Privacy
Privacy
What we collect, why, how long we keep it, and what you can ask us to do. "We" is refrace. This page covers the main site at refrace.lol and the race pages we host for customers.
Who is responsible
The controller is RefRace. Contact: cryptomikko@outlook.com. refrace is operated from Finland.
Account and sign-in
You can sign in with a wallet, with an email, or with both linked together.
- A wallet address, when you sign in with a wallet. We use it to know which page you own and to take or refund a payment.
- An email address, when you sign in with email or link one to a wallet. We use it to send the sign-in message and to keep your referral code, invites and quests on one account.
- A contact you type on the page, so we can reach the person who runs that race.
- A session cookie. Wallet sessions (
rf_session) last 30 days. Email sessions (rf_user) last 90 days. Signing out deletes that session. - A short-lived cookie (
rf_signin, 15 minutes) that ties a sign-in email to the browser that asked for it, so a forwarded link cannot silently sign someone else in.
Wallet sign-in challenges expire after 10 minutes. Email codes and links expire after 15 minutes and are kept only in memory until they are used or they expire. We do not keep a copy of the message after it is sent.
Affiliate keys
If you create a race page you give us a Stake or BetBolt affiliate API key. The key is stored encrypted (AES-256-GCM) and is used only to read leaderboard data from that platform. We do not use it to send tips, gifts or anything else.
Stake affiliate tokens of approved affiliates can also send tips and gifts. refrace never calls those endpoints. If the platform offers a read-only key or scope, use that one. The key stays while the page exists and is deleted with the page.
Race data
- Usernames and amounts returned by the platform, so the leaderboard can be drawn. The public page shows masked usernames. The page owner sees full usernames in the dashboard, because that is who pays the prizes.
- A short-lived copy of the latest board in memory, so every visitor does not trigger a new call to the platform.
- A snapshot of a finished race, with full usernames, kept for the page owner. We keep the last 24 races per page.
- Referral codes, invite counts and quest points for accounts that use those features. A monthly snapshot of those boards is kept for the operator.
Visitors of a race page
On a customer's subdomain or custom domain we count page views, Join clicks and widget loads per day. Those counts are kept for 90 days and then deleted. We do not store those visitors' IP addresses in that record, and we do not set cookies on race pages.
The server sees an IP address in order to answer the request. We use it in memory to slow down abusive sign-in and API calls. Those rate-limit records are not written to the visitor stats. Google Analytics is not loaded on race pages.
Analytics on the main site
refrace.lol (and www) can load Google Analytics 4, measurement ID G-L1W3NSNHJ2, and only after you click Accept.
Until then it is off. Reject stores that choice and does not load Google. The choice is a first-party cookie,
rf_analytics, kept for 180 days. Use Cookies in the footer to change it. Accepting or rejecting reloads
the page so the tag and the page's security policy turn on or off together.
If you accept, Google receives usage data about the main site (pages, a client id, and technical data such as the IP address, which Google may truncate) under its own terms. We use it to see which pages of the main site are used. We do not send race-page visitors to Google Analytics.
Payments
Page fees are paid in USDC on Base from your wallet. The transaction is public on that chain. We keep the transaction id, amount and time with the page so we can show what was paid and process a refund. Payment records stay for accounting after a page is deleted.
How long we keep it
- Account, page settings and the encrypted key: while the account or page exists, then until you ask us to delete them.
- Payment records: kept for accounting.
- Daily view and click counts: 90 days.
- Finished-race snapshots: the last 24 per page.
- Sessions: until they expire or you sign out. Sign-in challenges: minutes, in memory only.
- Analytics choice: 180 days, or until you change it.
Who else receives data
- Google Analytics, only on the main site and only if you accept. Race pages do not use it.
- Hosting. The site is served from a server we operate. Delivering a page means the host handles the connection, including the IP address.
- Stake or BetBolt, when we read a leaderboard. We send them the API key and the race dates, to their leaderboard endpoint only.
- Resend, when email sign-in is turned on. Your email address and the sign-in message go through Resend so the message can be delivered.
- Google Fonts. Pages load typefaces from Google, so your browser sends your IP address to Google for the font files. This is separate from Analytics and does not wait for the cookie choice.
- Base. Wallet payments are public on the blockchain. We do not control that record.
Why we are allowed to
- Contract: the account, the page, the key and the race data, because that is the service you asked for.
- Legitimate interest: keeping the service online, rate limits, and the daily counts on a race page.
- Consent: Google Analytics on the main site. You can refuse it, and you can withdraw it later, as easily as you gave it.
- Legal obligation: payment records we have to keep.
Your rights
If the GDPR applies to you, you can ask us to:
- access the personal data we hold about you, and receive a copy;
- correct it;
- delete it, including the page and the encrypted key;
- restrict or object to processing that is based on legitimate interest;
- receive data you provided, in a portable form, where the processing is based on contract or consent;
- withdraw analytics consent. Withdrawal does not affect processing that happened before you withdrew it.
Write to cryptomikko@outlook.com. We may need to confirm it is you. You can also complain to the Office of the Data Protection Ombudsman in Finland (tietosuoja.fi), or to the authority where you live.
The service is for people who are 18 or older. We do not intend to collect data about anyone younger.
Changes
If this page changes in a way that matters, the date below changes with it. The terms of service are a separate document. Questions: cryptomikko@outlook.com.
Version 2026-10-07.