Privacy Policy

Effective: 2026-06-04

Last updated: 2026-06-04

This Privacy Policy explains how MITH UG (haftungsbeschränkt) (“MITH”, “we”, “us”, “our”) collects, uses, and protects personal data when you use Rodeo (the “Service”), accessible at rodeo.ad. We process your data in accordance with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

1. Controller

The controller responsible for data processing is:

MITH UG (haftungsbeschränkt)

Brüderstraße 14

10178 Berlin

Germany

Email: hello@rodeo.ad

Impressum: https://rodeo.ad/impressum

For privacy-related inquiries, contact: privacy@rodeo.ad

2. Data Protection Officer

We have not appointed a Data Protection Officer as we are not required to under Art. 37 GDPR (we are below the relevant thresholds and do not process special categories of data on a large scale). For all data protection inquiries, please contact us at the address above.

3. Personal Data We Collect

When you create a Rodeo account and use the Service, we collect:

Account data (provided by you at signup)

  • Email address
  • Nickname
  • Password (stored as a salted bcrypt hash; we never see your plaintext password)
  • Avatar selection (pre-composed character; no facial biometrics, no upload)

Usage data (collected automatically as you play)

  • Bets placed, picks made, items used
  • Coin balances and transaction history
  • Arena and squad memberships
  • Tournament prediction history
  • Timestamps of actions (sign-ins, bet placements, settlements)

Technical data (collected automatically by our infrastructure)

  • IP address (for rate-limiting and abuse prevention; not stored long-term)
  • Browser type and version
  • Operating system
  • Pages visited within the Service
  • Referring URL (where you came from)
  • Approximate timezone (derived from browser)

Communication data (if you contact us)

  • Email contents
  • Support correspondence

We do NOT collect: precise location, biometric data, health data, political opinions, religious beliefs, ethnic origin, sexual orientation, criminal records, or any other Article 9 GDPR special category data.

4. Legal Bases and Purposes

We process your personal data on the following legal bases:

PurposeLegal basis (GDPR Art. 6)
Providing the Service (account, betting, leaderboards, items)6(1)(b) — performance of contract
Sending account emails (verification, password reset)6(1)(b) — performance of contract
Securing the Service (rate-limiting, abuse prevention)6(1)(f) — legitimate interest
Processing payments (B2B seat purchases)6(1)(b) + 6(1)(c) — contract + legal obligation
Responding to support requests6(1)(b) or 6(1)(f)
Complying with legal obligations (tax, accounting)6(1)(c) — legal obligation
Sending product updates (only if you opt in)6(1)(a) — consent

For processing based on consent (6(1)(a)), you may withdraw your consent at any time without affecting the lawfulness of processing before withdrawal.

For processing based on legitimate interest (6(1)(f)), you have a right to object under Art. 21 GDPR. We will assess your objection and discontinue processing unless we can demonstrate compelling legitimate grounds that override your interests.

5. Subprocessors

We use the following third-party services to operate Rodeo. Each has signed a Data Processing Agreement (DPA) with us as required by Art. 28 GDPR. Each is responsible only for the data we entrust to them for the specified purpose, and may not use it for any other purpose.

SubprocessorPurposeData sharedLocationTransfer safeguard
Vercel Inc.Hosting + edge networkAll Service trafficUSA / EU edgeEU Standard Contractual Clauses (SCCs) + DPA
Supabase, Inc.Database, authentication, file storageAccount data, usage dataEU (Frankfurt)DPA; data stored in EU
Resend Inc.Transactional email deliveryEmail address, email contentsUSAEU Standard Contractual Clauses + DPA
Upstash Inc.Redis cache layerShort-lived session and rate-limit keysEUDPA; data stored in EU
Stripe Payments Europe Ltd.Payment processing (B2B seat purchases)Billing contact, payment dataIreland (EU) / USAStripe’s own GDPR-compliant processing; EU SCCs

For non-EU transfers (Vercel, Resend, Stripe), we rely on the EU Standard Contractual Clauses (Modules 2 and 3) as the transfer safeguard under Chapter V GDPR, supplemented by the providers’ own technical and organizational measures.

We do NOT sell or rent your personal data to any third party.

6. Retention Periods

We retain your personal data only as long as necessary for the purposes described above. Specifically:

  • Account data: as long as your account is active. If you delete your account, we delete or anonymize your data within 30 days, except where we must retain it for legal reasons (e.g., billing records under §147 AO retained for 10 years).
  • Usage data: 24 months from event, then aggregated and anonymized for product analytics.
  • Email logs (Resend): 30 days, then deleted.
  • Server logs: 14 days.
  • Backups: 30 days rolling, then deleted.

7. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access (Art. 15) — request a copy of the data we hold about you
  • Right to rectification (Art. 16) — correct inaccurate or incomplete data
  • Right to erasure / “right to be forgotten” (Art. 17) — request deletion
  • Right to restriction of processing (Art. 18) — limit how we process
  • Right to data portability (Art. 20) — receive your data in a structured, machine-readable format
  • Right to object (Art. 21) — object to processing based on legitimate interest
  • Right to withdraw consent (Art. 7(3)) — for any processing based on consent
  • Right to lodge a complaint with a supervisory authority (Art. 77) — for Berlin-registered companies, the competent authority is the Berliner Beauftragte für Datenschutz und Informationsfreiheit (https://www.datenschutz-berlin.de/)

To exercise any of these rights, email privacy@rodeo.ad. We will respond within one month per Art. 12(3) GDPR.

8. Account Deletion

You can request account deletion at any time by emailing privacy@rodeo.ad or via Settings → Account → Delete account. Deletion is processed within 30 days (a 14-day grace period during which you can cancel the deletion, followed by hard delete). After hard delete, only legally required records (billing, accounting) are retained per § 147 AO.

9. Cookies and Local Storage

Rodeo uses the minimum cookies necessary to operate. Specifically:

  • Authentication cookie (NextAuth session token): required to keep you signed in. Legal basis: 6(1)(b) — performance of contract. Lifetime: 30 days.
  • Local storage: used only for ephemeral UI state (filter preferences, dismissed banners). No tracking. No third-party analytics.

We do not use Google Analytics, Meta Pixel, or any other behavioral tracking. We do not load third-party advertising. Rodeo Products are ad-free.

10. Security

We protect your data with industry-standard technical and organizational measures:

  • HTTPS / TLS 1.2+ for all traffic
  • Passwords stored as salted bcrypt hashes (cost 12)
  • Row-level security on database tables (multi-tenant isolation)
  • Limited employee access on a need-to-know basis
  • Regular security review of subprocessor practices

In the event of a data breach affecting your personal data, we will notify the supervisory authority within 72 hours per Art. 33 GDPR and notify you without undue delay per Art. 34 GDPR.

11. Automated Decision-Making

We do NOT use your personal data for automated decision-making within the meaning of Art. 22 GDPR (no scoring, no profiling, no automated rejections).

Match settlement and leaderboard calculations are deterministic game mechanics (parimutuel math defined in the Game Rules), not automated decisions about you as a person.

12. Children

Rodeo is intended for users aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@rodeo.ad and we will delete the account.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via the email address on your account at least 14 days before the changes take effect. The current version is always available at https://rodeo.ad/privacy.

14. Contact

For any questions about this Privacy Policy or how we handle your personal data, contact:

MITH UG (haftungsbeschränkt)

Brüderstraße 14

10178 Berlin

Germany

Email: privacy@rodeo.ad

General contact: hello@rodeo.ad