Privacy Policy
This Privacy Policy explains what data Ascend collects, how we use it, and the rights you have over your data. We apply the same set of rights to every user, worldwide — regardless of which country you live in. Questions? Email info@play-ascend.com.
- Effective
- May 27, 2026
- Updated
- May 27, 2026
01Who we are
Ascend (also referred to as Ascend Hub or Play Ascend) is operated by Ascend Operating Entity, Pvt. Ltd., a company registered in India. Our website is play-ascend.com.
For the purposes of data-protection law, Ascend is the data controller for personal data about our users (account details, tracker queries, shop orders, matchmaking profiles, rewards activity). Ascend acts as a data processor when a community admin uses Ascend AI and uploads markdown knowledge-base content to a server they manage — in that case, the community admin is the controller and Ascend processes that content on their behalf.
02What we collect
We only collect data that's necessary to operate the products you use. The full list, broken down by surface:
Account and identity
When you sign in with Discord:
- Your Discord user ID, username, display name, avatar URL, and email (provided by Discord with your consent).
- Optionally, your Riot ID (game handle + region) if you link it to use the VALORANT tracker.
VALORANT tracker
When you look up an account:
- The Riot ID and region you query.
- Publicly-available match data we fetch on your behalf from a third-party VALORANT data provider — this is data Riot Games already publishes about your account.
Shop
When you place an order:
- The game, denomination, and region of the item purchased.
- Order metadata (order ID, timestamps, delivery method).
- The delivery email or Discord identity we use to send the code.
- Payment data is handled by Whop, our payment processor. We do not see or store your card details — Whop sends us only the order confirmation and funded balance.
- Gift-card codes are deleted from our systems within 24 hours of successful delivery.
Ascend AI (Discord support bot)
When you install Ascend AI on a Discord server you manage:
- Your Discord server (guild) ID, server name, and member count.
- Your configured settings: allowed channels, bot personality, support-channel routing, daily question limits.
- The markdown knowledge-base documents you upload — you are the controller of this content; Ascend processes it on your behalf.
- Question / answer logs for the admin-dashboard analytics, retained for 30 days then aggregated.
Other surfaces
Matchmaking, marketplace, rewards, crosshairs, recruit, and esports collect only what's necessary to operate the feature: queue entries, listing content you write, ledger entries, crosshair codes you submit, queries you make.
Analytics
We use Amplitude for product analytics with autocapture (page views, events, sessions). Session replay is sampled at 10%. Analytics are recorded only in production — never on local development. You can opt out via your browser's Do Not Track / Global Privacy Control signal, or by emailing info@play-ascend.com.
Cookies and storage
We use a small set of cookies and local-storage keys, all strictly necessary or analytics:
| Cookie / key | Purpose | Lifetime |
|---|---|---|
sb-* (Supabase Auth) | Authentication session | Until logout |
auth-redirect-to | Remembers where to send you after OAuth | 10 minutes |
ascend-ai:discord-guilds:v1 | Caches your Discord server list for the picker | 7 days |
amp_* (Amplitude) | Product analytics | 1 year |
We do not use third-party advertising cookies or cross-site tracking pixels.
03How we use your data
We use the data above to:
- Operate the products you actively use — sign you in, return tracker results, fulfil shop orders, run Ascend AI replies, run matchmaking lobbies.
- Verify your account and the Discord/Riot identities you link.
- Send transactional emails and Discord DMs — shop delivery confirmations, promo codes, account notices.
- Improve the product through aggregated analytics, debugging, and usage measurement.
- Detect abuse and protect the platform — rate limits, fraud signals, anti-spam in Ascend AI.
- Comply with applicable law, including tax-record retention and lawful requests from law enforcement.
We do not:
- Sell your personal data.
- Use your data to train third-party AI models for our own benefit (community-admin-uploaded Ascend AI KB content is sent to model providers only to generate the reply that admin's server requested).
- Profile you for targeted advertising.
- Share your data with anyone other than the service providers listed in the next section.
04Who we share data with
We use a small set of third-party processors. Each has its own privacy policy:
| Processor | What we share | Where |
|---|---|---|
| Supabase | Database + auth records | AWS (ap-south-1) |
| Whop | Payment + subscription billing | United States |
| Third-party VALORANT data provider | Riot ID + region for tracker queries | Outside India |
| Discord | OAuth identity + Ascend AI runtime | Discord-operated regions |
| Resend | Transactional email delivery | United States |
| Amplitude | Product analytics + 10%-sampled session replay | United States |
| OpenAI / Anthropic | Ascend AI prompts (KB + the user's question) | United States |
| AWS Amplify | Web hosting | AWS (ap-south-1) |
We share data with these processors only as needed to operate the relevant feature. We do not sell data to data brokers or advertisers.
If we ever need to add or change a processor, we'll update the table above. Material changes will be announced on our Discord and via an in-app banner before they take effect.
05How long we keep your data
We keep data only for as long as we need it:
- Account data — until you ask us to delete it.
- Tracker queries — cached briefly to speed up repeat lookups, then discarded.
- Shop order records — 7 years (Indian tax and accounting compliance). Gift-card codes are deleted within 24 hours of delivery.
- Ascend AI knowledge-base documents — until the community admin deletes them or uninstalls the bot.
- Ascend AI question/answer logs — 30 days for admin-dashboard analytics, then aggregated.
- Analytics events — per Amplitude's default retention.
- Account-deletion backups — 30 days after a deletion request, all backups complete the purge.
06Your rights
We apply the following rights to all users worldwide, regardless of jurisdiction:
| Right | What you can do |
|---|---|
| Access | Request a copy of your personal data in a readable format. |
| Deletion | Request deletion of your account and personal data. Completed within 14 days of verification, with a 30-day backup-purge window. |
| Portability | Request an export of your data in a machine-readable format. |
| Correction | Ask us to correct inaccurate information. |
| Objection | Opt out of analytics, session replay, or any non-essential processing. |
| Withdrawal of consent | Disable specific data uses or revoke prior permissions. |
| Complaint | Lodge a complaint with your local data-protection regulator. |
To exercise any of these rights, email info@play-ascend.com from the email address linked to your Ascend account. We'll respond within 14 days, regardless of which legal regime applies to you.
Regulator addresses
If you're not satisfied with how we've handled your request, you can complain to your local regulator:
- India — Data Protection Board of India (forming under the DPDP Act 2023).
- European Union — your country's Data Protection Authority.
- United Kingdom — Information Commissioner's Office, ico.org.uk.
- California, US — California Privacy Protection Agency, cppa.ca.gov.
07International transfers
Ascend is registered in India and our primary database lives on AWS (ap-south-1, Mumbai). Several of the processors above are located outside India and the European Union (notably the United States). When we transfer your data internationally:
- We rely on appropriate safeguards (standard contractual clauses, transfer impact assessments) where required by GDPR or DPDP.
- We never transfer data to a jurisdiction that India has placed on a restricted-transfer list under the DPDP Act.
- Our processors are contractually bound to apply protections at least equivalent to those described in this policy.
08Security
We use industry-standard technical and organisational controls:
- TLS in transit, AES-256 at rest (provided by AWS / Supabase).
- Row-level security on the database, with explicit access policies on every table.
- Minimum-permission OAuth scopes everywhere — Ascend AI's Discord install requests only Embed Links + Stream, no moderation permissions.
- Service-role credentials rotated periodically; user-facing tokens scoped per session.
- Production-only analytics — no dev or staging data leaks to Amplitude.
No system is 100% secure. If we discover a personal-data breach, we'll notify affected users within 72 hours of confirming it, consistent with GDPR best practice.
09Children
Ascend is not directed at children under 13 years of age. We do not knowingly collect personal data from anyone under 13. If you become aware that a child has provided us personal data without parental consent, email info@play-ascend.com and we'll delete it promptly.
10Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top of this page always reflects the current version. Material changes — anything affecting your rights or expanding what we collect — will be announced at least 30 days in advance via:
- A banner on play-ascend.com
- An announcement in our Discord server
- An email to your account address, if we have one
By continuing to use Ascend after the effective date of a change, you accept the updated policy.
11Contact
For privacy questions, data-subject access requests, or anything else covered by this policy, email info@play-ascend.com. You can also reach us through the contact page — pick "privacy request" and your email opens with the right intake template.
We aim to respond within 14 days.