDDG, which we treat as a legal question separate from the subsequent GDPR processing. Advertising does not rely on legitimate interest.

c) IAB Transparency & Consent Framework (TCF)

We participate in the IAB Europe Transparency & Consent Framework (TCF), version 2.3. Our consent banner is provided by a Google-certified, IAB-registered Consent Management Platform, CookieYes (CMP ID 401), which records your choices as a TCF consent string and makes them available to advertising vendors.

d) Advertising vendors and recipients

Personalized advertising is delivered through a real-time bidding process in which your data may be shared with advertising-technology vendors (for example supply-side platforms, demand-side platforms, ad exchanges, and measurement providers). The vendors authorized to participate in our advertising are listed in our ads.txt file (currently approximately 86 ad-system domains, including Google, Amazon, Magnite, PubMatic, Xandr, OpenX, Index Exchange, Sharethrough, and TripleLift, among others). Before any data is shared for advertising, the individual IAB TCF vendors are named to you in the second layer of our consent banner, together with their processing purposes and links to their privacy policies, where the complete and current IAB TCF vendor list is also available.

e) Third-country transfers for advertising

Many advertising vendors are established in the United States or other third countries. These transfers are addressed in Section 6 (Data Transfer to Third Countries).

f) Ad-free membership

We offer a paid ad-free tier via Metafy; members are not shown advertising. This is not a condition of using the website: visitors who reject advertising consent can continue to use the site in full and are shown only non-personalized advertising.

g) Withdrawing consent

You can withdraw or change your advertising consent at any time via the "Your Privacy Choices" link in our website footer.

5. Data Sharing and Recipients

We share personal data with the service providers and partners listed below, based on appropriate legal bases and, where applicable, data processing agreements. In connection with personalized advertising (Section 4), personal data is also shared with advertising-technology vendors. Under some U.S. state privacy laws, this advertising-related sharing may be considered a "sale" or "sharing" of personal information; see Section 7 for your U.S. state privacy choices.

Categories of Recipients:

  • Hosting Provider — Railway Corp. (USA): Hosts our application, backend API, Redis cache and observability stack in the europe-west4 region (Netherlands).
  • Database Provider — Supabase Inc. (USA): Hosts our PostgreSQL database in an EU region.
  • Authentication Provider — Clerk Inc. (USA): Provides user authentication, account management and session handling. Sign-in via Google, Discord, Metafy, or e-mail magic link is enabled and routes data through Clerk to the respective identity provider you choose.
  • Edge Network & DNS — Cloudflare, Inc. (USA): Provides DNS, caching, DDoS protection and TLS termination for all incoming traffic. Cloudflare processes connection data including IP addresses and request metadata.
  • Consent Management — CookieYes Limited (United Kingdom): Provides our cookie consent banner and records your consent choices. CookieYes (company no. 13074037, Milton Keynes, UK) processes a consent ID, a truncated/pseudonymized IP address, the consent status per category, and a timestamp. A data processing agreement is in place.
  • Error Monitoring & Application Performance — Functional Software, Inc. (dba Sentry, USA, with EU data residency): Collects crash reports, performance traces, and (with consent) session replays from our website. Application data is stored in Sentry's EU region (Frankfurt, Germany); account-level metadata (organization settings, user accounts, access tokens) remains in Sentry's US infrastructure under the EU-US Data Privacy Framework and Standard Contractual Clauses.
  • Content Delivery Network — BunnyWay d.o.o. (Slovenia, EU): Delivers static images and assets via Bunny CDN.
  • Analytics Provider — Google Ireland Limited (Ireland) / Google LLC (USA): Provides Google Analytics 4 (only after consent).
  • Embedded Media Providers: When editorial content includes embeds, the respective platforms may receive technical request data: Google LLC / YouTube (USA), X Corp. / Twitter (USA), Bluesky Social PBC (USA), Meta Platforms Ireland Ltd. / Instagram (Ireland), Discord Inc. (USA).
  • Identity Providers (only if you choose them): Google LLC (USA), Discord Inc. (USA), Metafy Inc. (USA). For users who sign in via Metafy, we may also query Metafy to verify subscription entitlements in order to unlock premium features on our platform. Payment for those subscriptions is handled exclusively by Metafy on their own platform; we do not process any payment data.
  • Outbound Notifications — Discord Inc. (USA): Server-to-server webhook used by us to publish announcements (e.g., new cards, new articles) into our Discord channels. No personal user data is transmitted in these notifications.
  • External Play Platforms (only when you explicitly initiate):S. Goerlitz UG (haftungsbeschränkt), Werner-Bock-Straße 31, 33602 Bielefeld, Germany — operator of RiftAtlas. When you click "Play on RiftAtlas" from a deck view, your browser opens play.riftatlas.com with the public deck code (an anonymous, non-personal string representing the card list). No account information, username, or IP address is transmitted by Piltover Archive in this action; your browser itself will connect to RiftAtlas, which is governed by their own privacy policy. The Play menu also offers TCG Arena(tcg-arena.fr; contact tcgarena.contact@gmail.com; operated under French law, hosted in the EU by OVHcloud). When you click "Play on TCG Arena," your browser opens tcg-arena.fr/importwith the deck's name, its Piltover Archive deck ID, and the decklist (card names and quantities). No account information, password, or IP address is transmitted by Piltover Archive; your browser connects to TCG Arena directly, governed by their own privacy policy.
  • Advertising — Metafy, Inc. (USA), Rev.iq, and Google (Google Ad Manager): Operate our advertising as described in Section 4. Personalized advertising additionally involves approximately 86 authorized advertising-technology vendors listed in our ads.txt and named individually in our consent banner (categories: supply-side platforms, demand-side platforms, ad exchanges, and measurement providers). This applies only once advertising is enabled and only to the extent you consent.

We have entered into Data Processing Agreements (DPAs) with all relevant service providers to ensure they comply with GDPR standards and process your data only according to our instructions and applicable data protection laws.

6. Data Transfer to Third Countries

Personal data may be transferred to countries outside the European Economic Area (EEA), including the United States. This applies to some of our service providers (in particular Cloudflare, Clerk, Railway, Google, Discord, CookieYes (United Kingdom), and Sentry — for account metadata only; application data is stored in Sentry's Frankfurt region) and, once personalized advertising is enabled, to advertising-technology vendors (Section 4), a majority of which are established in the United States.

Where we transfer personal data to a third country, we rely on the following safeguards. As a general rule we rely on the EU Standard Contractual Clauses (SCCs) in their current version, supplemented where necessary by additional technical and organizational measures. For recipients that are certified under the EU-US Data Privacy Framework (DPF), we may additionally rely on the European Commission's adequacy decision of 10 July 2023. Because the DPF applies per organization and not to the United States as a whole, the safeguard relied on can differ from vendor to vendor. For transfers to the United Kingdom (CookieYes), we rely on the European Commission's adequacy decision for the UK.

You can request a copy of the specific safeguards by contacting us using the details provided above.

7. Your U.S. State Privacy Rights (Do Not Sell or Share)

If you are a resident of a U.S. state with a comprehensive privacy law (such as California), you may have the right to opt out of the "sale" or "sharing" of your personal information and of its use for targeted advertising. Because personalized advertising (Section 4) may constitute a sale or sharing under these laws, we provide a way to opt out.

You can exercise this choice at any time via the "Your Privacy Choices" link in our website footer. We also honor the Global Privacy Control (GPC) signal: if your browser or an extension sends a GPC signal, we treat it as a request to opt out of the sale or sharing of your personal information.

8. Affiliate Links

Some parts of our website contain affiliate links, such as "Buy on TCGPlayer" buttons. These links are operated through the affiliate network impact Germany GmbH, Wallstr. 9-13 c/o Spaces, 10179 Berlin, Germany (impact.com), and lead to the online store TCGPlayer. If you make a purchase after clicking such a link, we may receive a commission at no additional cost to you.

Data Collected: When you click an affiliate link, a unique click identifier and related information may be processed by Impact and the destination store to attribute a possible purchase to us. This may involve setting or reading identifiers on your device.

Purpose: To attribute purchases to us so that we receive the applicable commission, and to measure the performance of these links.

Legal Basis: Your consent. This tracking only takes place if you have consented; without your consent, clicking the link does not create an affiliate attribution.

TCGPlayer is located in the United States. Where personal data is transferred to the United States in this context, the safeguards described in Section 6 apply.

9. Data Retention

We store your personal data only as long as necessary for the purposes for which it was collected or as required by law.

  • Account Data: Your account data and associated deck data will be retained for as long as your account is active. If you delete your account, your personal data will be erased, subject to statutory retention obligations (e.g., tax or commercial law).
  • Analytics Data (Google Analytics 4): 14 months, then automatically deleted.
  • Crash Reporting & Performance Data (Sentry): Error events and performance traces retained for 90 days; session replays retained for 90 days. Data is automatically purged after these periods by Sentry. When you delete your account, we additionally instruct Sentry to delete events tagged to your user identifier within one month — see Section 10 for the right-to-erasure flow.
  • Consent Records (Audit Log): Three (3) years from the consent event, then deleted. The IP and user-agent values are stored as one-way hashes and cannot be reversed.
  • Communication Data: Correspondence (e.g., e-mails from contact forms) is retained for the duration of the communication and a reasonable period thereafter for reference or legal defense purposes.
  • Server Log Files: Typically retained for 7–14 days for security and technical purposes. In case of a security incident, logs may be retained longer for investigation and evidence purposes.

10. Your Data Protection Rights (GDPR Rights)

Under the GDPR, you have the following rights regarding your personal data:

  • Right to Access (Art. 15 GDPR)
  • Right to Rectification (Art. 16 GDPR)
  • Right to Erasure ("Right to be Forgotten") (Art. 17 GDPR): When you delete your account, we instruct Sentry to delete the error reports (issues) tagged to your user identifier within one month of your erasure request, as required by Art. 12(3) GDPR. Session replays and performance traces are not deleted individually; they are automatically purged by Sentry within 90 days (see Section 9). An automated deletion mechanism, triggered the moment you delete your account, is in development and will replace the current manual step.
  • Right to Restriction of Processing (Art. 18 GDPR)
  • Right to Data Portability (Art. 20 GDPR)
  • Right to Object (Art. 21 GDPR)
  • Right to Withdraw Consent (Art. 7(3) GDPR):Where the processing of your personal data is based on your consent, you have the right to withdraw this consent at any time. You can withdraw or modify your consent at any time via the "Your Privacy Choices" link in our website footer.
  • Right to Lodge a Complaint with a Supervisory Authority (Art. 77 GDPR): You have the right to lodge a complaint with a supervisory authority, particularly in the Member State of your habitual residence, place of work, or place of the alleged infringement if you believe that the processing of personal data relating to you infringes the GDPR. The competent authority for our company is the Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD).

To exercise any of these rights, please contact us using the details provided in Section 1 of this Privacy Policy.

11. Data Security

We implement appropriate technical and organizational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include, but are not limited to:

  • Using SSL/TLS encryption for all data transmission.
  • Implementing access controls to limit who can access personal data.
  • Regular data backups and disaster recovery plans.
  • Pseudonymization or anonymization where appropriate.
  • Regular security audits and updates.

We review and update these measures on a regular basis to reflect current technical standards.

12. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. If legally required, we will also notify registered users by e-mail of material changes affecting their rights.

Imprint·Privacy Policy·Terms of Service·Report illegal content·
All systems operational
PiltoverArchive

© 2026STGMNN Labs UG (haftungsbeschränkt) · PiltoverArchive.com. Piltover Archive was created under Riot Games' “Legal Jibber Jabber” policy using assets owned by Riot Games. Riot Games does not endorse or sponsor this project.

HomeCardsDecksEventsTools