← Back to Deadline Day

Privacy Policy — Deadline Day

Last updated: 3 October 2026

Deadline Day is a football auction game you play live with friends. We built it to work without accounts, without ads and without tracking. This policy explains the small amount of data the game needs to run, and what happens to it.

1. Who is responsible

The data controller is:

AddonNordic ApS Solvangen 15, 9210 Aalborg SØ, Denmark CVR (company no.) 46495985 Email: contact@addonnordic.dk

We have not appointed a Data Protection Officer, because the law does not require one for a service like ours. Please write to the email above with any privacy question.

2. The short version

3. What we process, why, and on what legal basis

Data Where it comes from Why we need it Legal basis (GDPR) How long we keep it
Team name (max. 20 characters) You type it We show it to the other players in your room during the game and on the result screen Art. 6(1)(b) — needed to provide the game you asked to play In server memory until the room is deleted (max. 6 hours after last activity)
Game data: room code, your bids, squad, line-up, ready status, results, and the "roast" lines generated from your bids Created while you play To run the auction, simulate the season and show results Art. 6(1)(b) Same as above (max. 6 hours)
Random game identifiers: a player ID and a secret session token Created by our server So you can rejoin your room if your connection drops Art. 6(1)(b) On our server: max. 6 hours. On your device: see section 4
Technical connection data: IP address, browser/device user-agent, time and path of the request Sent automatically by your device when it connects To deliver the game over the internet, keep the service secure and stable, and fix errors Art. 6(1)(f) — our legitimate interest in running a secure, working service In our hosting provider's request logs for up to 30 days (see section 5). We do not use your IP address to locate you or to identify you
Purchase information: that a Host Pass is paid, and a random purchase reference (the checkout reference on the website, or a random purchase ID in the apps) Stripe (website) or Apple/Google (apps), after you buy To unlock what you bought and to restore it on a new device; the reference is also stored on your device Art. 6(1)(b), and Art. 6(1)(c) for bookkeeping obligations As long as you use the purchase, and bookkeeping records for 5 years as required by Danish law
Restore details: the email from your receipt and the last 4 digits of your card, if you use "Restore" You type them To find your Host Pass at Stripe and put it back on your device Art. 6(1)(b) Not stored. They are sent to Stripe for the lookup and then discarded

We do not use any of this data for automated decisions that have legal or similarly significant effects on you, and we do not build profiles of you.

4. What is stored on your own device

The app saves a few small values in your device's local storage so the game works smoothly:

These values stay on your device. We cannot read them except when your device sends the session token to rejoin a room, or the Host Pass reference when you create a room. You can delete them at any time by clearing the app's data or the website data in your browser, or by uninstalling the app. These are strictly necessary for the service you asked for, so we do not ask for separate consent.

5. Who else receives data (processors and other recipients)

Recipient Role What they get Where
Railway Corporation (railway.com) Hosting provider (processor under a Data Processing Agreement) Everything our server processes (sections 3 and 4), and request logs with IP address and user-agent Our server runs in Railway's EU West region (Amsterdam, the Netherlands). Railway is a US company. Any transfer outside the EU/EEA, for example for support or log access, is covered by the EU–US Data Privacy Framework or the EU Standard Contractual Clauses, as set out in Railway's DPA
Stripe (Stripe Payments Europe, Limited, Ireland, and its affiliates) Merchant of record and independent controller for Host Pass purchases on the website Stripe collects your email, payment and billing details at checkout, handles VAT, receipts, refunds and fraud checks. We never see your card or payment details; we only receive confirmation that the purchase is paid. Stripe processes your data under its own privacy policy EU, with transfers under Stripe's safeguards
Apple (App Store) and Google (Google Play) Independent controllers for app downloads and in-app purchases Apple and Google handle payment, billing and refunds. We never see your card or payment details. They process your data under their own privacy policies See Apple's and Google's privacy policies
RevenueCat, Inc. (revenuecat.com) — apps only Processor that checks in-app purchases for us The random purchase ID from the app, the store receipt for your Host Pass, and basic technical data (IP address, device model, operating system and app version). We use it only to confirm that a Host Pass is paid and to restore it United States. Transfers are covered by the EU Standard Contractual Clauses in RevenueCat's Data Processing Addendum
Other players in your room — Your team name, your bids, your squad and your results —

When you tap "Invite friends" or "Share my card", your device's share menu opens. What you share, and with whom, is your choice. It is sent by the app or service you pick, not by us.

Our sound effects were generated in advance with an AI audio tool. The files are delivered with the game. No data about you is sent to that provider.

We do not otherwise disclose personal data, except where the law requires us to.

6. Our website

If you visit our website, we may measure visits with Plausible Analytics. Plausible is a privacy-friendly analytics tool from the EU. It does not use cookies and does not store IP addresses. It counts visits using a daily identifier that is deleted every 24 hours, so you cannot be tracked across days or across websites. Besides page visits we count a few anonymous events in the browser version of the game: a game was created or joined (with the sport and game mode), a result was shared, and a Host Pass checkout was started or completed. These events contain no names, room codes or payment details. We use it only for aggregated statistics, such as how many people visited a page or started a game. The legal basis is our legitimate interest in understanding how the site is used (Art. 6(1)(f)). The provider is Plausible Insights OÜ (Estonia, EU), which processes the data on our behalf in the EU. The mobile apps contain no analytics.

Some pages on our website show a short video from our YouTube channel. Nothing is loaded from YouTube until you press play: the preview image is stored on our own server. When you press play, the video loads from YouTube (Google Ireland Limited) in its privacy-enhanced mode (youtube-nocookie.com), and YouTube then receives your IP address and technical data about your device under Google's privacy policy. We count the play as an anonymous event in Plausible. The mobile apps show no videos.

In Song contest, Views and Funny, the host can turn on "With songs" or "Watch videos" or "Watch shorts". It is off by default. When it is on, the YouTube videos (in Song contest: the official performances from the Eurovision Song Contest YouTube channel) play on the screen that plays the music (the TV, or the host's phone when there is no TV), in YouTube's privacy-enhanced mode (youtube-nocookie.com). YouTube (Google Ireland Limited) then receives that device's IP address and technical data under Google's privacy policy. The other phones, the stream view and the mobile apps load nothing from YouTube.

7. Children

Deadline Day is not directed at children under 13, and it is not listed in any "kids" category. We do not knowingly collect personal data from children. We do not ask for age, and the game needs no personal information beyond a nickname-style team name. We recommend using a nickname, not your real name. Players under the digital age of consent in their country (for example 15 in Denmark or 16 in Germany) should have a parent's or guardian's permission before making any in-app purchase. Apple's and Google's family settings, such as Ask to Buy, can require parental approval. If you believe a child has given us personal data, contact us and we will delete it.

8. Your rights

Under the GDPR you have the right to:

We keep game data only for a few hours and hold no account, so in most cases the fastest way to erase it is to leave the game and wait: the room is deleted automatically within 6 hours. To help us find the right data if you contact us, please include your room code and team name. We answer within one month.

9. Complaints

You can complain to the Danish Data Protection Agency:

Datatilsynet Carl Jacobsens Vej 35, 2500 Valby, Denmark dt@datatilsynet.dk · +45 33 19 32 00 · www.datatilsynet.dk

If you live in another EU/EEA country, you can also complain to the data protection authority there. We would appreciate the chance to fix the problem first, so please write to contact@addonnordic.dk.

10. Security

All traffic between the app and our server is encrypted with HTTPS/TLS. Rooms are protected by a random code, and your session token is a random secret that only your device holds. Game data is kept in memory only and is deleted automatically.

11. Changes

If we change how we handle data, we will update this page and change the date at the top. We will announce significant changes in the app. One example would be adding user accounts.