Privacy Policy
Last updated: October 7, 2026
Michael Ketzer ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use and protect personal data when you use our Top Lords alliance tracker at toplordstats.com (the "Service"). Personal data is any information that relates to an identified or identifiable person.
Trial and subscription records
We record the account ID, normalised email address, game kingdom and alliance identity, workspace ID, and trial start and end times to enforce the once-per-user and once-per-alliance trial. Trial eligibility records survive workspace deletion and are retained to prevent repeat trials, subject to applicable data protection rights. Paddle receives your checkout email and workspace/account reference, and we store Paddle customer, subscription and processed event IDs to reconcile billing.
1. Controller and contact
The controller responsible for processing personal data on toplordstats.com is:
Michael KetzerEmail: support@toplordstats.com
For any privacy question or to exercise your rights, contact us at support@toplordstats.com.
2. What we process, why, and on what legal basis
| Data | Purpose | Legal basis |
|---|---|---|
| Account and sign-in: email address, one-time sign-in codes (stored only as a keyed hash), sign-in attempt records, session cookie | Create and secure your account, sign you in, prevent abuse | Art. 6(1)(b) GDPR (contract); Art. 6(1)(f) GDPR (security) |
| Workspace data: selected kingdom, managed alliances, settings, plan, members you invite and their roles | Provide your workspace and enforce access rights | Art. 6(1)(b) GDPR (contract) |
| In-game data about lords and alliances: in-game names and IDs, alliance tags, ranks, power, hero power, kills and their history | Show rosters, rankings, history and the kingdom overview | Art. 6(1)(b) GDPR for your workspace; Art. 6(1)(f) GDPR (managing an alliance; publicly visible game rankings) |
| Screenshots you upload and in-game screens captured for auto-sync | Extract the text and numbers needed for your import | Art. 6(1)(b) GDPR (contract) |
| Billing data from Paddle: name, email, country, subscription status and transaction references (no full card details) | Manage your subscription and entitlements; accounting | Art. 6(1)(b) and (c) GDPR (contract; legal obligations) |
| Support messages and the email address you write from | Answer your request and keep a record of it | Art. 6(1)(b) and (f) GDPR |
| Technical logs: IP address, browser and device type, requested page, time of access | Operate and secure the website, investigate errors | Art. 6(1)(f) GDPR (secure operation) |
In-game names are pseudonyms chosen by players. We only process in-game data needed to provide the Service. We do not use your data for advertising and we do not sell it.
3. AI processing of screenshots
When you import screenshots, or when auto-sync captures in-game screens for your alliance, the images are sent to Google's Gemini API to extract text and numbers. Google acts as our service provider. The images are used only to process your import; we do not use them to train AI models. Extracted data is stored in your workspace, where you can review and correct it.
4. Payments
Payments are processed by Paddle.com, which acts as our reseller and the Merchant of Record for all orders. Paddle collects and processes your payment details as an independent controller under its own privacy notice. We receive only the information needed to manage your subscription, such as your name, email address, country, subscription status and transaction references — never your full card details.
5. Recipients
We share personal data only where necessary:
- Service providers acting on our instructions: Vercel (hosting and logs), Neon (database), Letterpier (sending and receiving email) and Google (Gemini API for screenshot processing).
- Paddle, as Merchant of Record, for checkout, payments, tax, invoicing and refunds.
- People you invite to your workspace, who see the alliance data their role allows.
- Professional advisers, such as tax advisers or lawyers, where needed and bound to confidentiality.
- Authorities or courts, where we are legally required to disclose data or need to protect our rights.
6. International transfers
Some providers process data outside the European Economic Area, for example in the United States or the United Kingdom. Where this happens, we rely on an adequacy decision of the European Commission (such as the EU–US Data Privacy Framework for certified providers, or the UK adequacy decision) or on the European Commission's Standard Contractual Clauses, together with additional safeguards where required.
7. Cookies and local storage
We use only cookies and local storage that are strictly necessary to provide the Service: a session cookie that keeps you signed in, security tokens that protect sign-in, and local storage for preferences such as your theme. We do not use advertising or third-party tracking cookies, so no consent banner is needed. You can block cookies in your browser, but you will not be able to sign in.
8. How long we keep data
- Account data: until you delete your account.
- Sign-in codes: expire after ten minutes and can be used once; attempt records are kept only as long as needed to enforce sign-in limits.
- Workspace and alliance data: while your workspace exists, and for a limited period after a subscription ends so you can export your data or resume. You can ask us to delete it sooner.
- Screenshots and captures: kept only as long as needed to process and review the import, then deleted. The extracted data and a fingerprint of each image, used to detect duplicates, stay with your workspace.
- Billing records: as long as required by tax and commercial law (up to ten years).
- Support messages: as long as needed to resolve your request and for a reasonable period afterwards.
- Technical logs: typically up to 90 days.
9. Your rights
Under the General Data Protection Regulation (GDPR) you have the right to:
- access the personal data we hold about you (Art. 15);
- rectification of inaccurate or incomplete data (Art. 16);
- erasure of your data, subject to legal retention duties (Art. 17);
- restriction of processing in certain circumstances (Art. 18);
- data portability — receiving your data in a structured, machine-readable format (Art. 20);
- object to processing based on our legitimate interests (Art. 21);
- withdraw consent at any time where processing is based on consent, without affecting earlier processing;
- lodge a complaint with a data protection supervisory authority, in particular in the country where you live or work.
To exercise your rights, email support@toplordstats.com. We respond within one month; where requests are complex or numerous, this may be extended by up to two further months, and we will tell you why.
10. Security
We protect personal data with appropriate technical and organisational measures, including encryption in transit (HTTPS), hashed sign-in codes, role-based access controls and the principle of least privilege. No method of transmission or storage is completely secure, but we work to protect your data and will notify you and the authorities of a personal data breach where the law requires.
11. Children
The Service is not intended for children under 13 (or 16 where local law requires). We do not knowingly collect their personal data. If you believe a child has given us personal data, please contact us and we will delete it.
12. Changes to this policy
We may update this Privacy Policy. The date at the top shows the latest version; for significant changes we will inform you by email or in the Service. Please also see our Terms of Service and Refund Policy.
13. Contact
Questions about privacy at TopLordStats? Email support@toplordstats.com. Top Lords is a game by GAME SPARK PTE. LTD.; its own privacy practices are governed by the publisher's policies, not this one.