HomePrivacy Policy

Privacy Policy

Effective date: July 2, 2026

1. Introduction

Climbify ("we", "our", "us") operates the website climbify.gg and related services (collectively, the "Service"). This Privacy Policy explains what personal information we collect, how we use it, and what rights you have in relation to it. By using the Service, you agree to the collection and use of information as described in this policy.

2. Information We Collect

We collect only the information necessary to provide the Service:

  • Account data: email address and username, provided when you register.
  • Order data: rank details, service selections, and order history, necessary to fulfill your boost order.
  • Game account credentials: if you select the Piloted boosting mode, you provide your game login credentials so your assigned booster can complete the order. These are stored only for the duration of the order in a dedicated, access-restricted field and are automatically deleted when the order is completed, refunded, or cancelled.
  • Payment data: handled entirely by Stripe, Inc. We do not receive, process, or store card numbers or full payment details. We receive only a payment confirmation and your email.
  • Usage data: standard server logs (IP address, browser type, pages visited) for security and diagnostic purposes.

3. How We Use Your Information

We use the information we collect to:

  • Create and manage your account.
  • Process and fulfill boost orders.
  • Send transactional emails (order confirmations, status updates). We do not send marketing emails without your explicit consent.
  • Detect and prevent fraud or abuse.
  • Comply with applicable legal obligations.

We do not sell, rent, or share your personal data with third parties for advertising or marketing purposes.

4. Data Storage and Security

Your data is stored on Supabase (supabase.com), which operates servers in the United States and European Union. We apply industry-standard security measures including encrypted connections (HTTPS/TLS), hashed passwords, and access controls limited to authorised personnel. However, no system is completely secure, and we cannot guarantee absolute security.

International transfers. Where your personal data is transferred outside the European Economic Area (for example, to Supabase or Stripe infrastructure in the United States), that transfer is governed by the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the EU–U.S. Data Privacy Framework, which provide appropriate safeguards under Chapter V of the GDPR.

Data breaches. In the event of a personal-data breach that is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and will inform affected users without undue delay where the breach is likely to result in a high risk to them, as required by GDPR Art. 33–34.

Climbify is not liable for data breaches that result from circumstances beyond our reasonable control, including breaches of third-party infrastructure we rely on.

5. Payment Processing

All payments are processed by Stripe, Inc., a PCI-DSS Level 1 certified payment processor. Card data is handled entirely by Stripe: Climbify never sees, receives, stores, or processes your card number, CVC, or billing details. We receive only a payment confirmation and your email address. When you complete a purchase, you are also subject to Stripe's Privacy Policy (stripe.com/privacy).

Note: "end-to-end encryption" references elsewhere on this site refer exclusively to your connection to our servers over HTTPS/TLS, not to game account credentials, which you voluntarily share with your assigned booster at your own risk.

6. Cookies and Local Storage

Authentication is handled exclusively through secure, httpOnly session cookies: these cannot be read by page scripts and are the only cookies essential to the Service. We do not store authentication tokens in your browser's localStorage. No advertising or tracking cookies are used. We use localStorage only for non-essential interface preferences (for example, remembering that you have dismissed a notice). You may disable cookies in your browser settings, but this will prevent login from functioning.

7. Third-Party Data Processors

The Service relies on the following sub-processors who process personal data on our behalf under appropriate data processing agreements (DPAs) in accordance with GDPR Art. 28:

  • Supabase, Inc.: database hosting and user authentication. DPA available at supabase.com/privacy.
  • Stripe, Inc.: payment processing. Stripe is an independent data controller for card data. DPA and privacy policy at stripe.com/privacy.
  • Resend, Inc.: transactional email delivery. DPA available at resend.com/privacy.
  • Google LLC: if you choose to sign in with Google, Google authenticates you and shares your email address and basic profile information with us. This occurs only when you use the "Sign in with Google" option. Google's handling of your data is governed by its privacy policy at policies.google.com/privacy.

Discord is an independent platform that you may choose to use to contact our support team. Discord is not our data processor; any information you share via Discord is governed by Discord's own privacy policy at discord.com/privacy.

We are not responsible for the privacy practices of these independent third parties.

8. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you.
  • Receive a copy of your data in a portable, machine-readable format (data portability).
  • Request correction of inaccurate data.
  • Request deletion of your account and associated data (right to erasure).
  • Object to or restrict certain processing activities.

You can exercise the access, portability, and erasure rights directly and immediately from your Account Settings page: use Download my data to export a copy of your information, and Delete account to erase your account. For any other request, or if you are unable to access your account, contact us at privacy@mail.climbify.gg or via our Discord server, and we will respond within 30 days.

9. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you specific rights regarding your personal information.

Categories we collect: identifiers (email address, username, IP address), commercial information (order and purchase history), and internet activity (standard server logs). We collect these directly from you and from your use of the Service, for the purposes described in Section 3.

We do not sell or share your personal information as those terms are defined under the CCPA/CPRA, including for cross-context behavioral advertising. Because we do not sell or share, no "Do Not Sell or Share My Personal Information" action is required; however, you may still contact us to confirm this.

You have the right to know what personal information we collect, to access and delete it, to correct inaccurate information, and to not be discriminated against for exercising these rights. Exercise these rights from your Account Settings page or by contacting privacy@mail.climbify.gg.

10. Data Retention

We retain account and order data for as long as your account is active or as required to resolve disputes and fulfil legal obligations. If you delete your account, your personal data is anonymised or removed from our systems within 90 days, except for records required for financial compliance, which are retained for up to 7 years. Game account credentials provided for Piloted orders are deleted automatically when the order is completed, refunded, or cancelled.

11. Children

The Service is not directed at persons under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, please contact us immediately.

12. Limitation of Liability

To the maximum extent permitted by applicable law, Climbify's liability for any privacy-related claim is limited to the amount paid by you for the specific order in question during the 12 months preceding the claim. We are not liable for indirect, consequential, or incidental damages arising from our processing of your data.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page. Your continued use of the Service after any changes constitutes your acceptance of the revised policy. We encourage you to review this page periodically.

14. Data Controller

The data controller responsible for your personal data is:

Swift Studios s. r. o.
Palkovičova 226/1
821 08 Bratislava – mestská časť Ružinov
Slovak Republic
IČO: 56 315 864

For all data protection requests (including access, correction, deletion, and objection), contact our data protection point of contact at privacy@mail.climbify.gg. We will respond within 30 days as required by GDPR Art. 12.

You also have the right to lodge a complaint with the supervisory authority in your EEA member state. The Slovak supervisory authority is the Office for Personal Data Protection of the Slovak Republic.

15. Contact

For general privacy questions, contact us at privacy@mail.climbify.gg or via our Discord server at discord.gg/RUa28jvMTH.