Template — review with counsel. This is a plain-English starting point written for how PlayPad actually works. It hasn't been reviewed by a lawyer. Placeholders in [brackets] must be completed by the operator before launch.
The short version
- You sign in with a wallet signature — no email or password required.
- Blockchain transactions and round results are public by design.
- We use one essential session cookie and no advertising trackers. We don't sell personal data.
What we collect
- Wallet addresses you sign in with, and the one-time sign-in messages you sign (nonces expire after 10 minutes).
- Session data: a session record and an httpOnly cookie (
pp_session, valid for 7 days) with your browser's user agent. - Profile details you choose to add: handle, display name, avatar, bio.
- Eligibility data: the time you confirmed you meet the minimum age, and the country our hosting provider derives from your IP address when you enter a round (used only to apply regional rules).
- Gameplay data: your entries, inputs sent to game servers (for example taps, moves, strokes, answers, votes) and the results. These form the fairness log of each round.
- Uploads: logos, banners and avatars you upload.
- Usage events: page views, watch start/stop, entries and shares, tied to your profile when signed in or to a random anonymous id otherwise — used for creator analytics and to keep PlayPad working.
- Reports and moderation records you submit or that concern your content.
Public by design
Some information is public because that's how fair, verifiable competitions work:
- Everything on the blockchain: token launches, prize funding, payouts and refunds, with the wallet addresses involved. We can't change or delete on-chain data.
- Round entrants, standings, winners, replays, highlight clips and vote tallies — shown with your handle or a shortened wallet address.
- Each round's fair-play record (seed commitment, event-log hash, signed result).
How we use it
- Run rounds, verify results and pay prizes.
- Check entry rules and eligibility (age, region, bans, token balances read from the chain).
- Prevent cheating, abuse and fraud, and moderate content.
- Show creators aggregated analytics about their project (players, viewers, retention). Creators don't get your IP address or private data.
- Keep the service secure and fix problems.
How long we keep it
- Sign-in nonces: 10 minutes. Sessions: up to 7 days, or until you sign out.
- Round records and fairness logs: kept for as long as PlayPad operates, because they prove results were fair. Completed rounds can't be edited.
- Profile details: until you change or remove them.
- Usage events: [retention period].
Your choices and rights
You can edit or remove your handle, avatar and bio in Settings at any time. You can ask us for a copy of your data or to delete off-chain data we hold about you at [privacy email]. We'll keep only what we must for fairness records, fraud prevention or legal obligations — and we can't erase anything recorded on a public blockchain.
Depending on where you live (for example under the GDPR or CCPA) you may have further rights, including to object or complain to a regulator: [data controller details / EU representative].
Security
Sessions use signed httpOnly cookies, every sign-in signature is verified on our servers, and we never ask for your seed phrase or private keys. No system is perfectly secure; if you find a vulnerability please report it to [security contact email].
Children
PlayPad is not intended for anyone under 18, and players must confirm they meet the minimum age before entering a round.
Changes and contact
We'll update this notice when our practices change and change the date above. Contact: [privacy email], [operator legal name and address].