Skip to main content

Privacy Policy

Last updated: July 27, 2026 - Version 1.1

Courtesy translation. In case of any discrepancy, the French version prevails. Version française.

This policy describes how JDR Ninja (“we”, “our”, “us”) collects, uses and protects your personal information when you visit jdr.ninja. It is drafted in accordance with the Act respecting the protection of personal information in the private sector of Quebec (Law 25) and the European Union General Data Protection Regulation (GDPR).

1. Who we are

JDR Ninja is a collaborative directory dedicated to francophone tabletop role-playing game creators and resources, operated by JDR Ninja, a self-employed worker registered in Quebec, Canada.

For the purposes of Law 25 and the GDPR, JDR Ninja acts as controller (GDPR) and as the person exercising the highest authority within the enterprise for the purposes of protecting personal information (Law 25). This same person is designated as the person in charge of the protection of personal information (RPRP).

RPRP contact details: [email protected]

2. What data we collect

2.1 Data collected automatically

When you browse the site, our servers automatically record:

  • Your IP address, temporarily kept in the server access logs (14 days).
  • Your user agent (browser type, operating system).
  • The pages viewed, request timestamps, HTTP response code and processing time.
  • The essential cookies required for the operation of the site (see section 8).

2.2 Data you voluntarily provide to us

When you use the Contact form (for a question, a technical issue or to suggest a creator), we collect:

  • Your name or pseudonym.
  • Your email address (required, used only to reply to you).
  • The category of your request and the content of your message.

This information is not stored in our database: your message is sent directly to our team through a private Discord channel (Discord Inc., United States), where it may be kept for the time needed to process your request. By submitting the form, you consent to this transfer.

2.3 Dojo account data (if you create an account)

If you create a public account on the Dojo, we collect:

  • Your email address (required, used for authentication and account-related communications).
  • Your password, stored as an irreversible cryptographic hash (bcrypt) - we do not have access to your plain-text password.
  • A public username (displayed nickname, between 3 and 30 characters, alphanumeric).
  • An optional display name.
  • The date and time the account was created.

If you choose to sign in through a third-party provider (Google, Microsoft, Discord, Twitch or Facebook), that provider sends us your email address and profile name. No other information from the provider is stored. Sign-in through a third-party provider is entirely optional; you can always create an account with an email address and password.

2.4 “Find a Table” data

If you publish a listing or apply to a listing through the Find a Table feature, we also collect:

  • The listing content: title, short and long description, game system, language, availability, experience level, game format, number of open seats.
  • An optional public location (area, city, region, country) - intended to be displayed to all visitors.
  • An optional private location (place label, latitude and longitude, place identifier) - used only to calculate distance during a radius search. These fields are never displayed publicly and remain visible only to you and to the moderation team. You may choose to share the precise address in the private conversation with an applicant once you have accepted their application. When you enter an address using Google Places autocomplete on the listing creation or editing form, your partial input is sent to Google LLC servers (United States) to provide suggestions; no other page on the site loads a Google Places script.
  • The content of the applications you send (introduction message, answers to custom questions). This content is visible only to the organizer of the targeted listing and to the moderation team.
  • The content of messages exchanged in private conversations opened following an application. Visible only to both parties and to the moderation team in case of a report.
  • The blocks you set up (whom you blocked and why).
  • The reports you submit (target, reason, optional details, HMAC-SHA256 cryptographic fingerprint of your IP address, user agent - for anti-abuse audit purposes).

Notification emails sent as part of this feature (new application, conversation opened, new message, application not selected) are deliberately generic: they never contain the listing title, the content of a message, your answers to a question, or any contact details. You must sign in to the site to view the details.

2.5 What we do not collect

  • No newsletter, therefore no marketing mailing list.
  • No sensitive data within the meaning of Law 25 (ethnic origin, political or religious opinions, sexual orientation, biometric or health data) is requested or processed.
  • No payment data: the site currently offers no commercial transactions.
  • No automatic geolocation: a listing location is entered only at your explicit request, and radius search is activated only if you provide coordinates yourself.

3. Why we collect this data (purposes)

  • Provide the service: display pages, manage sessions for signed-in users, prevent attacks (CSRF, application denial of service).
  • Create and manage your Dojo account: allow you to register, authenticate (by email/password or through a third-party provider), customize your username and access member-only features.
  • Process creator submissions: review, validate and, where applicable, publish a creator profile. Contact you by email about your submission.
  • Security and anti-abuse: detect and prevent malicious submissions, spam and automated attacks. Access logs are consulted occasionally in the event of an incident.
  • Anonymized audience statistics (only if you consent via the cookie banner): understand how the site is used in order to improve it. No individual data is used for commercial purposes.
  • Legal compliance: keep proof of cookie consent (Law 25, GDPR) and respond to requests from competent authorities when required by law.

4. Legal basis for processing

For visitors located in Quebec and Canada, we rely on consent (Law 25, art. 12) for processing that is not strictly necessary, and on necessity for the performance of the service for essential processing.

For visitors located in the European Union, the GDPR legal bases are as follows:

  • Legitimate interest (art. 6.1.f): site security, abuse prevention, technical access logs.
  • Performance of a contract (art. 6.1.b): processing your creator submission when you write to us; creating and managing your Dojo account.
  • Consent (art. 6.1.a): analytics and marketing cookies, third-party video integrations (Twitch, YouTube).
  • Legal obligation (art. 6.1.c): keeping proof of consent.

5. Processors and sharing of your data

We do not sell, rent or exchange your personal information. We do, however, use technical processors necessary for the operation of the site:

Processor Service Data location
Microsoft Corporation (Azure) Application database Canada Central (Toronto)
Amazon Web Services (AWS) File storage (images, documents) ca-central-1 (Montreal)
Cloudflare, Inc. Content delivery network (CDN) for images and static files Global points of presence (the IP address transits through the nearest point of presence for caching)
Twitch Interactive, Inc. (Amazon) Live stream integration (only with your consent) United States
Google LLC (YouTube) Live video integration (only with your consent, through the youtube-nocookie.com domain) United States
Google LLC (Analytics 4) Anonymized audience measurement (only if enabled and with your consent) United States
Google LLC (Places API) Address autocomplete on “Find a Table” listing creation and editing forms - loaded only on those pages, never on the rest of the site United States
Amazon Web Services (SES) Sending transactional emails related to the Dojo account (address confirmation, password reset) ca-central-1 (Montreal)
Discord Inc. Receiving messages from the contact form (name, email, message), transmitted to a private channel of our team United States
Google LLC (Google sign-in) Authentication through a Google account - only if you choose this sign-in option United States
Microsoft Corporation (Microsoft sign-in) Authentication through a Microsoft account - only if you choose this sign-in option United States
Discord Inc. Authentication through a Discord account - only if you choose this sign-in option United States
Twitch Interactive, Inc. (Twitch sign-in) Authentication through a Twitch account - only if you choose this sign-in option United States
Meta Platforms, Inc. (Facebook) Authentication through a Facebook account - only if you choose this sign-in option United States

The application runtime infrastructure (web server) is also hosted in Canada.

Each of these providers is bound to us by contractual commitments (processing clauses or terms of service incorporating legal obligations) guaranteeing confidentiality, security and limited use of your data for the purposes described.

6. Transfers outside Quebec and outside the EU

For users in Quebec and Canada (Law 25, art. 17)

Data collected as part of the service (database, files, logs) is stored and processed in Canada. No systematic transfer of your personal information outside Quebec takes place.

Exceptions concern third-party integrations that you activate through your consent (Twitch, YouTube, Google Analytics), whose servers are located in the United States. By activating these integrations through the cookie banner, you consent to this transfer. If you do not want this, simply refuse these cookie categories.

If you use sign-in through a third-party provider (Google, Microsoft, Discord, Twitch or Facebook), your email address and profile name transit through that provider's servers in the United States as part of the OAuth 2.0 authentication protocol. This transmission takes place only if you explicitly initiate sign-in through that provider; it does not occur during simple browsing of the site.

If you use the contact form, the information you enter (name, email, message) is transmitted to a private channel of our team hosted by Discord Inc. (United States). This transmission occurs only when you voluntarily submit the form.

For users in the European Union (GDPR, Chapter V)

Data transfers to Canada are governed by the partial adequacy decision of the European Commission of December 20, 2001 (Decision 2002/2/EC), which recognizes an adequate level of protection for Canadian commercial organizations. Your data is therefore protected by a framework comparable to the GDPR when processed in Canada.

For transfers to the United States (Twitch, YouTube, Google Analytics, Discord), we rely on the European Commission's standard contractual clauses and on the additional encryption and minimization measures implemented by these providers.

7. Retention periods

Category Retention period
Server access logs (including IP address) 14 days, then automatic deletion
Authentication cookie (ninja_auth) 2 sliding hours / 12 absolute hours (Dojo and Sanctum accounts)
Anti-forgery cookie (.AspNetCore.Antiforgery.*) Session
Dojo account data (email address, username, display name) Kept until account deletion (irreversible anonymization, triggerable at any time from your profile), or 3 years after the last sign-in in case of inactivity
Consent cookie 12 months (renewed consent request each year)
Proof of consent (internal register) 3 years after the last consent (legal limitation period)
Creator submissions (form) 3 years after the final decision (acceptance, refusal or abandonment)
Analytics cookies (if enabled) Up to 13 months (CNIL recommendation)

At the end of these periods, data is deleted or irreversibly anonymized. Anonymized data is no longer considered personal information.

8. Cookies and trackers

We use cookies to ensure the operation of the site and, subject to your consent, for audience measurement and the integration of third-party content.

Cookie categories

  • Essential cookies (always active): necessary for the operation of the site. They include the authentication cookie (ninja_auth) for Dojo and Sanctum accounts, the request forgery protection token (.AspNetCore.Antiforgery.), and the OAuth correlation cookie (.AspNetCore.Correlation.) temporarily placed during sign-in through a third-party provider. No consent is required for these cookies.
  • Analytics cookies (consent required): anonymized audience measurement if enabled. Disabled by default.
  • Third-party content cookies (consent required): placed by Twitch and YouTube when you load an embedded video player. Disabled by default.

Local storage

In addition to cookies, one value is saved in your browser's local storage when you accept analytics cookies:

  • jdrn_cp (consent required): contains only a date. We use it to send the measurement described below once a day rather than on every page. This value is erased as soon as you withdraw your consent to analytics.

Display measurement

To adapt the site's layout to the screens actually in use, we measure two distinct things.

  • Without consent, and without placing anything on your device: we infer whether you are on a mobile device or a computer from the information your browser sends of its own accord with every request (the User-Agent header and, on browsers that send it spontaneously, the Sec-CH-UA-Mobile indication). We never ask your browser for additional information. This measurement relies on our legitimate interest in keeping the site readable on our visitors' devices.
  • With your consent to analytics only: once a day, we record the size of your window (in ranges, never the exact value), your screen's pixel density, the presence of a touchscreen, and your light or dark theme preference. We collect neither your screen's physical resolution, nor your time zone, nor your browser's language, nor the list of your fonts: that information would serve to identify you more than to improve the site.

These measurements are kept in aggregate form and attached to a temporary identifier that changes every day. They do not allow us to recognize you from one day to the next.

Manage your preferences

You may change your choices at any time through the cookie banner displayed on your first visit, or through the Cookie Preferences page. Withdrawing consent is as easy as giving it.

9. Your rights

You have the following rights regarding your personal information:

  • Right of access (Law 25 art. 27 / GDPR art. 15): obtain confirmation that your data is being processed and receive a copy.
  • Right to rectification (Law 25 art. 28 / GDPR art. 16): have any inaccurate or incomplete data corrected.
  • Right to erasure (Law 25 art. 28.1 / GDPR art. 17): request deletion of your data when it is no longer necessary.
  • Right to portability (Law 25 art. 27 para. 3 - in force since September 22, 2024 / GDPR art. 20): receive your data in a structured and commonly used technical format.
  • Right to withdraw consent (Law 25 art. 14 / GDPR art. 7): withdraw your consent at any time, as easily as you gave it.
  • Right to stop dissemination and to de-indexing (Law 25 art. 28.1): request that your data no longer be disseminated or that hyperlinks leading to it be de-indexed from search engines.
  • Right to object (GDPR art. 21): object to processing based on legitimate interest.
  • Right to restriction (GDPR art. 18): request suspension of processing in certain cases.
  • Right to define post-mortem instructions (Law 25 art. 40.1): specify what should happen to your data after your death.

To exercise any of these rights, write to our RPRP at [email protected]. We will respond within a maximum of 30 days (Law 25 art. 32 and GDPR art. 12.3). Proof of identity may be requested to process your request.

9.1 Self-service account deletion

If you have a Dojo account, you can exercise your right to erasure directly from your profile, without having to write to us:

  • Sign in, open My Profile and use the “Delete my account” button in the danger zone.
  • Confirmation is required (current password or confirmation phrase for accounts connected through an external provider).

Deletion proceeds by irreversible anonymization, an alternative to destruction expressly authorized by Law 25 (art. 23) and by the Quebec Regulation respecting the anonymization of personal information (in force since May 2024), as well as by the GDPR (recital 26).

What is immediately anonymized or deleted:

  • Email address, username, display name, profile identifier, phone number and time zone - overwritten with non-reidentifying values.
  • Password (already stored as a cryptographic hash) - deleted.
  • Connections with external providers (Google, Microsoft, Discord, Twitch, Facebook) - deleted.
  • Authentication tokens and custom claims - deleted.
  • Proof of cookie consent associated with your account (including the cryptographic fingerprint of your IP and your user agent) - deleted.

What is retained without a personal link:

  • Internal audit logs: kept for security and abuse detection purposes, but the link to your account is broken (user field set to NULL).
  • The files you uploaded: kept if they are used by published content, but without any link to your identity.
  • The creator submissions you reviewed (if you were a team member): the review remains recorded, but the link to your account is broken.
  • The blog articles published under your author signature (where applicable): they remain online with their display name, with your account no longer attached to them. A specific request to the RPRP is required to also anonymize the public signature.

The operation is irreversible: your account row is kept in the database (with identifying fields overwritten) to preserve the referential integrity of data retained without a personal link, in accordance with art. 23 para. 2 of Law 25. You will still be able to create a new account later with the same email address.

10. Automated decisions

JDR Ninja does not use any automated decision-making that has a legal effect or a significant effect on you (Law 25 art. 12.1 / GDPR art. 22). Directory creators and resources are added and reviewed manually by a human person before publication.

11. Security

We implement reasonable technical and organizational measures to protect your data:

  • Encrypted communications by default (HTTPS/TLS across the entire site).
  • Submission IP addresses stored as salted cryptographic fingerprints (not in plain text).
  • Limited administrator access, protected by a complex password (minimum length 12 characters, complexity requirements) and an 8-hour session expiration.
  • Traffic limiting (rate limiting) on public forms to prevent abuse.
  • Logs kept for 14 days only, on Canadian hosting infrastructure.
  • Regular security updates for software components.

In accordance with Law 25 (art. 3.5) and the GDPR (art. 33-34), we will promptly notify the Commission d'accès à l'information (CAI), the CNIL where applicable, as well as the persons concerned in the event of a confidentiality incident presenting a serious risk of harm.

12. Minors

JDR Ninja is intended for an adult and teenage audience interested in role-playing games. We do not knowingly collect personal information from children under 14 (threshold provided by Law 25 art. 4.1) or under 15 (threshold provided by the French law implementing the GDPR).

If you are a parent or guardian and notice that a minor under your responsibility has sent us personal information, contact us at [email protected] and we will delete it.

13. Changes to this policy

This policy may be updated to reflect legal, technical or operational changes. The last updated date and version number appear at the top of this page.

In the event of a substantial update (new processing, new processor, change of purpose), the cookie banner will reappear so that you can review your consent.

14. Complaints to authorities

If you believe that your rights are not being respected, you may first write to us at [email protected]. If our response does not satisfy you, you may file a complaint with the competent data protection authority:

15. Contact of the person in charge of the protection of personal information

JDR Ninja

Person in charge of the protection of personal information (RPRP)

Email: [email protected]

Any request relating to your personal information will receive a response within a maximum of 30 days.

}