Privacy Policy
FACEITSync – Data Protection Information
We take the protection of your personal data very seriously. This Privacy Policy explains how FACEITSync processes and protects your data when you use our services, including FACEITSync Premium, Twitch and FACEIT integrations, and all associated web features. We handle your information in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
1. Controller
The controller responsible for data processing on this website is:
Ioannis Pavlou
c/o IP-Management #8391
Ludwig-Erhard-Str. 18,20459 Hamburg, Germany
Email: [email protected]
2. General Information on Data Processing
We process personal data only to the extent necessary to provide a functional website, our FACEITSync services (including FACEITSync Premium), and to fulfill contractual obligations. The legal bases for processing are, in particular:
- Art. 6(1)(a) GDPR (Consent)
- Art. 6(1)(b) GDPR (Performance of a contract)
- Art. 6(1)(f) GDPR (Legitimate interests, e.g. IT security, service optimization)
Where legal obligations apply (e.g., tax retention requirements), processing is based on Art. 6(1)(c) GDPR.
3. Data Collection When Using FACEITSync
3.1 Twitch Integration
When you sign in with your Twitch account, we receive the following data:
Twitch ID, username, profile picture, email address, and permissions to manage Predictions.
These are required to authenticate your account and provide FACEITSync’s core functions.
Legal basis: Art. 6(1)(b) GDPR (Performance of a contract)
3.2 Steam Integration
When linking your Steam account, we receive your Steam ID. This is used to associate your FACEIT account and retrieve statistics. Legal basis: Art. 6(1)(b) GDPR
3.3 FACEIT Integration
You can alternatively authenticate via your FACEIT account. We receive your FACEIT ID, username, profile data, and gameplay statistics (e.g., ELO, level, match history). These are used solely to provide core features such as ELO display and automatic predictions. Legal basis: Art. 6(1)(b) GDPR
3.4 FACEIT Data
Through the FACEIT API, we process your FACEIT ID, username, level, ELO, K/D ratio, win rate, and match data (e.g., match ID, results, demo URLs). These are used for your statistics, Twitch overlays, and automatic prediction generation. Legal basis: Art. 6(1)(b) GDPR
Important: FACEITSync does not store any passwords. Authentication uses secure OAuth 2.0 (Twitch, Steam, FACEIT). Access tokens are encrypted and used only for the intended purpose.
4. FACEITSync Premium & Payments
4.1 Payments via PayPal
When purchasing a FACEITSync Premium subscription, we process contractual, order and payment-related data (e.g. selected plan, duration, transaction ID, payment status). Payment processing is carried out via PayPal. PayPal acts as an independent data controller within the meaning of the GDPR. We only transmit the data necessary to process the payment (e.g. amount, order ID, email address).
Legal basis: Art. 6(1)(b) GDPR (performance of a contract), Art. 6(1)(f) GDPR (fraud prevention) and Art. 6(1)(c) GDPR (statutory retention obligations). Accounting records are stored for up to 10 years.
4.2 Payments via Stripe
We also offer the option to pay for Premium subscriptions via Stripe. Stripe is an international payment service provider that processes credit card, debit card and other payment methods.
When paying via Stripe, the following data may be processed: name, email address, billing information, payment method, transaction ID, amount, currency and technical metadata (e.g. IP address, browser information). We do not store full payment details such as credit card numbers.
Data may be transferred to third countries (in particular the United States). Stripe uses EU Standard Contractual Clauses to ensure an adequate level of data protection.
Legal basis: Art. 6(1)(b) GDPR, Art. 6(1)(f) GDPR and Art. 6(1)(c) GDPR.
Further information: stripe.com/privacy
4.3 Payments via Coinbase Commerce
We additionally offer the option to pay for Premium services via Coinbase Commerce using cryptocurrencies (e.g. Bitcoin, Ethereum, USDC). The provider is Coinbase Commerce, Inc., which acts as an independent data controller under the GDPR.
When using Coinbase Commerce, the following data may be processed: payment amount, selected cryptocurrency, wallet address, transaction hash, timestamp and technical metadata (e.g. IP address).
Cryptocurrency payments are technically irreversible. Refunds, if applicable, are handled manually and outside the blockchain.
Processing is carried out for payment execution and fraud prevention purposes. Data transfers to third countries (in particular the United States) may occur. Coinbase relies on appropriate safeguards such as EU Standard Contractual Clauses.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract), Art. 6(1)(f) GDPR (fraud prevention) and Art. 6(1)(c) GDPR (statutory retention obligations).
Further information on data processing by Coinbase: coinbase.com/legal/privacy
5. Email Delivery & Live Chat via Brevo
We use Brevo (formerly Sendinblue) to send transactional and support emails and provide our live chat system. This may include processing your email address, chat messages, IP address, browser data, and timestamps. The purpose is to ensure communication, support handling, and reliable email delivery.
Legal basis: Art. 6(1)(b) GDPR (Communication) and Art. 6(1)(f) GDPR (Customer support). Where applicable, processing may also occur based on your consent (Art. 6(1)(a) GDPR), for example when chat cookies are used.
6. Cloudflare
We use Cloudflare to protect our website against cyberattacks (e.g., DDoS) and to improve performance via a global CDN.
Cloudflare may process technical data such as IP addresses, system configuration, and access timestamps.
Cloudflare acts as a data processor under Art. 28 GDPR.
Legal basis: Art. 6(1)(f) GDPR (Security & Performance)
7. Server Log Files & Hosting
When visiting our website, certain technical data is automatically recorded (e.g., IP address, timestamp, URL, referrer, user agent). These server logs are used for IT security and troubleshooting and are deleted periodically. Legal basis: Art. 6(1)(f) GDPR
8. Cookies & Local Storage
We use necessary cookies and local storage entries (e.g., session, consent status) to provide essential functionality. Optional tracking or marketing cookies are used only after your consent via the cookie banner.
Legal basis: Art. 6(1)(f) GDPR in conjunction with §25(2) TTDSG (necessary cookies) or Art. 6(1)(a) GDPR in conjunction with §25(1) TTDSG (consent).
9. Google Analytics
We use Google Analytics to anonymously analyze user behavior and improve our website. Cookies are used to collect information such as anonymized IP address, device, browser type, session duration, and page views. Data may be transferred to Google servers in the United States.
Legal basis: Art. 6(1)(a) GDPR in conjunction with §25(1) TTDSG (consent). You can withdraw your consent at any time through the cookie settings. Google Privacy Policy: policies.google.com/privacy
10. Analysis with Matomo
We use Matomo to measure reach and analyze user behavior. Matomo is operated in compliance with data protection regulations and without the use of cookies. The IP address is anonymized, and direct personal reference is excluded.
Our offer is generally aimed at persons aged 16 and over. If personal data of persons under the age of 16 is processed, this is done exclusively with the consent of their legal guardians.11. Yandex Metrica
We use Yandex Metrica to analyze user behavior on our website. Yandex Metrica uses cookies and processes information such as IP address (shortened/anonymized), device type, browser, operating system, visit duration, page views, and interactions.
The collected data may be transferred to and processed on servers of Yandex LLC located in Russia. Russia is considered a third country under data protection law and does not have an adequacy decision by the European Commission.
Legal basis: Art. 6(1)(a) GDPR in conjunction with § 25(1) TTDSG (consent). Yandex Metrica is only used after explicit consent via the cookie banner. Consent can be withdrawn at any time via the cookie settings.
Privacy policy of Yandex: yandex.com/legal/confidential
12. Data Retention & Deletion
Personal data is retained only for as long as necessary to fulfill the stated purposes or legal requirements. After deleting your account, personal data is generally erased within 30 days unless retention obligations apply.
13. Recipients & Processors
We engage service providers (e.g., hosting, Cloudflare, Brevo, Google Analytics) who process data solely according to our instructions (Art. 28 GDPR). Data is shared with third parties only where legally required or based on your consent.
14. Data Transfers to Third Countries
If personal data is transferred to recipients in third countries (e.g., the USA – Google, Brevo, Cloudflare), this is done based on appropriate safeguards such as EU Standard Contractual Clauses or adequacy decisions.
15. Minors
Our offer is generally aimed at persons aged 16 and over. If personal data of persons under the age of 16 is processed, this is done exclusively with the consent of their legal guardians.
16. Your Rights
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
17. Changes to This Privacy Policy
We reserve the right to update this Privacy Policy if our services or legal requirements change. The latest version is always available on our website.
18. Contact
For any questions regarding the collection, processing, or use of your personal data, please contact:
Ioannis Pavlou
c/o IP-Management #8391
Email: [email protected]