RL Portal · Legal information

Privacy policy

Last updated: 1 October 2026

This policy explains how the RL Portal website and its connected API handle personal information. The project is privately operated, rather than run as a registered business. Being a personal project does not remove your privacy rights.

1. Who is responsible

RL Portal is a personal community project operated from the Netherlands by its private operator. Contact: rlportal.contact@gmail.com.

The operator is responsible for the processing described here. This policy covers website features, profile verification, and information supplied through the connected RL Portal services. It does not replace the privacy policies of Discord, game platforms, external websites, or separate desktop software.

2. Information we use and where it comes from

  • Player information: player names, platform account identifiers, Rocket League ranks, statistics, rank history, and information needed to maintain player profiles and leaderboards. Information can be obtained from game/platform services, the RL Portal API, and player searches, including searches made by someone other than the player.
  • Discord login: your Discord account ID, username, display name, and avatar. Login requests Discord's identity permission. The website does not request your Discord password or your email address through that login permission.
  • Profiles and verification: your chosen biography and social links, the connection between your Discord identity and player profile, verification status, timestamps, and the one-time party verification command. The verification process uses friend/party information to check control of the requested game account.
  • Technical information: IP addresses, browser/request information, security and rate-limit records, and information needed to diagnose errors. Hosting infrastructure can also generate access and error logs.
  • Optional analytics: a browser identifier, session identifiers, pages and query strings visited, referring page, page title, time spent, and player-search information such as the query, player ID, and success of the search. Request-derived identifiers may be hashed; this does not necessarily make the information anonymous.

A public player name or account ID can still be personal information. Do not enter passwords, payment information, or private information about other people into profile fields.

3. Why we use information

We use player and technical information to provide searches, profiles, leaderboards, login, account verification, security, abuse prevention, and support. Our legal basis for these core operations is our legitimate interest in operating and protecting the community service, balanced against the rights of the people concerned. You can object to processing based on legitimate interests.

Optional usage analytics relies on your consent. Publishing a biography or social links is voluntary: saving those fields publishes them, and you can clear them again. The account-claim process links your Discord identity to the player profile so ownership can be shown. Requests to remove that association can be made to the operator.

Information may also be used where necessary to comply with a legal obligation or establish, exercise, or defend a legal claim. We do not sell personal information or use this website to serve AdSense advertisements.

4. Public profiles, recipients, and external services

Player information, verified profile associations, published biographies, and social links may be visible to other visitors, search engines, and users of connected RL Portal features such as Discord cards. A biography or social link is not a private message. Other people may copy public information, and external search caches may take time to update after a removal.

Information needed to run the service is processed through the connected API, database/storage infrastructure, and hosting providers. Discord receives information needed for Discord login and verification integrations. Third-party images or external links can cause your browser to contact their providers, which receive normal request information such as your IP address.

Discord and other external providers have their own privacy practices and may process information outside the European Economic Area. See Discord's privacy policy. Contact the operator for information about RL Portal's hosting arrangements, recipients, and any applicable international-transfer safeguards.

5. Cookies, browser storage, and your choices

Your privacy choices

Optional first-party analytics measures visits and searches using a browser ID. It stays off unless you allow it.

Checking preferences…

Necessary storage supports login, security, the privacy choice you make, and requested website settings. Optional analytics is off until you select “Allow analytics”. Refusing it does not prevent player searches, login, or profile features. You can withdraw consent here at any time; withdrawal stops new analytics events and removes the optional browser identifier from this browser.

Storage used by the website
StoragePurposeDuration
rlp_sessionDiscord login sessionUp to 30 days; cleared on logout
rlp_oauth_stateSecure login handoffUp to 10 minutes; consumed during login
rlp_analytics_consentRemember your analytics choiceUp to 180 days
rlp:visitor-id:v1Optional first-party analytics identifierUntil you withdraw consent or clear browser storage; not used without consent
Recent searches and OBS settingsRemember recent searches and overlay preferences locallyUntil you clear browser storage or change settings
rlp_obs_* cookiesRank-widget session and MMR changesUp to 6 hours

Browser settings can clear or block storage. Blocking necessary session cookies may prevent login. Analytics consent is separate from accepting the terms of use.

6. How long information is kept

Login and browser-storage periods are listed above. Analytics records use a rolling 14-day window and a limit of 8,000 events: old records are pruned when new analytics events are recorded. If no new events are received, records can remain until the next pruning operation or a deletion request.

Player records, rank history, profile associations, and submitted profile information do not currently have a fixed automatic deletion period. Retention is reviewed against the purpose of maintaining those features and any valid objection or deletion request. Verification commands have a short expiry, normally 10 minutes; expiry does not itself guarantee deletion of the corresponding verification record.

Security logs, support records, and backups follow the retention arrangements of the infrastructure used and any need to investigate abuse or meet legal obligations. Ask the operator for the current schedule. Deleting active records may not immediately remove a backup copy; any retained copy remains subject to your rights and applicable retention requirements.

7. Your rights and privacy requests

Depending on the processing and applicable exceptions, you can request access, correction, deletion, restriction, or a portable copy of your information, and object to processing based on legitimate interests. You can withdraw consent without affecting processing that was lawful before withdrawal. These rights also apply if your player information was obtained from another source rather than directly from you.

Contact the operator using the details above. Identify the player profile or Discord account involved and explain the request. We may ask for proportionate evidence that the information concerns you; do not send passwords or identity documents unless specifically needed and arranged through an appropriate channel. We normally respond within one month. Where a lawful extension is needed for a complex request, we explain it within that first month.

You can edit or clear your biography and social links through the profile editor. Logout clears the website session cookie; it does not by itself delete your stored profile or Discord association. Ask the operator to review deletion or unlinking of those records.

You may complain to the Dutch Autoriteit Persoonsgegevens or another competent supervisory authority.

8. Changes to this policy

We update this page when relevant features or processing arrangements change and show the update date above. A new purpose that requires consent will not be enabled on the basis of an unrelated earlier choice.