This Privacy Policy explains how Tarkov Raiders HQ (“we”, “us”, “the site”) at tarkovraiders.com collects, uses, stores, and protects information when you use the website and optional account features.
Who operates this site
Tarkov Raiders HQ is an independent fan-made companion tool for Escape from Tarkov, operated by the site maintainer (“Nick”). It is not affiliated with, endorsed by, or sponsored by Battlestate Games.
For privacy questions or data requests, contact us via our Discord community or the feedback form on the site.
What we collect
We only collect data needed to run the features you use. Most of the site works without an account.
- Account sign-in — If you register or sign in, we store authentication details through Supabase: your email address (legacy email accounts), Discord account identifier (if you use Discord sign-in), and an internal user ID. We do not receive your Discord password.
- Profile & synced progress — If you use cloud sync, we store gameplay tracking you choose to save: display username, PMC level, faction, game edition, Account ID (AID), quest/story progress, hideout levels, trader reputation, map quest pins, evidence checkboxes, ticket decisions, and similar per-mode data (PvP and PvE are stored separately).
- Raider chats — If you use Profile → Chats, we store 1:1 messages you send, conversation metadata, and the usernames needed to deliver them. Messages are stored on our database provider’s servers; they are not end-to-end encrypted.
- Story groups — If you create or join a group, we store the group name, invite code, membership, and shared progress snapshots visible to group members.
- Feedback submissions — If you submit a bug report or suggestion while signed in, we store the title, description, category, page URL, and your account ID as reporter. Anonymous visitors cannot submit to the database-backed feedback form.
- Teamkill reports — If you submit a teamkill report, we store the names, description, weapon, map, rating, and submission timestamp you provide. Reports are intended for community viewing on the Teamkills page.
- Local browser data — Whether or not you have an account, the site stores progress, preferences, and UI state in your browser (
localStorageandsessionStorage), including game mode selection and unsynced progress. - PMC profile lookups — If you enter a public in-game Account ID on the PMC page, our server requests matching public profile data from tarkov.dev. We cache responses briefly on the server to improve performance. We do not need your BSG account password.
- Usage analytics — On production (
tarkovraiders.com), we load Google Analytics 4 to measure aggregate page views. IP anonymization is enabled. Analytics is not loaded onlocalhost. - Server logs — Our host (Railway) may log standard technical data such as IP address, request path, user agent, and timestamp for security, abuse prevention, and reliability.
How we use information
- Provide site features, including optional sign-in, cloud sync, chats, groups, and community submissions.
- Display public or community-facing content you choose to submit (for example, teamkill reports).
- Maintain, secure, and improve the service.
- Respond to feedback and investigate abuse or rate-limit violations.
- Understand aggregate traffic patterns (analytics).
We do not sell your personal information. We do not use your data for advertising profiles.
Legal basis (GDPR / UK GDPR)
If you are in the UK or EEA, we process personal data under these bases:
- Contract / steps at your request — Running an account, syncing your chosen progress, delivering chats, and operating groups when you sign up and use those features.
- Legitimate interests — Securing the site, preventing abuse, rate-limiting submissions, caching public game API responses, and measuring aggregate site usage with anonymized analytics. We balance these interests against your rights and offer opt-outs where practical.
- Consent — Where required for optional processing, we rely on actions you take (for example, choosing to sign in, sending a message, or submitting feedback). You can withdraw by stopping use of that feature or requesting deletion.
Cookies & similar technologies
- Essential browser storage — The site uses
localStorage/sessionStoragefor progress, settings, and session state. These are not advertising cookies. - Google Analytics — May set analytics cookies or use similar identifiers on
tarkovraiders.com. We enable IP anonymization. You can block analytics with browser extensions, privacy settings, or opt-out tools from Google. - Authentication — Supabase may store session tokens in browser storage while you are signed in.
We do not run a separate cookie banner today; non-essential analytics can be blocked with browser controls.
Third-party services
We rely on trusted providers. Each has its own privacy policy:
- Supabase — authentication, database, and realtime delivery for synced data, chats, feedback, and teamkill reports.
- Discord — optional OAuth sign-in when you choose it.
- Railway — website hosting, API proxying, and server logs.
- Google Analytics — aggregate usage measurement on production.
- Google Fonts — web font delivery (your browser requests fonts from Google).
- tarkov.dev — public game data and PMC profile lookups.
- Escape from Tarkov Wiki (Fandom) — reference images and guide content loaded by your browser.
Some providers may process data outside your country. Where required, they use appropriate safeguards (such as standard contractual clauses).
Data retention
- Cloud account data — Kept while your account is active. You can clear per-mode progress from Profile → Account. Full account deletion is available on request.
- Chats & messages — Kept until you or we delete the conversation/account, subject to operational backups for a limited period.
- Feedback & teamkill reports — Retained to operate those features and moderate abuse; may be removed on request where feasible.
- Local browser data — Stays on your device until you clear site data.
- Server logs & analytics — Retained for a limited period per our providers’ defaults.
Your rights (GDPR / UK GDPR)
Depending on where you live, you may have the right to:
- Access — Ask what personal data we hold about you.
- Rectification — Correct inaccurate profile data (many fields are editable in Profile).
- Erasure — Request deletion of your cloud account and associated synced data.
- Restriction — Ask us to limit certain processing.
- Portability — Request a copy of progress data you provided, where technically feasible.
- Object — Object to processing based on legitimate interests (for example, analytics).
- Withdraw consent — Stop using optional features or unlink Discord from your account.
- Complain — Lodge a complaint with your local data protection authority.
To exercise these rights, contact us on Discord or via the feedback form. We may need to verify your identity before acting on account-related requests.
Your choices without contacting us
- Use the site without an account — progress stays in your browser only.
- Clear site data in your browser settings.
- Block or limit analytics with browser privacy tools.
- Clear synced PvP or PvE progress from Profile → Account.
- Unlink Discord or add email sign-in from Profile → Account, where available.
Children
The site is not directed at children under 13 (or the minimum age in your region). We do not knowingly collect personal information from children.
Security
We use HTTPS, authenticated access controls, and row-level security on cloud data through our providers. No method of transmission or storage is completely secure.
Changes
We may update this policy from time to time. The “Last updated” date at the top will change when we do. Continued use of the site after changes means you accept the updated policy.
See also our Terms of Service.