ROMISH

Legal

Privacy Policy

Last updated

How Romish collects, uses, shares and protects your information when you use the website and platform.

Introduction

ROMISH ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and platform (the "Service").

Information we collect

Steam account information

When you authenticate via Steam OpenID, we collect your Steam ID, username, avatar URL, and profile level. This information is used solely for account identification and authentication.

Match and performance data

We collect in-game statistics (kills, deaths, assists, ADR, KAST), match results, team composition, and map selections. This data is retained indefinitely for leaderboard rankings and historical stat tracking.

Usage data

We automatically collect information about your interactions with our Service, including IP address, browser type, pages visited, time spent, and referral source. This is used to improve our platform and understand user behavior.

Cookies and identifiers

We use session cookies to maintain your login state and CSRF tokens to prevent unauthorized actions. These are essential for platform security and functionality. Details are in the Cookie Policy.

How we use your information

  • To authenticate your account and maintain your session
  • To display your profile, statistics, and leaderboard rankings
  • To facilitate matchmaking and tournament functionality
  • To prevent fraud, cheating, and unauthorized access
  • To improve our Service through analytics and performance monitoring
  • To communicate important platform updates (when applicable)

Data sharing and third parties

We do not sell your personal data. We may share information with:

Valve / Steam
For authentication purposes via OpenID.
DatHost
Game server provider (receives match data).
Pusher
Real-time notification service (receives user session data).
Upstash Redis
For caching and rate limiting (no sensitive data stored).
Law enforcement
If required by legal process or to protect safety.

Data security

We implement industry-standard security measures:

  • HTTPS/TLS encryption for all data in transit
  • Secure, httpOnly session cookies
  • CSRF token validation on all state-changing requests
  • Rate limiting to prevent brute force attacks
  • MongoDB Atlas encryption at rest

However, no security system is 100% secure. We cannot guarantee absolute protection of your data.

Your rights (GDPR / CCPA)

If you are a resident of the EU or California, you have the right to request access to or deletion of your data. You can do both yourself, right here or from Profile → Settings:

Download your data

A JSON file with your profile and your match history.

Download my data

Delete your account

Permanently removes your Romish account and signs you out. This can't be undone.

Access
Request a copy of your data we hold.
Rectification
Correct inaccurate information.
Deletion
Request deletion of your account and associated data.
Portability
Request data in a portable format.
Opt-out
Object to certain types of processing.

To exercise these rights, contact us at privacy@romish.gg.

Data retention

Match statistics
Retained indefinitely for leaderboards and historical records.
Session cookies
Expire after 30 days of inactivity.
IP logs
Retained for 90 days for security auditing.
Deleted accounts
User profile deleted within 30 days; statistics retained.

Children's privacy

ROMISH is intended for users 13 years of age and older. We do not knowingly collect information from children under 13. If we become aware of such collection, we will take steps to delete the data.

Questions about this page? Write to privacy@romish.gg.

This privacy policy is subject to change at any time. We will notify users of material changes via the platform or email.