Vibora
EN PL ES

Vibora Privacy Policy

Version 2.0 — effective 7 August 2026

1. Controller

The controller of personal data processed in connection with Vibora (the “Service”) is PAWEŁ PŁOCHARCZYK, a sole trader entered in the Polish CEIDG register, address: Myszyniec Stary 1B, 07-430 Myszyniec Stary, Polska, Polish tax ID (NIP): 7582387927, statistical business number (REGON): 524221729.

For privacy questions and rights requests contact privacy@vibora.cloud. The Controller has not appointed a data protection officer; this is a privacy contact point, not a DPO address.

2. Data and sources

We process data received from you, generated through use of the Service, provided by a selected login provider, or supplied by a tournament organiser or another person adding a player. If you are added as an anonymous player, the organiser may be the source of your display name and results.

When you sign in with Google, we receive your email address, email-verification status, Google account identifier and basic profile data made available through the openid, email and profile scopes. We use this data only for authentication, account creation or linking, and login security; we do not use Google user data for advertising, data sales or AI-model training.

Depending on the functions used, data includes:

  • account data: internal user ID, email, password hash, verification status, OAuth provider and ID, account timestamps;
  • profile data: display name, avatar, optional social links, friendships and visibility settings;
  • sporting and organisational data: tournament or match role and participation, teams, scores, score proposals and confirmations, rankings, achievements, court names and anonymous-player claim history;
  • device and notification data: FCM token, platform, device description, locale, token registration time and notification-inbox entries, including event type, related identifiers and time;
  • consent, declaration and document records: choice type and status, document version, update time and confirmation of being at least 18; we do not collect a full date of birth;
  • technical and security data: IP address, request time and data, session or authorisation identifiers, error and security logs;
  • correspondence: complaints, reports and rights requests with related contact details.

We do not request special-category data such as health information. Do not enter it in names or other Service fields.

3. Purposes, legal bases and required data

  • Account creation, authentication and core Service functions — Article 6(1)(b) GDPR. Email, authentication data and a basic identifier are required to create an account.
  • Profiles, tournaments, matches, friendships, results and achievements — Article 6(1)(b) GDPR. Avatar and social links are optional.
  • Participants without accounts, their display names and results — Article 6(1)(f) GDPR; our legitimate interests are enabling organisers to run competitions, recognise participants and preserve an accurate result history while limiting data to what is necessary.
  • Transactional messages, including email verification and password reset — Article 6(1)(b) GDPR.
  • Push notifications — Article 6(1)(a) GDPR when voluntarily enabled. Consent can be withdrawn in app or device settings.
  • Electronic marketing — Article 6(1)(a) GDPR and applicable electronic communications law. Refusal does not affect core functions.
  • Security, abuse prevention, legal claims and integrity of match history — Article 6(1)(f) GDPR; our legitimate interests are protecting the Service and users and maintaining reliable results.
  • Legal requests and statutory obligations — Article 6(1)(c) GDPR.

The required acknowledgement of this Policy records that privacy information was provided. It is not consent to processing based on contract, law or legitimate interests.

4. Visibility and recipients

Your display name, avatar, participation, results, rankings and achievements may be visible to organisers and users connected with a tournament, match or friendship. Do not use a display name containing information you do not want disclosed to those persons.

Data may be accessed by authorised personnel and service providers giving appropriate safeguards, including:

  • Google — Google login, Cloud Storage for avatars, Firebase Cloud Messaging, Firestore for the notification inbox and cloud messaging infrastructure;
  • Apple, Meta and LinkedIn — only when the respective social login is selected;
  • Mailgun — transactional and, with consent, marketing email delivery;
  • Oracle Cloud Infrastructure and hosting, database, monitoring and backup providers — operation of the Service;
  • legal or accounting advisers, authorities and courts where needed for law or claims.

We do not sell personal data or disclose it to data brokers or advertisers for their own advertising purposes.

5. Transfers outside the EEA

Some providers belong to groups or use infrastructure outside the European Economic Area, particularly in the United States. Depending on the provider and service, transfers rely on a European Commission adequacy decision, standard contractual clauses or another Chapter V GDPR mechanism. Details or a copy of the relevant safeguard may be requested at privacy@vibora.cloud.

6. Retention and account deletion

  • Account and active-profile data is kept for the term of the contract.
  • After account deletion, authentication data, sessions, profile email and social links, friendships, avatar and active notification tokens are removed without undue delay, ordinarily through an asynchronous process completed within 30 days.
  • Match, tournament, result and achievement history remains under a generated alias so that other participants’ tables and histories remain coherent. A technical identifier may remain in those records. It is retained while history functionality and the relevant legitimate interest continue, subject to periodic review.
  • Push token, device description and locale are kept until notifications are disabled, the account is deleted or the token is found invalid.
  • Notification-inbox entries are kept while the account is active and are deleted with it.
  • Security logs are generally retained for up to 90 days and longer only where needed to investigate an incident or protect claims.
  • Correspondence and claim-related data may be kept until the relevant limitation period expires; legally required data is kept for the statutory period.

Data may remain for a limited period in protected backups and is deleted through backup rotation. Its use is restricted to restoration and security.

7. Your rights

Subject to the GDPR, you have rights of access and copy (Article 15), rectification (16), erasure (17), restriction (18), portability where processing is automated and based on consent or contract (20), objection to legitimate-interest processing based on your particular situation (21), withdrawal of consent at any time (7(3)), and complaint to the Polish supervisory authority: uodo.gov.pl.

Send requests to privacy@vibora.cloud. We respond without undue delay, normally within one month. Where the GDPR permits, this may be extended by two months and we will explain why. We may request information needed to verify identity.

Erasure is not absolute. If data must be retained due to law or overriding legitimate grounds, we will explain the scope and basis of refusal.

8. Automated decisions

We do not make decisions producing legal or similarly significant effects solely by automated means and do not profile users for advertising. Rankings and achievements are calculated automatically from confirmed scores but do not have such legal effects.

9. Cookies and device storage

The web login flow uses the SAVED_REQUEST cookie to preserve the OAuth2 return address. It is necessary, HttpOnly and Secure, lasts up to five minutes and is removed after use. Login providers’ mechanisms are governed by their policies.

We do not use first-party cookies for behavioural advertising or analytics. If this changes, we will update this notice and request consent where required.

10. Security

We use risk-appropriate measures including TLS, password hashing, access controls, service separation and event logging. No internet service can eliminate all risk. Report suspected account compromise to privacy@vibora.cloud.

11. Changes

We may update this Policy due to changes in law, Service functions or providers. Material changes will be notified in the Service or by registered email before they take effect where possible. A Policy change does not create a new legal basis for processing that requires consent.

12. Contact

  • Controller: PAWEŁ PŁOCHARCZYK
  • Address: Myszyniec Stary 1B, 07-430 Myszyniec Stary, Polska
  • NIP: 7582387927; REGON: 524221729
  • Privacy email: privacy@vibora.cloud
← Back to registration