Privacy Policy

This Privacy Policy explains how Bruce Myers ("we", "us", or "our"), the operator of Brackets and Brews (the "Service"), collects, uses, and shares your personal data. Bruce Myers acts as the data controller for personal data processed through the Service.

1. Personal Data We Collect

  • Account data: email address, display name, password hash, and authentication identifiers.
  • Profile & gameplay data: avatar, room memberships, scores, answers, leaderboard standings, and content you submit (e.g. custom questions, chat messages).
  • Support & communications: messages you send us via email or in-app forms.
  • Device & usage data: IP address, browser type, device identifiers, pages viewed, and timestamps, collected via standard server logs.
  • Payment data: handled by Paddle as our Merchant of Record. We receive a transaction confirmation and subscription status from Paddle but do not store full card details on our servers.

2. Purposes & Legal Bases

  • Creating and operating your account, providing the Service, and enabling gameplay — performance of a contract.
  • Security, fraud prevention, and enforcement of our Terms — legitimate interests.
  • Customer support and responding to your inquiries — performance of a contract / legitimate interests.
  • Improving the Service (aggregate analytics, debugging) — legitimate interests.
  • Compliance with legal obligations (tax, accounting, responding to lawful requests) — legal obligation.
  • Optional marketing communications — consent, which you can withdraw at any time.

3. Who We Share Data With

  • Paddle.com, our Merchant of Record, which processes payments, manages subscriptions, calculates and remits taxes, and issues invoices. See Paddle's Privacy Notice.
  • Infrastructure and service providers that host the Service, store data, provide authentication, send transactional email, and provide analytics or error monitoring, acting as our processors under appropriate agreements.
  • Professional advisers (such as legal or accounting advisers) where necessary.
  • Authorities where required by law, court order, or to protect our rights or the safety of users.

We do not sell your personal data. Where data is transferred outside your region, we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.

4. Data Retention

We keep personal data for as long as your account is active and for as long as necessary to provide the Service. After account deletion, account and gameplay data is deleted or anonymised within 30 days, except where we are required to keep certain records (for example, transaction and tax records, which are typically retained for up to 7 years by Paddle and ourselves to meet legal obligations).

5. Your Rights

Depending on your location, you have the right to: access your personal data; correct inaccurate data; request erasure; restrict or object to processing; receive a portable copy of your data; and withdraw consent at any time where processing is based on consent. You also have the right to lodge a complaint with your local data protection supervisory authority. To exercise these rights, email hello@bracketandbrew.app. We will respond within one month.

6. Security

We use appropriate technical and organisational measures to protect personal data, including encryption in transit (TLS), access controls, hashed credentials, and principle-of-least-privilege access for our systems. No method of transmission or storage is 100% secure, but we work to maintain reasonable safeguards.

7. Cookies

We use strictly necessary cookies for authentication and session management. Where we use analytics or non-essential cookies, we will ask for your consent and you can manage your preferences in your browser settings.

8. Children

The Service is not directed to children under 13 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal data from children.

9. Changes

We may update this Privacy Policy from time to time. Material changes will be announced via the Service or by email.

10. Contact

Privacy questions or requests? Contact Bruce Myers, the data controller, at hello@bracketandbrew.app.