HomeLegal
Privacy Policy
How Clubhouse AC collects, uses, discloses and protects personal data. Written to satisfy the transparency requirements of the GDPR (Articles 13/14), the UK GDPR and the CCPA/CPRA.
- Last updated
- September 16, 2026
- sections
- 15
Applies to all visitors, subscribers and scanned players
On this page
- 01Who We Are (Controller)
- 02Scope of This Policy
- 03Categories of Personal Data
- 04Purposes and Lawful Bases
- 05Recipients and Processors
- 06International Transfers
- 07Retention Periods
- 08Security Measures
- 09Your Rights
- 10Children and Minors
- 11Notice to US Residents (CCPA/CPRA)
- 12Automated Decision-Making
- 13Cookies and Tracking
- 14Changes to This Policy
- 15Contact and Complaints
Who We Are (Controller)
"Clubhouse AC", "we", "us" and "our" refer to the operator of the Clubhouse AC website, dashboard, scanner application and related tools accessible at clubhouseac.com (together, the "Service"). For the personal data we process for our own purposes (account management, billing, service operation, fraud and abuse prevention, aggregate detection telemetry), we are the controller under Article 4(7) GDPR.
For personal data we process on behalf of a server administrator (the forensic scan snapshot a player produces when redeeming a PIN issued by that administrator), the administrator is the controller and we act as the processor under Article 4(8) GDPR. See the separate Data Processing Addendum for the processor-side terms.
Contact.
Data-protection queries, rights requests and any concern about how we handle your personal data can be sent to support@clubhouseac.com or through the operator's Discord support server linked from the site footer. We do not currently have a formal statutory DPO because our processing volume does not meet the Article 37 GDPR threshold; the mailbox above is monitored by a member of the operating team empowered to act on your request.
Scope of This Policy
This Policy explains our practices for personal data processed when you visit the Clubhouse AC website, create an account, purchase a subscription, use the dashboard or workbench, or run the Clubhouse AC scanner application (whether as a subscriber or as a player redeeming a PIN). It does not cover third-party websites we may link to; those sites publish their own privacy notices.
Categories of Personal Data
We process the following categories of personal data. Not every category applies to every user; the categories below cover the full surface across visitors, subscribers and scanned players.
Account identifiers.
Email address, hashed password (never stored in plaintext), Discord user id (when you sign in via Discord OAuth), display name and profile picture URL as supplied by Discord, account creation timestamp, last sign-in timestamp and per-session records.
Subscription and billing data.
The plan you selected, its status and renewal date, the invoice history, the Stripe customer id and the last four digits of the payment method. Card numbers, CVCs and full bank details never touch our servers; they are handled directly by Stripe under their own privacy policy.
Network and device metadata.
IP addresses, User-Agent strings, coarse geolocation derived from IP (city / region / country), browser fingerprinting signals used only for anti-abuse (2FA verification, rate limiting, ban enforcement).
Scanner forensic data (players only).
When a player redeems a server administrator's PIN and runs the scanner, we collect the forensic snapshot described in Terms §05 and the linked DPA: OS metadata, hardware identifiers, running processes, loaded modules, installed programs, execution artifacts (Amcache, Prefetch, ShimCache, BAM, PcaSvc), file system metadata, registry artifacts relevant to anti-cheat detection, event log excerpts, DNS cache, network adapters, active and recent connections, and one or more screenshots of the player's display at scan time. This category applies only to individuals who voluntarily redeem a PIN and complete a scan; passive site visitors never trigger scanner collection.
Communications.
Support tickets, Discord messages you send to the operator, in-app chat with the scanner assistant.
Diagnostic and operational logs.
Server-side error logs, request logs, rate-limit counters, security events (failed logins, unusual sign-in locations, 2FA challenges). Retained short-term for incident response and abuse prevention.
We do not process special categories of data (racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic data, biometric data for uniquely identifying a person, health data, sex-life or sexual orientation data) as part of the normal Service.
Purposes and Lawful Bases
Each processing purpose maps to a specific Article 6(1) GDPR lawful basis. Where more than one basis could apply, we identify the primary one.
Providing the Service to subscribers.
Necessary for the performance of the subscription contract (Art. 6(1)(b)). Covers account management, dashboard access, PIN issuance, scan report delivery.
Running a scan on a player's machine.
Explicit consent (Art. 6(1)(a)): the player voluntarily redeems a PIN after being informed of what the scan collects. Consent is revocable: the player can decline the PIN or stop the scanner before it completes; consent already exercised for a completed scan cannot retroactively delete that specific scan report but does prevent future collection.
Security, fraud and abuse prevention.
Legitimate interests (Art. 6(1)(f)) in operating a secure and non-abused service, balanced against user rights. Covers rate limiting, IP logging, ban enforcement, 2FA and anti-account-sharing measures.
Billing and payment.
Contract performance (Art. 6(1)(b)) plus compliance with tax and accounting law (Art. 6(1)(c)).
Detection research and product improvement.
Legitimate interests (Art. 6(1)(f)) in improving cheat-detection accuracy. Uses only aggregated and de-identified telemetry; individual scan reports are not repurposed for research without additional consent.
Optional analytics.
Consent (Art. 6(1)(a)) via the cookie banner. If you have not accepted the analytics category, no analytics script is loaded and no analytics data is collected. See the Cookies Policy for details.
Legal claims and compliance.
Legal obligation (Art. 6(1)(c)) and establishment, exercise or defence of legal claims (Art. 9(2)(f) where applicable). Covers responding to lawful requests from authorities, defending abuse-report disputes and preserving evidence.
Recipients and Processors
We disclose personal data only to the categories of recipients below, each bound by contractual and/or statutory confidentiality and security obligations.
Infrastructure providers.
Vercel Inc. (application hosting, edge compute, CDN), Neon (managed Postgres), Supabase (managed Postgres + auth for legacy sessions), Cloudflare (DNS, WAF, DDoS mitigation, DNS-over-HTTPS for scanner name resolution).
Payment processing.
Stripe, Inc. Handles card details, produces receipts and manages recurring billing. We never see raw card numbers.
Transactional email.
Resend Inc. (verification codes, sign-in notifications, account emails).
Identity and communication.
Discord Inc. for OAuth sign-in, community support and administrator notifications.
IP geolocation.
ip-api.com (best-effort city/region/country lookup used only to enrich 2FA-verify sign-in-location emails).
Server administrators.
Scan reports produced by a player under a PIN are disclosed to the administrator who issued the PIN and to that administrator's authorised staff. This is the entire point of the Service.
Legal and safety.
Law-enforcement or regulatory authorities where we are legally required to disclose, and to protect the vital interests of a person where necessary.
We do not sell personal data. We do not share personal data with advertising networks, data brokers or profile-syndication vendors of any kind.
International Transfers
Some processors above are established outside the EEA or the UK. Where personal data is transferred to such a jurisdiction, we rely on adequate safeguards recognised under Chapter V GDPR (Articles 44-49), including the Standard Contractual Clauses adopted by the European Commission and, where the destination is the United States and the processor is certified under it, the EU-US Data Privacy Framework. A copy of the safeguards applicable to a specific transfer can be requested from the contact address in §01.
Retention Periods
Account records.
Retained for the life of the account and for a short grace period (typically 30 days) after account deletion so the deletion is reversible if requested in error. After that, identifiers are irreversibly anonymised or deleted, subject to the tax / accounting exception below.
Invoice history.
Retained for the periods required by applicable tax, accounting and anti-fraud law (typically 6-10 years depending on jurisdiction), even after account deletion.
Scan reports (players).
Retained for as long as the administrator's subscription is active and the administrator needs the report for investigation and audit. On subscription cancellation, reports are subject to the deletion terms in the DPA. Administrators can also delete an individual report at any time from the dashboard.
Security and abuse logs.
Rolling short-term window (typically 30-90 days) sufficient for rate-limiting, incident response and abuse investigation, then discarded.
Ban records.
Retained as long as the ban is enforced. Un-banning removes the record on request; a permanent ban record persists indefinitely because its purpose is durable exclusion.
Security Measures
We apply technical and organisational measures appropriate to the risk (Article 32 GDPR):
- All personal data is transmitted over TLS 1.2+.
- Databases sit behind private networking; access requires authentication, is logged and is limited to personnel whose role requires it.
- Passwords are stored as salted, iterated hashes; we never see or store the plaintext.
- Every authenticated action requires 2FA via email OTP; sign-in events are logged with IP, user agent and coarse geolocation, and unusual sign-ins trigger notifications.
- Scanner uploads are session-bound and encrypted end-to-end from the scanner binary to our ingestion endpoint.
- Personal-data breaches are notified to the affected controller without undue delay in accordance with Article 33 GDPR, and to affected data subjects where required by Article 34.
Your Rights
Under the GDPR, the UK GDPR and equivalent laws, you have the following rights over your personal data:
Access
(Art. 15): a copy of the personal data we hold about you.
Rectification
(Art. 16): correction of inaccurate or incomplete data.
Erasure
(Art. 17, "right to be forgotten"): deletion of your personal data, subject to the legal-hold exceptions in §07.
Restriction of processing
(Art. 18): temporary freeze on further processing while a dispute is resolved.
Data portability
(Art. 20): a machine-readable copy of the personal data you provided to us.
Object
(Art. 21): object to processing based on legitimate interests. Where the objection concerns direct marketing we will always honour it.
Withdraw consent
(Art. 7(3)): where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
Lodge a complaint
(Art. 77) with your local supervisory authority (in the EU, the data-protection authority of the member state where you live, work or where the alleged infringement took place).
How to exercise.
Send a request to support@clubhouseac.com from the email address on your account (or, for scanned players, from the address you would like us to reply to plus enough context to identify the scan: the report id from your dashboard is sufficient). We respond without undue delay and within one month, extendable by two further months where necessary given the complexity or number of requests (Art. 12(3)). We do not charge a fee unless the request is manifestly unfounded or excessive.
Children and Minors
The Service is not directed at children under the age of digital consent in the user's jurisdiction (16 in most EU member states, 13-16 in others, 13 in the UK and the US). Signing up requires an age confirmation on the sign-up form. If we become aware that we have collected personal data from a minor without appropriate parental consent, we will delete that data. See Terms §03 (Acceptable Use) and Terms §12 (Age and Eligibility, if present) for the operator-side rules.
Notice to US Residents (CCPA/CPRA)
If you are a resident of California (or another US state with an equivalent framework, including Virginia CDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA), you have the following rights in addition to those listed in §09:
- Right to know what personal information we collect, use, disclose and (if we did) sell or share.
- Right to delete personal information we hold about you, subject to statutory exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of the sale or sharing of personal information. We do not sell or share personal information under any state's definition of those terms, so there is nothing to opt out of, but the right exists.
- Right to limit use of sensitive personal information. We do not process sensitive personal information beyond what is strictly necessary to provide the Service you requested.
- Right to non-discrimination for exercising any of the above.
Requests are honoured on the same channels described in §09. You may designate an authorised agent to submit a request on your behalf; the agent will need to demonstrate authority and we may still contact you directly to verify.
Automated Decision-Making
The scanner analyses the forensic snapshot with automated rules that produce "detection" findings (e.g. "this DLL matches a known cheat family"). Those findings are recommendations to the human server administrator, who makes the final decision about whether to act on them. We do not make solely automated decisions that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR. Ban and enforcement decisions on a specific server are the server administrator's, informed by (but not dictated by) the scan report.
Changes to This Policy
We may update this Policy from time to time. When we make a material change, we will update the "Last updated" date at the top of the page and, where the change substantively affects your rights, notify you through the dashboard or by email. Continued use of the Service after the effective date of a change indicates acceptance.
Contact and Complaints
Data-protection queries and rights requests: support@clubhouseac.com. If you are not satisfied with our response, you have the right to complain to your local supervisory authority. For EU residents, that is the data-protection authority of your member state (a directory is maintained by the European Data Protection Board). For UK residents, it is the Information Commissioner's Office (ICO). For California residents, the California Privacy Protection Agency (CPPA).
Related documents
This policy sits alongside the other legal documents that govern the Service.