Battle Bridge — Privacy Policy
Version 2.0 — Effective 6 September 2026
Last updated: 6 September 2026
1. Who we are
Battle Bridge ("Battle Bridge", "we", "us") is an independently operated
virtual tabletop application, run from Australia by a sole developer.
- Contact: [email protected]
We are the data controller for the personal data described in this policy.
Battle Bridge is a small independent project rather than a company, and email
is the way to reach us about anything in this policy. We answer every request
sent to that address.
2. Scope
This policy covers the Battle Bridge web application at
play.battle-bridge.com and its API. It applies whether or not you have an
account.
You can use Battle Bridge without an account. If you do, we hold no account
data about you at all — your maps, tokens and sessions stay in your own
browser's storage. See §4.
3. What we collect, and why
We collect only what the Service needs to function. We do not run advertising,
we do not profile you, and we do not sell your data.
3.1 Account data — only if you register
| Data | Why | Lawful basis (GDPR Art. 6) |
|---|---|---|
| Email address | Login, password reset, service notices | Contract (6(1)(b)) |
| Username | Identifying you in-app and in the marketplace | Contract |
| Password | Stored only as a PBKDF2-SHA256 hash (600,000 iterations, per-user random salt). We never store or can recover your password. | Contract |
| Account tier, storage used, email-verified flag | Enforcing plan limits | Contract |
| Account created/updated timestamps | Account administration | Legitimate interests (6(1)(f)) |
3.2 Game content — only if you save it to your account
Saved sessions, custom tokens, uploaded map images, and marketplace
publications and downloads. This content is yours; we store it so you can load
it again. Lawful basis: contract.
We do not read, review or analyse your game content except where strictly
necessary to operate the Service, respond to a support request you make, or
investigate a specific report of prohibited content (§5.2 of the Terms).
3.3 Multiplayer session data
When you host or join a live session we process, in memory and transiently,
the display name you choose, your token positions and moves, dice rolls, and a
randomly-generated session join code. **We do not record or persist the content
of live multiplayer sessions.** When the session ends, this data is gone.
Your display name in a session is visible to everyone else in that session. Do
not use your real name if you do not want other players to see it.
Lawful basis: contract (for the person who requested the session);
legitimate interests (for delivering the session to other participants).
3.4 Payment data
If you buy Pro, payment is processed by PayPal. Your card or bank details
go directly to PayPal and never reach our servers. We store only:
- the PayPal order ID,
- the amount and currency,
- the transaction status,
- which account it relates to.
Lawful basis: contract, and legal obligation (6(1)(c)) for the financial
records we must keep. See §7 on retention.
3.5 Technical and security data
| Data | Why | Lawful basis |
|---|---|---|
| IP address | Rate limiting, abuse prevention, and standard server logs. Held for rate-limiting purposes for a short rolling window. | Legitimate interests — securing the Service |
| CAPTCHA token (Cloudflare Turnstile, on registration) | Blocking automated sign-ups | Legitimate interests |
| Error and crash reports: error message, stack trace, the page URL where it happened | Diagnosing faults | Legitimate interests |
| Bug reports you submit: your description, linked to your account | Support | Contract |
Error reports and bug reports are automatically deleted after 30 days by a
scheduled job. Error reports are not linked to a user ID.
3.6 What we do NOT collect
- No advertising or cross-site tracking identifiers.
- No analytics or behavioural profiling.
- No biometric data, precise location, or special-category data (Art. 9).
- No automated decision-making producing legal or similarly significant
effects (Art. 22).
- We do not use your data, content, or game sessions to train AI models,
and we do not provide them to third parties for that purpose.
4. Cookies and local storage
We do not use advertising or analytics cookies. **We use only what is strictly
necessary to make the Service work**, which is why you will not see an
"accept all / reject all" advertising banner — there is nothing to reject.
| Name | Type | Purpose | Duration |
|---|---|---|---|
__Host-vtt_token | Cookie (HttpOnly, Secure) | Keeps you signed in | 7 days |
vtt-* keys | Browser localStorage | Your maps, tokens, session state, and display settings — stored in your browser, not sent to us unless you save to the cloud | Until you clear it |
bb-consent | Browser localStorage | Records that you accepted the Terms, so we do not ask again | Until you clear it |
| Cloudflare Turnstile | Third-party, registration page only | Bot protection | Session |
| PayPal | Third-party, checkout only | Processing your payment | Set by PayPal |
You can clear all of this at any time via your browser settings, or by using
the "Clear Session" control in the app. Clearing it will sign you out and
remove locally-stored games.
If we ever add analytics, we will ask for your consent first.
5. Who we share data with
We do not sell your personal data. We have never sold personal data. We do not
"share" it for cross-context behavioural advertising as defined by the CCPA/CPRA.
We use these processors:
| Provider | What they handle | Where |
|---|---|---|
| Cloudflare, Inc. | Hosting, database (D1), file storage (R2), session infrastructure, CAPTCHA, DDoS protection | Primary database region: Asia-Pacific (Sydney); served via Cloudflare's global network |
| PayPal | Payment processing (independent controller for payment data) | Global |
| Resend | Transactional email (verification, password reset, receipts) | Global |
We may also disclose data where legally required — a valid court order, lawful
request from a regulator, or to establish or defend legal claims — or to
protect the rights and safety of users.
If Battle Bridge is ever sold or merged, your data may transfer to the
acquirer. We will notify you before that happens and before any change to this
policy takes effect.
6. International transfers
Our primary database is in Australia. Cloudflare, PayPal and Resend operate
globally, so your data may be processed in other countries, including the
United States.
For transfers out of the EEA or UK we rely on the **European Commission's
Standard Contractual Clauses** (and the UK Addendum / IDTA where applicable),
as incorporated into our providers' data processing agreements. You can request
a copy of the relevant safeguards using the contact details in §1.
7. How long we keep data
| Data | Retention |
|---|---|
| Account and game content | Until you delete your account |
| Bug reports | 30 days, then automatically deleted |
| Error / crash logs | 30 days, then automatically deleted |
| Live multiplayer session content | Not retained — discarded when the session ends |
| Payment records | 5 years, the period Australian tax rules generally require, to meet tax and financial record-keeping obligations. Retained in anonymised or pseudonymised form after account deletion. |
| Rate-limiting records | Short rolling window (minutes to hours) |
8. Deleting your account
You can delete your account from Account → Settings in the app. Deletion
removes your account record, saved sessions, custom tokens, marketplace
entries, bug reports, uploaded files, and closes any sessions you host.
One exception: we retain the minimum payment records required by tax and
accounting law (§7). These are decoupled from your identity where possible.
This is permitted by GDPR Art. 17(3)(b) — compliance with a legal obligation.
Deletion is immediate and cannot be undone.
9. Your rights
Your rights depend on where you live. We honour the following for **all users
worldwide**, regardless of whether your local law requires it:
- Access — get a copy of the data we hold about you.
- Correction — fix data that is wrong.
- Deletion — erase your account and data (§8).
- Portability — receive your data in a portable format. You can also export
any session to a file directly in the app at any time.
- Objection / restriction — object to processing based on legitimate
interests, or ask us to restrict it.
- Withdraw consent — where we rely on consent, withdraw it at any time.
This does not affect processing already carried out.
- Non-discrimination — we will not degrade your service for exercising any
of these rights.
To exercise any right, contact [email protected]. We will respond
within 30 days (or one month under GDPR, extendable by two further months
for complex requests, in which case we will tell you). We may need to verify
your identity first.
Additional rights by region
- EEA / UK (GDPR, UK GDPR): all of the above, plus the right to lodge a
complaint with your local supervisory authority. In Ireland: the Data
Protection Commission. In the UK: the Information Commissioner's Office
(ico.org.uk).
- California (CCPA/CPRA): the right to know, delete, and correct; the right
to opt out of sale or sharing — **we do not sell or share personal
information, so there is nothing to opt out of**; the right to limit use of
sensitive personal information — we do not collect any. We do not have actual
knowledge of selling the personal information of anyone under 16.
- Australia (Privacy Act 1988, APPs): access and correction rights as
above. You may complain to us first; if unsatisfied, to the Office of the
Australian Information Commissioner (oaic.gov.au).
- Canada (PIPEDA): access, correction, and complaint to the Office of the
Privacy Commissioner.
- Brazil (LGPD): access, correction, deletion, portability, and information
about sharing.
10. Children
Battle Bridge is not intended for children under 13, and we do not
knowingly collect personal data from them.
In the EEA, the minimum age to consent to information-society services ranges
from 13 to 16 depending on the country. If you are under the age of consent in
your country, a parent or guardian must agree to these terms on your behalf.
If you believe a child has given us personal data, contact
[email protected] and we will delete it promptly.
11. Security
- Passwords are hashed with PBKDF2-SHA256, 600,000 iterations, with a
unique random salt per user. We cannot see or recover your password.
- All traffic is encrypted in transit with TLS.
- Session tokens are signed, expire after 7 days, and are **invalidated
immediately when you change your password**.
- Authentication cookies are
HttpOnly,Secure, and use the__Host-prefix. - Rate limiting and CAPTCHA protect against brute-force and automated abuse.
- Access to production systems is restricted to authorised personnel.
No system is perfectly secure. We cannot guarantee absolute security, and you
share information at your own risk.
12. Data breaches
If a breach occurs that is likely to result in a risk to your rights and
freedoms, we will notify the relevant supervisory authority within 72 hours
of becoming aware of it, as GDPR Art. 33 requires, and notify affected users
without undue delay where the risk is high. We will also comply with the
Australian Notifiable Data Breaches scheme and equivalent obligations
elsewhere.
13. Changes to this policy
We will post any changes here with an updated "Last updated" date. For material
changes we will notify you in the app or by email before they take effect, and
where the law requires it we will ask you to accept the new terms.
14. Contact
Privacy questions, rights requests, or complaints: