베타 페이지로 돌아가기

Privacy policy

Last updated: 12 August 2026

This policy describes personal data processing by Crossup for the public teaser and closed-beta application form (J0 launch). It reflects the current repository behaviour, not future product features.

1. Data controller

The data controller is Tolotra Rakotomalala, sole trader / individual entrepreneur, publisher of Crossup.

Privacy / data-rights contact: contact@crossup.gg.

2. J0 scope

This policy mainly covers: the public landing page, the beta application form, cookies/storage strictly needed for the public site, and authentication infrastructure if you choose to sign in (for example to redeem an invite code).

It does not describe the full authenticated closed-beta product (profiles, feed, etc.), which will be covered in later updates when those features open.

3. Data collected via the application form

When you submit an application, Crossup stores:

  • email (required)
  • displayName / public name (required)
  • primaryRole (required)
  • mainGames (required, 1–5)
  • motivation / free text (optional)
  • optional Start.gg, Twitch, X (Twitter), YouTube URLs
  • optional Discord handle (free text)
  • optional countryCode
  • locale (UI language at submission time)
  • timestamps (created/updated, technical consentAt, admin review when applicable)
  • application status and internal review metadata (not public)

4. Purposes

Application data is processed to:

  • receive and store closed-beta applications
  • review and select applicants
  • communicate about applications (for example selection or access instructions)
  • issue and manage beta invitations
  • prevent duplicate or abusive submissions
  • ensure security and operation of the service

5. What Crossup does not do (current implementation)

Based on the current implementation, Crossup does not claim or use applications for:

  • promotional marketing outside the application / invitation workflow
  • advertising profiling
  • sale of applicant data
  • automated transactional invitation emails (when instructions are sent, delivery is operated manually; there is no dedicated mailer in the repository)

6. Legal basis

Processing of applications is based on Crossup’s legitimate interest in organising a closed beta and managing access requests (GDPR Art. 6(1)(f)), and on steps at your request prior to entering a contract when you submit an application (Art. 6(1)(b)).

Contact about your application is part of the application workflow; it is not presented as a separate marketing consent.

7. Recipients and access

Applications are not published. Access is limited to authorised Crossup staff (admin / moderator) via internal administration tools.

Technical processors may process data for hosting and operations (PostgreSQL, Next.js / Nest application stack, Redis where used, Keycloak identity provider if you authenticate). Hosting identity details appear in the Legal notice when completed.

8. Retention (J0 policy)

Internal Crossup policy (organisational choices, not fixed statutory durations):

PENDING, APPROVED or INVITED applications: retained for a maximum of 12 months from application, unless a shorter operational period applies.

REJECTED applications: retained for a maximum of 6 months after rejection.

Related invite codes may be revoked; technical retention follows beta security and audit needs.

You may request erasure via the contact below; requests are handled manually under an internal procedure.

9. Your rights

Under the GDPR you may request access, rectification, erasure, restriction, and object to processing on grounds relating to your particular situation, under the conditions set by law.

To exercise rights about beta applications: email contact@crossup.gg and include the email address used in the form. We may ask for reasonable information to verify your identity and the scope of the request.

You also have the right to lodge a complaint with the CNIL (French data protection authority — https://www.cnil.fr).

10. Cookies and local storage (current state)

Crossup does not use a cookie banner or third-party advertising analytics SDKs (Google Analytics, Meta Pixel, Hotjar, PostHog, etc.) for the J0 teaser.

First-party launch funnel measurement: Crossup records aggregable technical events (landing view, apply CTA, form start/success/error) with no analytics cookie, no identifier in localStorage/sessionStorage, no account link, and no IP or raw User-Agent in that model. An ephemeral in-memory journey id lasts for the page lifecycle only. Allowed UTM parameters and referrer hostname only. Indicative raw retention: 90 days.

The following may also be used:

  • NEXT_LOCALE cookie — language preference
  • Auth.js / session cookies — only if you sign in (authentication / security); may hold session tokens server-side
  • Keycloak identity-provider cookies — on the Keycloak host during sign-in
  • localStorage / sessionStorage for technical preferences (e.g. marquee speed, cached regions) — not advertising identifiers or analytics journey ids
  • Possible third-party font or CDN requests depending on front-end configuration (see cookies/storage documentation); primary layout fonts are delivered via next/font (build-time self-hosting)

11. Transfers

Depending on the host and services used in production, processing may occur in the EU or outside the EU. Where non-EU providers are used, Crossup relies on appropriate mechanisms (e.g. standard contractual clauses) according to the production setup. Hosting details will be completed in the Legal notice.

12. Updates

This policy may be updated as the product evolves (for example when authenticated beta features open). The last-updated date appears at the top of this page. For material changes, Crossup may adapt the information on the public site.

crossup·v1.0.105