# PitchNoir — Privacy Policy

**Data controller:** Campley Holdings Ltd ("Campley", "we", "us", "our"), a
company incorporated in England and Wales.
**Product:** PitchNoir (the "Game"), a web-based game.
**Last updated:** 2026-06-27
**Version:** 1.0 (draft for counsel review — see notice at end)

This policy explains what personal data we process when you play PitchNoir,
why, on what legal basis, who we share it with, how long we keep it, and the
rights you have. It is written to comply with the UK General Data Protection
Regulation (UK GDPR) and the Data Protection Act 2018, and with the EU GDPR
where it applies to players in the EEA.

> **Plain-English summary.** To play with a saved account you give us an email
> address and we create an account ID for you. Your game saves are stored under
> your account. We use Google (Firebase), and — if you buy in-game currency —
> Stripe, and (for live features) Cloudflare. We do not sell your data. You can
> get a copy of your data, correct it, or delete your whole account at any time.

---

## 1. Who we are and how to contact us

Campley Holdings Ltd is the **data controller** for the personal data described
in this policy.

- Privacy / data-protection contact: **privacy@campley.co.uk**
- Postal address: *[registered office address — insert before publication]*
- Data protection representative / DPO: *[insert if/when appointed; see §13]*

If we appoint a representative in the EU under Article 27 EU GDPR, their details
will be added here.

---

## 2. The data we collect

PitchNoir is designed to collect the **minimum** data needed to run accounts,
cloud saves and (optionally) payments. There are two modes of play:

### 2.1 Offline / local play (no account)
If you open the Game and do not sign in, the full single-player loop runs
entirely in your browser and your progress is saved only in your browser's
**`localStorage`** on your own device. In this mode **we do not collect or
receive any personal data about you on our servers.** (Standard web-server
access logs of your internet connection may still be generated by our hosting/
CDN providers — see §2.4.)

### 2.2 Signed-in play (account + cloud saves)
When you create an account or sign in, we process:

| Data | Source | Where it lives | Purpose |
|---|---|---|---|
| **Email address** | You, at sign-up / sign-in | Firebase Authentication (Google) | Account identity, sign-in, account recovery, service messages |
| **Account user ID (UID)** | Generated by Firebase Auth | Firebase Auth + Firestore | Stable key that ties your saves and wallet to you |
| **Authentication metadata** | Firebase Auth | Firebase Auth | E.g. account creation time, last sign-in time, sign-in method, hashed/managed credentials (managed by Google; we do not see your password) |
| **Game-save documents** | Generated as you play | Cloud Firestore (`users/{uid}/agencies/{agencyId}`) | Storing and syncing your saved agencies/progress across devices |
| **In-game wallet** | Generated as you play / purchase | Cloud Firestore (`users/{uid}`) | Tracking in-game currency (WahCoins) and entitlements |

**Game-save documents** contain in-fiction game state (your agency names,
rosters of fictional staff, scores, in-game economy). The agency *name* is
free-text you choose and could in principle contain personal data if you type
it in — please don't put real personal information into agency names.

### 2.3 Payments (only if you buy in-game currency)
If you purchase WahCoins, payment is handled by **Stripe**. You enter your card
details **directly with Stripe**; Campley does **not** receive or store your
full card number. We receive from Stripe a confirmation that a payment
succeeded, tied to your account UID and the pack purchased, which we use to
credit your wallet. Stripe processes your name, payment-card data, billing
details and transaction data as **its own controller / our processor** under
Stripe's terms and privacy policy.

### 2.4 Technical / log data
Our hosting and network providers (Firebase Hosting, and — for live multiplayer
features — Cloudflare) automatically process limited technical data such as IP
address, timestamps, user-agent and request metadata to deliver the service and
for security.

### 2.4a Product analytics (consent-based)
We operate **privacy-respecting product analytics** to understand how the Game is
used and to improve it. Analytics are **off by default** and only activate after
you give consent via the in-Game banner; you can decline, and you can withdraw
consent at any time (declining stops all transmission — events are then only
counted in a local, on-device aggregate that never leaves your browser).

When enabled, we record **anonymous product events** — for example, starting a
session, opening the store, winning or losing a pitch, or buying an in-Game item.
Each event carries an **anonymous client identifier** (a random id generated on
your device — **not** your name, email, or account id), a session id, the app
version, a coarse/truncated user-agent string, and a timestamp. We do **not** use
this analytics stream to track you across other websites, and we do **not** sell
it or use it for advertising. We rely on **Article 6(1)(a) — consent** for this
processing. Analytics events are retained in aggregate for product-improvement
purposes and are not linked back to your account profile.

### 2.5 Special-category and criminal-offence data
We do **not** intentionally collect any special-category data (Article 9 UK
GDPR — e.g. health, race, religion, sexual orientation, political opinions,
biometric/genetic data) or criminal-offence data. Please do not submit such
data through free-text fields (e.g. agency names).

---

## 3. Legal bases for processing

We rely on the following lawful bases under Article 6 UK GDPR:

| Processing | Lawful basis |
|---|---|
| Creating and operating your account; storing and syncing your cloud saves; authenticating you | **Article 6(1)(b) — performance of a contract** with you (our terms of service) |
| Processing a purchase of WahCoins and crediting your wallet | **Article 6(1)(b) — contract** |
| Security, fraud prevention, abuse mitigation, keeping the service reliable, and defending legal claims | **Article 6(1)(f) — legitimate interests** (our interest in a secure, functioning, non-abused service), balanced against your rights |
| Strictly necessary cookies / local storage that make the Game work | **Contract / legitimate interests**; no consent required for strictly-necessary storage |
| Any non-essential cookies/analytics, **if and when introduced** | **Article 6(1)(a) — consent** (we will ask first) |
| Sending service / account messages | **Contract**; marketing messages, if any, would be **consent** |

We do not currently carry out advertising profiling. The Game does include
*in-fiction* AI-driven game mechanics; these operate on game state, not on
profiling you as a person, and have no legal or similarly significant effect on
you under Article 22.

---

## 4. Cookies and local storage

PitchNoir uses browser storage rather than traditional advertising cookies:

- **`localStorage`** on your device to save offline single-player progress and
  remember UI preferences. This is **strictly necessary / functional** for the
  feature you are using.
- **Authentication tokens** (managed by Firebase Authentication) are stored in
  your browser so you stay signed in. These are **strictly necessary** to keep
  you logged in.
- We do **not** currently set advertising or cross-site tracking cookies.

Because the storage we set is strictly necessary or functional, it does not
require prior consent under PECR / the ePrivacy rules. If we later add non-
essential cookies or analytics, we will present a compliant consent banner and
update this policy first. You can clear local storage and cookies via your
browser settings at any time (this will remove offline saves held only in the
browser).

---

## 5. Who we share data with (sub-processors and recipients)

We do not sell your personal data. We share it only with service providers
("processors") who help us run the Game, under contracts that require them to
protect it. Our key sub-processors are:

| Provider | Role | What they process | Notes / safeguards |
|---|---|---|---|
| **Google (Firebase Authentication & Cloud Firestore, Firebase Hosting)** — Google Cloud project `phoenix-479815` | Identity, database, hosting | Email, UID, auth metadata, game-save documents | Google acts as our processor under the Firebase Data Processing Terms; serves from Google Cloud infrastructure |
| **Stripe** | Payment processing | Name, card/payment data, billing details, transaction data | Acts as processor / independent controller for payments; PCI-DSS compliant; we never see full card numbers |
| **Cloudflare** | Edge network / live multiplayer (Workers, Durable Objects) — *currently gated off* | IP, request metadata; live-session game state when enabled | Processor; multiplayer is not enabled in the current build |

We may also disclose data where required by law, to enforce our terms, to
protect rights/safety, or in connection with a corporate transaction (e.g. a
sale of the business), subject to appropriate confidentiality and this policy.

A current list of sub-processors will be maintained and made available on
request via **privacy@campley.co.uk**.

---

## 6. International transfers

Our providers are global and some processing may occur outside the UK/EEA
(notably in the United States). Where personal data is transferred outside the
UK/EEA, we rely on appropriate safeguards under Article 46 UK GDPR, which for
our providers means:

- the **UK International Data Transfer Agreement (IDTA)** / the UK Addendum to
  the EU **Standard Contractual Clauses (SCCs)**, and/or the EU SCCs;
- where applicable, the provider's certification under the **EU–US / UK–US Data
  Privacy Framework**; and
- the providers' published transfer mechanisms (Google, Stripe and Cloudflare
  each publish their transfer safeguards in their data-processing terms).

You can request a copy of the relevant safeguards via **privacy@campley.co.uk**.

> *Counsel action:* confirm and record the exact transfer mechanism relied on
> for each provider in the Record of Processing Activities (ROPA).

---

## 7. How long we keep your data (retention)

- **Account data (email, UID, auth metadata):** kept for as long as your account
  is active.
- **Game-save documents and wallet:** kept while your account is active so you
  can keep playing.
- **On account deletion:** we delete your authentication record and your game
  saves and wallet (see §9). Backups/replicas held by our providers are purged
  on their standard cycles (typically within a short, provider-defined window).
- **Payment records:** transaction records are retained by us and/or Stripe for
  as long as required by **tax, accounting and anti-fraud law** (in the UK,
  generally **6 years**), even after account deletion, on the basis of our legal
  obligation and legitimate interests.
- **Security logs:** retained for a limited period for security and abuse
  prevention, then deleted or aggregated.

> *Counsel/engineering action:* the current build does **not yet ship a verified
> self-service deletion flow**; see §9 and the deletion note. This must be in
> place before the Game is offered to the public.

---

## 8. Your rights

Under the UK GDPR you have the following rights, free of charge in most cases:

- **Right of access** — get confirmation we process your data and a copy of it.
- **Right to rectification** — have inaccurate data corrected.
- **Right to erasure ("right to be forgotten")** — have your data deleted (see
  §9 for how this works in PitchNoir).
- **Right to restriction** — limit how we use your data in certain cases.
- **Right to data portability** — receive certain data in a structured, machine-
  readable format and have it transmitted to another controller where feasible.
- **Right to object** — object to processing based on legitimate interests, and
  an absolute right to object to direct marketing.
- **Rights relating to automated decision-making and profiling** — we do not
  carry out solely-automated decisions producing legal or similarly significant
  effects on you; if that ever changes we will tell you and provide the relevant
  safeguards.
- **Right to withdraw consent** — where we rely on consent, you can withdraw it
  at any time (this does not affect prior lawful processing).

### How to exercise your rights
Email **privacy@campley.co.uk** from the email address on your account, telling
us which right you want to exercise. We will respond **within one month** (we may
extend by two further months for complex requests and will tell you if so). We
may need to verify your identity. We will not charge a fee unless your request
is manifestly unfounded or excessive.

### Right to complain
You can complain to the UK supervisory authority, the **Information
Commissioner's Office (ICO)** — ico.org.uk, helpline 0303 123 1113 — or to your
local EU supervisory authority. We'd appreciate the chance to resolve it first.

---

## 9. Deleting your account and data (erasure)

You can ask us to delete your account and personal data at any time by emailing
**privacy@campley.co.uk**, or (when available) using the in-app "Delete my
account" control.

When you delete your account we will delete:
- your **Firebase Authentication** record (email, UID, auth metadata);
- your **game-save documents** under `users/{uid}/agencies/*`; and
- your **profile and wallet** document at `users/{uid}`.

We will **retain** the minimum payment/transaction records we are legally
required to keep for tax, accounting and anti-fraud purposes (see §7), in a form
no longer linked to your live account where practicable.

> **Implementation status (must be true before public launch).** Erasure must
> be delivered by a **server-side** deletion routine (e.g. a privileged Cloud
> Function using the Firebase Admin SDK) that removes the Auth user **and**
> recursively deletes the user's Firestore documents (`users/{uid}` and the
> `users/{uid}/agencies` subcollection). Client-side deletion alone is not
> sufficient because Firestore security rules do not cascade-delete
> subcollections. Until this routine is shipped, tested and verified, deletion
> requests must be honoured manually via privacy@campley.co.uk within the
> statutory one-month window.

---

## 10. Children's data

PitchNoir is **not directed at children** and contains adult-oriented satirical
themes. We require players with accounts to be of the relevant age of digital
consent or older (**13 in the UK**, and the applicable age in your country —
up to 16 in parts of the EEA). We do not knowingly collect personal data from
children below that age. If you believe a child has provided us personal data,
contact **privacy@campley.co.uk** and we will delete it.

> *Product action:* an **age-gate** at sign-up should be implemented and its
> result recorded, consistent with the UK Age Appropriate Design (Children's)
> Code and the Game's adult-content posture (see `BRAND_SAFETY.md`).

---

## 11. How we protect your data

Security measures include Firebase Authentication for identity, Firestore
security rules that restrict each user to their own data, transport encryption
(HTTPS/TLS), and provider-managed encryption at rest. Payments are isolated to
Stripe. For the full security posture and the gap-list toward formal
certification, see `legal/COMPLIANCE_OVERVIEW.md`. No system is perfectly secure,
but we work to protect your data and will notify you and the ICO of any
qualifying personal-data breach as required by law (without undue delay, and to
the ICO within 72 hours where feasible).

---

## 12. Changes to this policy

We may update this policy. We will post the new version here with an updated
"Last updated" date and, for material changes, take reasonable steps to notify
signed-in players. Continued use after changes take effect constitutes
acceptance where lawful.

---

## 13. Counsel / readiness notice

> **This is a substantive, stack-specific draft — not a placeholder — but it is
> NOT yet a published, executed privacy policy.** Before PitchNoir is offered to
> the public, qualified data-protection counsel must:
> 1. verify and insert the registered office address and contact of record, and
>    decide whether a DPO and/or EU Article 27 representative is required;
> 2. confirm the lawful bases, retention periods and transfer mechanisms against
>    the finalised data flows and record them in a **ROPA** (Article 30);
> 3. complete a **DPIA** to the extent the live AI assessor / any profiling or
>    children's-data exposure is in scope;
> 4. ensure executed **Data Processing Agreements** with Google, Stripe and
>    Cloudflare are on file;
> 5. confirm the erasure routine (§9) and age-gate (§10) are implemented and
>    tested; and
> 6. publish this policy and link it from the sign-up flow with a clear consent/
>    acknowledgement step before any personal data is collected.
