Skip to main content
GrailBounty
GrailBounty© 2026
AboutWanted BoardCard CatalogChase TrackerTermsPrivacyBounty TermsCopyrightModeration

Privacy Policy

Last updated: [LAST UPDATED DATE]

Owner review required: Replace every bracketed placeholder with approved business, legal, retention, and jurisdiction information before publication. This policy is not legal advice.

1. Scope and Controller

This Privacy Policy explains how Bada Studios LLC ("GrailBounty," "we," "us," or "our") handles information through the GrailBounty website, applications, and related services. Our contact details are [PRIVACY CONTACT] and 30 N Gould St #Ste R, Sheridan, WY 82801, USA. The person or entity responsible for personal-data decisions in each jurisdiction must be confirmed: [DATA CONTROLLER / BUSINESS ROLE].

2. Information We Collect

  • Account data: email address, authentication identifiers, display name, username, profile details, and verification state.
  • Profile and community data: avatar, bio, interests, location fields, privacy settings, referrals, reports, and moderation records.
  • Hunt and inventory data: card searches, wanted items, ownership/listing information, target prices, bounty descriptions, images, notes, and status history.
  • Communications: messages, support requests, report details, and related metadata.
  • Technical and usage data: IP address, browser/device information, approximate location derived from IP where applicable, pages viewed, events, timestamps, errors, and security/rate-limit signals.
  • Notifications: push-notification tokens and notification preferences when enabled.
  • Cookies and similar technologies: authentication/session support, preferences, referrals, security, analytics, and measurement. The exact inventory and consent behavior must be confirmed: [COOKIE/CONSENT DETAILS].

We do not intentionally request sensitive personal information unless specifically identified at collection. Do not submit payment-card numbers, government identifiers, passwords, or other sensitive information in public fields or messages.

3. How We Use Information

  • Provide accounts, profiles, hunts, listings, matching, messaging, notifications, and moderation.
  • Authenticate users, secure the Service, prevent abuse, investigate reports, and enforce our Terms.
  • Operate, maintain, troubleshoot, measure, and improve the Service.
  • Respond to support, legal, privacy, copyright, and safety requests.
  • Comply with legal obligations and protect rights, safety, and property.
  • Send transactional or product communications as permitted by law.

4. Purposes and Legal Bases

The lawful bases relied on by jurisdiction must be completed by the owner and counsel: [LEGAL BASES BY PURPOSE AND JURISDICTION]. Potential categories may include contract, consent, legitimate interests, legal obligation, and protection of vital interests, but we do not represent that any particular basis applies until confirmed.

5. Firebase, Google Cloud, and Providers

We use Firebase and Google Cloud services, which may include Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Cloud Messaging, hosting/deployment, logs, and security services. Google and other providers process information on our behalf or as separate service providers according to the applicable agreements and configurations. The exact enabled services, provider list, subprocessors, and data-region commitments must be confirmed: [PROVIDER/SUBPROCESSOR LIST AND LINKS].

We may also use Vercel for hosting, deployment, performance, and Web Analytics, and other vendors for email, abuse prevention, monitoring, or support. The final vendor list and roles require owner confirmation: [SERVICE PROVIDER INVENTORY].

6. Sharing

We may share information with service providers, infrastructure providers, moderators, professional advisers, authorities when legally required, and parties involved in a merger, acquisition, financing, or sale of assets. Public profiles, hunts, listings, card data, reports, and messages may be visible according to the settings and features you use. We do not sell personal information as that term is defined by applicable law unless this statement is changed after owner and counsel review: [SALE/SHARING POSITION].

7. Retention

We retain information only for as long as needed for the purposes described here, account operation, security, dispute handling, backups, analytics, and legal duties. Exact periods must be supplied and documented by the owner: active account data [RETENTION PERIOD], deleted-account data [RETENTION PERIOD], messages [RETENTION PERIOD], reports/moderation records [RETENTION PERIOD], logs/security data [RETENTION PERIOD], backups [RETENTION PERIOD].

8. Your Choices and Requests

  • Delete: Use the account deletion flow at [ACCOUNT DELETION PATH] or contact [PRIVACY CONTACT]. Deletion may not remove records we must retain.
  • Export: Request a copy of available personal data through [DATA EXPORT PATH OR CONTACT]. The supported format and identity checks must be confirmed: [EXPORT DETAILS].
  • Correct: Update profile information in settings or contact [PRIVACY CONTACT].
  • Restrict/ object: Where applicable, request restriction or object to processing by contacting [PRIVACY CONTACT].
  • Withdraw consent: Where processing relies on consent, withdraw it using the offered control or by contacting [PRIVACY CONTACT].

Request identity verification, response deadlines, fees, and appeal process: [PRIVACY REQUEST PROCEDURE].

9. Children's Privacy

The Service is not directed to children under [MINIMUM AGE]. We do not knowingly collect personal information from a child in violation of applicable law. If you believe a child provided information, contact [PRIVACY CONTACT]. The legally approved age threshold and parental-consent process must be confirmed: [CHILDREN'S PRIVACY REQUIREMENTS].

10. International Transfers

Information may be processed in countries other than where you live, including countries where our providers operate. The transfer mechanism and supplementary safeguards must be confirmed: [INTERNATIONAL TRANSFER MECHANISM AND REGIONS].

11. Security Limitations

We use administrative, technical, and organizational measures intended to protect information. No system, transmission, or storage method is completely secure. Do not submit information that you would not want exposed if a security incident occurred. Our incident-response contact and legally required notification process are: [SECURITY CONTACT AND INCIDENT PROCESS].

12. State and Regional Rights

Depending on where you live, you may have rights to know/access, correct, delete, obtain portability, opt out of certain processing, limit sensitive-data use, appeal a decision, or avoid discrimination for exercising rights. The states/countries covered, categories of personal information, authorized-agent process, and appeal contact must be completed: [STATE/REGIONAL PRIVACY RIGHTS AND PROCESS].

13. Changes and Contact

We may update this Policy and will revise the effective date. Material-change notice methods must be confirmed: [MATERIAL CHANGE NOTICE]. Privacy requests and questions go to [PRIVACY CONTACT] at [PRIVACY CONTACT EMAIL] or 30 N Gould St #Ste R, Sheridan, WY 82801, USA.