Legal
Privacy
Volley Vendetta is a free game with no in-game advertising and no selling of data. Measurement happens only with your consent, and covers two things only: whether a Google ad led to a registration, and how the site is used overall. Beyond that, data is created the moment you open an account. This page tells you in full what that data is and what happens to it.
1. Controller and scope
The controller responsible for the processing described here is:
Spike-Set-Serve (Lukas Widmer)
Gewerbepark 5
9615 Dietfurt
Switzerland
Email: lw2wear@gmail.com
This policy covers the website volleyvendettamanager.com in all its language versions, the installable app version of that same website, and the iOS app insofar as it delivers notifications. It does not cover third party websites linked from here.
The Swiss Data Protection Act (revDSG) applies, and if you are located in the European Economic Area, the General Data Protection Regulation (GDPR) applies in addition. Where the two differ in scope, whichever is more favourable to you applies.
No representative in the European Union under Art. 27 GDPR has been appointed. Volley Vendetta is run by a single person on a non profit basis, processes no special categories of data and carries out no profiling. The controller can be reached directly at the address and email above, in German or English.
2. What data we process
This is the complete list. Anything not named here is not collected.
- Email address, for the account, sign in and system mail.
- Username, team name and manager name, freely chosen and visible to other players.
- Password, held only as a cryptographic hash by the authentication service. The operator never sees your password in plain text.
- If you sign in with Google or Apple, the profile data those providers send, usually name, email address and the identifier of your account with them.
- Game progress: team, squad, line ups, results, league and cup statistics, in game currency, achievements, trading history.
- The country you pick during onboarding. That is a fictional game attribute for your team's nationality, not a statement about where you actually live.
- Team logo, profile picture or card image, if you choose to upload one.
- Sign in timestamps and technical account data, used to protect the account.
- Chat messages from every channel, meaning global, league, clan, match and direct messages, each with content, sender and time. The chat is not a secure channel: messages are stored in plain text and are not end to end encrypted. Other players cannot read your direct messages, the operator technically can, and if a message is reported for abuse or spam he does read the reported message. So never type passwords, addresses or payment details into it. Match chats are deleted automatically once the match is over, all other messages remain.
- Bug reports you submit voluntarily, with the text you wrote.
- Reports sent through the form on the disclaimer page: name, email address, your request, and a non reversible check value derived from your IP address. That check value exists only to slow down mass submissions; the IP address itself is not stored.
- A device identifier for push notifications, if you allow notifications in the iOS app. It is a device token issued by Apple, not an identifier of you as a person.
- Server logs, which arise unavoidably whenever any website is served: IP address, time, the address requested, browser identification and referring page. They are created at the hosting provider, serve operation and defence against attacks, are deleted there after a short time, and are not combined into profiles by the operator.
- Short lived counters for abuse prevention. So that nobody can submit a form a thousand times over, an identifier derived from your IP address is counted for a few minutes and then discarded.
- In the case of a voluntary donation: your username, which is passed to the payment service provider as a reference so that the payment can be matched. Everything else you enter there stays with the payment service provider, not with us.
- Only with your consent: ad performance and reach measurement data. That means the identifier of an ad click and the fact that it turned into a registration, plus the pages you open, your approximate region, your device and browser type and the page you arrived from. Without consent none of it comes into being.
We store no payment details, no postal addresses, no phone numbers, no identity documents, no location data and no special categories of data within the meaning of Art. 9 GDPR. Card details never come into existence with us in the first place: the only payment option is the voluntary donation, and that runs entirely at the payment service provider.
Anything you voluntarily type into a free text field, be it the chat, a bug report or a report form, we process exactly as you wrote it. Please do not type anything into those fields that does not belong there.
3. Legal basis
Account, sign in, gameplay, chat and rankings rest on performance of the user agreement you enter into when you register (Art. 6(1)(b) GDPR, Art. 31(2)(a) revDSG). Without that data the game cannot be provided.
Server logs, abuse prevention, handling of reports and defence against attacks rest on the legitimate interest in a secure and functioning service (Art. 6(1)(f) GDPR).
Push notifications and uploading an image rest on your consent (Art. 6(1)(a) GDPR). You can withdraw either at any time by turning notifications off in your device settings or by deleting the image. The lawfulness of processing up to the withdrawal is unaffected.
Where we are legally obliged to act, for instance when handling a report about an infringement, we rely on compliance with that obligation (Art. 6(1)(c) GDPR).
Measuring ad performance and reach rests on your consent (Art. 6(1)(a) GDPR). You give it in the banner on your first visit and can withdraw it at any time, see section 9. The lawfulness of processing up to the withdrawal is unaffected.
4. What we use the data for
Only to provide the game, for sign in and account security, for communication between players, to send system and game notifications, to diagnose faults and to prevent abuse.
The data is not used for in-game advertising, market research, building user profiles, credit checks or passing on to data brokers. We embed no ad networks. With your consent, Google Analytics runs and measures how this website is used: which pages are opened, for how long and by which route. Without consent it does not run.
Volley Vendetta does not sell user data and has no intention of doing so. Should the operating model ever change, it will be announced here and in the in game news before it takes effect.
5. Services and processors
Running the game is not possible without technical service providers. These providers process data solely on our behalf, on our instructions, and not for their own purposes. Your data is not passed to third parties for their own purposes, and it is certainly not sold.
- Supabase (database, authentication, file storage). Servers in Switzerland, Zurich. This is where account, game progress, chat and uploaded images live.
- Vercel (hosting and delivery of the website). Servers in the USA and the EU. This is where the server logs arise.
- Resend (delivery of sign in and system mail, and forwarding of reports to the operator). Processes recipient address and mail content.
- Google, only if you choose to sign in with a Google account. Google then learns that you are signing in to this service.
- Apple, for delivering push notifications to the iOS app and for signing in with an Apple account, if you use that.
- Upstash (short lived cache for abuse prevention), where that protection is enabled. Stores only counters, for a few minutes.
- Stripe (processing of voluntary donations), locations Ireland and the USA. Only comes into play if you click the donation button yourself; without a donation nothing is transmitted to Stripe.
- Google Ireland Limited (Google Tag Manager, Google Analytics and the Google Ads conversion measurement), servers in the EU and the USA. The service only sets cookies after your consent.
Beyond this list, no third party scripts are loaded: no embedded videos, no fonts from external servers, fonts are served from our own domain. The only external script is Google Tag Manager. It runs on every page, but without your consent it is switched off: no cookies, no identifier transmitted. Only after your consent does it load Google's measurement tools, meaning Google Analytics and the Google Ads conversion measurement.
We disclose data to authorities only where we are legally obliged to, and only to the extent of that obligation.
Two exceptions in this list: Stripe and Google. Neither acts on our instructions on our behalf, both act as their own controller under their own privacy policy. We have no influence there over which data are collected and how long they are kept.
6. Transfers abroad
The core data, meaning account, game progress, chat and images, sits on servers in Switzerland. Part of the processing nevertheless happens abroad, in particular in the USA: serving the pages, sending mail, delivering push notifications and, if you donate, processing the payment.
For those transfers we rely on the Standard Contractual Clauses of the European Commission, on the safeguards recognised by the Swiss Federal Data Protection and Information Commissioner, and on the corresponding assurances given by the providers we use. A residual risk connected to the legal situation in the destination country cannot be ruled out entirely. We would rather write that down than leave it unsaid.
If you consent to ad and reach measurement, Google is added, with servers in the EU and the USA. Withdrawing your consent ends that transfer.
7. Artificial intelligence
Your data is not processed by artificial intelligence. No language model runs on your chat messages, your images, your game progress or anything else you enter. There is no AI assisted moderation, no automated analysis of your text and no handing of your content to an AI provider.
Where AI does appear is in the production of game content. Some of the artwork, in particular portraits of fictional youth players, and some of the text and program code are created with the help of AI tools. That happens during development, outside the running service, and with no connection to user data whatsoever. Images showing a person are either such fictional creations or come from publicly accessible sources. How that is handled, and how to reach us if you believe you are depicted, is set out in the disclaimer.
There is no automated decision making within the meaning of Art. 22 GDPR. The match engine calculates match results, which is a game and not a decision with legal effect for you. If an account is suspended, that is decided by the operator, not by an automated process.
Your data is not used as training material for AI models and is not passed on for that purpose.
8. What others can see
Volley Vendetta is a multiplayer game, so part of what you enter is visible on purpose. Visible to other signed in players:
- Manager and team name, team logo and card image.
- League, table position, results, statistics and rankings entries.
- Squad, transfers, auction bids and trade offers.
- Achievements and progress, as far as they are shown in the profile.
- Anything you write into a public chat channel.
Your email address is not visible to other players. Direct messages are visible only to you and the person you wrote to, but as described above they are technically readable by the operator.
Uploaded images sit in publicly reachable file storage. Anyone who knows the exact address of an image file can open it without signing in. The addresses cannot be guessed, but they are not secret either. Deleting an image removes it from the game; copies other people made in the meantime cannot be recalled.
Public, meaning reachable without an account and visible to search engines, are only the home page, the manager information page, the card gallery, the security page and the legal pages. All game areas are reserved for signed in players and excluded from indexing.
9. Cookies and local storage
Technically necessary cookies are always set, there is nothing to decide there. Alongside them, exactly one category is up to you: the cookies for ad and reach measurement. The banner asks about it on your first visit.
- Sign in and session cookies of the authentication service. Without them, signing in is impossible.
- A cookie for your language choice.
- A cookie that distinguishes the mobile from the desktop view.
- A cookie for the display time zone you selected.
- A short lived cookie for an invitation link, so the invitation is credited to the right account.
- A cookie holding your decision on measurement, so the banner does not return on every visit.
- Only after your consent: Google's cookies. _gcl_au records that an ad click turned into a registration. _ga and _ga_LE6R37WZBC recognise returning visits for reach measurement, without knowing you by name. If you decline, none of them are set.
In addition, your browser stores data locally on your device: the cache of the installable app so it starts without a connection, plus small markers for hints you have already seen and for a draft of a report form. This data never leaves your device and disappears when you clear website data in your browser.
You can change your decision at any time:
10. How long we keep data
We keep data as long as the purpose requires and no longer.
- Account, profile and game progress: until you delete your account.
- Match chats: deleted automatically once the match is over.
- Other chat messages: permanently, and after account deletion without any link to your account. The reason is in section 12.
- Server logs: briefly, at the hosting provider, usually a few days to a few weeks.
- Abuse prevention counters: a few minutes.
- Bug reports: until the reported fault is fixed and the report evaluated.
- Reports sent through the disclaimer form: permanently, because they are a legal matter that has to stay traceable. After an account deletion the link to your account is removed.
- Device tokens for push notifications: until you turn notifications off, the device reports the token as invalid, or you delete your account.
- Ad and reach measurement data: held at Google under its own periods. The data tied to individual visits in Google Analytics is capped at 14 months, after which only aggregated figures remain.
11. Your rights
You are entitled to:
- Information about which data we process about you.
- Correction of inaccurate data.
- Deletion of your data, within the limits of the law.
- Restriction of processing.
- A copy of your data in a common format, for transfer to another provider.
- Objection to processing that rests on a legitimate interest.
- Withdrawal of any consent you gave, with effect for the future.
An informal message is enough for any of these. We answer as quickly as possible and in any case within the statutory deadlines. Since a single person is doing the work, it may take a few days; if you have heard nothing after two weeks, please ask a second time.
You may also lodge a complaint with a supervisory authority. In Switzerland that is the Federal Data Protection and Information Commissioner (FDPIC), in the European Economic Area the data protection authority of your country of residence.
For access, correction, deletion and every other request under section 11: lw2wear@gmail.com or the report form on the disclaimer page, which works without an account.
12. Deleting your account
You can delete your account yourself in the settings at any time, or request deletion by email. Profile and sign in account are deleted immediately after confirmation (revDSG Art. 32, GDPR Art. 17). Your team then stays in the league as a computer controlled team, so the running season does not fall apart for everyone else. It is given a neutral name, and your uploaded logo or card image is deleted.
Chat messages are the exception: the link to your account is removed, the message text itself remains. Otherwise ongoing conversations would develop one sided gaps for the other players. So expect written messages to be permanent, even once your account no longer exists.
Reports sent through the disclaimer form also remain, for the reason given in section 10, along with anything we are legally obliged to retain.
13. Minimum age
Volley Vendetta is intended for people aged 16 and over. By registering you confirm that you are at least 16. We deliberately collect no data to verify that age, because age verification would demand more data than the game needs in the first place. If you learn that an account is run by someone younger, please report it and we will delete it.
14. Security
The connection to the website is encrypted throughout. Passwords are stored only as hashes, and database access is secured row by row so that an account sees only its own data. The exception is the operator, who can technically reach everything.
Absolute security does not exist. If you find a hole, please report it rather than exploit it. More about the technical setup is on the security page.
Should a data breach occur despite every precaution and pose a risk to you, we will inform the competent supervisory authority and, where the law requires it, you as well.
15. Changes and language versions
This policy is adjusted when new features arrive or the legal situation changes. The version published here is the one that applies. For substantial changes we point it out in the in game news as well.
The German version is authoritative. Translations into other languages serve comprehension and create no differing rights or obligations.
The terms of use and the disclaimer apply in addition.
Last updated: August 2026