Privacy Policy
Last updated: March 2026
1. Who We Are
ClanHQ is operated by [Your SRL Name] SRL, a company registered in Romania. Our registered address is [Your Address], Romania.
As an EU-based company, we process personal data in accordance with the General Data Protection Regulation (GDPR) and applicable Romanian law. For privacy enquiries, contact us at privacy@clanhq.app.
2. What Data We Collect
Account Data
When you register, we collect your email address, username, and a hashed password. We never store your password in plain text.
Wargaming Data
If you link your Wargaming account via the official Wargaming OAuth system, we receive and store your Wargaming account ID, in-game nickname, and region. We never receive or store your Wargaming password.
Clan Data
For clans using ClanHQ, we store member activity snapshots, recruitment records, planner events, and other operational data you enter into the platform. This data is associated with your account and the relevant clan.
Technical Data
We log IP addresses for rate limiting and abuse prevention. We do not use third-party analytics, advertising networks, or tracking pixels.
Payment Data
Subscription payments are handled entirely by Stripe. We never receive or store your card number, CVV, or full payment details. We receive only a Stripe customer ID and subscription status to manage your account tier.
3. How We Use Your Data
- To provide and operate the ClanHQ service.
- To authenticate your account and maintain secure sessions.
- To display clan and player information relevant to your account.
- To send transactional emails (account confirmation, billing receipts). We do not send marketing emails without your explicit consent.
- To detect and prevent abuse, fraud, and Terms of Service violations.
We do not sell, rent, or share your personal data with third parties except as described in this policy. The only third parties who receive your data are Stripe (payment processing) and the Wargaming Public API (data source for in-game information).
4. Wargaming API Data
Player and clan data is retrieved via the official Wargaming Public API. This data is publicly available and subject to Wargaming's API Terms of Use.
We store only what is necessary to provide the service. API data is not used for rankings, competitive advantage, or any purpose outside the ClanHQ service itself. Data is not retained beyond what is required to operate the associated account or clan record.
5. Cookies
We use a single HttpOnly authentication cookie (a refresh token) to maintain your session after login. This cookie is strictly necessary for the service to function. It is inaccessible to JavaScript and is not readable by third parties.
We do not use advertising cookies, tracking pixels, or third-party analytics. You may clear cookies at any time via your browser settings, which will log you out of ClanHQ.
6. Data Retention
Your account data is retained for as long as your account is active. If you request account deletion, we will delete your personal data within 30 days, except where retention is required by Romanian or EU law (for example, billing records required for tax purposes).
Anonymised or aggregated data that cannot identify you may be retained for service improvement purposes.
7. Your Rights (GDPR)
As an EU resident, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request deletion of your data (“right to be forgotten”).
- Receive your data in a portable, machine-readable format.
- Object to or restrict certain processing activities.
- Lodge a complaint with the Romanian data protection authority (ANSPDCP) at www.dataprotection.ro.
To exercise any of these rights, email privacy@clanhq.app. We will respond within 30 days.
8. Data Security
Passwords are hashed using bcrypt. Authentication tokens are stored as HttpOnly, Secure cookies. All data is transmitted over HTTPS. We apply rate limiting on authentication endpoints to reduce brute-force risk.
No internet service can guarantee absolute security. If you believe your account has been compromised, contact privacy@clanhq.app immediately.
9. Changes to This Policy
We may update this policy from time to time. If changes are material, we will notify registered users by email or via an in-app notification at least 14 days before the changes take effect. The “Last updated” date at the top of this page reflects the most recent revision. Continued use of ClanHQ after the effective date constitutes acceptance of the updated policy.