Privacy policy
Last updated:
This English version is provided for convenience; the French version prevails in case of any difference.
This page explains what data sardoche.tv processes when you use the Sardoche account, the League of Legends rank badges and the SardAlert extension, why, for how long, and what your rights are.
Data controller
Andreas Honnet
Contact for any question about your data: privacy@sardoche.tv
The data we process
- Your Twitch or Kick account: your user ID on the platform, username, display name and public avatar, provided by Twitch or Kick when you log in. Your session is kept in an encrypted cookie in your browser.
- Your League of Legends account, if you link it: a technical identifier provided by Riot, your server and your current official Solo/Duo rank (tier and division). Your Riot ID is never stored: it is read from Riot when you view your page, or when a sardoche.tv administrator looks it up (see “Recipients and sources”).
- Your choices: where your rank is shown, the display options, your “I am 15 or older” declaration, and a dated receipt of each change of consent (including the one that records the consent given in the old Twitch extension, for a legacy connection).
- For the badges: the last username you used to write in Sardoche’s chat on each platform, and the day of that message.
- Your account activity (account linking, display changes), with no IP address.
- Your Discord link, if you linked your Twitch or Kick account to Discord for the subscriber roles: your Discord ID and username, your subscription tier and how long you have been subscribed, and the sync status of your roles. Sardoche’s Discord bot announces the link in a channel of the Discord server and sends it to you as a direct message when it is created, and again when an administrator resyncs your roles.
- The old Twitch extension data, if you had linked your League of Legends account there: the tier and division it had stored, and the link to that account, carried over to your Sardoche account (see “Legacy connections from the old Twitch extension”).
We do not collect your email address or any password. We do not keep your Riot access tokens (used only once, then deleted), your LP, your match history, your summoner level or icon, or your rank history.
Site audience measurement: for each page you open on sardoche.tv, your browser sends our server the page address, the site you came from, your browser, your language, your screen size, your time zone, your connection type (for example 4G), your light or dark theme preference, the page load time and any campaign parameters (“utm”) in its address. This measurement sets no cookie and stores nothing in your browser. To count unique visitors, the server computes a fingerprint from your IP address and your browser: it stays in the server’s memory, is never stored and is erased when the server restarts.
Only totals are stored, without that fingerprint or your IP address: page views per page address (without its parameters), visitors, referring sites reduced to their domain name, campaign parameters, device types, browsers… On Sardoche TCG profile pages, the username of the profile viewed is counted too. They are stored in our Google Cloud database in Belgium: in 5-minute slices, kept for 7 days, and per day, kept for 90 days. The totals stored before this version of the page may still contain the full address of the pages, with its parameters (for example the click identifier added by Facebook, or your Discord ID in the account-linking link sent by the Discord bot), until they are deleted after those same periods.
These statistics are used only by Sardoche, to know how much traffic his site gets (legitimate interest, Article 6(1)(f) GDPR). They are not tied to your account and cannot be used to track you on other sites. The daily totals (number of page views and visitors, most viewed pages, referring sites and Sardoche TCG profiles, devices, browsers…) are public: anyone can read them on the API of our status page.
Why, and on what basis
- Logging you in with Twitch or Kick and linking your League of Legends account: performance of the service you request (Article 6(1)(b) GDPR).
- Showing your rank publicly (badges in the chat,
!rangcommand) and letting others look it up with!rang @username: your consent (Article 6(1)(a) GDPR), which you can withdraw at any time. For a legacy connection, it is the consent you had given in the old Twitch extension, for the Twitch chat only. - Moderating the chat (“rank-restricted chat” mode (“chat réservé par rang”),
!pmoderation command) and securing the service (activity log): Sardoche’s legitimate interest in moderating his chat and protecting accounts (Article 6(1)(f) GDPR). Only your tier and division are used, without LP, and this rank is never published. You can object to it by unlinking your LoL account. - Support and moderation by sardoche.tv administrators (viewing your account to answer a request or deal with abuse, removing a badge, unlinking your LoL account, refreshing your rank, resyncing your Discord roles): Sardoche’s legitimate interest in assisting his users and moderating his chat (Article 6(1)(f) GDPR).
What is public
- If you turn it on, and only then (or, for a legacy connection from the old Twitch extension, by default in the Twitch chat: see below): your tier and division (or only the tier, or “Master+”, shown as “Maître+”) next to your username on the platform you chose. The badge list is a public file that anyone can download. You only appear in it if you have written in Sardoche’s chat on that platform in the last 30 days.
- Never public: your Riot ID, your Riot identifier, your server, your LP, your history, your username on the other platform, or the link between your Twitch and Kick accounts. Your Discord account only appears in the announcement of your Discord link, on Sardoche’s Discord server.
- If you show your rank on both Twitch and Kick, someone comparing the two public lists could guess that both usernames belong to you.
- What has already been seen, captured or recorded (screenshots, clips, VODs, chat logs) cannot be erased.
Legacy connections from the old Twitch extension
If you had linked your League of Legends account in Sardoche’s old Twitch extension, that link was carried over to your Sardoche account, only when we were able to verify with Riot that it is still the same account. By linking it in the extension, you had agreed to your rank being shown. On the basis of that consent, your rank (Solo/Duo tier and division) is shown by default next to your username in Sardoche’s Twitch chat, and your account page presents it as a “Legacy connection”. Nothing is shown on Kick, and the other options stay turned off.
You can object and withdraw this consent at any time: in one click on your account page (“Stop showing my rank”), by typing !rang off in Sardoche’s Twitch chat, or by unlinking your LoL account, which also deletes the old extension data. We encourage you to reconnect your account with Riot (Riot Sign-On) from your account page, so that it stays verified and up to date. Reconnecting the same LoL account keeps your display setting, but your rank is then shown only if you confirm that you are 15 or older, as for any account linked with Riot; linking a different LoL account turns the display off (new consent required).
Recipients and sources
- The public, for the badges you choose to show (or shown by default for a legacy connection, see above).
- Google Cloud and Firebase (Google), as processor: hosting of the site and of the database in the European Union (europe-west1 and eur3 regions).
- Riot Games: we query Riot’s official API to read your rank.
- The sardoche.tv administrators, for support and moderation: they can view your account data described above, your Discord link if you have one (Discord ID and username, subscription tier and length, role sync status) and the old Twitch extension data (tier and division), including your Riot ID, read live from Riot at the time of the lookup and never stored. Each lookup of your Riot ID is recorded in a log (which administrator, when, for what reason), without the Riot ID itself.
- Sources: Twitch or Kick (login), Riot Games (Riot Sign-On and official API) and Sardoche’s chat (username and day of the last message, for the badges).
Transfers outside the European Union: the following recipients are established outside the European Union, or may process data there.
- Google (Google LLC, United States). In addition to the hosting described above, the server’s technical logs (IP address, browser, requested page and referring page) are kept for 30 days by Google Cloud, in a global location that may be outside the European Union. The emails you send us are received by Google’s email service (Google Workspace). If you turn on the SardAlert extension’s Pandora proxy, your connections to pandora.com go through our relay server, hosted by Google in the United States. Safeguards: Google LLC is certified under the EU–U.S. Data Privacy Framework, and its data processing terms provide for the European Commission’s standard contractual clauses.
- Supabase (Supabase Pte. Ltd, Singapore). If you collect Sardoche TCG cards, your collection (Twitch or Kick ID, username and display name, cards obtained and their date) is stored at Supabase, in Ireland, like some of the site’s images. Your browser downloads these images directly, which sends your IP address to Supabase and to its global content delivery network. Safeguard: the European Commission’s standard contractual clauses, provided for in Supabase’s data processing agreement.
- Vercel (Vercel Inc., United States). The www.sardoche.tv address still points to Vercel, which receives your IP address and your request if you use it. Safeguard: Vercel Inc. is certified under the EU–U.S. Data Privacy Framework.
- Riot Games (Riot Games, Inc., United States). To link your account, you log in at Riot yourself. Then we send your technical Riot identifier to Riot’s API, to read your rank and your Riot ID. Safeguard: Riot Games, Inc. is certified under the EU–U.S. Data Privacy Framework.
- Discord (Discord, Inc., United States), for your Discord link: the bot assigns your subscriber roles and posts the messages described above there. The sardoche.tv administrators also log in with Discord. Safeguard: Discord, Inc. is certified under the EU–U.S. Data Privacy Framework.
- Twitch (Twitch Interactive, Inc., United States) and Kick (Kick Streaming Pty Ltd, Australia). What you send them yourself (logging in with your account, chat messages) falls under your own relationship with Twitch or Kick. We also send them what Sardoche’s chat needs (bot replies, for example your rank in reply to
!rang, and moderation), your username when a Sardoche TCG card is awarded to you and, to Twitch, your username when an administrator looks up your account for support. Twitch is not on the Data Privacy Framework list and Australia has no adequacy decision from the European Commission.
How long
- Profile, linked accounts and LoL account: as long as your profile exists, and deleted as soon as you ask.
- Rank: only the current rank is kept, replaced at each refresh, with no history.
- Turning the display off: the badge disappears from the chat in less than 15 minutes and the old copies of the public file are deleted within 2 hours.
- Consent receipts: as long as your profile exists.
- Discord link: as long as it exists, and deleted when you unlink it.
- Account activity: 12 months.
- Moderation command log: 90 days.
- Log of administrator actions, including each lookup of your Riot ID: 12 months.
- Pending link requests: 10 minutes at most.
- Riot ID: never stored. It stays at most 10 minutes in an encrypted cookie in your browser during linking, and 10 minutes in the server’s memory when you view your page. When an administrator looks it up, it is neither stored nor kept in memory.
- Database backups: 30 days at most.
- If Riot asks us to delete the data of a Riot account, we do so within 30 days.
Your rights
On your account page, you can at any time view your data, withdraw your consent (one click, or !rang off in the chat), unlink your LoL account and delete your profile.
To get a copy of your data, have it corrected, object to its processing or restrict it, write to privacy@sardoche.tv. You can also lodge a complaint with the CNIL, the French data protection authority (www.cnil.fr).
Under 15
In accordance with Article 45 of the French Data Protection Act (loi Informatique et Libertés), you must be 15 or older to make your rank public. If you are under 15, your account can stay linked, but your rank is not shown.
A legacy connection from the old Twitch extension is shown without this declaration, on the basis of the consent given in the extension, as long as you have not reconnected it with Riot. If you are under 15, turn this display off in one click on your account page.
Cookies
The Sardoche account only uses necessary cookies: your login session, protection against forged requests and, while you link your account with Riot, two temporary cookies (10 minutes at most). They are used neither for advertising nor for tracking.
SardAlert extension
The extension downloads the public badge list; it sends nothing about what happens in the chat, and nothing about you, unless you turn on the Pandora proxy (see below). The twitch.tv access it requests is only used on Sardoche’s chat page: the extension stays inactive elsewhere. On that page, it also reads your Twitch username (the “login” cookie, never your authentication tokens) to tell you in the popup whether your rank is shown there; your username stays in your browser and is sent nowhere.
If you turn on the Pandora proxy, your connections to pandora.com go through our relay server in the United States (see “Recipients and sources”): it sees your IP address during the connection, without writing it to a log.
Clicks on the content shown in the extension go through sardoche.tv/go and are counted anonymously, like the views of that content (at most one view per day per browser): no cookie, no identifier, no IP address stored. To avoid false counts, the IP address is only used transiently, in memory and in hashed form, so that the same address counts only one view and one click per content item per day; it is never stored and these hashes are erased every day. On Firefox, clicks and views are only counted if you accept sharing the extension’s “technical and interaction data”.
Terms of use
See the terms of use.