1. Introduction
Al Fhoud Guild ("Al Fhoud", "we", "us"), available at alfhouds.com, is the controller of the personal data described here. This policy covers the whole platform — sign-in, your profile, social features, multiplayer games, notifications, the game information tools and content hubs, the esports hub, and the free-games feed — and the new games and features we add over time.
Al Fhoud operates from the State of Kuwait, and we handle personal data in line with the laws of the State of Kuwait and the regulations of CITRA (the Communication and Information Technology Regulatory Authority of Kuwait), including its data privacy protection regulations.
You can browse the public parts of the site without an account. Personal data is only involved once you sign in and use account features.
2. Account and identity data
Sign-in is OAuth-only through Google or Discord. From your chosen provider we receive your email address and basic profile (name and avatar) using the standard email and profile scopes. We never receive or store a password.
For your account we store: your email; a display name (which you can edit); a permanent public ID in the form AF-XXXXXX; your chosen language; and your join date. You can link both a Google and a Discord identity to the same account.
4. Game and multiplayer data
When you play Zonko, we store the game rooms and seats you take part in and the server-authoritative game state. Each player’s private hand is readable only by that player; the deck order is kept server-side and is never sent to clients. This keeps multiplayer fair and private.
You control who can invite you to games with per-user privacy toggles (allow friends, followers, and people you follow). Only you can read your own toggle values; others only get a computed yes/no when they try to invite you.
5. Notifications and Web Push
Notifications are opt-in. You can turn on alerts for free games, game patch notes, and live esports, and we store those preferences.
If you enable browser (Web Push) notifications, we store the push subscription your browser provides (its endpoint and the p256dh and auth keys) so a scheduled job can deliver the alerts you asked for. You can turn any of these off at any time.
You can also subscribe to a specific match, team, or tournament to be alerted when it goes live; we store those subscriptions to send the alert.
6. Game profile lookups
Some features let you look up a public game profile. Today this is the League of Legends summoner lookup: when you search a summoner, you provide a public Riot ID (game name and tag line) and a region, and we use these to fetch that public profile from Riot’s and op.gg’s public resources on the server. To protect the service we apply per-IP and global rate limiting, which uses your IP address transiently for that purpose.
The League of Legends match-history feature calls the Riot Games API directly. When a player’s match history is viewed, we resolve the public Riot ID to a Riot player identifier (a "PUUID", scoped to our Riot API key) and we durably cache that PUUID together with the returned match data (such as the match list, champions, results, and per-match statistics) in our database, so the history can be shown efficiently without re-querying Riot every time.
Each match returned by Riot includes every player in that game, so for every match we cache we store the public Riot ID (game name and tag line) and the PUUID of all of its participants — typically around ten players per match — not only the player who was searched. This means we store, and durably retain, the Riot ID and PUUID of players who were never searched on Al Fhoud and who have no Al Fhoud account, purely because they appeared in a match alongside a searched player. The lookup itself works without an account and can be run for any player, including players who do not have an Al Fhoud account.
This cached match data and the PUUIDs originate from and belong to Riot Games, and your use of this Riot-sourced data is also subject to Riot’s own terms and policies. We keep it only as a cache: a searched summoner’s rank and match list are refreshed on a short cycle, and immutable finished-match records — including every participant’s Riot ID and PUUID — are kept until they are erased. The match-level record on its own (game time, duration, and result) carries no player identifier; the per-participant records that hold the Riot IDs and PUUIDs are the personal part, and are what an erasure removes. Any participant in a cached match can ask us to erase their data, whether or not they were the player searched and whether or not they have an Al Fhoud account (see "Your rights" below).
You can ask us to erase all of a player’s cached Riot match data at any time — a Right-to-be-Forgotten / deletion request — and this works even for a searched player who has no Al Fhoud account. See "Your rights" below for how to exercise it; every such erasure is logged (using only a one-way hash of the identifier, never the raw identifier) so we can prove it was carried out.
Note that if you use the share control on such a page, the link you share contains the identifier that was searched (for example the Riot ID), because it is part of the page address.
7. Public content and share controls
The public content hubs — for example champions, meta and tier lists, ARAM, skins, items, the rune builder, the leaderboard, patch notes, the esports schedule and standings, and the free-games feed — do not collect personal data. They display public information cached from third-party sources.
The share control uses your device’s native share sheet or copies a link; it collects no data of its own and simply passes the current page address.
9. Advertising and monetization
Today, Al Fhoud runs no third-party advertising network and no behavioural or cross-site ad tracking. The platform includes an ad space that can show a "house" ad we configure directly; it loads no third-party ad script, no tracking pixel, and no profiling cookie, and it shows nothing when no ad is configured, which is its state today.
Our current, privacy-friendly analytics are described in the "Cookies, analytics, and similar technology" section above. If in the future we introduce third-party ad networks, sponsorship measurement, or any analytics that tracks or profiles individuals, we will update this policy first to name the partners and describe the data involved, and — where the law requires it — ask for your consent before any such tracking runs.
We do not currently use affiliate or referral links. If we add them in the future, following one may pass a referral identifier to the destination store or service so a purchase can be attributed to us; from that point the destination’s own privacy policy governs what it collects, and we would not receive your card or payment details from such purchases.
We do not currently offer paid features. If we introduce them, your payment and card details would be handled by a third-party payment processor and would not be stored by us; we would receive only what we need to confirm a purchase, such as its status and, for a subscription, its renewal state.
We do not sell your personal data.
10. How we use your data
We use your data to: create and run your account; provide the social, multiplayer, and information features; deliver the notifications you opted into; remember your language and preferences; protect the platform through rate limiting and abuse prevention; and meet our legal obligations.
Our legal bases are: performing our agreement with you (running your account and the features you use); your consent (notifications and Web Push, which you can withdraw at any time); and our legitimate interest in keeping the service secure and working.
11. Who we share data with
We do not sell your data. We use a small set of service providers ("sub-processors") to run the platform:
- Supabase — our database, authentication, realtime, and storage provider, which holds your account, social, and game data;
- Vercel — our hosting provider, which serves the site, processes requests and technical logs, and provides the cookieless, aggregate Web Analytics described above;
- Google — when you choose Google sign-in;
- Discord — when you choose Discord sign-in;
- third-party game data providers such as Riot Games, op.gg, Data Dragon, and Community Dragon — public sources for the games we cover (currently League of Legends and VALORANT), queried (with the Riot ID you enter) when you use a game lookup or view game content;
- the lolesports feed — for public esports schedules, teams, and standings;
- GamerPower — for the free-games giveaway feed (no personal data is sent);
- your browser’s Web Push service — to deliver push notifications you subscribed to.
12. International transfers
Our providers may process data on servers outside your country. Where that happens, we rely on the providers’ own safeguards for international transfers.
13. Data retention
We keep your account data for as long as your account exists. When you delete your account, your authentication record is permanently deleted and, by database cascade, every row you own — profile, social graph, game data, notification preferences, and push subscriptions — is deleted with it. Transient technical data such as rate-limit counters is short-lived by design.
Cached League of Legends match data (described in "Game profile lookups" above) is kept only as a cache: a searched summoner’s rank and match list are refreshed on a short cycle, and immutable finished-match records are retained until a Right-to-be-Forgotten / deletion request erases a player’s data. Because each cached match stores the Riot ID and PUUID of all of its participants — around ten players per match, including people who were never searched and have no Al Fhoud account — this cache can hold data about players well beyond the searched summoner, so deleting your Al Fhoud account does not, by itself, remove it. Any such player’s data is removed by a match-data erasure request (see "Your rights"). An erasure removes every stored record tied to that player’s Riot identifier and writes a log entry containing only a one-way hash of the identifier; we also add that one-way hash to a suppression list so that a later search does not re-cache the player, which is what keeps the erasure durable.
14. Your rights
You can: see and update your display name and language in Settings; withdraw notification and push consent with the in-app toggles; and delete your account yourself at any time (Settings sends a request that hard-deletes your account and cascades to all your data). Depending on where you live you may also have rights to access, correct, export, restrict, or object to the processing of your data, including under the applicable Kuwaiti data-protection framework.
You also have the right to have cached League of Legends match data erased (a Right-to-be-Forgotten request), including for a player who has no Al Fhoud account, and including anyone who only appears as a participant inside someone else’s cached match. To request this, contact us at the address below with the Riot ID (game name, tag line, and region) whose data should be erased; we verify the request and then permanently delete every stored record tied to that player’s Riot identifier across our cache. So the deletion is durable, we also add a one-way hash of that identifier to a suppression list, which prevents a later search from re-caching that player; the only thing we retain is that one-way-hashed audit and suppression entry proving the erasure was carried out.
To exercise any of these rights, use the in-app controls or contact us at info@alfhouds.com.
15. Children
Al Fhoud is not directed to children under 13, and we do not knowingly collect data from them. If you are under the age of majority where you live, you should only use Al Fhoud with a parent or guardian’s consent. If you believe a child has given us data, contact us and we will remove it.
16. Security
We protect your data with row-level security so each person can only read their own private data, with private-by-default multiplayer hands, and with OAuth-only sign-in so no password is ever stored with us. No online service can be perfectly secure, but we work to keep your data safe.
17. Changes to this policy
We may update this policy from time to time. When we make a material change we will update the effective date at the top of this page.
18. Contact
For any privacy question, or to exercise your rights, contact us at info@alfhouds.com. You can also manage your data directly from the in-app Settings.
You can also reach us through the public channels listed on our Contact page — email, Instagram, Discord, and WhatsApp. When you contact us through any of these, we receive your message and the contact details you choose to share, only to respond to you; those third-party platforms carry the message on their own side under their own privacy policies, which we do not control. Using them is your choice, and the Contact page is informational only — it hosts no form and stores nothing itself.
19. Player feedback and reports
Al Fhoud includes an in-app feedback tool — the "!" report-and-suggest control — that lets anyone, whether or not they are signed in, flag something on a page that is wrong, outdated, or broken, or send us a suggestion or idea. We only collect the information described below when you actually submit a report or a suggestion; opening the tool and closing it without sending stores nothing.
When you submit a report or a suggestion, we store: whether it is a report or a suggestion, and for a report the category you chose (wrong, outdated, or broken); the note or idea you write in your own words; which page you were on — its path and the full web address, including anything after the "?" in it — and, when you point at a specific element, that element’s identifier, a short label, the visible text snippet you saw, a coarse indication of where it sits in the page, and, if it shows a translated label, the translation key for it (which also lets us flag reports about translated wording for our translation review); the size of your screen (its width, height, and pixel ratio) and your browser’s general user-agent line (which broadly identifies your browser and operating system), which help us reproduce a display or layout problem; the interface language you were using; and the date and time. If you are signed in, we also store your account, so we can follow up with you — a report or suggestion can equally be sent without signing in, and then no account is attached to it.
To keep the tool from being flooded with automated spam, we also compute a salted, one-way hash of your IP address and store only that hash, used solely as an anti-abuse rate-limit key. We never store your actual IP address, and the hash cannot be turned back into it.
We use what you send only to review, reproduce, and act on the issue or idea you raised, and to protect the tool from abuse; we do not use it for advertising and we do not sell it. Our legal bases are your consent, given when you choose to submit, and our legitimate interest in improving and securing the platform. A report or suggestion is about the platform rather than about you, so we keep it in order to act on it: if you delete your Al Fhoud account, a report or suggestion you filed is not deleted with your account — instead the link to your account is removed, so that the report becomes anonymous, and the report itself is retained so we can still resolve the issue you raised.
20. Who reviews your feedback and reports
Reports and suggestions you submit are reviewed by authorized Al Fhoud guild staff so that we can act on them. Access to this internal review console is granted by role — only people we have explicitly authorized can open it — and everyone who opens it is signed in to their own Al Fhoud account, so each review action is attributable to a specific person.
When authorized staff review a report or suggestion, they see what you sent — the note or idea, the page and the element it was about, the interface language, and the date and time — together with your public Al Fhoud handle (AF-XXXXXX) if you were signed in, or the fact that it was sent anonymously if you were not. They do NOT see the salted hash of your IP address, which stays a server-side anti-abuse key and is never shown in the console. Staff use this access only to review, reproduce, resolve, or dismiss the issue or idea you raised, and each resolution is recorded together with who actioned it and when.
21. Language of this Policy
The Arabic and English versions of this Privacy Policy are the official, authoritative versions. Any version provided in another language is a convenience translation only. In the event of any discrepancy, ambiguity, or error between a translated version and the Arabic or English version, the Arabic and English versions govern and prevail.
3. Social data
If you use the social features, we store your follows (one-directional) and your friendships (which require a mutual follow and approval). Removing a follow also removes the related friendship.
You can add someone by their public handle (AF-XXXXXX). This lookup only returns the public profile fields — display name, avatar, and public ID — and never exposes email, contact details, or language.