Skip to main content

Version 1.0 · Last updated 2026-09-09 · This policy is currently under legal review. Its wording may be refined before launch, and any material change will be announced in advance.

Privacy Policy — GridBlitz

1. About This Policy

Your privacy matters to us, and this Privacy Policy is our straightforward explanation of what we do with your data. GridBlitz is a software-as-a-service ("SaaS") coordination tool built for invite-only football-squares games among groups of people who already know each other — friends, family, coworkers, your weekly crew. It is not a public marketplace, a betting platform, or a money-handler. (See Section 4 — How We Share Your Data — and the GridBlitz Terms of Service for the full picture of what the platform does and does not do.)

This Privacy Policy explains how GridBlitz collects, uses, shares, and protects your personal information when you use the platform.

A note on tone. Privacy disclosures are often written in dense legal English. We've tried to write this one in plain English — explaining the legal terms when they first show up, so you can actually understand what we do with your data. The substantive commitments are binding; the plain-English explanations are there to help you read what you're agreeing to.

Your acceptance. By creating an account, accessing the platform, or using any feature, you confirm you have read and understood this Privacy Policy. This Privacy Policy works alongside the GridBlitz Terms of Service ("Terms") — the two documents together govern your relationship with GridBlitz. If anything in this Privacy Policy appears to conflict with the Terms, this Privacy Policy controls on privacy and data-handling specifics; the Terms control on overall contract questions.

What this Policy does NOT cover. This Privacy Policy describes what GridBlitz does with your data. It does NOT cover what your Host or fellow Players might do with information you share inside a Grid — GridBlitz cannot control what other Users do once they can see information you've put on the platform (for example, your display name on a Grid they joined). It also does NOT cover any offline arrangement among you and other Users — money you contribute to a Host or receive from a Host happens entirely outside GridBlitz (see Terms Section 4 — Platform Description & Classification).


2. Information We Collect

The Platform collects only what's needed to operate the service. Below is a complete category-by-category inventory.

2.1 Account Information

When you create a GridBlitz Account, we collect:

  • Email address — used to sign you in, to send transactional emails (game invites, account confirmation, password reset), and as your Account's unique identifier
  • Password (if you sign in with email + password) — stored hashed using an industry-standard one-way scrambling function (called "scrypt" — once your password is stored we can't get it back as text; we can only check whether a future sign-in matches)
  • Display name — shown to other Users in Grids you join or host
  • Age attestation — your confirmation that you are at least 18 years old, with the timestamp of when you confirmed (per ADR-025; preserved as a compliance audit-trail artifact)

If you sign in with Google instead of email + password, Google sends us:

  • Your email address (same as above)
  • Your display name as listed in your Google account
  • An OAuth token (a temporary credential that lets us verify with Google that you are who you say you are)

If you sign in with a Magic Link (a one-time sign-in link delivered to your email), we send you the link via email and verify the click; no password is involved.

We do NOT collect: phone number (not required at signup), payment method (only collected if you purchase Hosting access — see Section 2.5 below), social media connections beyond the sign-in path you choose, or any government identification.

2.2 Profile Information

You may set:

  • Custom tile name preference — an optional display override for Squares you claim (otherwise we use your first name and last initial)
  • Notification preferences — which channels (email / push / in-app) you want certain notifications on, plus quiet-hours windows
  • Marketing opt-in status — whether you want to receive marketing emails (default: opted out)
  • Block list — Users you've chosen to block from invitations or interactions

2.3 Session Information

When you sign in, we create a session — a time-limited identifier that keeps you signed in across pages. The session record holds:

  • Session token — a randomized string (a small string of random characters that proves your browser is the one we authenticated)
  • IP address — the network address your sign-in came from (used for security: detecting unusual sign-in patterns)
  • User agent — a string your browser sends that identifies it (e.g., "Chrome on iPhone")
  • Created / expires-at timestamps

Sessions last about 7 days by default. You can sign out from any session via Account Settings.

2.4 Game Participation Data

When you create or join a Grid, we record:

  • Which Grids you host (as Host: the Grid you created, its title, schedule, NFL matchup reference)
  • Which Grids you've joined (as Player: which Grids accepted your join request)
  • Which Squares you claim in each Grid, with a frozen display-name snapshot at the moment you confirmed the Square (so historical Grids stay readable even if you later change your display name)
  • Path-to-Victory state — information about how close each of your Squares is to becoming a Score Match (visible only to you and to the Host of that Grid; not visible to other Players)
  • Block relationships — Users you've blocked or who have blocked you

Important — what this is NOT. GridBlitz does NOT record any money you contribute to a Host or receive from a Host. All such transactions happen offline between you and your Host. The Platform has no knowledge of, no record of, and no involvement in those amounts. (See Terms Section 4.)

2.5 Purchase Information (Hosts Only)

If you purchase Hosting access to create more Grids than your free starting allotment provides:

  • Payment confirmation — Stripe (the third-party payment processor we use) sends us a confirmation that your payment succeeded, including the payment ID and the amount you paid
  • Purchase type — which tier you bought (Single Grid, Bundle, Season Pass)

We do NOT see or store your card number, card details, or banking information. Those go directly to Stripe. We only see the payment confirmation. See Section 5 below for more about how Stripe handles your payment information.

Players do NOT purchase anything from GridBlitz; this section does not apply to Players.

2.6 Audit Log

For compliance and dispute-resolution defense, GridBlitz keeps an internal record of state-changing actions on the platform — Grid creation, Square claiming, invite sending, account deletion, and similar events. Each audit log entry records:

  • What event (Grid created, Square claimed, invite sent, etc.)
  • Who took the action (your User ID, or "SYSTEM" if it was an automated action)
  • When (timestamp)
  • What was affected (the relevant Grid ID, Square ID, etc.)
  • A small payload with event-specific details (for example, when a Grid locks, the payload includes the drawn row/column numbers)

The audit log is internal to GridBlitz — used by our operators for compliance defense and incident investigation. It's not visible to other Users. The retention period is 7 years (see Section 6.1 below).

2.7 Operational Telemetry

We collect technical signals to keep the platform running:

  • Error reports sent to Sentry (a third-party error-monitoring service) — these include the error itself + the page you were on; we redact personal data from error payloads before they leave our backend
  • Uptime and performance signals sent to BetterStack — these are system-level (response times, error counts) and don't include personal data
  • Server-side logs (kept in our hosting infrastructure for a brief operational window — typically a few weeks — for incident investigation)

We do NOT use third-party advertising trackers, analytics SDKs that fingerprint Users, or social-media pixels.

2.8 What We Do NOT Collect

To be explicit:

  • We don't collect government IDs, driver's licenses, or any identity verification documents
  • We don't collect financial information beyond Stripe's payment confirmations
  • We don't collect health data, biometric data, or genetic data
  • We don't collect data about your activity on other websites (no advertising trackers, no third-party cookies for advertising)
  • We don't buy User data from third parties
  • We don't collect data about non-Users (someone who hasn't signed up doesn't have a profile with us)

3. How We Use Your Data

We use the information we collect to:

3.1 Operate the Platform

  • Authenticate you — confirm you're who you say you are when you sign in
  • Coordinate Grids you host or join — show you your Grids, route invitations, accept join requests, track Square claims, display scores
  • Display scores from the NFL data feed — match scores to the Squares on your Grid (see Terms Section 4.3 — Score Match, Not Prize Distribution)
  • Deliver transactional emails — game invitations, account confirmations, password resets, magic links, milestone nudges that help new Hosts get started
  • Resolve technical issues — diagnose bugs, restore service after outages, investigate error reports

3.2 Maintain Safety and Compliance

  • Enforce platform rules per the Terms and Acceptable Use Policy — limit, suspend, or remove accounts that violate the rules
  • Keep an audit log — for compliance defense, dispute resolution, and the right-of-access flow described in Section 7.3 below
  • Detect abuse — invitation-spam patterns, account-impersonation attempts, automated scraping; the platform does not publicly disclose the specific signals it uses (per Terms Section 7.2)
  • Comply with applicable law — respond to lawful regulator inquiries, subpoenas, court orders within their scope

3.3 Communicate With You

  • Transactional emails (default opt-in; cannot be opted out of while you have an active account because they include security and compliance notices like password resets or material policy changes)
  • In-product notifications for events relevant to Grids you host or join (default on; configurable in Account Settings)
  • Marketing emails — only if you explicitly opt in; defaults to off; opt-out link in every marketing email

3.4 Improve the Platform

  • Use aggregated, anonymized usage patterns to understand which features Hosts and Players use most
  • Use error reports to fix bugs (with personal data redacted before review)

What we do NOT use your data for: we do not sell your personal data, do not share your personal data with advertisers, do not use it to build advertising profiles, do not use it to train AI models that are not GridBlitz's own.


4. How We Share Your Data

The Platform is designed to share as little of your data as possible. The complete list of who can see what:

4.1 Other Users — Limited, Game-Scoped

Other Users see your data only inside Grids you've chosen to host or join, and only as much as the Grid context requires:

  • Your Host sees your display name when you join their Grid (as a participant in their Grid)
  • Other Players in a Grid you joined see your display name on Squares you've claimed
  • A frozen display-name snapshot is recorded on each Square at the moment you claim it; this snapshot stays on that Square in historical Grid views (see Section 8 — Account Deletion — for what happens to these snapshots when you delete your Account)

Outside the Grids you participate in: other Users cannot see you, cannot find you, cannot list your Grids. There is no public game directory, no public leaderboard, no public profile.

4.2 Third-Party Service Providers

We share specific data with the third-party services we use to run the platform. Each service receives only the data it needs to perform its function. See Section 5 below for the complete list.

4.3 Legal & Compliance

We may disclose information when required by law, including:

  • In response to a valid subpoena, court order, or other legal process (we resist overbroad requests where appropriate)
  • To investigate suspected fraud, harassment, or other illegal activity affecting other Users or the Platform
  • To enforce the Terms or Acceptable Use Policy
  • To protect the rights, safety, or property of GridBlitz, Users, or others

4.4 Business Transitions

If GridBlitz is acquired by another company, merged with another company, or restructured, your data may be transferred to the resulting organization. We will give you advance notice of any such transfer (per Section 13 — Changes to This Policy) and the receiving organization will be bound by this Privacy Policy (or one with at least equivalent commitments) for your data.

4.5 What We Do NOT Share

  • We do not sell your data to anyone for any purpose
  • We do not share your data with advertisers
  • We do not share your data with data brokers
  • We do not share your data with other Users beyond the limited, game-scoped sharing in Section 4.1

5. Third-Party Services

We use a small number of third-party service providers ("vendors" or "data processors") to run the platform. Each receives only the data it needs to perform its specific function.

5.1 Stripe — Payment Processing (Hosts Only)

(to be finalized before launch)

When you purchase Hosting access, Stripe handles your card transaction. We send Stripe your email address; you provide your card details directly to Stripe. Stripe sends us back a confirmation that the payment succeeded plus a Stripe customer ID we use to reference your purchase history.

Stripe is a regulated US payment processor with its own privacy policy and security commitments. See stripe.com/privacy for what Stripe does with your data.

5.2 SendGrid — Transactional Email Delivery

SendGrid delivers our transactional emails — game invitations, account confirmations, password resets, magic links, and milestone nudges. We send SendGrid your email address and the email content. SendGrid does not use your email for any other purpose.

5.3 SportsDataIO — NFL Data Feed

SportsDataIO provides the NFL matchup and score data we display on Grids. No personal data is shared with SportsDataIO. This is a one-way feed: SportsDataIO sends us scores; we never send User data to SportsDataIO.

5.4 Neon — Database Hosting

Neon hosts the Postgres database that stores your Account, Grid participation, audit log, and other platform records. Neon is a US-based managed Postgres provider. Your data is stored in Neon's infrastructure in the United States (see Section 11 — International Users for cross-border considerations).

5.5 Railway — Application Hosting

Railway hosts the GridBlitz application servers. Railway processes your requests when you use the platform but does not have access to the underlying database content beyond what passes through the request/response chain.

5.6 Sentry — Error Monitoring

Sentry collects error reports when the platform encounters an unexpected error. We redact personal data (email addresses, display names, payload contents) from error payloads before they leave our backend.

5.7 BetterStack — Uptime Monitoring

BetterStack monitors whether the platform is up and responding. BetterStack receives system-level health signals (response times, error counts) but not User data.

5.8 Cloudflare Turnstile — Bot Protection

(to be finalized before launch) When you create an account, ask for an email sign-in link, or reset your password, we use Cloudflare Turnstile (a service that helps tell humans apart from bots without making you solve a CAPTCHA puzzle). Cloudflare may receive limited technical signals from your browser to make that determination. Signing in with your password does not run this check.

5.9 No Other Third Parties

We do not use any third-party advertising networks, analytics-fingerprinting services, behavioral tracking tools, or social media SDKs. If we add a new third-party service that processes your data, we will update this Section 5 and notify Users per Section 13 (Changes to This Policy).


6. Data Retention

We keep different categories of data for different periods, depending on what the data is for and what compliance rules apply.

6.1 Audit Log — 7 Years

The internal audit log (see Section 2.6) is retained for 7 years per ADR-022 §5. This window is calibrated to several external compliance standards:

  • US record-retention norms for SaaS services (typically 4–7 years)
  • The European Union's General Data Protection Regulation, specifically Article 5(1)(e), which says we shouldn't keep data "longer than necessary" — 7 years is the standard duration that meets the compliance-evidence-retention need without overshooting
  • Compliance review windows for major business partners (Apple App Store, Stripe, similar)

After 7 years, audit log entries are permanently deleted from the system.

6.2 Account Deletion Reversibility — 30 Days

When you request Account deletion (see Section 8), your Account enters a "soft-delete" state for 30 days per ADR-028 §4. ("Soft-delete" means we keep your record on file but treat it as deleted — your identifying information is replaced with placeholders everywhere, but the row stays in the database briefly in case you want to undo. See Section 8 below for the full mechanics.) During those 30 days, you can ask us to restore your Account through support. After 30 days, an automated system permanently removes your Account row from the database; restoration is no longer possible.

(After the 30-day window, the cascading anonymization stays in place; audit log entries persist per the 7-year retention above.)

6.3 Session Data — For the Duration of Your Session, Plus a Short Tail

Session records (see Section 2.3) persist as long as the session is active — typically up to 7 days — plus a small operational window after session expiry for safe sign-out. After that operational window, expired sessions are removed.

6.4 Operational Backups — Standard Infrastructure Backups

Our hosting provider (Neon) maintains database backups as part of its standard service. Backup retention is governed by Neon's infrastructure (typically a brief operational window — days to weeks, not years). When you delete your Account, the anonymization sweep applies to the active database; previously-existing backup snapshots age out under Neon's normal lifecycle.

6.5 Operational Telemetry — Brief Operational Window

Server-side logs, error reports, and uptime signals are retained for a brief operational window — typically a few weeks — long enough to investigate incidents and fix bugs. After that, they're either purged or aggregated into long-term metrics with no per-User identifiers.

6.6 Account Data — Until Deletion

Your Account record (display name, email, age attestation, profile preferences) is retained until you delete your Account, per Section 8.

6.7 Block Relationships — Until Removed or Account Deleted

Your block list persists in your Account until you remove a specific block (via Account → Manage Blocks) or until your Account is deleted.


7. Your Privacy Rights

You have rights over the data we hold about you. Different rights apply depending on where you live; this Section enumerates them by jurisdiction. You can exercise these rights regardless of where you live by contacting us via the channels in Section 14.

7.1 Rights Available to All Users

Regardless of where you live, GridBlitz extends the following rights to every User:

  • Right to access — request a copy of the data we hold about you (we will provide it as a structured download file — typically JSON or CSV that you or your tools can read — within a reasonable timeframe, normally 30 days)
  • Right to correction — ask us to fix inaccurate data (display name, email, profile preferences — most you can fix directly in Account Settings; for fields you cannot change yourself, contact us)
  • Right to deletion — request deletion of your Account (see Section 8 below for the deletion process)
  • Right to opt out of marketing — unsubscribe from marketing emails at any time (every marketing email has an unsubscribe link; you can also disable marketing in Account Settings; transactional emails for security and compliance cannot be opted out of while your Account is active)
  • Right to lodge a complaint — if you believe we've mishandled your data, contact us via Section 14; you also have the right to complain to a privacy regulator in your jurisdiction

7.2 California Residents (CCPA)

If you are a California resident, the California Consumer Privacy Act (a US state privacy law that gives California residents specific rights over their personal information; the law is commonly shortened to "CCPA") gives you the following rights in addition to those in Section 7.1:

  • Right to know what categories of personal information we collect about you, the sources we collect it from, the purposes we use it for, and the categories of third parties we share it with (this Privacy Policy provides those disclosures; you can also request a personalized export)
  • Right to delete personal information we have collected (same mechanism as the general right to deletion above)
  • Right to non-discrimination — we will not deny you service, charge you a different price, or provide a different level of service for exercising any CCPA right

Right to opt out of sale: the CCPA also gives California residents the right to opt out of having their data "sold." GridBlitz does not sell your personal data (see Section 4.5). There's nothing to opt out of, but you have the right anyway.

7.3 European Union Residents (GDPR)

If you are in the European Union (EU), the European Economic Area (EEA), or the United Kingdom, the General Data Protection Regulation (commonly shortened to "GDPR" — the EU's foundational privacy law) gives you the following rights in addition to those in Section 7.1.

Quick reference. Each right below is identified by its GDPR article number (the section of the law that creates it). We've added a plain-English description for each so you can recognize the right by what it does, not just by its legal label. The list covers access, correction, deletion, restriction, portability, objection, and protection from purely automated decisions.

  • Article 15 — Right of access — request a copy of the personal data we hold about you, plus information about how we use it, who we share it with, how long we keep it, and where we got it (we will respond within 30 days, in line with GDPR's standard response window)
  • Article 16 — Right to rectification — ask us to correct inaccurate data
  • Article 17 — Right to erasure (also called the "right to be forgotten") — ask us to delete personal data we hold about you. We honor this through the Account deletion flow described in Section 8 below. Note: the audit-log entries retained per Section 6.1 are NOT considered "personal data" after the cascading anonymization step described in Section 8.3 — the User-identifying fields are replaced with placeholders, leaving only event metadata
  • Article 18 — Right to restriction of processing (plain English: keep your data on hold without using it further) — ask us to stop using your data for purposes beyond storage (limited applicability for a coordination platform — most of our processing is operational; if your concern is a specific use case, contact us via Section 14)
  • Article 20 — Right to data portability — receive your data in a structured, commonly used, machine-readable format (we will provide a JSON export)
  • Article 21 — Right to object — object to specific processing, particularly direct marketing (you can disable marketing emails at any time per Section 7.1)
  • Article 22 — Automated decision-making — GridBlitz does not make decisions about you using solely automated processing that has legal or similarly significant effects on you (enforcement actions are reviewable per Terms Section 7.2)

Storage limitation per Article 5(1)(e): GDPR Article 5(1)(e) requires that personal data be kept "in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed." ("Data subjects" is GDPR's term for the individual people whose data is being processed — that's you.) Section 6 above describes our retention windows. The 7-year audit-log retention is calibrated to meet the necessary-for-compliance test under Article 5(1)(e); we do not retain personal data in identifiable form longer than that.

Lawful basis for processing. GDPR Article 6 requires us to identify a specific legal justification (a "lawful basis") for handling your data. Our lawful bases are:

  • Performance of a contract (Article 6(1)(b)) — operating the platform you signed up for
  • Legitimate interests (Article 6(1)(f)) — security, abuse prevention, audit-log retention for compliance defense, operational telemetry; balanced against your interests and rights
  • Legal obligation (Article 6(1)(c)) — responding to lawful regulator requests, complying with applicable law
  • Consent (Article 6(1)(a)) — for marketing emails (separately opted in; revocable at any time)

Right to lodge a complaint with a supervisory authority in your EU member state. If you live in an EU country, your national data protection authority is your supervisory authority.

(to be finalized before launch)

7.4 How to Exercise Your Rights

To exercise any right in this Section 7:

  • For deletion, use the Account deletion flow in Account Settings (Section 8 below)
  • For opting out of marketing, use the unsubscribe link or Account Settings toggle
  • For access, correction, portability, restriction, or objection, contact us via Section 14 below

We will respond to requests within 30 days (the GDPR standard timeline). If we need more time for a complex request, we will tell you and explain why.

We may ask you to verify your identity before responding (typically by confirming control of your registered email address) — this prevents someone else from impersonating you to make a request about your data.

We will not charge you a fee for reasonable requests. We may charge a reasonable fee for excessive or repetitive requests, or decline them, where permitted by applicable law.


8. Account Deletion

You can request deletion of your Account at any time through Account Settings. Account deletion follows the process below, defined in ADR-028 (Account Deletion + Cascading Anonymization).

Plain English first. When you delete your Account, we don't just hide your record — we replace your identifying details (name, email, profile fields) with placeholders everywhere they appear, so future viewers of historical Grids you participated in see "[Deleted user]" rather than your name. The audit log keeps the record of what happened (which Grid was created, which Square was claimed) for compliance, but with your identity scrubbed.

8.1 Active-Engagement Check (Step 1)

Before deletion proceeds, we check whether you have ongoing commitments that would block deletion. The full mechanics live in the GridBlitz Terms of Service Section 7.1; in summary:

  • As Host: if you currently host any Grid in DRAFT, FILLING, LOCKED, or LIVE state, deletion is blocked until those Grids reach FINAL state or you cancel them
  • As Player: if you currently own active Squares in any Grid in DRAFT, FILLING, LOCKED, or LIVE state, deletion is blocked until those Squares are released (for DRAFT/FILLING) or those Grids reach FINAL state (for LOCKED/LIVE)

If either check fails, the platform returns an error explaining which engagement is blocking and how to resolve it. Both checks must clear before deletion proceeds.

8.2 Confirmation Email (Step 2)

If both checks pass, we send a confirmation email to your registered email address with a one-time verification link. Click the link to confirm. Without confirmation, no deletion occurs.

This step exists to prevent accidental deletion and to make sure someone who briefly accesses your Account can't delete it without your separate email confirmation.

8.3 Soft-Delete + Cascading Anonymization (Step 3)

On confirmation, we:

  • Mark your Account as "soft-deleted" — your data is marked deleted but preserved for 30 days in case you want to restore it. Your email is replaced with an anonymized placeholder (in the format <anonymized-{userId}>@anonymized.local) and your display name is replaced with "[Deleted user]".
  • Anonymize your profile fields — your first name, last initial, custom tile name, and notification preferences are replaced with placeholders or cleared (per ADR-028 §1 Phase A).
  • Run a cascading-anonymization sweep across the data graph — your identifying information is replaced with placeholders or removed across audit log entries, notification records, historical Square ownership snapshots (which show "[Deleted user]" instead of your name in historical Grid views), block-list relationships (removed entirely), invitation tokens, and entitlement records.
  • Invalidate all your active sessions — you are signed out everywhere.
  • Record the deletion in the compliance audit trail per ADR-022 — the audit log keeps the event "this account was deleted" with a system-recorded timestamp, but no longer ties your name or User ID to the entry (you no longer have an active account at that point, so the audit row simply notes "deleted by SYSTEM" rather than attaching your identity).

This entire sweep runs in a single database transaction — either all of it commits, or none of it does. There is no partial state.

8.4 30-Day Reversibility Window (Step 4)

For 30 days after confirmation, you may request restoration of your Account by contacting us through the channels in Section 14. Restoration is a manual operation handled by support; it is not self-service.

If you restore within 30 days, your Account is reactivated; the cascading-anonymization replacements (the "[Deleted user]" snapshots, the audit log entries) are NOT undone — those preserve the historical record. Only your Account-level fields (display name, email, profile) are restored from backup if available.

8.5 Permanent Removal (After 30 Days)

After 30 days, an automated system permanently removes your Account row from the database. After permanent removal:

  • The cascading-anonymization replacements stay in place — historical Grids continue to show "[Deleted user]" for your former Squares
  • Audit log entries persist per the 7-year retention policy in Section 6.1; they no longer contain User-identifying information
  • Operational backups age out per the standard backup lifecycle (Section 6.4)

You can re-register on GridBlitz with the same email address after permanent removal — the email is freed up by the anonymization step in 8.3.

8.6 What's NOT Removed

For the avoidance of doubt:

  • Money you contributed to a Host offline: not collected, recorded, or removed by GridBlitz at any point — it's between you and your Host (see Section 4.5 — What We Do NOT Share)
  • Historical NFL scores: the Grids you participated in stay in the platform for the Host and other Players to see; only your identity is anonymized
  • Other Users' data: your deletion does not affect data about other Users (their Squares stay theirs, their accounts stay active)

9. Cookies & Similar Technologies

GridBlitz uses cookies (small pieces of data your browser stores on your device) only for essential and functional purposes:

  • Essential cookies — authentication tokens (so you stay signed in across pages), session identifiers (so the platform knows it's still you between requests), security tokens (so the platform can block cross-site request forgery, and can tell humans apart from bots when you create an account, request an email sign-in link, or reset your password)
  • Functional cookies — preferences that make the platform work the way you set it up (e.g., notification preferences)

GridBlitz does NOT use:

  • Third-party advertising cookies
  • Tracking pixels that fingerprint your device
  • Social-media-platform cookies
  • Behavioral analytics that profile your browsing across sites

The separate Cookie Policy with the full per-cookie inventory and category-based disclosure is now available at 01_global/canonical/legal/policies/COOKIE_POLICY_v1.md (Code v1 DRAFT Session 115 SC1; pending attorney v2 per Phase H of LEGAL_PAGES_DRAFTING_CHARTER.md). The Cookie Policy is the authoritative cookie-specific disclosure; this section provides a summary that cross-references it.

If you are in a jurisdiction with cookie-consent requirements (EU/UK under the ePrivacy Directive — the EU's specific law on cookies and electronic communications, working alongside GDPR), you may withdraw consent for non-essential cookies at any time via Account Settings (when implemented per the Cookie Policy's forward-commitment in §5) or by configuring your browser to reject non-essential cookies. Note: essential cookies cannot be rejected without breaking your ability to sign in to the platform.


10. Children's Privacy

GridBlitz is for adults only. You must be at least 18 years old to use the Platform (see Terms Section 3.1 — Minimum Age). We do not knowingly collect personal information from anyone under 18.

If we discover that we have inadvertently collected personal information from a person under 18, we will delete that information promptly. If you are a parent or guardian and believe your child under 18 has provided us with personal information, contact us via Section 14 and we will take steps to remove the information.

GridBlitz is not directed to children, does not market to children, and does not knowingly collect, use, or disclose any data covered by the Children's Online Privacy Protection Act ("COPPA" — a US federal law protecting children under 13).


11. International Users & Data Transfers

GridBlitz operates from the United States. Our application servers (Railway), database (Neon), and most operational infrastructure are hosted in the United States. If you access the Platform from outside the US, your data will be transferred to and stored in the United States.

11.1 For EU / EEA / UK Users

The US has not received a general "adequacy decision" from the European Commission (an "adequacy decision" is the EU's formal determination that a country offers data protection comparable to the EU's). When your personal data is transferred from the EU/EEA/UK to the US, we rely on the following safeguards under GDPR Chapter V (the section of GDPR that governs how personal data can leave the EU and travel to countries that do not have an adequacy decision):

(to be finalized before launch)

If you are in the EU/EEA/UK and prefer your data stay in your local jurisdiction, GridBlitz is not currently able to offer EU-hosted infrastructure. By continuing to use GridBlitz from within the EU/EEA/UK, you accept that your data will be transferred to and processed in the United States as described above. If you don't want that, the only option is to stop using GridBlitz before signing up or to delete your Account per Section 8.

11.2 For Other Non-US Users

If you access GridBlitz from a country outside the US with privacy laws governing cross-border data transfer (e.g., Brazil's LGPD, Canada's PIPEDA), GridBlitz processes your data in compliance with applicable transfer mechanisms. Contact us via Section 14 if you have a specific question about your jurisdiction.


12. Security

We take reasonable security measures to protect your data, including:

  • Encryption in transit — all communication between your browser and GridBlitz is encrypted (HTTPS / TLS)
  • Encryption at rest — your data is stored on encrypted disks managed by our hosting providers (Neon, Railway)
  • Password hashing — passwords are stored using an industry-standard one-way scrambling function (scrypt) so we cannot recover them as text; only verify whether a sign-in matches
  • Rate-limited authentication — to make automated guessing attacks much slower
  • Bot protection — Cloudflare Turnstile (or equivalent) on the account-creation, email-sign-in-link, and password-reset paths to make automated account creation much harder
  • Multiple security layers in depth ("defense-in-depth" — overlapping protections so a single failure doesn't expose your data) — including 18+ age attestation, audit-log immutability, and cascading anonymization on deletion
  • Append-only audit log — once a security-relevant event is recorded, it cannot be modified or deleted (per ADR-022 §4); this preserves the evidence of what happened
  • Limited administrative access — internal administrative access to your data is restricted, logged, and reserved for incident response, compliance review, and customer-support escalation

No system is perfectly secure. We cannot guarantee that your data will never be accessed by an unauthorized party. If we become aware of a security incident affecting your personal data, we will notify you and the relevant regulators in accordance with applicable law.

(to be finalized before launch)


13. Changes to This Policy

GridBlitz may update this Privacy Policy over time — adding new features, fixing gaps, complying with new laws, or clarifying existing language. When we make a material change — a change that meaningfully affects what data we collect, how we use it, who we share it with, or what rights you have — we will notify Users at least (to be finalized before launch) before the changes take effect, by:

  • Email to the email address on file with your Account, AND/OR
  • An in-app banner or notification on next sign-in

If you do not agree with a material change, your options are: (a) stop using the Platform before the effective date, or (b) request Account deletion per Section 8.

Non-material changes (e.g., typo corrections, clarifications, contact-information updates, addition of a new service provider that doesn't change the data-handling substance) take effect immediately and are recorded in the changelog at the top of this document.

Each version of this Policy is preserved with its effective date. You may request the current and historical versions from GridBlitz at any time per Section 14.


14. Contact Information

Privacy questions, data-rights requests, complaints, or general inquiries about this Privacy Policy may be directed to:

  • Operating Entity: (to be finalized before launch)
  • Privacy Contact / Email: (to be finalized before launch)
  • Mailing Address: (to be finalized before launch)

(to be finalized before launch)

We will respond to data-rights requests within 30 days per Section 7.4. For Account-level questions (sign-in problems, billing, general support), use the support channel reachable from within the Platform.


15. Standard Clauses

What this section covers (plain English): four standard housekeeping commitments that every privacy policy carries — what happens if a court strikes down part of this policy, whether our not enforcing something means we've waived it forever, whether we can transfer this policy to another company, and which state's law governs disputes about it. These mirror the same four clauses in our Terms of Service (Section 14).

This section captures the same housekeeping commitments that appear in the Terms of Service Section 14, applied to this Privacy Policy.

  • Severability — if a court or regulator strikes down any provision of this Privacy Policy, the rest stays in effect to the maximum extent permitted by applicable law
  • No waiver — our failure to enforce any provision of this Privacy Policy is not a waiver of that or any other provision
  • Assignment — we may transfer our rights and obligations under this Privacy Policy in connection with a merger, acquisition, or sale of assets, subject to Section 4.4 (Business Transitions)
  • Governing law and dispute resolution — disputes about this Privacy Policy are governed by the same law and resolved through the same mechanism as the GridBlitz Terms of Service (see Terms Section 12) (to be finalized before launch)

Appendix A — Required Disclosures Summary

The following disclosures are made consistent with the GridBlitz LEGAL_COMPLIANCE_FRAMEWORK_v1.md governance authority:

  1. Platform Classification (per CLAUDE.md §1 + LEGAL §1). GridBlitz is a SaaS coordination platform, not a gambling platform, betting service, financial intermediary, or prize authority.
  2. Money-Handling Statement (per LEGAL §3 Critical Rule 1). GridBlitz does not collect, process, hold, transfer, or distribute money between participants. All Player–Host money flows are offline and outside the Platform.
  3. No Sale of Personal Data (per CCPA + general commitment). GridBlitz does not sell User personal data to any third party.
  4. No Advertising Trackers (per Section 2.7). GridBlitz does not use third-party advertising trackers, behavioral analytics that fingerprint Users, or social-media pixels.
  5. 18+ Age Requirement (per ADR-025 + Terms Section 3.1). Users must be at least 18 years old; no children's data is knowingly collected.
  6. Audit Log Retention (per ADR-022 §5). Audit log entries retained 7 years; post-deletion anonymization preserves event immutability per ADR-022 §6.
  7. Account Deletion (per ADR-028). Active-engagement pre-check + soft-delete + cascading anonymization + 30-day reversibility mechanics per Section 8 + Terms Section 7.1.
  8. Hosted-Game Privacy Invariant (per ADR-019). Hosted-game state is never returned by an anonymous request; auth + host-approved game membership are required (see also Terms Section 4 — Platform Description).

Appendix B — Definitions Cross-Reference

For convenience, key terms used in this Privacy Policy and where they live:

  • GridBlitz / Platform / we / us / our — see Terms Section 2 + this Privacy Policy header
  • You / your / User — see Terms Section 2
  • Account — see Terms Section 2
  • Host / Player / Grid / Square / Score Match / Content — see Terms Section 2
  • CCPA — California Consumer Privacy Act (US state privacy law; see Section 7.2)
  • GDPR — General Data Protection Regulation (EU privacy law; see Section 7.3)
  • COPPA — Children's Online Privacy Protection Act (US federal law for children under 13; see Section 10)
  • PII ("personally identifiable information") — data that identifies you specifically (name, email, etc.)
  • Soft-delete — marking a record as deleted but preserving it for a reversibility window (see Section 8.3)
  • Cascading anonymization — sweep that replaces User-identifying information with placeholders across the data graph (see Section 8.3)
  • Audit log — internal append-only record of state-changing events (see Section 2.6)