Scope and controller
This Privacy Policy applies to SoonGG and its related website features, accounts, notifications, calendar feeds and support interactions. For the purposes of applicable data-protection law, SoonGG is the operator responsible for the personal data described in this Policy.
Privacy questions and rights requests can be sent to [email protected]. We may ask for reasonable verification before acting on a request involving account data.
Data we collect
Account and profile data
If you create an account, we may store your email address, display name, avatar URL, preferred language, country/store region, timezone, account role and status, verification state, account creation date and last login time.
Authentication and security data
For password accounts, SoonGG stores a password hash rather than your plain-text password. We also store hashed session or single-use token values and security timestamps. If you sign in with Google, we may receive your Google account identifier, verified email address, display name and profile picture according to the scopes you approve.
Preferences and activity you choose to save
This can include tracked games, calendar filters, notification choices, subscription-showcase preferences, store region, personal calendar-feed settings and other account preferences needed to provide the features you use.
Notification and Web Push data
SoonGG may store notifications created for your account, read/dismissed state, delivery status, scheduling information and notification preferences. If you enable Web Push, we store the browser push endpoint, public encryption key material, authentication secret and user-agent information required to deliver push messages.
Billing and subscription data
If you purchase SoonGG PRO, SoonGG may receive and store billing-related identifiers and subscription state from Paddle, such as customer, subscription and price identifiers, plan status and relevant billing dates. Paddle handles payment-card credentials; SoonGG does not store full card numbers or card security codes.
Product analytics and technical data
SoonGG uses PostHog for product analytics. Events can include page views, calendar interactions, searches, game opens, authentication completion, tracking actions, PNG export usage, PRO checkout starts, notification preferences, calendar-feed actions and subscription-showcase settings. For signed-in users, SoonGG identifies analytics with an internal user ID and may attach language, role and account status; it does not intentionally send your account email as an analytics property in the current implementation. Web infrastructure and security services may also process IP address, user agent and request metadata.
Support and communications
If you contact us, we receive the email address and any content, screenshots, links or other information you choose to include. If a dedicated report form is used later, the report content and related game/account identifiers may also be stored.
How we use data
- to create and operate accounts, sessions and authentication;
- to remember your region, language, filters, tracked games and other preferences;
- to generate and deliver release, price, subscription and reminder notifications you have enabled;
- to understand how SoonGG is used and improve product design and reliability;
- to prevent abuse, bots, fraud, unauthorized access and service disruption;
- to respond to support, data-correction and partnership messages;
- to comply with legal obligations, enforce our Terms and protect legitimate rights.
SoonGG does not sell your personal data.
Legal bases
Where laws such as the GDPR require a legal basis, SoonGG relies on one or more of the following depending on the processing:
- Contract: processing needed to provide an account or feature you request.
- Legitimate interests: operating, securing, improving and measuring the Service, provided those interests are not overridden by your rights.
- Consent: where you make an optional choice that legally requires consent, such as browser permission for Web Push or other consent-based processing.
- Legal obligation: processing required to comply with applicable law, tax, accounting, fraud-prevention or lawful requests.
Service providers and data sources
SoonGG uses third parties where they are needed to operate the Service. Depending on the feature and production configuration, these may include:
- Google — authentication through OpenID Connect / OAuth using the openid, email and profile scopes.
- PostHog — product analytics. The current frontend is configured to send analytics to the PostHog EU host.
- Cloudflare Turnstile — bot and abuse protection on supported forms. Turnstile can process browser and network signals such as IP address, user agent and other client-side security signals.
- Resend / email delivery provider — delivery of verification, password-reset and notification emails when Resend or another configured email provider is enabled.
- Paddle — payment processing and subscription billing for SoonGG PRO. Paddle acts as Merchant of Record for transactions it processes and may process billing, transaction, tax and support information under its own terms and privacy notices.
- IGDB / Twitch — core game metadata used by SoonGG. SoonGG uses application credentials for the IGDB API; it does not use your Twitch account to fetch game data.
- Platform stores and official sources — price, availability, release or subscription information and outbound store links for supported platforms.
These providers process information under their own terms and privacy notices. They may change independently of SoonGG.
How long we keep data
We keep personal data only for as long as reasonably needed for the purpose described here, subject to legal, security and operational requirements.
- Account and preference data is generally kept while the account remains active.
- Authentication sessions are configured to expire after up to 30 days and can be revoked earlier.
- Email-verification tokens are configured for up to 24 hours and password-reset tokens for up to 30 minutes; used or replaced tokens are invalidated.
- Notification history and delivery records may be kept until deleted, dismissed, aged out under operational retention rules or the account is removed.
- When an account-deletion request is completed, direct account identifiers and credentials are deleted or anonymized where reasonably possible. Limited records may remain where required for security, fraud prevention, legal obligations, backups or integrity of non-personal aggregate records.
Security
SoonGG uses technical and organizational safeguards appropriate to the Service, including hashed passwords and session tokens, HttpOnly cookies, secure production cookies, access controls and anti-bot protections. No internet service can guarantee absolute security, so you should protect your password and secret calendar-feed URL and contact us if you suspect unauthorized access.
International processing
SoonGG and its providers may process data in countries other than the one where you live. Where applicable law requires safeguards for international transfers, we rely on the mechanisms made available by the relevant provider or otherwise permitted by law.
Your privacy rights
Depending on where you live, you may have rights over your personal data, including the right to:
- request access to personal data we hold about you;
- correct inaccurate or incomplete account data;
- request deletion of your account and personal data;
- object to or request restriction of certain processing where the law provides that right;
- request a portable copy of eligible data;
- withdraw consent where processing is based on consent, without affecting earlier lawful processing;
- complain to an applicable data-protection authority.
To exercise a privacy right, email [email protected]. Please use the email linked to your account when possible. We may need to verify your identity before completing the request.
Children
SoonGG is not intentionally designed to collect personal data from children who cannot legally consent to use an online service in their jurisdiction. If you believe a child has provided personal data contrary to applicable law, contact us so we can review and take appropriate action.
Changes to this Policy
We may update this Privacy Policy when the Service, providers or legal requirements change. The “Last updated” date identifies the current version. Material changes may be communicated through the Service or by another reasonable method where required.
Contact
For privacy questions, data requests or concerns, contact:
[email protected]