Privacy Policy

Privacy Policy

How Protocol15 handles facilitator accounts, hosted sessions, participants, analytics, and product operations.

This Privacy Policy explains how Protocol15 collects, uses, shares, protects, and retains information when facilitators, hosts, participants, visitors, and account contacts use the website, hosted game sessions, account features, and related services.

Protocol15 is built for hosted group activities. Hosts create sessions and participants usually join by link or code without creating accounts. Please do not enter sensitive personal information into nicknames, team names, support messages, or session content.

01

Who controls your information

Protocol15 is operated by Ilya Vaiman, a sole proprietor trading as Protocol15 (“Protocol15,” “we,” “us”). Ilya Vaiman is the data controller for personal information processed to operate the Protocol15 website, host accounts, hosted sessions, participant access, and related service operations.

For privacy requests or questions, contact support@protocol15.com.

02

Information we collect

  • Host account information, including email address, authentication provider details, profile fields, login metadata, and session-credit or usage status.
  • Participant information, including nickname, team assignment, join time, connection state, participant session token, and session participation records.
  • Gameplay information, including scenario selection, team rankings, locks, scores, result views, completion PDFs, and facilitator-owned session data.
  • Legal acceptance records, including subject category, Terms and Privacy document versions, acceptance source, and server-recorded acceptance time. Participant evidence uses internal participant and session identifiers rather than copied nicknames.
  • Support, billing, purchase, and contact information you choose to send, including email address and message content.
  • Device, usage, log, and analytics information, including browser type, approximate location derived from IP address, timestamps, referral data, diagnostics, security events, limited cookieless measurement signals from eligible public pages, and limited product-interaction events.
  • Payment and billing information when you purchase session packs or other paid services. Card details are handled by the payment provider; Protocol15 does not store full card numbers.

03

How we use information

  • Provide, secure, and operate hosted sessions, participant join flows, host dashboards, scoring, results, completion PDFs, and account features.
  • Authenticate hosts, preserve intended redirects, enforce session-credit and room limits, prevent abuse, and troubleshoot live-session reliability issues.
  • Respond to support requests, billing or purchase questions, security reports, account questions, and legal requests.
  • With consent where required, measure aggregate product usage and improve usability and performance. Essential diagnostics and security monitoring remain separate from optional analytics.
  • Maintain records needed for billing, tax, compliance, dispute handling, fraud prevention, and enforcement of the Terms of Service.

04

Legal bases for processing

Where privacy law requires a legal basis, Protocol15 processes information to perform a contract with hosts, based on legitimate interests in operating and improving the service, with consent where required for optional analytics or communications, and to comply with legal obligations.

05

Cookies, local storage, and analytics

Protocol15 uses essential cookies, local storage, session storage, and similar technologies to operate the service, including authentication, security, redirect recovery, language preferences, participant session continuity, and live-session functionality.

On eligible public pages, Google Analytics uses Advanced Consent Mode with analytics storage denied by default. Before acceptance and after rejection, Google may receive limited cookieless measurement signals, but Google Analytics cookies are not permitted.

Google Analytics cookies are permitted only after you explicitly accept analytics. Advertising storage, advertising user data, and ad personalization remain denied.

You can clear Protocol15 site data in your browser and choose again when the consent prompt returns. Rejecting or withdrawing analytics consent sets analytics storage to denied and removes Google Analytics cookies that Protocol15 can access. Blocking essential browser storage can break host login, participant join, or live session behavior.

Protocol15 disables analytics on authentication, participant-join, live-game, and presentation routes. Analytics events are limited to an approved parameter list that excludes room codes, raw identifiers, and user-provided names.

Tools currently used or wired for use include:

  • Supabase, for authentication, session management, database, and realtime product functionality.
  • Google Analytics, for limited cookieless measurement on eligible public pages with analytics storage denied by default, and for fuller product-usage analytics only after explicit opt-in.

06

How information is shared

  • With service providers that help run the product, such as hosting, database, authentication, analytics, email, error monitoring, and payment providers.
  • Within a live session, where hosts and participants may see nicknames, team names, team progress, submitted rankings, scores, and published results.
  • With professional advisers, authorities, or other parties when needed for legal compliance, safety, fraud prevention, security, or enforcement.
  • In connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate protections for personal information.

07

No sale of personal information

Protocol15 does not sell personal information. Protocol15 also does not use participant gameplay data to create formal psychological, employment, credit, health, or educational assessments.

08

Retention

  • Host account records are kept while the account is active and for a reasonable period afterward for security, billing, legal, and backup purposes.
  • Session, participant, result, and completion PDF records may be kept so hosts can run, review, and support sessions, unless deleted under applicable policy or law.
  • Solution Trajectory data, when retained for paid session-credit usage, is limited to sampled team score points and follows the retention period shown in the product. Free Demo sessions may keep only browser-local trajectory data for the current browser session.
  • Analytics, security logs, backups, and payment-related records may be retained for different periods where needed for operations, compliance, or fraud prevention.

09

Children, students, and classroom use

Protocol15 is not directed to children under 13 and should not be used by children under 13 without legally valid school, parent, or guardian authorization. Hosts using Protocol15 with students or minors are responsible for obtaining required permissions, following school or organization policies, and avoiding unnecessary personal information. Participants should use non-identifying nicknames where appropriate.

10

Your privacy choices and rights

Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, objection, withdrawal of consent, or opt-out of certain processing. To make a privacy request, contact support@protocol15.com. For account access or authentication issues, contact auth@protocol15.com. Protocol15 may need to verify the request and may keep information where allowed or required by law.

11

Security

Protocol15 uses technical and organizational safeguards designed to protect information, including authentication, row-level access controls, participant-scoped access tokens, and provider-managed infrastructure. No internet service is completely secure, so hosts and participants should avoid entering sensitive or confidential information into the product.

12

International use

Protocol15 may process and store information in countries other than where you live. Those countries may have data protection rules different from your local rules. Where required, Protocol15 relies on appropriate transfer mechanisms or provider safeguards.

13

Changes to this policy

Protocol15 may update this Privacy Policy as the product, providers, legal requirements, or business model change. The updated version will be posted on this page with a new effective date.

14

Contact

For privacy requests or questions, contact support@protocol15.com. For account access or authentication issues, contact auth@protocol15.com.