Skip to main content

WorstPlayerLoose · TOKENS

Privacy Policy & Legal Notice

This notice explains how WorstPlayerLoose TOKENS ("we", "us", "our") collects, uses, stores, and shares personal information when you use arraytokens.eu and related services. It also includes trademark disclaimers for Epic Games, Fortnite®, and Twitch, and describes integrations using Epic Account Services (OAuth).

Last updated: August 10, 2026

← Back to home
Important: This page is provided for transparency and compliance awareness. It is not personalised legal advice. Operators must insert accurate corporate identity details where indicated (registered name, address, registration numbers, designated privacy contact).

1. Who We Are (Legal Publisher Information)

  • Service: WorstPlayerLoose TOKENS — a competitive matchmaking and virtual‑currency platform accessible primarily at arraytokens.eu.
  • Contact: For privacy requests (access, deletion, portability, objections), contact us through the official channels published on the site (for example support or the Discord linked from the homepage). Mark requests clearly as "Privacy / GDPR" and include your account identifier (username or login email you used to register).
  • Data controller: For personal data processed via this website, the controller is the legal entity operating WorstPlayerLoose TOKENS — replace this clause with your full legal name, registered office, company ID, and VAT number where applicable.

2. Scope & Acceptance

By accessing or using the Service (creating an account, browsing logged‑in areas, linking Twitch or Epic, participating in chats or matches), you acknowledge that you have read this Policy alongside our Terms of Service. If you do not agree, discontinue use of the Service.

This Policy applies to visitors and registered users worldwide; specific rights may vary by region (see Sections 14–15).

3. Trademarks & Third‑Party Brand Disclaimer

Fortnite®, Epic Games, Unreal Engine, and related logos and marks are trademarks or registered trademarks of Epic Games, Inc. in the United States of America and elsewhere. WorstPlayerLoose TOKENS is not affiliated with, endorsed by, or sponsored by Epic Games unless expressly stated on our Site.

Twitch and the Twitch marks are property of Amazon / Twitch Interactive, Inc. External ranking tools or trackers linked from profiles are operated by third parties and governed solely by their own terms.

You remain solely responsible for compliance with Epic's Terms of Service, Epic's Community Rules, the Fortnite® End User License Agreement, age restrictions in your territory, and any applicable publisher policies when interacting with Epic‑controlled games or accounts outside WorstPlayerLoose TOKENS.

4. Categories of Personal Data We Collect

  • Identity & account: user identifier (UUID), email address from auth where applicable, display username, avatar image URL, internal roles or tags (including moderation tiers stored as metadata).
  • Epic linkage (optional): Epic Account ID, Epic display name as authorised via Epic OAuth (e.g. basic_profile), linkage flags, anti‑smurfing locks tied to your profile — not your Epic password (never transmitted to us in plaintext OAuth flows).
  • Twitch linkage (optional): Twitch user identifier, login/display name, avatar — obtained via Twitch OAuth according to Twitch's authorisation screens.
  • Economy & gameplay stats: virtual balances ("tokens" / coins), win/loss history aggregated on leaderboards, ELO or comparable ranking metrics stored by our backend.
  • Communications: global chat messages, match‑scoped chat text and attachments where the feature exists, moderation logs tied to enforcement actions.
  • Preferences: client‑side or saved preferences such as anonymous mode, notification settings where persisted server‑side.
  • Technical & security logs: IP addresses and timestamps processed by hosting/CDN providers for TLS termination and abuse mitigation; server-side diagnostic logs with hashed identifiers where feasible.

We do not intentionally seek sensitive categories (health, biometric identifiers outside gameplay metaphors, etc.). Do not submit sensitive personal data in chat or ticket attachments unless strictly required for dispute handling — redact documents appropriately.

5. Purposes & Legal Bases (EEA / UK Reference)

  • Performance of a contract — operating accounts, matches, wallets, and support flows.
  • Legitimate interests — fraud prevention (Epic linkage), moderation, analytics limited to service reliability and misuse detection.
  • Consent — optional integrations such as Twitch or Epic linking when legally framed as consent under EU law.
  • Legal obligation — responding to lawful requests from competent authorities.

Where consent is withdrawn for optional integrations, certain ranked features may remain inaccessible until alternative eligibility checks apply — see match‑creation rules in‑product.

6. Epic Games & Epic Account Services (EAS / OAuth)

When you choose "Link Epic", your browser is redirected to Epic's official Epic Account Services / Epic OAuth endpoints. We request only the application scopes configured in our Epic Developer Portal (typically restricted scopes compatible with basic_profile‑style access intended for displaying identity and tying accounts fairly).

Upon successful authorisation, Epic issues tokens to our backend so we can retrieve limited profile attributes — principally Epic Account ID and Epic display name. Access tokens are handled server‑side and not embedded in public pages for third‑party extraction.

Epic remains an independent controller for processing that occurs on Epic's domains before data reaches us. Consult Epic's privacy notice at epicgames.com/site/en-US/privacy and Epic's developer documentation for Epic Account Services as updated from time to time.

If Epic updates eligibility, certification, or disclosure obligations for applications using Login with Epic / EOS features, we may adjust our flows and update this Policy accordingly.

7. Twitch & Other Third‑Party Services

Twitch linkage requires acceptance of Twitch's authorisation UI and is governed by Twitch's Privacy Notice and Terms of Service. We store Twitch identifiers and profile imagery strictly as needed to render linked profiles and homepage integrations (such as live directory previews).

Embedded streams or outbound links may transmit technical data (referrer, IP) to those platforms — review their policies separately.

8. Cookies, Local Storage & Similar Technologies

We use strictly necessary cookies / storage sets required for authentication sessions (Supabase), CSRF/state cookies for OAuth round‑trips (Epic), and lightweight preference keys (theme). We do not operate invasive cross‑site behavioural advertising cookies through this Policy baseline — if analytics or marketing pixels are introduced later, we will update this section and obtain consent where mandated.

Browser controls may delete cookies; doing so may log you out or interrupt OAuth completion until retried.

9. Recipients, Processors & International Transfers

We rely on subprocessors such as Supabase (database, authentication APIs), cloud hosting providers (for example environments comparable to Railway), and optionally CDN / edge security vendors. Their infrastructure may be located in the European Economic Area, the United Kingdom, or the United States — subject to contractual safeguards ( Standard Contractual Clauses, UK Addendum, or equivalent mechanisms) when transferring personal data from the EEA/UK.

Epic Games and Twitch process data under their own infrastructures when you interact directly with them — refer to their disclosures for transfer frameworks.

10. Retention

  • Account data: kept while the account is active and for a reasonable grace period after deletion requests or bans unless longer retention is legally required.
  • Chat logs: retained as needed for moderation, disputes, and audit — typically rolling windows unless escalated cases require archival holds.
  • Security logs: short‑to‑medium retention consistent with abuse mitigation (often weeks to months depending on severity tiers).

Exact durations may evolve; material extensions affecting user rights will be reflected here or communicated where feasible.

11. Security & Incident Response

We implement defence‑in‑depth controls appropriate to risk: TLS encryption in transit, separation of secrets for OAuth clients, role‑based database policies where configured, rate limiting on sensitive endpoints, and staff permission tiers for moderation tooling.

No online platform can guarantee absolute security. If we become aware of a breach likely to affect your rights or freedoms, we will notify supervisory authorities and affected users where required by applicable law without undue delay.

12. Automated Decision‑Making

We do not execute solely automated decisions producing legal or similarly significant effects under GDPR Article 22 as a default product posture. Automated scoring for matchmaking or ranking does not replace human review channels for sanctions — appeals follow moderation workflows described in our Terms or staff procedures.

13. User‑Generated Content & Moderation

Material you post (chat text, uploaded screenshots for disputes) may be processed to enforce rules, investigate cheating allegations, and comply with law. Severe violations may lead to account termination and preservation of evidentiary records consistent with retention Section 10.

14. Your Privacy Rights (EEA / UK / Switzerland Overview)

Subject to verification and statutory exceptions, you may request:

  • Access to categories/specific pieces of personal data we hold;
  • Rectification of inaccurate data;
  • Erasure ("right to be forgotten") where applicable;
  • Restriction or objection to certain processing;
  • Data portability for structured machine‑readable exports where technically feasible;
  • Lodge a complaint with your supervisory authority (for example the CNIL in France or the ICO in the UK).

15. U.S. Residents — California & Other State Privacy Rights (Summary)

Depending on your state of residence, privacy statutes may grant rights to know, delete, correct, or opt out of certain processing (including "sale" or "sharing" for cross‑context behavioural advertising where defined).

WorstPlayerLoose TOKENS does not sell personal information for monetary consideration as traditionally understood in privacy statutes. If our practices materially change, we will update this disclosure and provide any legally required opt‑out mechanics.

California residents may have additional rights under the CPRA — submit privacy requests using the contact methods above; we will verify identity before fulfilling sensitive requests.

16. Children's Privacy

The Service is not directed to children below the digital consent threshold applicable in their jurisdiction. Epic Games imposes its own age rules for Epic Accounts — you must comply with Epic's requirements when linking. If you believe a minor has submitted personal information improperly, contact us so we can investigate and delete where appropriate.

17. Changes to This Policy

We may revise this Policy to reflect product changes, regulatory guidance, or subprocessors. We will update the "Last updated" date and, where legally required or commercially reasonable, provide additional notice (banner, email to registered users, or changelog).

Continued use after the effective date constitutes acceptance of the revised Policy unless mandatory law requires explicit renewed consent for specific processing.

18. Relationship With Our Terms of Service

This Policy supplements — but does not replace — our Terms of Service, which govern gameplay rules, acceptable conduct, dispute resolution, and limitation of liability applicable to use of WorstPlayerLoose TOKENS.

Operators should maintain internal records of subprocessors, DPIA outcomes where applicable, and templates for Data Processing Agreements (DPAs) upon enterprise customer request.