Legal

Privacy Policy

Last updated:  ·  Effective: April 1, 2026

Overview

Sudak Customs (“we”, “us”, “our”) is committed to protecting your personal data. This Privacy Policy explains what information we collect, why we collect it, and how we use it in accordance with the General Data Protection Regulation (GDPR) and applicable privacy laws.

By using our website at sudakcustoms.xyz and related services, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of our services.

Data We Collect

Information You Provide

  • Account data: Username, email address, and password when you register.
  • Contact submissions: Name, email, and message content when you use our contact form.
  • Purchase data: Transaction records, product selections, and payment confirmation (payment processing handled by SellAuth; we do not store card data).

Information Collected Automatically

  • Log data: IP address, browser type, operating system, referring URLs, and pages visited.
  • Cookies and tracking: Session cookies required for site functionality and optional analytics cookies (see Cookies section).
  • Device information: Screen resolution, device type, and browser version for rendering optimisation.

How We Use Your Data

We process your personal data only where we have a lawful basis to do so. The purposes include:

  • Providing and maintaining our tournament platform and services.
  • Processing and fulfilling your purchases and product orders.
  • Sending transactional emails (order confirmations, support replies).
  • Displaying personalised scoreboard results tied to your account.
  • Improving site performance and user experience through aggregate analytics.
  • Complying with legal obligations and resolving disputes.

We do not sell your personal data to third parties. We do not use your data for automated profiling that produces legal or similarly significant effects.

Data Sharing & Third Parties

We share minimal data only with trusted service providers necessary to operate our platform:

  • SellAuth - payment processing for product purchases.
  • Hosting provider - server infrastructure to run the website.
  • Analytics provider - aggregate, anonymised usage statistics only.

All third-party processors are contractually bound to process data only as instructed by us and in compliance with GDPR.

Cookies

We use cookies to ensure essential site functionality. For detailed information, see our Cookie Policy.

  • Essential cookies: Session management, theme preference, and security tokens. These cannot be disabled without affecting site functionality.
  • Analytics cookies: Optional. Used to understand aggregate traffic patterns. You may opt out at any time.

Your Rights (GDPR)

Under GDPR and applicable data protection law, you have the following rights:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request correction of inaccurate or incomplete data.
  • Right to erasure: Request deletion of your personal data (“right to be forgotten”).
  • Right to restriction: Request that we restrict processing of your data.
  • Right to portability: Receive your data in a structured, machine-readable format.
  • Right to object: Object to processing based on legitimate interests.
  • Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes described in this policy:

  • Account data: Retained for the duration of your account plus 2 years after closure.
  • Purchase records: Retained for 7 years for legal and accounting compliance.
  • Contact form submissions: Retained for 12 months.
  • Server logs: Retained for 90 days.

Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include HTTPS encryption, password hashing, and restricted database access.

While we strive to use commercially acceptable means to protect your data, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.

Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of significant changes by posting the new policy on this page and updating the “Last updated” date. Continued use of our services after changes constitutes acceptance of the updated policy.

Contact & Data Controller

Data Controller: Sudak Customs
Email: [email protected]
Website: sudakcustoms.xyz

If you believe we have not addressed your concern adequately, you have the right to lodge a complaint with your national data protection authority.