Who controls your data
The data controller is Achillefs Kastanas, trading as GridStrike, operating as an individual business established in Greece.
- Business address: Argonautou 4, 190 05 Nea Makri, Greece.
- Telephone: +30 694 923 2421.
- Privacy contact: support@gridstrike.net.
Who this Policy covers
This Policy covers visitors and registered users of the GridStrike website, mobile applications, teams, events, live maps, Team Tracker, replays, support, and moderation services. GridStrike is for adults aged 18 or older.
Data GridStrike collects
- Account identity and profile data, including name, callsign, email, profile image, account state, and timestamps.
- Authentication data, including a password verifier or identifiers supplied by Google or Apple. GridStrike does not receive your Google or Apple password.
- Adult confirmation and the versions and times of accepted Terms and Privacy notices.
- Teams, events, invitations, rosters, maps, markers, drawings, objectives, images, reports, and other content you provide.
- Precise device location while you participate in an active event or Team Tracker session, including background updates after disclosure and operating-system permission.
- Participation data, such as memberships, assignments, session presence, roles, event activity, and private replay records.
- Support correspondence, moderation reports, block relationships, operator notes, and actions taken.
- Security and technical data, such as IP address, request time, device and operating-system information, app release, native build, crash stack, and service logs.
- A mobile push token and app/device identifiers when you enable push notifications. Alert payloads exclude names, email, location, event details, and tactical content.
Why GridStrike processes data
- Contract: To create and secure accounts, provide teams, events, invitations, live maps, replays, support, and deletion.
- Consent: For precise background location where consent is required. You can withdraw operating-system permission, leave the session, or stop using the feature.
- Legitimate interests: To prevent fraud and abuse, secure and diagnose the service, moderate public content, respond to reports, and improve reliability without behavioral advertising.
- Legal obligations: To comply with applicable law, lawful requests, accounting duties, and the establishment, exercise, or defense of legal claims.
Location and background tracking
Before requesting location permission, GridStrike explains who can receive the location, when background tracking runs, and how it stops. Location starts only after permission and an active-session join.
Permitted participants and organizers receive live location according to event roles and faction visibility. Team Tracker participants share one accepted-team view. Background tracking stops when you leave, are removed, the session ends, permission is rejected, or your account is deleted. GridStrike does not use precise location for advertising.
Public and shared information
- Public profiles, teams, events, and public images can be viewed worldwide.
- You may hide your full name from other players when your account has a callsign. Ordinary players then see your callsign instead of your full name.
- Event owners, authorized event staff, active members of a Team Tracker host team, and authorized GridStrike operations staff can view a full name when required for their role.
- Live location is limited to permitted session participants and organizers.
- Private replays are available only to the audience captured when recording finalizes.
Service providers
GridStrike uses providers only as needed to deliver and protect the service:
- Hostinger for production hosting, database infrastructure, transactional email, and the hosted GlitchTip monitoring service.
- Apple and Google for sign-in and mobile app distribution.
- Expo for opt-in mobile push notification delivery.
- Bunny.net for media and replay object storage and delivery.
- OpenStreetMap, OpenFreeMap, and related mapping services for maps, map data, and place search.
- Google Analytics and Google Analytics for Firebase for optional, consent-based measurement across the website and mobile apps.
Providers may use approved subprocessors. Where processing involves a transfer outside the European Economic Area, GridStrike relies on an applicable lawful transfer mechanism and provider safeguards.
GridStrike Social and YouTube API Services
GridStrike Social is the private publishing dashboard used by authorized GridStrike operators. It uses YouTube API Services only after an operator connects a Google account through Google OAuth and grants the requested YouTube permissions. GridStrike Social never receives or stores a Google or YouTube password.
For a connected YouTube channel, GridStrike Social may access and store:
- encrypted OAuth access and refresh tokens, the granted scopes, and the connected channel identifier and display information;
- the original video, title, description, category, privacy setting, and other publication choices supplied by the operator; and
- the provider video identifier and limited upload or processing status returned by YouTube.
GridStrike Social uses videos.insert to upload the exact video and metadata that the operator confirms, and videos.list to confirm the resulting upload and processing status. It does not read a channel's viewing history, comments, subscriptions, analytics, or unrelated videos. YouTube API data is not sold, used for advertising, or disclosed to unaffiliated third parties. It is available only to authorized GridStrike operators and processors that host or secure GridStrike Social.
GridStrike's use of information received from YouTube API Services is governed by this Policy and the Google Privacy Policy. YouTube actions are also subject to the YouTube Terms of Service.
An authorized operator can revoke a connected YouTube grant from the account controls in GridStrike Social. This immediately disconnects its destinations and clears the stored OAuth tokens. Access can also be revoked from the Google security settings page. After either form of revocation, GridStrike deletes any remaining Authorized Data obtained under that grant as soon as possible and no later than seven calendar days. Operator-supplied publication media and copy remain GridStrike business content and can be deleted through the publishing dashboard or by contacting support@gridstrike.net.
Optional product analytics
GridStrike does not sell personal data or use analytics for advertising or ad personalization. With your consent, Google Analytics measures visits and product usage on the website, Android, and iOS. It receives an anonymous app-instance identifier, device and operating-system details, app version and language, coarse geographic information, fixed screen names, app-launch and coarse engagement lifecycle, and allowlisted actions such as completed sign-in, team, event, Tracker, live-session, map-tool, and replay actions.
GridStrike does not send names, callsigns, email addresses, account, team, event, session, replay, invitation, or entity identifiers, raw URLs or query strings, precise or map coordinates, map content, support messages, notification bodies, form values, tokens, or raw errors to Analytics. Automatic screen reporting, advertising identifiers, Google Signals, ad personalization, and advertising storage are disabled.
Analytics is disabled by default and starts only after you choose "Allow analytics." Declining leaves every feature available. Your versioned choice is stored on this browser or device. You can change it at any time in Analytics preferences; withdrawal stops future collection and clears local analytics identifiers, but cannot remove information already included in anonymous aggregate reports. .
Necessary session and preference storage remains available to keep you signed in, protect accounts, and remember product settings.
Diagnostics and security
Crash reports are configured without account email, authentication tokens, precise location, profile images, or event content. GridStrike uses reasonable technical and organizational safeguards, but no internet service can guarantee absolute security.
Retention
- Unverified accounts are eligible for deletion after 30 days.
- Temporary live markers and drawings expire after 15 minutes.
- Replays expire 30 days after the runtime session ends.
- Moderation reports and evidence remain for 12 months after case closure.
- Support correspondence remains for 24 months.
- Security and authentication logs remain for 90 days.
- Routine operational logs remain for 30 days.
- Consent-based Analytics event-level and user-level exploration data remains for 14 months; new activity does not reset that period.
- Disabled push registrations and completed delivery records remain for no more than 30 days.
- Deleted data may remain in protected backups for no more than 30 days.
Data may be kept longer where necessary for fraud prevention, security, a legal obligation, or legal claims. Anonymous aggregate information that no longer identifies a person may be retained.
Account deletion
Account deletion is available in the app and through the public deletion process. Owned teams and events must first be transferred or deleted. A valid request revokes access immediately and is normally completed within 30 days.
Your privacy rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent without affecting earlier lawful processing. GridStrike normally responds to a valid privacy request within 30 days.
Send requests to support@gridstrike.net. GridStrike may request proportionate information to verify the requester without asking for a password.
You may also complain to the Hellenic Data Protection Authority or another competent supervisory authority.
Changes to this Policy
GridStrike may update this Policy when the service or legal requirements change. Material changes will be announced by email or in the app before they take effect where practicable, and renewed acceptance may be required.
