Privacy Policy
What we collect, why we need it, and where it goes.
Last updated 27 August 2026
1. Controller
MVP Royale is operated by ФОП Шевченко Дмитро Юрійович, registered in Ukraine, at the public service address 1 Davida Oistrakha Street, Odesa, Odesa Oblast 65000, Ukraine. The operator is responsible for the personal data described in this policy. You can reach the privacy contact at privacy@mvproyale.com or support at support@mvproyale.com.
Privacy rights and formal notices are handled under the mandatory data-protection rules that apply to you. Contact the published privacy address above for a request or complaint.
2. Data we collect
- Account: name, email, avatar, connected-account identifier, sign-in time and security records supplied by Google or GitHub. Our service also receives the network address and browser information that accompany a request.
- Products: submitted URL, ownership evidence, public page text, logo, desktop and mobile captures, review results, AI-assisted drafts, corrections, publication status and versions.
- Arena: assigned matchup, choice, reason, timing, essential session identifier, security signals and whether the answer was accepted.
- Usage and security: request metadata, errors, rate-limit events, aggregate activity and evidence needed to detect bots, abuse or coordinated voting. Product measurement may include country, device and browser categories, landing page, traffic type and referring domain. It does not keep a full referring URL or full user agent. Approximate daily visitor counts use a product-specific value that changes each day; the raw network address is not stored in product analytics.
- Payments: Creem customer, checkout, order, invoice, refund and dispute identifiers and status. Creem receives payment details directly; we do not store full card numbers.
3. Why we use it
We process account and order data to perform our contract; security, moderation, service measurement and fair matching for our legitimate interests; payment and compliance records for legal duties; and optional communications only with consent where required.
4. Public and private data
Published product profiles, page captures, aggregate findings, accepted totals, rankings and version summaries are public. Account email, sign-in credentials, raw security evidence, rejected answers, review notes and payment identifiers are not public. We do not publish a voter’s identity with an answer.
5. Service providers
- Cloudflare: hosting, storage, AI-assisted analysis, browser capture, traffic security and delivery.
- Google and GitHub: account sign-in when you choose that provider.
- Creem: Merchant of Record and contractual reseller for checkout, tax, invoicing, refunds and payment support. Creem processes information it receives directly under its Privacy Notice; MVP Royale remains responsible for its application-side order and fulfilment records. The privacy role therefore depends on the processing activity.
These providers may process data outside your country under their own safeguards. We do not sell personal data or share it for behavioural advertising.
6. AI and automated checks
Public product-page material and captures may be processed by AI tools to draft descriptions and identify potential clarity, usability, accessibility and mobile issues. Outputs are subject to quality and safety checks and, where required, manual review. Account credentials and payment details are not included in this processing.
7. Cookies
MVP Royale does not use cookies or similar browser storage for analytics or advertising. We use only browser storage that is strictly necessary for account sign-in, security and keeping an arena round tied to the browser that opened it. The arena record lasts only for the browser session and is not used for analytics. Our security provider may process browser and interaction signals to distinguish people from abusive automation.
Measurement stays on MVP Royale. We do not append a visitor identifier to outbound links, combine activity across customer websites or build an advertising profile. Referrers are reduced to a source group and domain, without their path or query. Global Privacy Control and Do Not Track disable optional page, click and live-presence measurement in browsers that send those signals.
8. Retention
Account and product data is kept while the service is provided or until it is no longer needed. Temporary sign-in and live-activity records expire after short security or session periods. Minimized analytics events are normally deleted after 30 days, security logs after up to 90 days and rejected feedback evidence after up to 180 days. Public reports and accepted aggregate findings may remain while a profile is public. Payment, tax, dispute and legal records are kept for the period required by law. Backups expire on their normal cycle.
9. Your rights
Depending on your location, you may ask for access, correction, deletion, restriction, portability or object to processing, and may complain to your data-protection authority. We may need to verify your identity and may retain records the law requires.
10. Security and contact
We use encrypted transport, access controls, rate limits, security checks and audit records. No system is perfectly secure. For privacy and incident reports, email privacy@mvproyale.com.