Corridor beaver logocorridorLog In

Privacy & Data Settings

Last updated: 30 July 2026

This notice explains what personal data playcorridor.com collects, why we collect it, how long we keep it, and the rights you have. It is written to satisfy the EU GDPR, the UK GDPR, the Swiss FADP, the California CCPA/CPRA and comparable privacy laws in Canada, Brazil, Japan and Australia.

1. Who is responsible

PlayCorridor is the data controller for the personal data described here. You can reach us at support@playcorridor.com for any privacy request.

2. What we collect

Account data: email address, username, password hash (never the password itself), and - if you sign in with Google - the identifier, email and name Google returns.

Profile data you choose to add: display name, country, bio and avatar image.

Gameplay data: moves, results, ratings, puzzle progress, timestamps, and opponent pairings.

Technical data: IP address, approximate country derived from that IP, browser/user-agent, and log data needed for security, matchmaking and abuse prevention. We show only the resulting country flag to other players - never your IP address.

We do not collect special-category data, we do not knowingly collect data from children under 13, and we do not sell or share personal data for cross-context behavioural advertising as defined by the CPRA.

3. Why we use it and our legal bases

To provide the service - accounts, matchmaking, ratings, puzzles and game history: performance of a contract (GDPR Art. 6(1)(b)).

To keep play fair and the site secure - anti-cheat analysis, rate limiting, abuse investigation: legitimate interests (Art. 6(1)(f)).

To display your country flag to opponents: legitimate interests in a transparent competitive environment; you can override or hide the detected country in your profile settings.

To comply with legal obligations, such as responding to lawful requests: Art. 6(1)(c).

Any optional communication or analytics beyond the above is based on your consent (Art. 6(1)(a)), which you may withdraw at any time.

4. Cookies and local storage

We use strictly necessary cookies and browser local storage to keep you signed in, remember guest sessions and store interface preferences. These are exempt from consent requirements under the ePrivacy Directive because the service cannot function without them.

We do not run third-party advertising or cross-site tracking cookies. If we ever introduce optional analytics, they will be off by default and load only after your explicit consent.

5. Who we share data with

Processors that host and run the service on our behalf: our cloud database, authentication and hosting providers, and - where you use AI-assisted game analysis - our AI inference provider, which receives the game position only and no account identifiers.

Google, if and only if you choose Google sign-in.

Authorities, where we are legally required to respond to a valid request.

All processors are bound by data-processing agreements. Where data leaves the EEA/UK, transfers rely on the EU Standard Contractual Clauses and the UK Addendum together with supplementary safeguards.

6. How long we keep it

Account and profile data: for as long as your account exists, then deleted within 30 days of a deletion request.

Game records: retained after account deletion in anonymised form (no username, email or IP) so opponents keep coherent histories and ratings.

Security and abuse logs, including IP addresses: up to 12 months, or longer where an active investigation or legal claim requires it.

7. Your rights

You may request access, correction, deletion, restriction, portability, and object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it at any time without affecting past processing.

California residents may request disclosure of categories of data collected, deletion, correction, and may opt out of sale/sharing - we do not sell or share, so no opt-out signal is required, but Global Privacy Control signals are honoured. We never discriminate against you for exercising a right.

Most rights can be exercised directly in your profile page (edit or delete your data). Otherwise email support@playcorridor.com; we respond within 30 days.

You have the right to lodge a complaint with your local supervisory authority (for example, your national data protection authority in the EU, or the ICO in the UK).

8. Security

Data is encrypted in transit with TLS and at rest by our hosting provider. Access to production data is restricted, passwords are stored only as salted hashes, and database access is enforced by row-level security so players can only read their own private records.

If a breach is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours and inform affected users without undue delay.

Questions about this page? Contact us at support@playcorridor.com.