// PRIVACY POLICY
PRIVACY POLICY.
⚠️ The site administrator has not yet filled in the contact details for this privacy policy (PRIVACY_CONTACT_NAAM / PRIVACY_CONTACT_EMAIL in .env). Please use StreamersClub’s regular channels for now.
About this document
StreamersClub (streamersclub.nl) is a hobby project: a community and promotion platform for content creators with a YouTube, Twitch, or Spotify profile. This privacy policy explains what personal data we collect when you create an account or visit the site, why, and what rights you have. Because StreamersClub is not a registered company, the controller below is a private individual — this does not change the GDPR obligations that apply.
Data controller
Responsible for processing your personal data on StreamersClub is:
What data we collect
When creating a creator account
Name, email address, password (never stored in readable form — see "Security" below), country, the links to your YouTube, Twitch, and/or Spotify channel, and optionally your Discord, Instagram, and TikTok usernames. You provide this data yourself to fill in your profile; we never invent or auto-fill anything here.
If you link your Discord account (optional)
Your Discord user ID and username, only if you choose to link your account (via Discord’s own login screen). We use this to automatically assign you the correct role in our Discord server.
If you become a Premium member (optional)
Payments run entirely through PayPal — StreamersClub never sees or stores payment details itself (no card numbers, no PayPal login credentials). We only store that you are a Premium member and until when.
Automatically collected data
- A functional session cookie once you log in, so the site remembers you’re logged in. This cookie contains no tracking data, is never shared with third parties, and expires automatically after 4 hours.
- When you attempt to log in, we temporarily record your IP address together with the email address/username you entered, solely to detect and block repeated, automated login attempts (brute-force attacks). This data is automatically deleted after at most 45 minutes and never used for any other purpose.
- Anonymized, self-hosted visitor statistics: we count unique visitors per day using a daily-rotating hash (built from IP address, browser type, and date). Because the date is part of the hash, it changes every day — so there is no cookie, no stored IP address, and no way to track a visitor across multiple days. At the end of each day we discard the individual hashes and keep only the total.
Why we process this data
We process account data to perform our agreement with you as a creator (showing your profile, letting you log in). We process security measures (rate-limiting, CSRF protection) and anonymous statistics based on our legitimate interest in keeping the site safe and reliable. We only process the Discord link and a Premium purchase after your own explicit action (consent).
Sharing with third parties
- PayPal — processes payments for a Premium membership. Only active at the moment you start a purchase yourself.
- Brevo — sends our transactional emails (e.g. password reset, periodic digest emails). Note: Brevo applies link rewriting/click tracking to these emails, which we are unable to disable.
- Discord — only if you choose to link your account yourself, to automatically assign the correct role.
- YouTube, Twitch, and Spotify — we never send visitor data to these platforms. We only retrieve publicly available channel data (e.g. avatar, channel statistics) for the profile that you, as a creator, linked yourself.
How long we keep data
We keep profile data for as long as your account exists, and delete it upon your request (see "Your rights"). Session cookies expire after 4 hours. Login security data (rate-limiting) automatically expires after at most 45 minutes. We keep anonymized visitor statistics as an aggregated daily total, with no link to any individual visitor.
How we secure your data
Passwords are never stored in readable form: they are salted and hashed with scrypt, a modern hashing function built into Node.js. The site uses CSRF protection against unauthorized form submissions, rate-limiting against automated login attempts, security headers against common web attacks, and encrypted connections (HTTPS) for all traffic.
Your rights
Under the GDPR, you have the right to access, correct, and delete your personal data, the right to object to certain processing, and the right to data portability. Contact us via the email address below to exercise these rights. You also have the right to file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Changes to this policy
We may update this privacy policy from time to time, for example when the site gains new features that process personal data. The date at the top of this page shows when it was last updated.
Contact
Questions about this privacy policy or your data? Get in touch via: