GOALROOK · PROJECT POLICIES
Privacy notice
What the current GoalRook service stores, why it stores it and how to ask about your information.
Last updated:
Who operates this service
GoalRook is an independent, unincorporated project operated under the GoalRook name by pseudonymous contributors. There is no incorporated company, registered office or incorporation jurisdiction to list. Contact the project through Support for privacy questions and requests. Future incorporation or a change in the operator will be published here.
This notice describes GoalRook-controlled services. Wallet software, blockchain networks, explorers and Discord handle information under their own policies when you use them.
Accounts, authentication and game records
Creating a demo club stores a manager identity, club name, colors, squad and progress. Wallet sign-in associates a wallet address and network with the manager account. The server checks a one-use sign-in message and signature; it does not receive your private key or recovery phrase.
Session and sign-in records include identifiers, timestamps, expiry, IP address and browser user-agent information. Authentication and administrative audit records record relevant actions. Club, squad, competition, credit, match, ownership and transaction-recovery records support gameplay, access checks, abuse prevention and recovery.
The server uses an HttpOnly session cookie and verifies origin and anti-forgery credentials for protected changes. The browser keeps non-secret language, wallet-provider and display preferences, player caches and pending transaction hashes where needed for recovery. Clearing browser storage can remove those local preferences and recovery hints; it does not erase the server account or chain history.
Short-lived product observations
GoalRook records wallet connection/sign-in outcomes and whether a club is ready or a public broadcast begins playing to understand problems in the player journey. Wallet-outcome requests omit session cookies and contain only an attempt token, stage and outcome; they do not store a wallet address, provider error text or device identifier in the observation record.
Club-ready and playback observations are linked to a club identifier and can include a public broadcast identifier and playback progress. These are first-party product observations, not advertising profiles. Dashboard counts are suppressed below five attempts or five distinct clubs, as appropriate; aggregation does not make the underlying club records anonymous.
Optional support and community
Support chat connects to the GoalRook Chatwoot service only after you choose to open it. It uses a conversation cookie and receives browser information plus the messages and files you choose to send. GoalRook does not automatically attach your wallet address, account, session credentials or game history to the chat.
Messages are asynchronous. Only send information needed for your question and redact screenshots. A transaction hash is public information but may link to wallet activity. Do not send passwords, private keys, recovery phrases, recovery codes or unnecessary identity documents. Closing chat stops displaying it; it does not delete the conversation.
If a Discord invite is published on Support, following it leaves GoalRook for Discord. Discord receives your account and activity under its own policy; server members can see messages in rooms they can access. Moderators can review reports and apply the Community rules. Neither a community role nor a badge verifies NFT ownership.
Hosting, network providers and public information
Vercel delivers the website; GoalRook-hosted services store game and support records. Hosting and network services receive connection information such as IP addresses, requested URLs and browser headers and may keep operational logs. Authorized project operators can access records needed to run, secure and support the service.
Wallet connections can involve your selected wallet, Reown/WalletConnect and RPC providers. Blockchain reads and transactions expose public addresses, ownership, approvals and transaction history to the network and anyone inspecting it. The project cannot erase or make public blockchain records private. These external services may process information outside your country.
GoalRook does not sell these records or use them for advertising profiles. Information can be disclosed where required by applicable law or needed to investigate abuse and protect the service. No particular international-transfer arrangement or statutory certification is claimed by this notice.
Retention and deletion limits
The product-observation store has a seven-day retention window. Unused wallet-attempt tokens expire after 15 minutes and are pruned; consumed wallet outcomes and club/playback observations older than seven days are pruned. A periodic cleanup runs, and reporting excludes expired observations even if cleanup is delayed.
Sign-in sessions expire according to their server-issued expiry, with a 24-hour default. Expiry or logout disables access; it does not automatically delete the session, authentication audit, club, match, transaction-recovery or competition history.
Durable game, security and support records currently have no automatic deletion schedule. Support conversations, attachments and backups can remain retained after a case is closed. There is no self-service account-erasure function. This is the current retention limit, not a promise that all records disappear after seven days. Request review through Support if you want information removed or restricted.
Browser preferences and local recovery data remain until you clear them or the relevant feature replaces them. Public blockchain records remain outside GoalRook’s deletion control. Backups and records needed to preserve other players’ results, recovery or security may limit immediate removal.
Your choices and privacy requests
You can browse public guides without a wallet, decline support chat, avoid Discord, log out and clear browser storage. Game features requiring an account or wallet cannot work without their associated records.
Open Support and begin your message with “Privacy request”. Say whether you want access, correction, deletion, restricted use or an explanation, and identify only the relevant club, public wallet address or conversation. Requests are reviewed asynchronously. Account-related disclosure or changes require a suitable ownership check; never provide a secret to prove ownership. If you cannot open chat, use another contact option shown on Support.
Applicable law may give you additional access, correction, erasure, objection, restriction or portability rights and a right to complain to your local data-protection authority. The project reviews requests against those rights and the records it controls. This notice does not waive those rights or guarantee that every request can remove public-chain data or another player’s retained history.
Age policy and updates
The game, wallet features, support submissions and community are for adults aged 18 and over. Age is not currently verified and a date of birth is not collected. If information was submitted by someone under 18, contact Support to request review.
This notice will be updated when the operator or data practices change. A new use of personal information will be described before it is introduced.