Skip to main content
BETADécouvrez la nouvelle version d'EZGather : testez les nouvelles fonctionnalités et optimisez vos parcours.
Legal documents

Privacy Policy

Which data EZGather processes, why, for how long, and what you can ask of us.

01Controller

EZGather is responsible for processing your personal data. For any question about your data, write to support@ezgather.io with "Personal data" as the subject.

02Personal Data Collected

We collect the following data:

  • Email address and sign-in profile (name, avatar) provided by Discord or Google
  • Device identifier (a fingerprint derived from your machine, hashed before it is sent — used to count the devices allowed by your plan)
  • Subscription data (plan type, start/end date, payment status)
  • Payment data (processed by Stripe, we don't store card details)
  • Connection logs (IP address, date/time, browser, operating system)
  • Synced content (your sequences, circuits, settings and schedule, so you find them on your devices)
  • Usage time and session counters, tied to your account
  • Bug reports, only when you click "Send": your description, the technical logs of the session (encrypted before sending, and possibly containing your character's name), an activity summary, a copy of your settings, the app version and your system
  • Private messages received in-game, only if you enable Auto-reply: their text is sent to a text-generation service to draft a reply
  • Technical telemetry (error reports: message and trace, version, platform — no session data or screenshots, via Sentry)
  • Site browsing data, measured by Google Analytics (see "Cookies")

03Processing Purposes and Legal Basis

Your data is processed on the following legal bases:

  • Account management and software provision : Contract (Article 6.1.b GDPR)
  • Service provision : Contract (Article 6.1.b GDPR)
  • Payments : Contract and legitimate interest (Articles 6.1.b and 6.1.f GDPR)
  • Security and fraud detection : Legitimate interest (Article 6.1.f GDPR)
  • Legal and tax obligations : Legal obligation (Article 6.1.c GDPR)
  • Communications about your account and subscription : Contract (Article 6.1.b GDPR)

04Data Recipients

Your data is accessible to authorized EZGather team members. We rely on the following technical providers: Stripe (payments), Supabase (database, EU), Vercel (hosting of the site and API), Cloudflare (network protection), Resend (email delivery), Sentry (error reports, EU), GitLab and Discord (bug report tracking), Google (site audience measurement, and text generation for Auto-reply). Discord and Google are also your sign-in providers. No data is shared for commercial or marketing purposes.

05Data Transfer Outside the EU

Some of our providers (Stripe, Vercel, Cloudflare, Resend, GitLab, Discord, Google) are established in the United States or may process data there. These transfers rely on the European Commission's standard contractual clauses or on the EU–US Data Privacy Framework, depending on the provider.

06Data Retention Period

Your data is retained for the following periods:

  • Account data and synced content : as long as your account exists
  • Subscription and billing data : 6 years (tax obligations)
  • Technical license-check logs : 7 days
  • Connection logs and registered devices : as long as your account exists
  • Bug reports : while the issue is being handled, then limited archiving
  • Payment data : according to legal obligations and Stripe

When your account is deleted, this data is erased, except where the law requires us to keep it.

07Your Rights

You have the following rights under the GDPR:

  • Right of access : obtain a copy of your data
  • Right to rectification : correct inaccurate data
  • Right to erasure (right to be forgotten)
  • Right to restrict processing : limit how we use your data
  • Right to data portability : receive your data in a structured format
  • Right to object : object to processing
  • Right not to be subject to automated decision-making

To exercise these rights, write to support@ezgather.io. Erasure and portability requests are handled manually, within one month.

08Security

We implement the following security measures:

  • HTTPS/TLS encryption for communications
  • Secure authentication with machine UUID
  • Restricted access to data (least privilege principle)
  • Regular backups via Supabase
  • Real-time monitoring and alerts
  • Compliance with OWASP standards and security best practices

09Cookies

The site uses technical cookies (sign-in session, display preferences) and Google Analytics to measure its audience. You can block or delete these cookies from your browser settings.

10Processing of Minor's Data

EZGather is reserved for adults. We do not knowingly collect personal data from minors; if you believe a minor has created an account, write to us and we will delete it.

11Email Communication

We only send you emails related to your subscription: purchase confirmation, renewal, failed payment, cancellation, refund, plan change. These emails are necessary to perform the contract and carry no unsubscribe link. We do not send a newsletter.

12Breach Notification

In the event of a personal data breach, we undertake to notify the relevant data protection authority within 72 hours and inform you if the breach poses a high risk to your rights and freedoms.

13Policy Modifications

EZGather reserves the right to modify this privacy policy at any time. Changes will be published on this site with an updated date. Your continued use of the service after modifications constitutes acceptance.

14Applicable Language

The English version of this privacy policy applies to English-language users, with the French version prevailing in case of dispute.

A question about this document?

Write to us: we answer any question about these terms and about your data.

Last updated: September 4, 202615 articlesThe French version prevails