Privacy PolicyБългарски

Privacy Policy

Last updated: October 5, 2026

This Privacy Policy explains how Belot Arena ("we", "us", "our") at belotarena.com collects, uses, stores, and protects your personal data when you use our Service. We are committed to protecting your privacy in accordance with the General Data Protection Regulation (GDPR), the Bulgarian Personal Data Protection Act, and other applicable privacy laws.

1. Data We Collect

We collect the following categories of personal data, limited to what is necessary for the Service to function:

Account and Identity Data

  • Account identifier — a unique user ID generated upon registration or anonymous session creation
  • Display name and username (chosen by you; may be changed at any time)
  • Email address (only if you register via email or link a Google/Apple account)
  • OAuth profile data from Google or Apple (name, email, profile picture) if you use social sign-in

Game Data

  • Game statistics: games played, wins, losses, ELO rating, and ranking history
  • Game session logs (moves, outcomes, timestamps) retained temporarily for anti-cheat analysis and, for premium users, game review features
  • Club memberships and tournament participation records

Technical Data

  • IP address — collected for abuse prevention, rate limiting, and geographic anti-fraud checks
  • Device type, browser type and version, and operating system (collected via standard HTTP headers)
  • Session tokens and authentication cookies
  • Approximate geolocation derived from IP address (country/region level only)

Payment Data

  • Subscription status, plan type, and billing history
  • Payment card details are collected and stored exclusively by Stripe; we only receive a tokenized reference and the last four digits of your card

Communications

  • In-game chat messages (retained temporarily for moderation purposes)
  • Support emails and correspondence

2. Legal Basis for Processing (GDPR)

We process your personal data under the following legal bases as defined in Article 6 of the GDPR:

  • Contract performance (Art. 6(1)(b)). Processing necessary to provide you with the Service, manage your account, process payments, and fulfill our obligations under the Terms of Service.
  • Legitimate interests (Art. 6(1)(f)). Processing for anti-cheat enforcement, fraud prevention, platform security, service improvement, and ensuring fair play. We balance these interests against your rights and freedoms.
  • Consent (Art. 6(1)(a)). Where you have given explicit consent, such as for the use of non-essential cookies (analytics and advertising). You may withdraw consent at any time without affecting lawfulness of processing prior to withdrawal.
  • Legal obligation (Art. 6(1)(c)). Where processing is required to comply with applicable law, such as retaining financial transaction records.

3. How We Use Your Data

  • Account management. Creating and maintaining your account, authenticating your identity, and managing sessions.
  • Game functionality. Matching you with opponents, calculating ELO ratings, maintaining leaderboards, and enabling club and tournament features.
  • Anti-cheat and fair play. Analyzing gameplay patterns and IP/device data to detect bots, multi-accounting, collusion, and other forms of cheating.
  • Subscription management. Processing recurring payments, managing your subscription plan, and sending billing receipts.
  • Advertising. Displaying advertisements to free-tier users via Google AdSense. We do not sell your data to advertisers.
  • Analytics and improvement. Understanding how users interact with the Service to fix bugs, improve performance, and develop new features.
  • Safety and legal compliance. Preventing abuse, responding to legal requests, enforcing our Terms of Service, and protecting the rights and safety of our users.
  • Customer support. Responding to your inquiries, resolving disputes, and communicating important service changes.

4. Cookies and Tracking

We use the following types of cookies and tracking technologies:

  • Essential cookies. Required for the Service to function, including session authentication tokens and security cookies. These cannot be disabled without breaking the Service.
  • Analytics cookies. We use aggregated analytics to understand traffic patterns and feature usage. You may opt out via your browser settings or our cookie consent interface.
  • Advertising cookies (Google AdSense). For free-tier users, Google AdSense may serve personalized or contextual advertisements and may set its own cookies. You can manage Google's advertising preferences at adssettings.google.com. Premium subscribers with an ad-free experience are not subject to advertising cookies.

You can control cookie preferences through your browser settings or through the "Cookie settings" link at the bottom of every guide page, where you can give or withdraw consent at any time. Disabling cookies may affect certain features of the Service.

4.1. Advertising by Google and other vendors

The free version of Belot Arena may show ads through Google AdSense only on content pages (guides, rules and reference pages). We do not show ads during games, in the match queue, in rooms or in sign-in dialogs.

  • Third-party vendors, including Google, use cookies to serve ads based on a user's prior visits to this website or other websites.
  • Google's use of advertising cookies enables it and its partners to serve ads to users based on their visit to our site and/or other sites on the Internet.
  • You may opt out of personalized advertising by Google by visiting Ads Settings. You can also opt out of third-party vendors' use of cookies for personalized advertising at www.aboutads.info or, in the EU, at www.youronlinechoices.eu.
  • Learn more about how Google uses data when you use its partners' sites at policies.google.com/technologies/partner-sites.
  • We also use a Google Ads tag to measure our own advertising campaigns. It runs in Consent Mode: until you accept cookies, Google is not permitted to store advertising or analytics cookies on your device.

Ads load only after you accept cookies in the consent banner. If you decline, content pages are shown without ad units.

5. Third-Party Services

We share personal data only with the following trusted data processors, under binding data processing agreements, to the extent necessary to operate the Service:

  • Supabase. Our primary database, authentication, and backend infrastructure provider. User data including accounts, game statistics, and session tokens are stored on Supabase infrastructure hosted in the EU. Supabase Privacy Policy
  • Stripe. Our payment processor. Stripe handles all credit card and payment data. We never receive your full card number. Stripe Privacy Policy
  • Google. Used for OAuth sign-in (Google Sign-In), advertising (Google AdSense), and potentially analytics. Google Privacy Policy
  • Vercel. Our web hosting and CDN provider for the frontend application. Vercel may process IP addresses for request routing and edge caching. Vercel Privacy Policy
  • Apple. Used for Sign in with Apple functionality, where applicable. Apple Privacy Policy

We do not share your personal data with any other third parties for their own marketing or commercial purposes.

6. Data Storage and Retention

Your data is stored on servers hosted within the European Union (via Supabase). We retain your personal data for as long as your account is active or as necessary to provide the Service and comply with legal obligations.

  • Registered accounts. Account data is retained until you request deletion or until we terminate your account for violations. Following deletion, residual data may be retained in encrypted backups for up to 90 days before being permanently purged.
  • Anonymous (guest) sessions. Anonymous accounts with no completed games are automatically deleted after 24 hours of inactivity. Anonymous accounts with game history are retained for up to 30 days of inactivity, after which they are permanently deleted.
  • Game logs. Detailed game session logs are retained for up to 90 days for anti-cheat analysis. Aggregated statistics are retained indefinitely.
  • Payment records. Transaction and billing records are retained for a minimum of 7 years to comply with financial and tax regulations.
  • Chat and moderation logs. Chat messages may be retained for up to 30 days. Messages reviewed in connection with a moderation action may be retained for up to 12 months.

7. Data Sharing

We do not sell, rent, or trade your personal data to any third party. We only share your data in the following circumstances:

  • With the data processors listed in Section 5, under binding contractual agreements
  • When required by law, court order, or government authority
  • To protect the rights, property, or safety of Belot Arena, our users, or the public
  • In the event of a merger, acquisition, or sale of assets, in which case the acquiring entity will be bound by this Privacy Policy or you will be notified and given the opportunity to delete your account

Publicly visible data includes your display name, avatar, ELO rating, and game statistics as shown on leaderboards. You may change your display name at any time.

8. Children's Privacy

Belot Arena is not directed at children. We do not knowingly collect personal data from children under the age of 13 (as required by COPPA) or under the age of 16 in EU member states where a higher age threshold applies under the GDPR.

If you are a parent or guardian and believe your child has provided us with personal data without your consent, please contact us immediately at dumbakod@gmail.com. We will promptly delete such data upon verification.

9. Your Rights Under GDPR

If you are located in the European Economic Area, you have the following rights regarding your personal data under the GDPR:

  • Right of access (Art. 15). You have the right to request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16). You have the right to request correction of inaccurate or incomplete personal data.
  • Right to erasure / "right to be forgotten" (Art. 17). You have the right to request deletion of your personal data, subject to certain exceptions (e.g., legal retention obligations).
  • Right to data portability (Art. 20). You have the right to receive your personal data in a structured, commonly used, machine-readable format, and to transmit it to another controller.
  • Right to restriction of processing (Art. 18). You have the right to request that we limit how we process your data in certain circumstances.
  • Right to object (Art. 21). You have the right to object to processing based on our legitimate interests, including profiling and direct marketing.
  • Rights related to automated decision-making (Art. 22). You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects, and to request human review of such decisions.
  • Right to withdraw consent. Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact our Data Protection contact at dumbakod@gmail.com. We will respond within 30 days. You also have the right to lodge a complaint with the Commission for Personal Data Protection of Bulgaria (CPDP) at cpdp.bg or with the supervisory authority in your EU member state.

10. Data Security

We implement industry-standard technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:

  • All data in transit is encrypted using TLS 1.2 or higher (HTTPS)
  • Authentication is handled by Supabase Auth, which uses secure hashing for passwords and industry-standard OAuth 2.0 flows for social sign-in
  • Database access is restricted to authorized services only, with role-based access controls enforced at the row level (Supabase RLS)
  • Payment data is handled entirely by Stripe, which is PCI DSS Level 1 certified
  • We conduct periodic security reviews and promptly address identified vulnerabilities

Despite our efforts, no method of data transmission or storage is 100% secure. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected users without undue delay, as required by GDPR Art. 33–34.

11. International Data Transfers

We store and process your data exclusively within the European Union. Our primary infrastructure provider, Supabase, is hosted in EU data centers, and we have selected EU regions for all applicable services.

Some of our third-party processors (including Google and Stripe) may transfer data internationally. These transfers are governed by Standard Contractual Clauses (SCCs) approved by the European Commission or by adequacy decisions, ensuring an equivalent level of data protection.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Last updated" date at the top of this page.

For significant changes that affect your rights, we will provide additional notice through an in-app notification or by email to registered users. Your continued use of the Service after such changes become effective constitutes your acceptance of the revised Privacy Policy.

13. Contact and Data Protection

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

We aim to respond to all privacy-related requests within 30 calendar days, as required by applicable law.