Last reviewed:
1. Scope and data
This policy covers the Avoid guild portal, EU Sanguino. Public browsing does not require an account. The portal displays character names, realms, classes and statistics from Battle.net, Raider.IO and Warcraft Logs. Game data may be linked to an individual.
Member access uses Battle.net to verify which account characters belong to the guild. Administration uses Clerk and, if selected, Google or GitHub. Clerk manages account identifiers, email addresses, basic profile data supplied by the provider and sessions. The portal does not receive your Google, GitHub or Battle.net password.
2. Purposes and legal bases
Account and session data provide the access you request and enforce permissions. Character statistics describe guild activity. Security, access protection and technical operation serve the legitimate interest of keeping the portal secure; community information serves the legitimate interest of organising and reporting its activity. You may object where applicable.
Authorising an OAuth provider permits access to authorised data, not advertising or unrelated uses. Optional processing requiring consent must have a specific, revocable choice. Displayed game scores do not produce solely automated decisions with legal effects.
3. Google, GitHub and Battle.net
Google and GitHub authenticate authorised administration users. Received data identifies the account and manages access; it is not sold or used for advertising. Signing in does not provide this portal with access to Gmail messages, Drive files or private GitHub repositories.
Battle.net provides account characters for comparison with the guild roster. Its access token is used on the server during verification and is not included in the member cookie. You can revoke access in each provider's settings; this does not automatically delete an existing Clerk account or public game-source data.
4. Cookies and embedded videos
The technical avoid-guild-member cookie stores a signed session with identifiers, names and realms for up to 20 characters for a maximum of 12 hours. The avoid-bnet-oauth-state and avoid-bnet-return-to cookies protect OAuth and preserve the return path for up to 10 minutes; they are removed when the callback completes. These session cookies are not advertising mechanisms.
The avoid-guild-character cookie stores only the selected character identifier for up to 30 days in this browser, to restore the selection on the next sign-in. Choosing a character or completing sign-in updates it; signing out preserves it without extending access. Account ownership and guild membership are verified again before restoration. Delete the site cookies to remove this preference.
Clerk and identity providers may use their own authentication and security cookies. You can manage cookies in your browser, but blocking necessary cookies may prevent access.
Guide videos remain blocked until you agree to load each video. No remote YouTube thumbnails load before that choice. Accepting loads a youtube-nocookie.com player: Google may receive your IP address and browser data and use its own cookies or storage. You can read without accepting and withdraw permission using the close button. The choice is not saved in cookies or local storage and is lost when the player is unmounted or the page reloads. Closing stops the player but does not erase data already received by Google or its storage; manage those through your browser and Google controls. Privacy-enhanced mode does not guarantee absence of data processing.
5. Providers and recipients
Vercel hosts the portal, and Clerk manages administrative authentication. GitHub stores editorial content and version history. Battle.net, Raider.IO, Warcraft Logs and WoWAudit supply game data for the relevant sections; private member data is displayed according to portal access controls.
Authorised personnel may access information needed to manage the community. Identity and video providers process data within their own services under their policies. Processing may take place outside the European Economic Area. Published Clerk and Vercel data processing agreements address applicable transfer safeguards: Clerk describes the EU-US Data Privacy Framework and Vercel incorporates standard contractual clauses where applicable. You may request information or a copy of applicable safeguards from the controller, excluding confidential third-party information.
6. Retention
Battle.net sessions have the lifetimes stated in the cookies section. Administrative accounts remain while editor access is needed. The controller manually deletes accounts in Clerk when access is no longer needed or the user requests erasure, except for legal obligations or justified limited retention of specific data.
Cache refresh intervals are 30 minutes for recent logs, 1 hour for Mythic+ and content, 6 hours for the roster and 12 hours for raid progress. These are refresh intervals, not guaranteed deletion deadlines: earlier responses may remain during revalidation or provider failures. Historical activity and GitHub editorial versions may remain while relevant to the community and content recovery. Erasure requests also cover versions and copies controlled by the controller; deleting a session alone is insufficient.
Technical log availability depends on the service and plan: Hobby documentation specifies 1 hour for Vercel runtime logs and 1 day for Clerk application logs. These periods do not describe all backups or providers' own legally required processing. The controller does not extend retention by default through a portal log database. Privacy messages remain during request handling and, where necessary, to demonstrate the response or address obligations and claims. Deleting local data does not automatically delete game-source data.
7. Rights and contact
Use the controller's contact at the end of this policy to request access, correction, erasure, restriction, portability where applicable or to object. Consent may be withdrawn without affecting earlier lawful processing. Do not send identity documents pre-emptively; proportionate verification will only be requested if needed.
You can complain to the competent data protection authority, including the Spanish Data Protection Agency at www.aepd.es. Requests concerning original provider data may also require contacting that service.
8. Changes
The review date identifies this version. Material changes to purposes or data use will be communicated appropriately. Publishing an updated policy does not replace consent where required.