Privacy Policy
Last updated 2026-08-26
This policy explains what personal data RiftCompass processes, for what purpose, for how long, and what rights you have over it, in accordance with the EU General Data Protection Regulation (GDPR) and, since RiftCompass's operator is based in Spain, Spanish Organic Law 3/2018 on Data Protection and Digital Rights Guarantee (LOPDGDD).
If you have any question about this policy or about how we handle your data, write to riftcompass@gmail.com.
1. Data controller
No Data Protection Officer (DPO) has been appointed, as it isn't required: RiftCompass doesn't carry out large-scale processing of special categories of data or systematic, large-scale monitoring of individuals under GDPR Article 37. Any request about your data can be sent directly to the email above.
- Controller: Julio López Suárez
- Email: riftcompass@gmail.com
- Website: riftcompass.com
2. What data we process and where it comes from
We distinguish two different situations, because not all the data we process comes from someone registered with RiftCompass:
- Data you give us directly when creating an account or using the Site: email address, password (always stored as an irreversible hash, never in plain text), optional username and avatar, and any content you choose to save (draft simulator picks, map editor boards, saved player profiles, folders).
- Technical data generated by your browser as you use the Site: your IP address (used solely to rate-limit login/signup attempts and prevent abuse, see section 5) and the strictly necessary cookies described in our Cookie Policy.
- Public League of Legends match data tied to a Riot ID (summoner name#tag): when you or anyone else looks up a Riot ID on RiftCompass, we query Riot Games' public API to show rank, match history, and stats. This happens the same way whether you look up your own Riot ID or someone else's — it's the same function offered by op.gg, u.gg, or porofessor.gg.
3. Purposes and legal basis for processing
| Purpose | Data involved | Legal basis (GDPR) |
|---|---|---|
| Creating and managing your account, logging in, verifying your email, and resetting your password | Email, password (hash), verification/reset tokens | Performance of the contract to provide the service (Art. 6.1.b) |
| Saving your profiles, draft picks, maps and folders | Content you save, linked to your account | Performance of the contract (Art. 6.1.b) |
| Showing stats, rank and match history for a looked-up Riot ID (yours or someone else's) | Public match data via Riot Games' API; the looked-up player's PUUID | Legitimate interest (Art. 6.1.f): this is public data from Riot's own API, already visible in-client and on equivalent sites; processing is limited to displaying it and, optionally, keeping a history so we can chart rank progress over time |
| Preventing abuse: rate-limiting login, signup, and verification-resend attempts | IP address, email, timestamp | Legitimate interest (Art. 6.1.f): account and service security |
| Receiving and replying to suggestions submitted through the homepage form | Your message and, if you choose to provide it, your contact email | Consent, given by submitting the form (Art. 6.1.a) |
| Building aggregate champion win-rate stats by role/patch/rank tier (background crawler) | PUUID and outcome of public ranked matches, from players not necessarily registered with RiftCompass | Legitimate interest (Art. 6.1.f) — see section 4 for the detail behind this specific purpose |
4. About players who don't have a RiftCompass account
RiftCompass queries Riot Games' public API for two distinct purposes worth separating out:
(a) When someone looks up a specific Riot ID on the Site, we fetch their public match data on the spot, display it, and optionally save a point-in-time snapshot of their rank (so we can show LP progress over time the next time anyone looks up that same Riot ID). This happens identically whether it's your own Riot ID or any other player's you choose to look up.
(b) Separately, an automated background process (a "crawler") walks public ranked matches starting from the highest leagues (Challenger and below) to compute aggregate win-rate stats by champion, role, patch and rank tier — shown in the Meta Tier List and the Champion Pool Builder. This process reads the PUUID (player identifier) of match participants in order to walk the match graph, but the data actually published on the Site (`champion_stats`) is aggregated and anonymised: it never shows any identifiable player's individual performance, only a win-rate percentage per champion across all sampled players.
A PUUID is a public, pseudonymous identifier issued by Riot Games (not a real name or contact detail), and the data queried (rank, wins, champions played) is data Riot Games already makes publicly available to any developer through its API and through the game client itself. Even so, we treat this information with the same care as any other personal data.
Given the number of players potentially involved (potentially hundreds of thousands) and that there is no direct contact channel with them through Riot Games, it isn't practically possible to individually notify every player whose data we've queried (GDPR Art. 14.5.b, exemption for disproportionate effort). This policy serves as the general notice required under that same provision.
If you're a League of Legends player (whether or not you have a RiftCompass account) and want to know whether we hold data tied to your Riot ID, or want it deleted, write to riftcompass@gmail.com with your Riot ID (name#tag) and region/platform; we'll handle the request within one month.
5. Recipients and processors
As these providers are located outside the European Economic Area, these international transfers rely on the safeguards set out in GDPR Chapter V (Standard Contractual Clauses approved by the European Commission and/or the provider's own adherence to the EU-US Data Privacy Framework, as stated in each provider's own compliance documentation).
| Provider | Role | Data processed | Location |
|---|---|---|---|
| Vercel Inc. | Site hosting, server functions, and avatar storage (Vercel Blob) | All information transmitted while using the Site; uploaded avatars | United States |
| Neon Inc. | Database (PostgreSQL) storing accounts, saved profiles, and rank snapshots | All data described in section 2 | United States (AWS infrastructure, us-east-1 region) |
| Resend | Transactional email delivery (account verification, password reset) and the suggestions form | Your email address and the content of the message/link sent | United States |
| Riot Games, Inc. | Source of the public match data shown on the Site | The looked-up Riot ID and the public response from its API | United States / global — subject to Riot Games' own privacy policy, which RiftCompass has no control over |
6. Retention periods
| Data | Retention period |
|---|---|
| Account data (email, password, username, avatar, saved content) | As long as the account remains active. Deletion is currently handled manually by writing to riftcompass@gmail.com (there's no self-service option in the interface yet). |
| Email verification tokens | 24 hours or until used, whichever comes first; single-use |
| Password reset tokens | 1 hour or until used, whichever comes first; single-use |
| Rate-limit attempt records (including IP address) | 15 minutes; automatically purged |
| Rank snapshots and crawler data tied to a Riot ID/PUUID | Indefinitely, for statistical and historical purposes (LP progress, aggregate win rates), unless deletion is requested — see section 4 |
| Suggestion form messages | Not stored in our database; sent directly by email via Resend, subject to that provider's own retention periods |
7. Your rights
We'll act on your request within one month at the latest. If you believe we haven't processed your data in line with the law, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD), www.aepd.es, or with the supervisory authority in your own EU member state of residence.
- Access: find out what data of yours we process
- Rectification: correct inaccurate or incomplete data
- Erasure ("right to be forgotten"): request deletion of your data once it's no longer needed
- Restriction of processing: ask us to temporarily limit how we use your data
- Portability: receive your data in a structured, commonly used format
- Objection: object to processing based on legitimate interest (for example, the processing described in section 4)
- Withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal, where processing is based on consent (for example, the suggestions form)
8. Minors
RiftCompass isn't specifically aimed at anyone under 14 (the minimum age to give valid consent to data processing under Spanish law). The Site doesn't currently verify the age of registered users. If you're a parent or legal guardian and find that a child under 14 has created an account without your authorisation, write to riftcompass@gmail.com so we can delete it.
9. Security
We apply reasonable technical measures to protect your data: passwords are stored using scrypt (never in plain text or a reversible form), the Site is served over encrypted connections (HTTPS), and email verification and password reset flows use short-lived, single-use tokens. No system is 100% invulnerable; if we detect a security breach that poses a risk to your rights, we'll notify you as required under GDPR.
10. Cookies
Our use of cookies is described in detail in our Cookie Policy.
11. Changes to this policy
We may update this Privacy Policy to reflect changes to the Site or to applicable law. The last-updated date appears at the top of this document; for substantial changes, we'll try to give visible notice on the Site.