PRIVACY POLICY
How SiteClash handles participant, vote-integrity, email, and sponsor data.
1. Controller
SiteClash is operated by SmartBotCrafters S.à r.l.-s, RCS Luxembourg B283.863, Wormeldange, Luxembourg. Contact privacy@siteclash.com.
2. Fight entries
We collect the submitted website, its bounded public metadata, an optional project X handle, a required email address, policy versions, acceptance time, and minimized request evidence. Email verifies inbox control; it does not by itself prove site authority. The purpose and legal basis are administering the competition and taking steps at your request to perform the participation agreement.
3. Public disclosure
Before activation SiteClash publishes anonymous roster occupancy only. At activation, the frozen website name, domain, URL, description, optional project handle, icon, public voting token, and committed tie-rank mapping become public together. Completed fight snapshots and crowns remain public history. Participant email and private dashboard credentials are never public.
4. Email choices
SMTP2GO delivers verification, scheduling, activation, elimination, postponement, cancellation, recovery, and crown messages. These operational messages are required to participate and are not marketing. Open and click tracking are disabled. The dashboard, not inbox delivery, is authoritative.
Marketing email is separate and optional. If you tick the marketing box, we record that choice and its time so we may send occasional SiteClash news, fight announcements, or sponsor offers. Refusing marketing does not affect entry or ranking. You can withdraw that consent at any time using the unsubscribe link in a SiteClash newsletter or by contacting privacy@siteclash.com.
5. Votes and abuse evidence
An eligible public-link visit records the fight entry, UTC time, and a one-way IP hash scoped to that specific fight with a server secret. This prevents repeat credit to the same fighter throughout one fight while preventing correlation of that hash across different fights. Accepted votes are immutable. Suspected abuse creates separate review evidence; it does not silently rewrite scores.
6. Storage and retention
Cloudflare Workers, D1, and private R2 host the service. Verification links and unresolved pending intake expire after 72 hours. A replacement verification link supersedes the earlier link and does not extend the original pending-entry window. Terminal entry email is scheduled for anonymization after 90 days, subject to final legal sign-off and any required preservation. Vote hashes are retained for 90 days. Frozen public fight results and champion records remain as competition history. Old unreferenced fighter assets are removed by maintenance.
7. Sponsors and payments
Sponsor inventory and payment records are structurally separate from competition data. A configured merchant-of-record provider may process billing and receipt data as described at checkout. Sponsor state cannot change admission, votes, rank, survival, or champion placement.
Explorer rewards · addendum 2026-09-05
When you choose Explorer, an essential HttpOnly browser cookie identifies your saved progress for up to 30 days. We store which participant website links were explicitly opened, timestamps, a daily salted IP hash for request limits, reward details, verification attempts and required policy acknowledgments. An outbound opening does not prove that an external website loaded or was read. Explorer records do not cast votes.
Reward email is private and is used for verification and booking messages. The name, homepage, description and optional X handle can appear publicly with an earned ad. Explorer records are removed within 90 days after the session or the end of a booked placement, whichever is later, unless preservation is required. Reward verification and booking emails do not subscribe you to marketing. The Explorer reward rules describe eligibility and scheduling.
8. Your rights
Under the GDPR, applicable rights may include access, rectification, erasure, restriction, portability, and objection. Contact us from an address or site-control channel we can proportionately verify. You may complain to Luxembourg's CNPD.
9. Security and children
Private dashboard access uses high-entropy browser sessions stored only as hashes and carried in an HttpOnly cookie. Email sign-in links and six-digit codes are short-lived and single-use. Sessions expire after 180 days and can be revoked by signing out. The service is not directed to children under 16.

