Privacy Policy
This policy explains what personal data we collect when you use SPEEDRUN, why we hold it, who else sees it, and what you can require us to do about it. It is written to meet the EU General Data Protection Regulation (GDPR). For how cookies work specifically, see the Cookie Policy.
1 Who is responsible
The data controller is Speedruntrading (sole trader, Sweden), org. no. available on request, Åkerbärsvägen 24, 181 64 Lidingö, Sweden, Sweden. For any question about this policy or about your data, write to support@speedruntrading.org.
We have not appointed a Data Protection Officer, and are not required to. Your enquiry goes straight to the person who runs the business.
2 What we collect
We deliberately collect as little as the Service can function on.
| Data | When | Why |
|---|---|---|
| Email address | When you sign in or buy | It is your account identifier and the only way to restore your access |
Purchase recordbundle, date | On payment | To know what you own, and for statutory accounting records |
Lesson progresslesson, date completed | As you study | To show you where you left off |
Session cookiesr_session | While signed in | Keeps you signed in. Contains your email and a signature, nothing else |
Consent recordsr_consent | When you answer the cookie banner | Stored in your own browser so we do not ask again. Never sent to us |
Server logsIP address, timestamp, page | Every request | Security, abuse prevention and fault diagnosis. Kept short |
We never see your card details. Payment happens on Stripe's own hosted checkout page. Your card number, expiry and security code are entered on Stripe's systems and are never transmitted to or stored by us. We receive only confirmation that a payment succeeded, the amount, and the email you gave Stripe.
We do not collect special category data, we do not profile you, we make no automated decisions producing legal effects, and the Service is not directed at children under 16.
3 Our legal basis
- Performance of a contract (Art. 6(1)(b)) — your email, purchases and progress. Without them we cannot give you what you paid for.
- Legal obligation (Art. 6(1)(c)) — transaction records retained for accounting and tax law.
- Legitimate interests (Art. 6(1)(f)) — server logs, for keeping the site up and secure. We have weighed this against your rights and consider the impact minimal.
- Consent (Art. 6(1)(a)) — any analytics or marketing cookie. None are active unless you have said yes in the cookie banner, and you can withdraw at any time from the footer.
4 Who else processes it
We do not sell your data, rent it, or share it for anyone else's marketing. It is disclosed only to the service providers we need to run the site, each bound by a data processing agreement:
| Provider | Role | Data |
|---|---|---|
| Stripe Payments Europe, Ltd. | Payment processing | Email, amount, card data (held by Stripe, not us) |
| Cloudflare, Inc. (edge network, EU/global) | Website hosting | Server logs, IP address |
| Turso (ChiselStrike Inc.), EU region | Data storage | Email, purchases, progress |
| Resend Inc. | Sign-in links and receipts | Email address |
Where a provider processes data outside the EU/EEA, the transfer is covered by the European Commission's Standard Contractual Clauses or an adequacy decision. We will also disclose data where we are legally compelled to, and will tell you unless we are prohibited from doing so.
5 How long we keep it
- Account and progress — until you ask us to delete it, or after 3 years of inactivity.
- Purchase and transaction records — 7 years after the end of the financial year, as required by the Swedish Accounting Act (bokföringslagen). This retention overrides a deletion request, and we will tell you if it applies.
- Server logs — up to 90 days.
- Support correspondence — up to 2 years after the matter is closed.
6 How it is protected
The site is served over HTTPS only. The session cookie is signed with HMAC-SHA256, is HttpOnly and SameSite, and cannot be edited to impersonate another account. Access to the database is restricted to the operator. We do not store passwords at all, so there are none to leak.
No system is perfectly secure. In the event of a personal data breach likely to result in a risk to you, we will notify the Swedish Authority for Privacy Protection (IMY) within 72 hours and inform you directly where the risk is high.
7 Your rights
Under the GDPR you may, free of charge, require us to:
- Give you access to the personal data we hold about you, as a copy.
- Correct anything inaccurate.
- Erase your data, except records we must keep by law.
- Restrict or object to our processing.
- Port your data to you or another provider in a machine-readable format.
- Withdraw consent at any time, without affecting processing already carried out.
Write to support@speedruntrading.org from your account address. We respond within one month. We will not charge you, and we will not make the Service worse for you because you asked.
If you are unhappy with how we handled it, you may complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY — imy.se), or to the supervisory authority where you live.
8 Changes
If we change this policy we will update the date at the top and, where the change materially affects you, tell you by email or by notice on the site before it takes effect.
9 Contact
Speedruntrading (sole trader, Sweden) · org. no. available on request · Åkerbärsvägen 24, 181 64 Lidingö, Sweden · support@speedruntrading.org