Privacy Policy
Last updated: 12 June 2026
This Privacy Policy describes how Faceplant Studios ("we", "us", "our") collects, uses, shares and protects your personal information when you use DBD Randomizer and its related sites and subdomains (the "Service").
By using the Service you agree to this Policy. If you do not agree, please do not use the Service.
1. Who we are
Faceplant Studios is a UK-based company. For any privacy-related questions, requests or complaints, contact us at contact@faceplant-studios.com.
2. Information we collect
- Account information - name (display name), email address, password (hashed), and account preferences when you register.
- Subscription information - subscription tier, start/end dates, and a PayPal subscription identifier when you subscribe. We do not see or store your card or bank details; PayPal handles all payment data.
- Usage data - pages visited, randomizations made, loadouts saved, comments posted, achievements earned, and other actions you take on the Service.
- Technical data - IP address, browser type and version, device type, screen size, language, time zone, and referring URL. Collected automatically by your browser and our analytics.
- Cookies and similar technologies - see Section 8.
3. How we use your information
- To provide the Service - run your account, save your loadouts, deliver randomizations.
- To process subscriptions and prevent fraud or abuse.
- To communicate with you - confirmations, security alerts, replies to your inquiries.
- To measure and improve the Service via analytics.
- To serve advertising to non-subscribed users via Google AdSense.
- To comply with legal obligations.
4. Legal basis for processing (UK / EU users)
- Contract - processing necessary to provide the Service to your account.
- Consent - for advertising cookies and personalised ads, where required.
- Legitimate interests - for security, fraud prevention, and basic analytics in a privacy-respecting way.
- Legal obligation - where we must retain or disclose data to comply with the law.
5. Who we share your information with
We do not sell your personal information. We share data with the following categories of third parties so the Service can operate:
- Google AdSense - to serve ads to non-subscribers. Google may use cookies and identifiers for ad personalisation. See Google's Advertising Policy and manage your preferences at Google Ads Settings.
- Google Analytics - for usage measurement. See Google's Privacy Policy.
- PayPal - to process subscription payments. See PayPal's Privacy Statement.
- Ko-fi - to process one-off donations made via the embedded Ko-fi widget. Ko-fi receives the data you choose to provide on their donation form (e.g. name, email, message); we receive no payment details. See Ko-fi's Privacy Policy.
- OVH - hosting provider for our servers.
- Cloudflare - CDN, DDoS protection and edge delivery. See Cloudflare's Privacy Policy.
6. International data transfers
Some of our service providers (notably Google, PayPal and Cloudflare) are based in the United States, and your information may be transferred outside the UK / EEA. Where this happens, transfers are protected by Standard Contractual Clauses approved by the UK ICO and the European Commission. Cloudflare and Google are also certified under the EU-US Data Privacy Framework.
7. How long we keep your information
- Account data - for as long as your account is active. When you request deletion, we delete or anonymise your account immediately, except where we must retain limited records for legal or accounting purposes (e.g. invoice records for up to 6 years under UK tax law).
- Analytics data - retained for up to 14 months in Google Analytics, then automatically deleted.
- Server logs - typically retained for up to 90 days for security and abuse-prevention purposes.
8. Cookies and similar technologies
We use cookies and similar technologies to keep you logged in, remember your preferences, measure usage, and serve advertising. Categories include:
- Strictly necessary - session and authentication cookies. Cannot be disabled.
- Analytics - Google Analytics (e.g.
_ga,_gid). - Advertising - Google AdSense (e.g.
__gads,__gpi,IDE).
EEA / UK / Swiss visitors are shown a consent banner via Google's Funding Choices on first visit. You can revisit your choices any time using the "Manage Cookie Settings" link on the page.
9. Your rights
Depending on where you live, you have rights including:
- Access - obtain a copy of the data we hold about you.
- Correction - have inaccurate data corrected.
- Deletion - request your account and associated data be deleted.
- Portability - request a copy of your data in a portable format.
- Object / restrict - object to or restrict certain processing.
- Withdraw consent - withdraw any consent you previously gave (e.g. for ad personalisation).
- Opt-out (California / US states) - opt out of the sharing of your information for cross-context behavioural advertising. Use the consent banner or contact us.
- Complain - lodge a complaint with the UK Information Commissioner's Office (ico.org.uk) or your local data protection authority.
To exercise any of these rights, email contact@faceplant-studios.com. We aim to respond within 30 days.
10. Children
The Service is not intended for children under 13 (or under 16 in the EEA / UK). We do not knowingly collect personal information from children. If you believe a child has provided us with information, contact us and we will delete it.
11. Security
We use reasonable technical and organisational measures to protect your information, including hashed passwords, HTTPS, and access controls. No method of transmission or storage is 100% secure, however, so we cannot guarantee absolute security.
12. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified on the site or by email where appropriate. The "Last updated" date at the top reflects the most recent revision.
13. Contact
Questions about this Policy? Email contact@faceplant-studios.com.