PRIVACY
We aim to collect only what is needed for accounts, player discovery, communication and service protection. ARENACTIVE is not designed as a permanent message archive and the current release intentionally uses no advertising or third-party analytics trackers.
ARENACTIVE is still in closed testing. Before a public commercial launch, this area will be completed with the operator's legal identity and a dedicated public contact for privacy requests. The retention, security, account-deletion and moderation rules below describe the current system.
01 WHO HANDLES THE DATA
ARENACTIVE currently operates as a pre-release project. The operator's legal identity and a dedicated public privacy/support contact will be published before a public commercial launch. Until then, users can delete their own account in settings, use built-in blocking and submit reports through ARENACTIVE.
- We intentionally do not publish invented legal details or a non-existent support address.
- This section must be completed before mass advertising and an open public release.
02 DATA WE USE
For an account, ARENACTIVE stores username, email, password hash, language, region, email-verification state, account role/status and service timestamps. Plain-text passwords are not stored.
- Profile: display name, bio, selected games, languages, region, preferences and reputation.
- Game activity: lobbies, match participation, ready/presence state, feedback and required technical status.
- Social data: friends, invites, blocks and lobby-local exclusions.
- Platforms: if voluntarily linked, ARENACTIVE may store a verified external identifier such as SteamID; ARENACTIVE does not receive a Steam password.
03 MANUAL LOCATION & VISIBILITY
Location in ARENACTIVE is fully optional and entered manually by the user. The current release does not request browser GPS/geolocation and does not infer country, region or city from IP for this feature.
- A user may add country, region/state and city; street, home address, neighbourhood and precise coordinates are not needed for player discovery.
- Country is shown only when the user saves a location. Region is shown only with a separate visibility choice; city is shown only when both region and city visibility are enabled.
- Region/city filters return only players who chose to reveal that level. Hidden values are not used for disclosure through search.
- Location can be changed or cleared in the profile. ARENACTIVE does not build location history.
04 MESSAGES AND VOICE
Text exists for coordination and is intentionally retained for a limited period. ARENACTIVE does not record or store the content of voice audio. Voice uses WebRTC in the browser, and a technical relay/TURN service may forward audio packets without creating a recording of the conversation.
- Lobby chat: ordinary messages are retained up to 48 hours.
- DMs: unread messages up to 7 days; after being read, up to a further 48 hours.
- Reporting a message creates a separate temporary moderation snapshot, normally up to 7 days.
- Short-lived WebRTC signalling and voice-presence data exist only to establish and maintain the connection.
05 WHY WE PROCESS DATA
The main purposes are to create and protect accounts, verify email, find players, run lobbies/matches, provide friends and communication, recover passwords, prevent abuse and review reports.
- Processing needed for requested features is necessary to provide the service.
- Anti-abuse, fraud prevention, security and infrastructure protection rely on the legitimate interest in protecting users and the service where applicable.
- If applicable law requires separate consent for a future feature, that consent must be requested separately.
06 COOKIES AND BROWSER STORAGE
The current release uses only technical mechanisms needed for sign-in and interface preferences. ARENACTIVE intentionally sets no advertising cookies or third-party analytics cookies at this time.
- A protected session cookie supports sign-in and CSRF protection.
- An optional Remember Me cookie can retain sign-in for up to 30 days and is revoked on important security changes.
- A locale cookie remembers the selected language.
- localStorage/sessionStorage may remember sound preference, chat/voice UI state and a notification baseline; this is not an advertising profile.
07 SECURITY DATA AND RETENTION
ARENACTIVE uses temporary rate-limit/anti-abuse records, sessions and audit events to protect accounts and infrastructure. In rate-limit tables the network address is used as input for a SHA-256 bucket key rather than stored there in plain form; server-side security logs hash the network address and filter sensitive context fields.
- Normal sessions have idle/absolute limits; Remember Me is capped at 30 days in the current configuration.
- For the admin live-online counter, ARENACTIVE keeps a short-lived browser-session presence row containing only a SHA-256 session identifier, a coarse page category and activity timestamps. Raw IP, user-agent, coordinates and URL history are not stored in that row; stale rows are removed by maintenance, normally no later than 24 hours after the last activity.
- Rate-limit buckets live around their short windows and are later removed by maintenance; temporary abuse history is cleared after a quiet period.
- Moderation/security audit records are retained up to 180 days and should not contain passwords, reset/verification tokens or raw IP addresses.
- Infrastructure providers may keep their own server/security logs under their own retention policies.
08 PROVIDERS AND EXTERNAL SERVICES
ARENACTIVE may use OVHcloud hosting/email, relay infrastructure for WebRTC, and external game/platform APIs only as needed for a specific feature. When you move to an external service, that service's own privacy terms also apply.
- ARENACTIVE does not ask for the password of an external gaming platform.
- Technical processing by a provider may occur in another country depending on the selected infrastructure and the provider's applicable safeguards.
- Before public launch, the key processor list and international-transfer information must be finalised together with the operator's legal details.
09 ACCOUNT DELETION AND RIGHTS
A user can delete an account through ARENACTIVE settings. Account-linked and social data are removed, credentials are irreversibly replaced, and retained completed-match history is anonymised as “Deleted player”. Short-lived moderation/security records may remain until their retention period ends where needed for safety or an already-created report.
- Depending on applicable law, users may have rights of access, correction, deletion, restriction, portability and objection.
- Users may also have the right to complain to the competent data-protection authority.
- A public channel for formal privacy requests will be added before the open commercial launch.