ratajski.info

Pax Dei LFG — Privacy Policy

Privacy Policy Terms & Conditions Support Delete Account

Effective Date: 27 August 2026

This Privacy Policy explains how personal data is collected, used, disclosed, stored, and protected in connection with Pax Dei LFG (the “App”).

1. Data Controller

The controller responsible for personal data processed through the App is:

Paweł Ratajski
Email: paxdeilfg@ratajski.info

Privacy requests and questions may be submitted using the email address above.

2. Scope of This Policy

This Privacy Policy applies only to Pax Dei LFG.

Separate documents describe the Terms and Conditions, support arrangements, and the procedure for deleting a Pax Dei LFG account.

3. Information We Process

Depending on how the App is used, we may process the following categories of information.

3.1 Account and authentication information

For registered users, this may include:

Authentication is handled by Supabase Auth. We do not have access to the user’s password in plain text.

The App may also be used in guest mode. Guest users are assigned an anonymous technical identifier. A guest account does not require an email address, but information created during the guest session may still be associated with that identifier.

3.2 Profile and preference information

This may include:

3.3 Event and participation information

This may include:

3.4 Discord integration information

If a user connects a Discord webhook, we process:

The complete webhook URL is not displayed again in the App after it has been saved.

3.5 Push notification information

If push notifications are enabled, we may process:

Notifications can be disabled in the App where the relevant setting is available or through the notification settings of the device operating system.

3.6 Technical and operational information

When the App communicates with its service providers, the following information may be processed:

This information is used only to operate, secure, diagnose and maintain the App.

The App does not use third-party advertising SDKs, behavioral tracking SDKs, Firebase Analytics, Firebase Crashlytics or Sentry.

4. How and Why We Use Information

We use personal data for the purposes described below.

For users in the European Economic Area, the corresponding legal bases under Article 6 of the GDPR are as follows:

Purpose Categories of information Legal basis
Creating and authenticating an account Account and authentication information Performance of a contract or taking steps requested by the user before entering into a contract — Article 6(1)(b) GDPR
Providing guest access Anonymous identifier and information created during the guest session Performance of the service requested by the user — Article 6(1)(b) GDPR
Saving profiles and preferences Profile and preference information Performance of a contract — Article 6(1)(b) GDPR
Creating, displaying and managing events Event, profile and participation information Performance of a contract — Article 6(1)(b) GDPR
Managing event participation Account, profile, event and participation information Performance of a contract — Article 6(1)(b) GDPR
Sending notifications requested by the user Notification token, preferences and relevant event information Performance of a contract — Article 6(1)(b) GDPR
Connecting a Discord webhook and publishing an event at the user’s request Discord credential, first name, event information and delivery status Performance of a contract — Article 6(1)(b) GDPR
Securing the App, preventing abuse and diagnosing failures Technical, operational and security information Our legitimate interest in protecting users, the App and its infrastructure — Article 6(1)(f) GDPR
Responding to service-related support requests Account information and the content of the request Performance of a contract — Article 6(1)(b) GDPR
Responding to privacy requests and complying with legal duties Information necessary to identify and handle the request Compliance with a legal obligation — Article 6(1)(c) GDPR
Establishing, exercising or defending legal claims Information relevant to the claim Our legitimate interest in protecting our legal rights — Article 6(1)(f) GDPR

We do not use personal data for advertising, profiling or the sale of personal data.

The legal bases listed above apply to processing covered by the GDPR. In other jurisdictions, we process information under the corresponding applicable legal grounds.

5. Publicly Visible Information

Pax Dei LFG is designed to help users publish and find multiplayer events.

Information intentionally included in an event may be visible to other App users. Depending on the event, this may include:

Users should not include private, confidential or sensitive personal information in an event description or other publicly visible field.

Deleting information from Pax Dei LFG does not guarantee that copies previously made by other users, such as screenshots, have also been deleted.

6. Discord Webhook Integration

Connecting a Discord webhook is optional.

A Discord webhook URL contains a secret credential that allows messages to be published to the associated Discord channel. Users should treat this URL as confidential and should connect only webhooks they are authorised to use.

The webhook credential is transmitted over an encrypted connection and stored in a restricted server-side secret system. The full value is not returned to the App after it has been saved.

The App uses the connected webhook only to:

Publishing to Discord is disabled by default for each event and requires a separate choice by the event author.

A Discord message may contain the author’s first name and the event information selected for publication. The message is delivered to the Discord channel associated with the webhook.

The App does not use the integration to read:

A user may replace or disconnect their webhook at any time. Disconnecting the integration removes the user’s stored webhook credential and related active connection data from Pax Dei LFG. It does not delete the webhook from Discord.

Disconnecting the integration or deleting the Pax Dei LFG account does not delete, recall or edit messages that have already been sent to Discord. Previously delivered messages remain under the control of Discord and the administrators of the relevant Discord server or channel.

If the same Discord webhook is independently connected by another authorised user, disconnecting one user’s integration does not affect the other user’s connection.

7. Push Notifications

The App uses Firebase Cloud Messaging to deliver requested notifications concerning events and App activity.

The notification provider may receive a device notification token, device platform, delivery information and the content necessary to deliver the notification.

Notification permission can be withdrawn at any time through the device’s system settings. Disabling notifications does not remove events or other information stored in the App.

8. Service Providers and Recipients

We use service providers only where necessary to operate specific App functions.

Supabase

Supabase provides:

The primary Supabase project used by the App is hosted in the European Union, in the Paris, France region.

More information: Supabase Privacy Policy

Google Firebase

Firebase Cloud Messaging provides push notification delivery.

More information: Google Privacy Policy

Discord

Discord receives information only when a user connects a webhook, requests a test message or enables Discord publication for an event.

Once a message has been delivered, Discord processes and stores it under Discord’s own policies and the settings of the destination server.

More information: Discord Privacy Policy

We do not sell, rent or trade personal data.

9. International Data Transfers

The primary application database is hosted in the European Union.

Some service providers, including Google and Discord, may process information outside the European Economic Area. Where GDPR transfer restrictions apply, transfers are handled using a recognised legal mechanism, such as an adequacy decision, Standard Contractual Clauses or another safeguard made available under applicable law.

Information about the transfer mechanisms used by each provider is available in that provider’s privacy and data protection documentation.

10. Data Retention and Deletion

We keep personal data only for the period connected with the purpose for which it is processed.

In particular:

When deletion of a Pax Dei LFG account is completed, the account’s Pax Dei LFG-specific content, preferences, participation information, notification data and Discord integration data are permanently removed from the active Pax Dei LFG database, subject only to a legal or security-related retention obligation described above.

This is deletion of the relevant Pax Dei LFG data, not merely suspension or freezing. A later return to the App does not restore deleted Pax Dei LFG events, participation records, preferences or integration data.

The authentication infrastructure is shared with other, separately operated applications of the same controller. Deleting Pax Dei LFG data does not automatically delete data belonging to another application that the same person has separately used. It also does not delete content already delivered to an independent third party, including Discord messages.

We do not maintain separate application-level backups of Pax Dei LFG user data. The current database service plan does not include automatic daily database backups. If this technical arrangement changes in a way that affects the retention of personal data, this Privacy Policy will be updated accordingly.

The account deletion procedure and available deletion methods are described in the separate Pax Dei LFG Account Deletion document. It is available at https://ratajski.info/apps/paxdeilfg/delete-account.html.

11. Data Security

We apply technical and organisational measures appropriate to the nature of the App and the information processed.

These measures include:

No system can guarantee absolute security. Users should protect their account credentials and Discord webhook URLs and should report suspected unauthorised access promptly.

12. User Rights

Depending on applicable law, users may have the right to:

Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal. At present, the core processing described in Section 4 is not based on consent under Article 6(1)(a) GDPR.

Requests may be submitted to paxdeilfg@ratajski.info. We may need to verify the requester’s identity before fulfilling a request.

Users in Poland may lodge a complaint with the President of the Personal Data Protection Office:

Urząd Ochrony Danych Osobowych

Users in other countries may contact the data protection authority responsible for their place of residence.

13. Automated Decision-Making

The App does not use personal data to make decisions based solely on automated processing that produce legal effects or similarly significant effects concerning a user.

The App does not perform behavioral profiling for advertising or marketing purposes.

14. Age Requirement

The App is intended only for users aged 16 or older.

We do not knowingly collect or process personal data from persons under 16. If we learn that a person under 16 has provided personal data through the App, we will take reasonable steps to delete that person’s Pax Dei LFG data.

A parent, guardian or other person who believes that someone under 16 is using the App may contact us at paxdeilfg@ratajski.info.

15. Changes to This Privacy Policy

We may update this Privacy Policy when the App, its service providers, legal requirements or data-processing practices change.

The current version will be made available through the App or the App’s public legal-information page. The effective date at the beginning of the document identifies the latest revision.

Where required by law, material changes will be communicated through an additional notice.

16. Contact

Questions, privacy requests and concerns regarding this Privacy Policy may be sent to:

Paweł Ratajski
Email: paxdeilfg@ratajski.info