Legal
Privacy Policy
This Privacy Policy explains how CF Ranking processes personal data in the application and related services. It applies to an international audience. References to GDPR concern processing within its scope; other mandatory applicable data protection laws remain unaffected.
1. Controller and principles
1.1. In this Policy, “Operator” means the person determining the purposes and means of processing CF Ranking personal data. Personal data enquiries: support.cfranking@gmail.com. Support: support.cfranking@gmail.com. This Policy covers the application, related enquiries and payouts. Independent processing by the developer of Standoff 2, app stores and independent payment providers is also governed by their own notices.
1.2. Processing is limited to data necessary for the stated purposes. A pseudonym, game ID, token, IP address or voice recording may be personal data even without a real name. Absence of passport information does not itself make data anonymous.
1.3. The main data categories and purposes are set out below and in Appendix A. Refusal to provide data essential to a function may make that function unavailable. An optional avatar or notification permission must not be a condition of a basic account.
2. Data categories and purposes
2.1. Account data includes the Standoff 2 ID, unique nickname, password hash, optional email, region, interface language, platform and linked game nickname. It is used for registration, login, access recovery, localisation and matching game results to the user. Passwords must not be stored in plain text.
2.2. Gameplay data includes rosters, results, rankings, statistics, eligibility, cybercoin credits and disciplinary history. It is used to organise competitions, administer entitlements and resolve disputes. Processing necessary to provide the service is based on contractual performance. Offence verification and service protection require a separate assessment of the appropriate lawful basis, including legitimate interests.
2.3. Purchase and exchange data includes order and transaction identifiers, items, amounts, currency, gift recipients, cybercoin credits and spending, and skin delivery requests and confirmations. CF Ranking receives payment status information; full card numbers and CVV codes are not stored in the application database.
2.4. Cash payments may additionally require the recipient's name, payment details, country, legal representative information and documents necessary for legally required checks. The required information is determined for each payment and disclosed before collection. Routine document collection from all users is not provided for.
2.5. Profile data and user content include player and clan avatars, match messages, result screenshots, complaints and support attachments. Avatars may be public and must not be used to publish confidential information. Access to correspondence and complaints is limited by the function's purpose and operational necessity.
2.6. Voice communications use LiveKit infrastructure. According to the supplied implementation description, ordinary voice rooms are not continuously recorded into the project's main database. Separate anti-cheat recordings or evidential material fall under clause 2.7 and are distinct from ordinary voice transmission.
2.7. For anti-cheat reviews and disputes, users may submit gameplay video extracts, device demonstrations, explanations and relevant technical information under section 7 of the Rules. Before separate screen or voice recording, the purpose, scope, recipients and retention are explained; separate consent and an accessible proportionate alternative are provided where necessary. The general rules do not authorise covert recording or unrestricted device inspection.
2.8. Authentication, notifications and user-selected streaming functions use refresh token hashes, push tokens, settings and revocable OBS overlay tokens. An overlay displays project information in a stream. Its access token is confidential and must be revoked if compromised.
2.9. Technical logs contain the request method, path and identifier and service error information used for diagnostics. According to the supplied implementation description, an IP address is not included by default in every ordinary user request log. IP addresses are processed in administrative action logs and referral relationships to prevent abuse. The profile stores the time of last activity. Third-party technical log processing is limited to the purposes, lawful bases and safeguards in this Policy.
2.10. According to the supplied technical description, advertising identifiers, cross-service advertising tracking and personalised analysis of screen-view sequences are not used. Aggregate service metrics are collected without user IDs in labels. Changes in processing require updates to the Policy and necessary consents before that processing begins.
3. Lawful bases
3.1. Contractual performance under Article 6(1)(b) GDPR applies to processing objectively necessary to maintain an account, conduct matches, fulfil a purchase or exchange and support that transaction. Merely describing processing in the Agreement does not establish contractual necessity.
3.2. Compliance with a legal obligation under Article 6(1)(c) GDPR applies to mandatory accounting and tax records and lawful requirements of competent authorities. The obligation is determined for the particular operation. This basis does not permit collection without an established legal duty.
3.3. Legitimate interests under Article 6(1)(f) GDPR may justify proportionate security, fraud prevention, moderation and defence of claims following an assessment of necessity and the balance with user rights, particularly those of minors. Users may object to such processing.
3.4. Consent under Article 6(1)(a) GDPR is used where genuinely voluntary and necessary, such as a separately offered recording or optional processing without another lawful basis. It may be withdrawn for future processing without affecting the lawfulness of previous processing. Operating-system microphone or notification permission does not replace all necessary lawful bases.
3.5. Special categories of personal data are not requested as a condition of ordinary participation. If accidentally included in an attachment, access is restricted and unnecessary information deleted. Intentional processing of such data requires a separate applicable lawful basis; acceptance of the Agreement does not supply one.
4. Recipients, transfers and safeguards
4.1. Public nicknames, avatars and competitive results displayed by the interface are available to other users. Restricted support cases, payment details and evidence are not automatically made public. Sanction information is published only as necessary for the competition, without confidential materials.
4.2. Authorised staff and hosting, file storage, voice communication, notification and payment providers receive access within their functions. Processors operate under contractual restrictions; independent controllers, including payment organisations for relevant operations, act on their own lawful bases.
4.3. Recipient categories are listed in clause 4.2. The Operator identifies the actual providers, their roles and processing locations before granting access. Information about recipients and applicable international transfer conditions is provided as required by law through this Policy, a relevant processing notice or a request to the contact in clause 1.1. The name LiveKit or FCM alone does not identify where data is hosted.
4.4. Transfers outside the European Economic Area (EEA) require an applicable basis under Chapter V GDPR: a valid adequacy decision or appropriate safeguards, including standard contractual clauses with the necessary assessment and supplementary measures. The foreign service's compliance with these requirements must be established. Information about safeguards and obtaining a copy is available through the privacy contact.
4.5. Role-based access, token protection, connection encryption, administrative logging, backups and access revocation upon departure or compromise are applied in proportion to risk. Actual implementation of these measures is checked before launch.
4.6. Supervisory authorities and affected individuals are notified of security breaches in the cases and within the periods required by GDPR. Reports of a suspected leak are accepted even where the user's account is banned.
5. Retention and deletion
5.1. Account data is retained as long as necessary to provide the service. After account deletion it is deleted or anonymised, except for information with an independent lawful retention basis. Each category must have a specific period or verifiable retention criterion. Indefinite retention solely at the administration's discretion is prohibited.
5.2. Orders and payment documents are retained to the extent and for the period required by applicable record-keeping duties. Dispute material is retained until final resolution and thereafter only as needed for a specific legal claim. Evidence of serious fraud and restriction evasion must have a limited scope, documented period and periodic review.
5.3. Chat and attachment retention is limited to providing the relevant function and handling related requests; anti-cheat material to verification, appeals and protection of specific legal claims; and technical logs and referral IP addresses to diagnostics and investigation of substantiated indications of abuse. Backups are excluded from ordinary use after deletion from the live system and deleted or overwritten within the established backup cycle. Specific periods or applicable criteria are disclosed before the relevant processing begins. Further retention requires an independent lawful basis and periodic review of necessity.
iOS edition
5.4. Users may initiate account deletion within the application: Settings → Delete account (password confirmation). Alternative deletion enquiries are accepted through the privacy contact in clause 1.1. Deactivation or logout does not replace deletion. The retention conditions and exceptions in subsection 5 apply.
Android edition
5.4. Users may initiate account deletion in the application: Settings → Delete account (password confirmation), or through the external page https://cfranking.tech/en/delete. Deactivation or logout does not replace deletion. The retention conditions and exceptions in subsection 5 apply.
5.5. Before deletion, the user is informed of the consequences for orders, prizes and subscriptions. An unresolved dispute does not justify retaining all data without assessing necessity. Records that must be kept are separated from the active profile; the user is told the data categories and grounds for retention.
6. User rights and minors
6.1. Within the scope provided by GDPR, users may access and obtain a copy of data, rectify it, request deletion or restriction, receive portable data and object to legitimate-interest processing. Consent may be withdrawn. These rights do not depend on paid status.
6.2. Requests may be sent to the privacy contact or through the designated application function. Additional identification is permitted where there are reasonable doubts and must be proportionate to risk. A passport is not a mandatory condition for every request.
6.3. Responses are provided without undue delay, normally within one month. A lawful extension of up to two further months requires notice within the first month, with reasons. Refusals must state the grounds and appeal options; charges are permitted only in exceptional cases allowed by law.
6.4. Users may complain to a competent data protection authority, including where they habitually reside, work or where an alleged infringement occurred, and may seek judicial protection. The authority competent for the Operator is determined under the applicable jurisdictional rules. Contacting the Operator first is not a prerequisite for a supervisory complaint.
6.5. Automated matchmaking and ranking use results, eligibility and queue parameters. Decisions falling under Article 22 GDPR receive the statutory safeguards, including review by an authorised person where applicable. An automated anti-cheat alert does not exclude the right to appeal under section 10 of the Rules.
6.6. CF Ranking accounts are available from age 12 subject to clause 1.11 of the Rules. Where processing a child's data in directly offering an online service relies on consent, a legal representative must give or authorise consent until the applicable age of independent consent is reached. That age is determined by applicable law. CF Ranking takes reasonable, proportionate steps to verify consent. Other lawful bases are assessed separately and must not be selected artificially to bypass child protection. If a user is found to be under 12 or necessary consent is missing, relevant access or processing is restricted and unnecessary data is considered for deletion. Age and representative-authority checks must not lead to excessive document collection.
7. Data and permissions
iOS edition
7.1. App Store transaction information and appAccountToken, which links a transaction to a CF Ranking order, are used to verify purchases. The token provides a pseudonymous link and does not make the user anonymous to Apple. The user's name and contact details are not included in plain text in the token.
7.2. Push notifications use APNs. A separate Live Activity token may be used to display current matchmaking status. Users manage notifications and their display in iOS settings. Essential match information is available in the application.
7.3. The microphone is used for voice communication selected by the user. Access to a selected photograph or file is requested for the relevant upload. Permissions are requested in connection with a specific function. Refusing optional permission does not terminate access to the account as a whole.
7.4. Account deletion requests are submitted within the application. Users with an Apple subscription receive instructions for managing it and stopping future charges. Account deletion and payment refunds are separate procedures; a refund does not automatically delete all data.
7.5. According to the supplied implementation description, advertising tracking and advertising identifier collection are not performed. If functionality changes, necessary permissions and Apple disclosures are updated before processing begins. App Privacy declarations must reflect the SDKs, server infrastructure and account-linked data actually used.
Android edition
7.1. Payment verification uses the order identifier, status and transaction information from the relevant payment provider. If an email address is required to issue a receipt, its necessary disclosure is explained before confirmation. Storage of the address by CF Ranking depends on the relevant function and is described to the user.
7.2. Push notifications use Firebase Cloud Messaging (FCM). Users manage notifications in Android and application settings. Disabling push notifications does not terminate the account; essential match information remains available in the application.
7.3. Microphone permission is requested for voice communication and access to selected files for uploading them. Access is limited to the relevant function. Refusing an optional permission does not restrict functions independent of it.
7.4. Account deletion requests are available in the application and through the external page https://cfranking.tech/en/delete, without requiring reinstallation. Deletion covers associated account data, subject to lawful retention exceptions explained to the user. Subscription cancellation and stopping future charges are explained separately.
7.5. Data Safety declarations and pre-collection notices must match the actual application, SDK and server behaviour. According to the supplied description, advertising identifiers and advertising tracking are not used. Users are informed of processing changes before they begin.
Appendix A. Application data categories
iOS edition
A.1. This table supplements the Policy and reflects the supplied description of the main processing operations. App Store App Privacy declarations are completed separately using the store's definitions and verification of actual builds, SDKs and server infrastructure. Age verification, prize payment, anti-cheat and dispute data are additionally described in clauses 2.4 and 2.7.
Android edition
A.1. This table supplements the Policy and reflects the supplied description of the main processing operations. Google Play Data Safety declarations are completed separately using the store's definitions and verification of actual builds, SDKs and server infrastructure. Age verification, prize payment, anti-cheat and dispute data are additionally described in clauses 2.4 and 2.7.
Application data categories, their purpose and the link to the user
| Category | Data | Purpose | Linked to the user |
|---|---|---|---|
| Contact details | Email (optional) | Verification, contact and receipts where applicable | Yes, if provided |
| Identifiers | Standoff 2 ID, nickname, session token hash, push token | Account, matches, authentication, notifications | Yes |
| Purchases | Order history and items | Fulfilment, purchase history, support | Yes |
| Payment security | Full card number and CVV | Not stored by CF Ranking; processed by the payment provider | Not in the app database |
| User content | Avatars, chat, complaints, screenshots, support | Matches, communication, moderation, support | Yes |
| Audio | Voice through LiveKit | Voice communication; separate review recordings: clause 2.7 | Technically linked to a room participant |
| Diagnostics | Aggregate Prometheus metrics | Stability and diagnostics | No player ID in labels |
| Network data | IP in admin logs and referral links | Security and fraud prevention | Yes, in these scenarios |
| Advertising | Advertising ID | Not collected | No |
| iOS edition | |||
| Purchases / identifiers | appAccountToken, App Store transaction info | Linking transactions to orders; purchase verification | Yes, linked to order and account |
| Identifiers | Live Activity token | Current matchmaking status | Yes, technically |
| Android edition | |||
| Purchases | Receipt email, if required by provider | Issuing a receipt | Yes, if provided |
| Identifiers | FCM token | Push notifications | Yes, technically |