1. Scope and controller
This policy applies to use of Persistly. Northshore Labs LTD is the data controller for account, billing, website, and support data. For customer game/player data processed through the service, the customer is normally the controller and Northshore Labs LTD acts as processor under the DPA.
2. Data we collect
Depending on how the Service is used, we may collect account information, profile details, billing-related customer data, technical data such as IP address, browser type, logs, support communications, project configuration, runtime environment metadata, and service-specific data required to operate Persistly.
- Account data: email address, authentication identifiers, profile details, and organization or developer account details.
- Billing data: Stripe customer identifiers, plan, subscription status, invoice metadata, billing address, tax ID, and payment status.
- Service data: project names, environment names, runtime key metadata, save identifiers, save metadata, save state, versions, and operational events.
- Auth Bridge data: external authentication provider identifiers, issuer and subject identifiers, token claim metadata needed to verify player sign-in, email claim or display hints where provided by the provider, account-link metadata, and provider configuration metadata.
- Technical data: IP address, user agent, request logs, security logs, error logs, and audit records.
- Support data: messages, attachments, and context you provide when contacting us.
3. Why we process data
We process personal data to provide and secure the Service, communicate with users, operate billing and subscriptions, improve reliability and performance, prevent abuse, investigate incidents, and comply with legal obligations.
When Auth Bridge is enabled for a customer project, Persistly processes provider tokens only to verify player identity with the configured identity provider and issue a Persistly account session. Normal save, load, and sync routes use the Persistly account session rather than provider tokens. Persistly does not intentionally retain raw provider tokens after the exchange; we may store derived link metadata such as provider, issuer, subject identifier, display or email hints, timestamps, and audit records.
4. Legal bases
Where GDPR applies, we rely on contract performance, legitimate interests, consent where required, and legal obligation.
5. Analytics and cookies
Persistly uses essential authentication, session, and security cookies for account and dashboard operation. Where required, non-essential cookies or similar technologies are used only after consent. See the Cookie Policy.
With consent, Persistly may collect first-party product analytics from the website, docs, and dashboard, such as page views, SDK guide views, code-copy actions, signup/dashboard clicks, project creation, runtime key copy, and first successful runtime milestones. These events help us understand developer onboarding and support release readiness. They are not used to store runtime keys, raw save payloads, payment card details, or customer player data.
Product analytics events are retained for a limited analytics window, currently up to 90 days, and may be linked to a dashboard developer account after sign-in when consent is present.
Persistly may use Cloudflare Turnstile on sign-up or other abuse-sensitive forms to help distinguish legitimate visitors from automated abuse. Turnstile may run in invisible mode. Cloudflare's processing for Turnstile is described in the Cloudflare Turnstile Privacy Addendum.
6. Children and player data
Persistly is a developer service and is not directed to children. Customers are responsible for deciding what player data they send to Persistly and for complying with laws that apply to their games, including child privacy, consent, and parental notice requirements where relevant.
Customers should avoid sending children's personal data, sensitive personal data, payment card data, passwords, government IDs, health data, or secrets through Persistly unless a separate written agreement and appropriate legal controls are in place.
7. Payments
Payments are processed by Stripe. We do not store full payment card details.
8. Subprocessors and service providers
We use third-party service providers including Stripe for payments, Clerk for authentication, DigitalOcean for hosting, Cloudflare for DNS/security services including Turnstile where enabled, and Sentry for error monitoring and diagnostic metadata. See the Subprocessors page for the current list.
Customers may also configure their own identity providers, such as Firebase, Supabase, or Auth0, for Auth Bridge. Those provider relationships are controlled by the customer. Persistly processes provider tokens and claims only as instructed by the customer's project configuration and does not use customer-configured identity providers for Persistly dashboard authentication.
9. Retention
We retain personal data only as long as necessary for the purposes described in this policy, including legal, accounting, backup, security, and incident review needs. Billing and tax records may be retained for the period required by accounting and tax law. Backups and logs may persist for a limited period after deletion from active systems.
10. International transfers
Data may be transferred internationally with appropriate safeguards where required by law.
11. Your rights
Depending on applicable law, including GDPR or UK GDPR where they apply, you may request access, correction, deletion, restriction, portability, objection, or withdrawal of consent where processing depends on consent. You may also have the right to complain to a data protection authority.
12. Account deletion and erasure requests
Persistly dashboard users can request account deletion from account settings or by contacting us. We review destructive deletion requests before completion so billing, security, fraud-prevention, backup, legal-claim, and legal-obligation retention can be handled correctly. Where required, we will delete or anonymize eligible data.
13. US privacy rights
If US state privacy laws apply to you, you may have rights to know, access, correct, delete, or receive a copy of personal information. Persistly does not sell personal information and does not intentionally share personal information for cross-context behavioral advertising. If this changes, we will update this policy and provide the required opt-out mechanism.
14. Security
We implement reasonable technical and organizational measures to protect personal data.
15. Changes
We may update this Privacy Policy from time to time.
16. Contact
Privacy questions: privacy@persistly.app. Security reports: security@persistly.app. Product support: support@persistly.app.