BAR
  • Home
  • Terms of Service

Privacy Policy

Last Updated: April 10, 2026

1. Introduction

Battle Among Regions ("we", "our", "the Game") is committed to protecting your privacy. This Privacy Policy explains what data we collect, how we use it, and your rights regarding your personal information.

By creating an account or using the Game, you agree to the collection and use of information in accordance with this policy. This policy applies regardless of how you access the Game — whether via Steam, the official website, the desktop client, or the Android app.

2. Data We Collect

2.1 Account Information

When you create an account, we collect:

  • Username — your unique identifier in the game
  • Display Name — the name shown to other players
  • Email Address (optional) — used for email verification and password recovery
  • Password — stored as a one-way cryptographic hash (bcrypt); we never store or see your actual password

2.2 Gameplay Data

We automatically collect data related to your gameplay:

  • Match history (wins, losses, draws, duration, regions played, decks used)
  • Ranked rating and leaderboard statistics
  • Card collection and deck configurations
  • Rank achievements and promotion series progress

2.3 Purchase Data

If you make in-game purchases, we store:

  • The type and ID of purchased cosmetic items
  • Transaction amount and currency
  • Payment processor session/transaction ID (for transaction tracking)
  • Date/time of purchase

We do not store your credit card number, bank details, or full payment information. All payment processing is handled securely by the applicable payment provider (e.g., Stripe for direct purchases, or via the platform's own payment system such as Steam Wallet).

2.4 Authentication Tokens

We generate and store authentication tokens on your device to keep you logged in. These tokens are randomly generated strings and do not contain personal information.

2.5 Technical Data

We may collect technical information such as:

  • Game version and platform (Steam, web, Android, desktop)
  • Connection timestamps for matchmaking

We do not collect IP addresses, device identifiers, or hardware fingerprints.

3. Legal Basis for Processing (GDPR / UK Data Protection Act 2018)

If you are located in the European Economic Area (EEA) or the United Kingdom, we process your personal data under the following legal bases:

  • Contract Performance — Processing necessary to provide you with the Game and your account (Art. 6(1)(b) UK GDPR)
  • Legitimate Interests — Processing necessary for anti-cheat enforcement, matchmaking integrity, and service improvement (Art. 6(1)(f) UK GDPR)
  • Consent — Where you have opted to provide an email address for verification or recovery (Art. 6(1)(a) UK GDPR)

4. How We Use Your Data

We use the data we collect to:

  • Provide and maintain your game account
  • Enable online multiplayer matchmaking and ranked play
  • Track your card collection, decks, and progression
  • Display leaderboards and match history
  • Process in-game purchases
  • Send email verification codes and password reset codes
  • Detect cheating and enforce our Terms of Service

We do not sell your data to third parties. We do not use your data for advertising or profiling.

5. Data Storage & Security

Your data is stored in a database on our server, hosted by Render.com (servers located in the United States). We take reasonable measures to protect your data, including:

  • Passwords are hashed using bcrypt with a salt (never stored in plain text)
  • Authentication tokens are cryptographically random
  • Verification and reset codes expire after 30 minutes
  • Device link codes expire after 5 minutes
  • All data is transmitted over encrypted connections (HTTPS/WSS)

While we strive to protect your data, no method of electronic storage is 100% secure. We cannot guarantee absolute security.

6. International Data Transfers

Your data may be transferred to and stored on servers located outside your country of residence, including the United States. Where such transfers occur, we ensure that appropriate safeguards are in place in compliance with the UK GDPR.

7. Third-Party Services

We use the following third-party services:

  • Stripe — for processing in-game purchases on the website and desktop client. When you make a purchase, you interact directly with Stripe's checkout page. Please review Stripe's Privacy Policy.
  • Steam (Valve Corporation) — if you access the Game through Steam, Valve may collect additional data in accordance with their Privacy Policy. We do not control Steam's data collection.
  • Google Play (Google LLC) — if you access the Game through Google Play, Google may collect additional data in accordance with their Privacy Policy. In-app purchases on Android are processed through Google Play Billing. We do not control Google's data collection.
  • Render.com — our server hosting provider. Please review Render's Privacy Policy.
  • Nodemailer / Gmail SMTP — for sending verification and password reset emails from our server.
  • GitHub — for hosting game updates and releases.

8. Data Retention

We retain your account data for as long as your account is active. If you wish to delete your account and all associated data, please contact us at BattleAmongRegions@gmail.com. We will process account deletion requests within 30 days.

Expired verification codes, password reset codes, and device link codes are automatically purged from the database.

Purchase records may be retained for accounting and legal compliance purposes for up to 7 years after the transaction date, in accordance with UK tax law.

9. Your Rights

Under the UK GDPR and the Data Protection Act 2018, you have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — request correction of inaccurate data
  • Erasure — request deletion of your data ("right to be forgotten")
  • Restriction — request restriction of certain processing
  • Data Portability — request your data in a structured, machine-readable format
  • Object — object to processing based on legitimate interests
  • Withdraw Consent — withdraw consent at any time where processing is based on consent

To exercise any of these rights, contact us at BattleAmongRegions@gmail.com. We will respond within 30 days.

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).

10. Children's Privacy

The Game is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us and we will take steps to delete such information.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. Where changes are significant, we will make reasonable efforts to notify you (e.g., via an in-game notification). Continued use of the Game after changes constitutes acceptance of the updated policy.

12. Contact Us

If you have any questions about this Privacy Policy, please contact us at:

BattleAmongRegions@gmail.com

BAR

Battle Among Regions — War for Supremacy

Home Privacy Policy Terms of Service

© 2026 Battle Among Regions. All rights reserved.