Privacy Policy
Last updated: 2 September 2026
Data we collect
- Account: email, username, hashed password, optional display name / bio / avatar / banner.
- Streaming: camera video, screen capture, microphone and internal device audio when you choose to broadcast, plus RTMP stream metadata, peak viewer counts, category, and tags. Stream recording (VOD) is optional per channel.
- Chat: messages you send (retained for history + moderation).
- Optional PS5 Twitch chat sync: your Twitch user id and login, plus encrypted OAuth access and refresh tokens limited to reading and sending chat. Tokens are revoked and deleted when you disconnect the feature or lose VPZ+.
- Optional YouTube multistream: if you choose to relay your VPZONE broadcast to your own YouTube channel, we request one-time access to your YouTube live streaming settings to obtain your own live stream's RTMP ingest address and stream key. The access token is revoked immediately after that single operation and no refresh token is ever stored. See YouTube API Services below.
- Mobile notifications and activity: Expo push token, channels watched, follows, likes, moderation actions, and an approximate country inferred from network information for live-service operation, analytics, and abuse prevention.
- Billing: handled by Stripe — we receive the subscription status, tier, and transaction timestamps but never your card details.
- Pixels & cases: your Pixels balance, purchase and transfer ledger, and case openings. Note that case openings are public (your username, the item won, and its tier can be shown in chat and on the channel page).
- Creator payouts: if you monetize, Stripe Connect onboarding status and payout amounts (identity verification is done by Stripe; we never see your documents).
- Account deletion proof: when you delete your account, we permanently keep a signed consent record (IP address, timestamp, HMAC signature) as legal proof the deletion was authorized — see the Terms for details.
- Technical: IP address, user agent, request logs (retention: 30 days) for fraud prevention.
How we use it
- Provide the service (authenticate, stream, chat, pay creators).
- Moderate abuse (chat bans, account investigations).
- Send transactional emails (signup confirmation, billing receipts, tier changes). No marketing emails unless you opt in.
- Aggregate analytics (no individual tracking beyond your own channel).
Third parties
- Supabase — database and authentication hosted in the Canada (Central) region.
- Stripe — payment processing and creator payouts (PCI-compliant; card data never touches our servers).
- Dedicated servers — the web application and chat server are self-hosted on dedicated infrastructure in Canada; streaming origin and edge servers are located in North America and France.
- Cloudflare — DNS, web proxy, and Turnstile bot protection on signup/login (sees your IP and browser characteristics for those requests).
- Google AdSense — advertising shown only to visitors who are not VPZONE+ members, Founders or guest-pass holders (receives your IP and browser characteristics to serve and measure ads; in the EEA, UK and Switzerland nothing loads until you consent through the dialog, which you can reopen to change or withdraw your choice).
- Resend — transactional email delivery (receipts, notifications; receives your email address and the message content).
- Discord — optional account linking for badge/role sync (only if you connect it; we store your Discord user id).
- Twitch — optional native PS5 streaming and bidirectional chat sync (only if you authorize it; chat messages are transmitted between Twitch and VPZONE).
- YouTube / Google (YouTube API Services) — optional relay of your broadcast to your own YouTube channel (only if you connect it). Detailed in the YouTube API Services section below.
- TikTok — optional clip export to your TikTok drafts (only if you connect it; the clip video is transmitted to TikTok).
- IGDB — game metadata (queries anonymized).
- OpenAI — optional AI-assisted metadata generation (your stream title or description is sent only when you request suggestions; API inputs and outputs are not used for model training by default and abuse-monitoring data can be retained for up to 30 days under OpenAI's API data policy).
YouTube API Services
VPZONE's optional "multistream to YouTube" feature uses YouTube API Services. By connecting your YouTube account to VPZONE, you agree to be bound by the YouTube Terms of Service. Google's handling of any data it receives is governed by the Google Privacy Policy.
What we access.Only when you click "Connect with YouTube", and only with your explicit consent, we request the youtube.force-ssl scope and call exactly two endpoints once: liveStreams.list to read your own persistent live stream's RTMP ingest address and stream key, and — only if your channel has no persistent live stream yet — liveStreams.insert to create one for you. We also read the email address of the Google account you connect, so we can show you which account is linked.
How we use it. The ingest address and stream key are used for one purpose only: to relay the broadcast you start on VPZONE to your own YouTube channel, at your request. We do not use this data for advertising, we do not sell or share it, and no human at VPZONE reads it except where strictly necessary to resolve a support issue you raise, to comply with the law, or to investigate abuse.
What we never do. We never read, upload, edit, publish or delete your YouTube videos, comments, captions, playlists or subscriber data, and we never post anything to your channel. The feature is limited strictly to obtaining your own live stream ingest credentials.
Storage and retention. Authorization is one-shot: we request an online-only access token, revoke it as soon as the two calls above complete, and never request or store a refresh token. The stream key is encrypted at rest and is deleted when you remove the YouTube destination or delete your account.
Revoking access.You can remove the YouTube destination at any time from Dashboard → Stream. You can also review and revoke VPZONE's access to your Google account directly at myaccount.google.com/permissions.
Your rights (GDPR / CCPA)
You can:
- Access & export your data — from Settings → Privacy.
- Correct errors — edit your profile directly.
- Delete your account — Settings → Privacy → Delete account (14-day grace period).
- Opt out of tracking cookies — see the Cookies page.
- Object to processing — contact us.
Retention
Account data is kept as long as your account exists. Chat messages: 30 days. Billing records: 7 years for tax and accounting purposes. After the 14-day deletion grace period, profile and service data is purged or anonymized, except records retained for legal, tax, accounting, fraud-prevention, security, dispute, or deletion-consent evidence purposes.
Stream recordings (VODs): recording is opt-in per channel (Dashboard → Stream settings → Record stream). When a creator opts in, finished streams are kept for 72 hours for general users and 7 days for VPZONE+ subscribers, after which the file is automatically purged. Creators can also delete a VOD on demand from their dashboard.
Security
Web, API, authentication, chat, and playback traffic use encrypted HTTPS/WSS connections. Mobile live ingest currently uses RTMP transport and is not TLS-encrypted; do not broadcast sensitive content. Passwords are securely hashed by our authentication provider. Stream keys are restricted to the creator and our ingest infrastructure, and we use Row-Level Security on our database.
Children
VPZONE is not directed at children under 13. If you believe a child has created an account, contact us and we'll delete it.
Loi 25 — Quebec Privacy Act
In accordance with Quebec's Loi modernisant des dispositions législatives en matière de protection des renseignements personnels (Loi 25), VPZONE has designated a person responsible for the protection of personal information:
- You may submit a request to access, correct, or delete your personal information by contacting the person designated above.
- We will respond within 30 days of receiving your request.
- If you are unsatisfied with our response, you may file a complaint with the Commission d'accès à l'information du Québec (CAI).
Contact
Data-protection requests: info@technoredac.ca