Privacy Policy
This privacy policy explains how LongestRally collects, uses, and protects your personal data in accordance with the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
1. Data Controller
The data controller within the meaning of Art. 4 No. 7 GDPR is:
Nikita Pashkov
Oranienburger Str. 70
10117 Berlin, Germany
Email: napashkov@gmail.com
2. Hosting
This website is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. When you visit this website, Vercel may process server log data including your IP address, browser type, and the pages you visit. This processing is necessary for delivering the website (Art. 6(1)(f) GDPR β legitimate interest).
Data may be transferred to the United States. Vercel participates in the EU-US Data Privacy Framework and uses standard contractual clauses to ensure adequate data protection.
3. Database & Authentication (Supabase)
We use Supabase Inc. as a data processor for user authentication and database storage. Our Supabase project is hosted in the EU (Frankfurt) region.
The following personal data is stored when you create an account:
- Email address
- Password (stored as a cryptographic hash β we never see your password)
- First name and last name
- City (optional, only if you provide it)
- Tournament enrollment records
- Ranking points earned from tournament participation
Legal basis: Art. 6(1)(b) GDPR β processing is necessary for the performance of our contract with you (providing the tournament platform service).
4. Analytics (Vercel Analytics)
We use Vercel Analytics to collect anonymous, aggregated usage data such as page views, referrer URLs, and device types. Vercel Analytics is cookie-free and does not track individual users or store personal data. No cross-site tracking occurs.
Legal basis: Art. 6(1)(f) GDPR β legitimate interest in understanding how the website is used to improve it.
5. Fonts
This website uses the Geist font. The font files are downloaded at build time and served directly from our own servers. No connection to Google's servers is established when you visit this website, and no IP address is transmitted to Google.
6. Cookies
This website uses only technically necessary cookies for session management. When you sign in, Supabase Auth sets a session cookie to keep you authenticated. These cookies are HTTP-only, secure, and are deleted when you sign out or your session expires.
We do not use any tracking, advertising, or third-party cookies. No cookie consent banner is required because these cookies are strictly necessary for the functioning of the service (TTDSG Β§ 25 Abs. 2 Nr. 2).
7. Contact Form
When you use our contact form, we collect your name, email address, and message. This data is used solely to respond to your inquiry and is deleted after 6 months.
Legal basis: Art. 6(1)(b) GDPR β processing is necessary to respond to your pre-contractual or contractual inquiry.
8. Public Display of Names
When you enroll in a tournament, your full name appears on the tournament's participant list, which is visible to all visitors. On the public rankings page, logged-out visitors see abbreviated names (e.g. "Nikita P."), while logged-in users see full names.
Legal basis: Art. 6(1)(a) GDPR β you give your consent to the public display of your name when you create your account and accept our Terms of Service.
9. Your Rights (GDPR Art. 15β21)
You have the following rights regarding your personal data:
- Right of access (Art. 15) β request a copy of the data we hold about you
- Right to rectification (Art. 16) β correct inaccurate data via your profile page or by contacting us
- Right to erasure (Art. 17) β request deletion of your account and data
- Right to restriction (Art. 18) β request that we limit the processing of your data
- Right to data portability (Art. 20) β receive your data in a structured, machine-readable format
- Right to object (Art. 21) β object to processing based on legitimate interest
- Right to withdraw consent β withdraw any consent you have given at any time, without affecting the lawfulness of processing before withdrawal
To exercise any of these rights, contact us at napashkov@gmail.com.
10. Right to Complain
You have the right to lodge a complaint with a data protection supervisory authority. The responsible authority for Berlin is:
Berliner Beauftragte fΓΌr Datenschutz und Informationsfreiheit
Friedrichstr. 219
10969 Berlin
www.datenschutz-berlin.de
11. Data Retention
- Profile data (name, email, city) β retained until you delete your account
- Tournament enrollments and ranking points β retained for 3 years for the legitimate purpose of maintaining ranking history and resolving disputes
- Contact form messages β deleted after 6 months
- Server logsβ retained per Vercel's and Supabase's standard data retention policies
Last updated: June 2026