Privacy policy
Version 1.3 · Effective 2 August 2026
Who is responsible
Boardgame Tracker is a free, non-commercial hobby service operated by a private individual based in the Netherlands (the “controller” in GDPR terms). For anything in this policy — questions, complaints, or exercising your rights — contact contact@boardgame-tracker.com.
What we collect
- Account data — your email address, display name, unique handle, and sign-in provider (Google or email/password). If you upload a profile picture, we store the cropped image.
- Social data — your friends list, friend requests, and any private nicknames you give friends (visible only to you).
- Content you create — game sessions (date, time, and the free-text “where” you enter), recorded plays (who played, winners, scores, notes), your game library, and your collections.
- Names of people without accounts — if you add a “guest” or type a one-off player name, we store that name as part of your sessions and plays. If someone has stored your name this way and you want it removed, email us.
- Technical data — sign-in metadata (such as IP address and last sign-in time, kept by Firebase Authentication), server request logs and technical error reports (kept about 90 days — see “Error and diagnostic logs” below), and abuse-prevention signals (see “Keeping the service safe” below).
We keep anonymous, aggregate usage counts (the total number of accounts, and how many games are added, plays logged, sessions created, or pages viewed per day) with no cookies, no identifiers, and no IP stored — they count events, not people, and can’t be traced back to you. We do not use advertising trackers, we do not profile you, and we do not sell data.
Why we process it (legal bases)
- Providing the service — storing and showing your library, sessions, plays, and friends is the product itself (GDPR art. 6(1)(b), performance of a contract).
- Keeping the service safe — abuse prevention, rate limiting, and request attestation (GDPR art. 6(1)(f), legitimate interest: keeping a free service affordable and available).
We do not use your data for marketing.
What other users can see
- Sessions and plays are shared with the people in them: every participant of a session can see its details, its recorded plays, and the names of the other participants. Leaving a session removes your name from it: any seat you held in a recorded play keeps its result but is relabelled — “Rejected user” if you declined the invite, “Removed user” if the host took you off the roster.
- Your display name, handle, and profile picture are visible to other signed-in users (that’s how friends find you). Your email address is not — it is never stored in the profile other users can look up.
- Profile pictures are served via hard-to-guess public links — anyone holding the exact link can view the image.
Error and diagnostic logs
When something goes wrong we record a technical error report — an error message and stack trace, and the page it happened on; server-side logs may also include limited technical data such as an IP address. We use these only to diagnose faults and keep the service secure (GDPR art. 6(1)(f), legitimate interest), never to track you or build a profile. Error reports carry no account identifier, and logs are kept for a limited period (up to about 90 days) before automatic deletion. This stays within our existing Google Cloud infrastructure — it adds no new third party and sets no cookies.
Keeping the service safe (reCAPTCHA)
The app uses Firebase App Check with Google reCAPTCHA v3 on every page to verify requests come from the real app and not from abusive scripts. reCAPTCHA sets a cookie (_GRECAPTCHA) and analyses interaction signals; Google processes this data as described in Google’s privacy policy. We rely on legitimate interest (fraud and cost-abuse prevention) for this. It is the only third-party script that loads on every page; the only other one is Google’s sign-in script, which loads when you choose “Sign in with Google”.
Who can see your data on our side
Boardgame Tracker is run by one person. To operate it, fix faults, and answer support requests, that person can access the data stored in the app — this is inherent to running any service, and is not something we do casually or for curiosity. There is no advertising, profiling, or sale of data, and nobody outside the operator and Google (as our infrastructure provider) has access.
Who processes your data, and where
The app runs on Google Firebase / Google Cloud (Google as our processor under the Google Cloud Data Processing Addendum): Authentication, the Firestore database, file storage, and server hosting. The database and the file storage that holds profile pictures are both located in the European Union (the database in multi-region eur3). Some processing (such as authentication and request handling) involves Google LLC in the United States; those transfers are covered by the EU-US Data Privacy Framework and EU Standard Contractual Clauses.
Game metadata (titles, images, player counts) is fetched from BoardGameGeek by our server. These requests normally include no personal data. The one exception is the optional “Import from BoardGameGeek” feature: if you use it, we send the BGG username you type so we can fetch that public collection. We use the username only for that import and do not store it; BoardGameGeek is an independent service with its own privacy policy.
How long we keep it
- Account and content data — for as long as your account exists, deleted or anonymized when you delete your account (or on request, see below).
- Server request logs and technical error reports — about 90 days, then automatically deleted.
- Abuse-prevention counters — each counter holds only a request count and the start of the current time window (a minute or less), tied to your account. Nothing about what you did is recorded, and the counter is overwritten the next time you use the app.
- Backups: a snapshot of the whole database is taken every Monday and deleted automatically 30 days later. Backups stay in the EU, in the same place as the live database, and exist only so the service can be restored after a failure. This does mean something you delete can still exist inside a backup for up to 30 days afterwards.
Providing account data is necessary to use Boardgame Tracker — it is an account-based service, so without it we cannot give you a library or sessions. Everything beyond that (a profile picture, notes, guests) is optional and up to you.
Your rights
Under the GDPR you can ask for access to your data, correction, deletion, a machine-readable export, restriction of processing, or object to processing. Most of this is self-service: correct your profile and content in the app, and use Settings → Your data to download everything (JSON, plus a CSV play log) or to delete your account — deletion removes your profile, library, collections, guests, friendships and sign-in, and anonymizes your seats in shared sessions to “Deleted user” — the recorded result stays for the other participants, your name and account id do not. Deletion takes effect in the live app straight away. A copy can remain in our weekly backups until they expire automatically, at most 30 days. We use backups only to restore the service after a failure, never to bring a deleted account back, and after any restore we re-apply the deletions we hold on record. For anything else, email contact@boardgame-tracker.com and we will handle it within 30 days.
You also have the right to complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens.
No automated decisions
The app makes no automated decisions about you and does no profiling. The “pick a game for us” feature runs entirely on the game data in your own library.
Age
Boardgame Tracker is not directed at children. You must be 16 or older to create an account.
Changes to this policy
If the app starts processing new kinds of data or using new services, this policy is updated before that starts, and the version number above changes. How you hear about it depends on what changed:
- Wording and clarifications — the version and date here change. Nothing else happens, because nothing about your data changed.
- New data or a new purpose — we tell you before it starts, with a notice in the app and, for anything material, an email. Where we rely on legitimate interest you can object; the contact address above is how.
- Anything needing your consent — for example advertising or tracking, neither of which we do today — nothing is switched on until you have actively opted in, per purpose, with refusing as easy as accepting and no loss of access if you refuse. Continuing to use the app is never treated as consent.