Privacy Policy
Last updated July 30, 2026
This policy explains what personal data Rift collects, why we collect it, and what rights you have over it. It applies to the Rift game service and the Rift community forum.
1. Who we are
Rift is the controller of the personal data described in this policy.
You can contact us about anything in this policy, including to exercise any of your rights, at:
2. What we collect
We collect the following personal data:
Data you give us when you create an account
- Email address
- Discord username
- Discord account ID
Where you sign in with Discord, we receive all three of these from Discord with your authorisation, rather than asking you to type them.
Data you give us when you use the forum
- The posts and other content you submit
Data collected automatically when you connect to us
- Your IP address, and basic technical information about your request (browser or client type, time of request, pages or resources accessed). This is recorded in server logs by our hosting and network providers and is used for security and to keep the service running. See section 11 for what we store on your device.
We do not collect your real name, address, date of birth, or payment details. We do not ask Discord for any data beyond your email address, username, and account ID.
3. Why we use it, and our legal basis
Under the GDPR we must have a lawful basis for each purpose. Ours are:
To create and operate your account — your email address and Discord identifiers identify you, let you sign in, and link your access to the game and the forum. Legal basis: performance of a contract (Article 6(1)(b)) — we cannot give you an account without this.
To operate the community forum — we store the posts you submit so they remain visible to other users and the forum works as a forum. Legal basis: performance of a contract (Article 6(1)(b)).
To contact you about your account — we use your email address to reach you where we need to, for example about a security problem, a change to this policy, or a response to a request you have made. We do not send marketing. Legal basis: performance of a contract (Article 6(1)(b)), and legal obligation (Article 6(1)(c)) where we are required to notify you, for example of a data breach under Article 34.
To keep the service secure and prevent abuse — investigating cheating, spam, harassment, and unauthorised access, protecting against denial-of-service attacks and automated traffic, and enforcing our community rules. Legal basis: our legitimate interests (Article 6(1)(f)) in keeping Rift safe and functioning for all users. We consider this proportionate because it uses only the limited data listed above and only where there is a specific concern or an automated security measure applies.
To comply with the law — where we are legally obliged to retain or disclose data. Legal basis: legal obligation (Article 6(1)(c)).
We do not use your data for advertising, we do not sell it, and we do not share it with anyone for their own purposes.
4. Who we share it with
We share personal data only with service providers who process it on our behalf, under contract and on our instructions:
| Provider | What they do | Where |
|---|---|---|
| Hetzner Online GmbH | Zap server host | EEA |
| Cloudflare, Inc. | Content delivery, DDoS protection, and network security. Traffic to Rift passes through Cloudflare’s network, which processes your IP address and request data. | United States, with a global network |
The forum is not public. Your posts and the username shown alongside them are visible only to other people signed in to a Rift account, and to us. They are not readable by search engines or by anyone without an account. Your email address is never shown to other users.
We may also disclose data where we are required to by law, or where necessary to establish, exercise, or defend legal claims.
5. International transfers
Your account data and forum posts are stored on servers in the European Economic Area and are not transferred outside it.
Cloudflare, Inc. is based in the United States, and traffic to Rift may be processed at Cloudflare locations outside the EEA. These transfers are covered by Cloudflare’s certification under the EU-US Data Privacy Framework, which the European Commission has recognised as providing an adequate level of protection, and additionally by the European Commission’s Standard Contractual Clauses in our data processing agreement with Cloudflare. You can request further information about these safeguards by emailing dpo@playrift.co.
6. How long we keep it
Account data (email, Discord username, Discord ID) — kept for as long as your account exists. We do not delete accounts for inactivity, so your data stays with us until you ask us to remove it or you delete your account. You can do either at any time, and we act on it promptly.
Forum posts — posts remain on the forum after your account is deleted, but are dissociated from your account and shown as posted by a deleted user. We do this so that discussion threads other users have taken part in remain readable. If you want your posts removed as well as your account, tell us and we will remove them.
Server and security logs — 30 days, after which they are deleted.
Moderation and ban records — where an account is suspended or banned for breaching our rules, we keep the Discord ID and a note of the reason for two years so the ban can be enforced. Legal basis: legitimate interests (Article 6(1)(f)).
Backups — after data is deleted from the live service it may persist in backups for up to 30 days, after which those backups are overwritten.
You can ask us to delete your data at any time — see section 7.
7. Your rights
You have the right to:
- Access the personal data we hold about you, and receive a copy of it
- Rectify data that is inaccurate or incomplete
- Erase your data (“right to be forgotten”), in the circumstances set out in Article 17
- Restrict how we process your data in certain circumstances
- Object to processing we carry out on the basis of legitimate interests, on grounds relating to your particular situation
- Data portability — receive the data you gave us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible
To exercise any of these, email dpo@playrift.co. We will respond within one month. We may ask you to confirm control of the email address on the account before we act, to make sure we are not disclosing your data to someone else.
Exercising these rights is free. We will only charge a fee, or refuse, if a request is manifestly unfounded or excessive, and we will explain why if that happens.
8. Complaints
If you are unhappy with how we have handled your personal data, you have the right to complain to a data protection supervisory authority.
If you are in the EU or EEA, you can complain to the supervisory authority in the country where you live, where you work, or where you believe the problem occurred. The European Data Protection Board publishes contact details for every national supervisory authority at edpb.europa.eu.
We would appreciate the chance to resolve it first, but you are not required to contact us before complaining.
9. Is providing this data required?
Providing your email address and Discord identifiers is not a statutory requirement, but it is necessary to create an account. Without it we cannot give you access to the game or the forum. You are not obliged to provide it, and you can stop using Rift and delete your account at any time.
10. Automated decision-making
We do not make decisions about you that produce legal or similarly significant effects based solely on automated processing, and we do not carry out profiling.
11. What we store on your device
Authentication token (local storage). When you sign in, we store an authentication token in your browser’s local storage. This is what keeps you signed in — without it you would have to log in on every page. It is strictly necessary for a service you have asked for, so we do not need your consent for it, but you should know it is there. It is removed when you sign out, and you can clear it at any time through your browser settings.
Cloudflare security cookies. Cloudflare, our network security provider, sets a small number of cookies to distinguish real users from automated traffic and to remember that you have passed a security check. The main ones are __cf_bm (bot management, expires after about 30 minutes) and, if you have been shown a challenge, cf_clearance. These are strictly necessary for the security of the service and are not used to track you across other sites.
We do not use analytics, advertising, or tracking cookies of any kind. Because everything we store on your device is strictly necessary, we do not show a consent banner.
12. Age
You must be at least 13 to use Rift, because a Discord account is required and Discord sets 13 as its own minimum age.
If you are under 16, you may only use Rift with the permission of a parent or guardian.
We do not knowingly collect data from anyone below these ages. If you believe an account has been created by someone too young to have one, contact dpo@playrift.co and we will look into it and delete the account if appropriate.
13. Changes to this policy
If we change this policy in a way that materially affects how we use your data, we will notify you by email and on the forum before the change takes effect. The date at the top shows when this version was published.