RaidReady · issued contract
Setup Challenge Privacy Notice
Effective and last updated: September 2, 2026
Notice version: setup-privacy-2026-09-02
This notice explains the additional information used to sell, deliver, support, and refund the Setup Challenge. It supplements the general RaidReady Privacy Policy. RaidReady is operated from Montreal, Quebec, Canada. The Privacy Officer can be reached at support@raidready.app.
1. Information collected
Identity and access: email address, internal user and enrollment identifiers, sign-in link status, session status, login and resend records, and account-security events. Payment and refund records: checkout name and billing/postal address, amount, currency, Stripe Checkout and payment references, payment status, purchase time, accepted Terms and Privacy Notice versions, immutable purchase-contract copy and integrity hashes, duplicate and replay evidence, refund claim, refund status, and dispute status. Stripe receives card data; RaidReady does not store the full card number or card security code. Challenge activity: day and step progress, answers and reflections, saved outputs, the Day-7 self-report of your 60-minute Twitch stream, review flags, support and admin actions, and any refund receipt. Connected Twitch data: the Twitch identity and public channel details associated with your account where you have connected or named them, and the Twitch link you provide in your Day-7 self-report. Day-7 stream evidence is self-reported; the Setup Challenge does not observe your streams automatically. Day-6 screenshot custody: one Day-6 OBS Stats screenshot, stored in a private server-controlled bucket. It is never given a public object URL and is not routinely exposed in Admin. It is available only through owner-authenticated server routes and the service operations needed for storage, security, and deletion. You may download an owner-controlled copy or request deletion; a replacement makes the previous screenshot eligible for deletion. Aggregate readiness and operations reporting does not display screenshot bytes, filenames, object keys, hashes, URLs, or participant rows. AI tool data: prompt inputs, generated or fallback outputs, saved challenge artifacts, usage and quota records, and sanitized provider-failure status. Do not enter secrets or sensitive personal information the requested tool does not need. Technical and attribution data: IP address, user agent, request and error logs, security and rate-limit signals, referring page, UTM attribution, cookie preferences, and consented analytics events.
2. Purposes
RaidReady uses this information to create Checkout and reconcile payment; grant one entitlement and purchase-linked enrollment; deliver and recover access; maintain the challenge session; create, retain, and securely provide the purchase contract as it existed when payment completed; save progress; receive and safeguard the Day-6 screenshot; record the Day-7 self-report and settle the run; generate AI tool outputs; process refund requests and revoke access after an approved access-granting refund; review disputes; send required transactional messages; provide support; prevent fraud and abuse; diagnose failures; maintain an audit trail; and meet accounting, tax, consumer-protection, privacy, and lawful-request obligations. Purchasing does not by itself opt the buyer into unrelated marketing.
3. Service providers and disclosures
Stripe processes Checkout, payment, refund, and dispute data. Supabase stores restricted account, purchase-contract, entitlement, enrollment, progress, screenshot, audit, and operational records. Brevo transports transactional access, progress, support, and refund email; buyer name, billing/postal address, and purchase-contract text are not inserted into the access email. Twitch processes the identity and channel data of the Twitch account used for the challenge. Anthropic processes the prompt context needed to generate in-product challenge tools when the AI service is available. Hosting, security, and consented analytics providers process infrastructure requests, operational logs, and permitted analytics events. RaidReady does not sell personal information. Information is disclosed only for the purposes above, with the person's direction, to investigate security or fraud, or where law requires or permits it.
4. Sessions and the purchase-contract portal
Sign-in links are single-use and time-limited. Verification copies of token material are hashed. Restricted email-delivery records may temporarily contain a private access URL for delivery and retry. A signed first-party session cookie keeps the user signed in. Essential security, session, and consent-preference storage is used where the service cannot work without it; analytics storage is used only after applicable consent. After sign-in, the private purchase-contract portal uses the exact internal user and purchase identifiers to return only contracts belonging to that user. A contract URL contains only an opaque purchase identifier. Contract access does not depend on feature flags, current entitlement state, or later refund status.
5. Transactional email
RaidReady and Brevo use the purchase email to deliver and resend access, notify the user about relevant challenge progress or operational issues, and communicate about a refund or dispute. Delivery jobs and provider status are recorded. Provider email links back to RaidReady and does not include buyer name, billing/postal address, or the retained legal copy. Private action links must not be forwarded.
6. Retention
Each Day-6 screenshot upload receives a deletion deadline thirty calendar days after upload. While the challenge run is active, required evidence may remain available until the run becomes completed or abandoned. Once the run is terminal, the cleanup worker deletes the screenshot at or after its deadline, immediately when that deadline has already passed. Only the minimum non-content audit record remains. Single-use credentials expire and are invalidated when claimed or replaced; limited audit evidence is retained to prevent replay and resolve access issues. Enrollment, progress, refund, and support data is retained while needed to deliver the product, preserve access, resolve disputes, prevent abuse, and maintain the refund record. Purchase, refund, invoice, and related accounting records are generally retained for at least six years from the end of the relevant Canadian tax year. Buyer identity/address and the immutable contract copy are retained with restricted access for applicable accounting, consumer-protection, transaction, refund, and dispute periods. Other provider, security, failed-job, and consented analytics records are deleted or de-identified when their documented purpose ends.
7. International processing
Some providers may process information outside Quebec or Canada, including in the United States or European Union. Privacy laws may differ. RaidReady remains responsible for its handling and uses provider and contractual safeguards appropriate to the service and applicable law.
8. Choices and rights
Subject to applicable exceptions, a person may ask what personal information RaidReady holds and how it is used or disclosed; request access or correction; withdraw consent for consent-based use; object to direct marketing; or request deletion. Use the product controls to export or remove the Day-6 screenshot. Deletion may not remove purchase, refund, fraud, security, or other records that law requires or that remain necessary to resolve a transaction or claim. Requests go to the Privacy Officer at support@raidready.app; identity may be verified before disclosure or change.
9. Security and incidents
RaidReady uses measures appropriate to the information, including TLS, signed sessions, hashed one-time credential verification, a private server-controlled screenshot bucket, restricted operational access, row-level security on challenge tables, webhook signatures, audit records, and provider-access controls. No online service is risk-free. If a privacy incident creates a risk of serious harm, RaidReady will mitigate and provide notices required by applicable law.
10. Age requirement
The Setup Challenge is for people age 18 and older. RaidReady does not knowingly sell it to a minor.
11. Complaints, changes, and contact
Questions or complaints go to the Privacy Officer at support@raidready.app. If unresolved, a person may contact the Commission d'accès à l'information du Québec. RaidReady may update this notice for future purchases or when practices or law change; the version stored with this purchase remains the acknowledged notice for that transaction.