Privacy Policy
Last updated: 17 June 2026
This Privacy Policy explains how [PLACEHOLDER: legal entity name] (“Playband”, “we”, “us” or “our”) collects, uses, discloses and safeguards your personal data when you visit our website, create an account, or use the Playband platform and related services (collectively, the “Services”). Playband provides a managed realtime-multiplayer backend — deterministic simulation, rollback netcode and a hosted game cloud — to game developers and studios.
By using the Services you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Services.
1. Who we are & how to contact us
The data controller responsible for your personal data is [PLACEHOLDER: legal entity name], registered at [PLACEHOLDER: registered address]. For any privacy question, request or complaint, contact us at [PLACEHOLDER: contact email].
2. Data we collect
We collect the following categories of personal data:
- Account & organization data. When you sign up, your authentication and organization records (email address, display name, organization name, organization membership and role) are created and stored through our authentication provider, Neon Auth. You may also provide optional profile information.
- Product usage & telemetry. We collect technical and usage data generated as you use the Services — such as concurrent-player and player-hour counts, room and region metrics, request logs, API and SDK usage, device and browser type, IP address, timestamps, and diagnostic or crash data. We use this to operate, secure, meter and improve the Services.
- Payment data. Once paid billing launches, payments will be processed by a third-party payment processor. We do not store full card numbers on our systems; the processor handles your card or bank details and shares with us only limited information needed for billing (for example, billing contact, plan, the last four digits of a card, and transaction status).
- Communications. If you email us or contact support, we keep the content of those messages and our responses.
3. How we use your data
We use personal data to:
- provide, maintain, authenticate and secure the Services;
- meter usage, calculate quotas and (once billing launches) bill paid plans;
- monitor performance, prevent abuse and fraud, and debug issues;
- communicate with you about your account, security, and service changes;
- improve and develop new features; and
- comply with our legal obligations and enforce our agreements.
Where required by law, we rely on the following legal bases: performance of our contract with you, our legitimate interests in operating and securing the Services, your consent (where requested), and compliance with legal obligations.
4. Cookies & local storage
We use a small number of strictly-necessary cookies and browser local storage to keep you signed in, remember preferences (such as your light/dark theme), and maintain the security of your session. We do not use third-party advertising cookies. You can clear or block cookies in your browser settings, but some features (including sign-in) may not work without them.
5. Sub-processors
We rely on a small set of trusted infrastructure providers (“sub-processors”) who process personal data on our behalf under data-processing agreements:
- Cloudflare — web hosting, edge delivery, DNS and security.
- Neon — managed Postgres database and authentication (Neon Auth).
- A third-party payment processor — payment processing (named here once paid billing launches).
We require each sub-processor to provide a level of data protection consistent with this policy and applicable law.
6. How we share data
We do not sell your personal data. We share it only with the sub-processors above, with professional advisers, in connection with a merger or acquisition, or where required by law or to protect our rights and the safety of our users.
7. Data retention
We retain personal data for as long as your account is active and as needed to provide the Services. When you delete your account, we delete or anonymize your personal data within a commercially reasonable period, except where we must retain it to comply with legal obligations, resolve disputes, or enforce our agreements (for example, billing and tax records). Aggregated or de-identified data that can no longer be linked to you may be retained indefinitely.
8. Your rights
Depending on where you live (including under the EU/UK GDPR and the California Consumer Privacy Act, as amended by the CPRA), you have the right to:
- Access — request a copy of the personal data we hold about you;
- Correct — ask us to fix inaccurate or incomplete data;
- Delete — request erasure of your personal data;
- Export (portability) — receive your data in a portable, machine-readable format;
- Object or restrict — object to or restrict certain processing; and
- Opt out — of any “sale” or “sharing” of personal data (we do not sell or share it for cross-context behavioral advertising).
To exercise any right, email [PLACEHOLDER: contact email]. We will respond within the timeframe required by applicable law. We will not discriminate against you for exercising these rights. If you are in the EU/UK, you also have the right to lodge a complaint with your local data-protection authority.
9. Security
We protect personal data with technical and organizational measures appropriate to the risk, including encryption in transit, access controls and the principle of least privilege. No method of transmission or storage is perfectly secure, but we work to protect your data and to promptly address any incident.
10. International transfers
Playband operates globally and your data may be processed in countries other than your own, including the United States. Where we transfer personal data out of the EEA, UK or other regulated regions, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or another lawful transfer mechanism.
11. Children’s data
The Services are intended for developers and businesses and are not directed to children. We do not knowingly collect personal data from children under the age of 16 (or the minimum age in your jurisdiction). If you believe a child has provided us personal data, contact us and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, for material changes, provide additional notice (for example, by email or an in-product notice). Your continued use of the Services after an update means you accept the revised policy.
13. Contact
Questions about this policy or our data practices? Email [PLACEHOLDER: contact email], or write to us at [PLACEHOLDER: registered address].