Data controller and contact details
For personal data that -PTF- Armada decides how and why to process through ptfarmada.com and its community email, the data controller is -PTF- Armada, an independent, non-commercial Star Trek Online player community administered from the United Kingdom. Privacy enquiries and data-protection requests can be sent to contact@ptfarmada.com.
Data Protection Officer
-PTF- Armada has not appointed a Data Protection Officer (DPO). Privacy enquiries and data-protection requests are handled through contact@ptfarmada.com.
Personal data we process
Public browsing does not require you to create an account or provide a name. Ordinary technical request data may be processed when the site is used, such as IP address, browser or device information, requested pages, timestamps and security logs. Cloudflare processes that request and security metadata as part of delivering and protecting the site.
The Home and About pages make credentialless browser requests to Discord for approximate member or presence counts. The Home, About and Fleets public Fleet data is served through same-origin -PTF- Worker responses, normally from published Cloudflare R2 snapshots generated from the canonical Cloudflare D1 Fleet directory; D1 remains authoritative. The public Activity timeline and Resources directory use the same D1-authority/R2-publication model. Published Fleet, Activity and Resources information may also be exposed through same-origin public machine-readable responses used by the site and by permitted automated retrieval.
The Player Count and System Requirements Answers pages call same-origin -PTF- Worker endpoints. The Server Status tool and Answer instead read a dedicated public Cloudflare R2 status snapshot at status-data.ptfarmada.com. A scheduled -PTF- Worker refreshes that snapshot every five minutes by reading Cryptic's official launcher Up/Down state and maintenance text, selected Cryptic patch/login/routing diagnostics, and Valve/Steam activity. Those upstream status checks run independently of page visits, so the visitor's IP address, browser headers, cookies and page URL are not intentionally forwarded to Cryptic or Valve as part of the status check. The published status snapshot contains service state, diagnostic results, timing information and Steam activity only; it does not contain visitor identifiers. The browser request to the -PTF- status-data subdomain is delivered by Cloudflare and may involve the ordinary technical request metadata described above. The Player Count Worker separately queries Valve's public Steam player-count API, while the System Requirements Worker reads the official Arc Games requirements and cross-checks core fields against Epic Games Store.
If you email -PTF- Armada, your email address, message and any information you choose to include are processed so we can deal with the enquiry. Authorised administrators authenticate through Google Firebase. The Firebase user identifier for an authorised administrator may also be recorded in Cloudflare D1 change/audit fields when that administrator makes a managed change, so the change can be attributed and investigated if necessary.
Sources of public community information
Public community information such as in-game handles, fleet ownership, member or fleet names, creator/operator display names, public profile images and public service links may be supplied by the person concerned, supplied by authorised -PTF- officers or administrators, read from Star Trek Online community records, or taken from the public profile, page or service to which the directory entry relates. Where such information is published, it is used for the specific community-record, fleet-directory or Resources-directory purpose described on this site.
Fleet invite requests and anti-abuse
If you submit a Fleet Invite request, the faction and exact Character@Handle you provide are sent to the private -PTF- Discord invite queue so an authorised member can act on the request. The invite backend does not store that faction or Character@Handle in its D1 rate-limit database.
Cloudflare Turnstile is used to check the submission for abuse. On the Fleet Invite page, Turnstile processes security signals needed to distinguish human visitors from automated traffic, such as IP address and browser/network characteristics. -PTF- does not intentionally send the Character@Handle or faction to Turnstile as verification fields; those form values are submitted separately to the invite backend. Cloudflare supplies the request IP address to the invite backend for server-side verification; the raw IP address is not stored by -PTF- application code. For the rolling one-hour rate limit, the backend converts the IP address to a keyed HMAC-SHA-256 value and stores only that pseudonymous hash with accepted-request timestamps in D1. Rows older than one hour no longer count toward the rate limit. The backend removes expired rows when a later valid invite request runs its cleanup, so physical deletion can occur later if no further valid invite traffic occurs.
Public Activity archive
The public Activity timeline is a historical community record maintained by authorised -PTF- administrators. Canonical Activity records are held in Cloudflare D1 and published public entries are materialised into an R2 publication snapshot; managed Activity images are also stored in R2. Published entries may include Star Trek Online character or account handles, fleet or member names, screenshots, dates and links where they are relevant to the recorded event. Published Activity entries and their images are publicly visible and may be accessed by search engines or other automated/public retrieval systems under the site's published crawler policy. If you are identifiable in an Activity entry and want personal information corrected or reviewed for removal, email contact@ptfarmada.com.
Public community identifiers
Fleets may display recorded in-game fleet-owner handles, and Connect may publish leadership names, handles and contact routes supplied for that public community purpose. Published public content can be indexed or retrieved by search engines and permitted automated/AI systems. The site's automated-access permission does not apply to private or administrative data and does not waive privacy or data-protection rights. If you want a public community identifier corrected or reviewed for removal, email contact@ptfarmada.com.
Curated Resources directory
The public Resources directory may identify third-party Star Trek Online creators, community operators or resource maintainers by a public display name or handle and may use a public profile image, logo and links to their public services where those details are selected for directory inclusion. Canonical Resource card and editorial data are stored in Cloudflare D1; the published public Resources directory is materialised into a Cloudflare R2 publication snapshot, and managed card images are stored in R2. The private Resource Manager also records editorial verification details such as the image-source/provenance URL and last-checked date. Those editorial provenance fields remain in the private administrative/publication records and are excluded from the R2 public read model. If you are identifiable in a Resources listing and want information corrected or reviewed for removal, email contact@ptfarmada.com.
Browser-based tools
The Fleet Contributions and Fleet Hierarchy tools process the CSV files you choose locally in your browser. CSV contents are not uploaded to any -PTF- service. Fleet Hierarchy does not store a rank-order preference unless you explicitly select Remember rank order on this device. If selected, the preference is stored only in that browser's localStorage, keyed by fleet name, and is not sent to any -PTF- service. The tool provides a control to clear saved hierarchy orders. When you download a PNG, the file is created in your browser and includes visible and embedded provenance relevant to that tool, such as fleet identity and snapshot information.
Defender leaderboard
Defender requires a 2–12 character leaderboard display name before a run can start. The accepted name is held in browser memory for that page session; Defender does not store leaderboard names or score history in cookies, localStorage or sessionStorage. Before gameplay begins, the browser registers a random run session with the Defender service. When a winning run completes, the browser automatically sends the frozen display name and run-validation evidence so the server can reconstruct the score and decide whether it enters the current Top 10. If the score does not enter the Top 10, the display name is not inserted into the leaderboard.
Run-session records contain transport and validation metadata needed to verify and safely retry a completed submission, including a random run identifier and challenge, protocol/ruleset/seed values, timestamps and, after submission, a SHA-256 submission fingerprint plus the stored result. An unconsumed run session expires after 12 hours. Consumed result metadata remains available for exact-retry recovery for 24 hours after submission; after that point it is eligible for removal during normal cleanup. A failed completed submission can remain temporarily in browser memory for retry while the game page stays open; closing or reloading the page loses that unsent RAM-only payload.
The server retains only the current Top 10 leaderboard rows for the active scoring ruleset and removes displaced or obsolete entries. A current leaderboard row stores the display name, score and submission timestamp; the timestamp is used for deterministic ordering but the public leaderboard response exposes only rank, name and score. Defender application code does not store player IP addresses in the leaderboard database, although Cloudflare processes ordinary request and security metadata as part of delivering and protecting the service. For questions about a published leaderboard entry, email contact@ptfarmada.com.
Purposes and legal basis for processing
Where UK data-protection law applies, the main purposes and legal bases are:
- Website delivery, security and anti-abuse: legitimate interests in operating a secure, reliable non-commercial community service and protecting it from misuse.
- Fleet, Activity and Resources community records: legitimate interests in administering the Armada, maintaining accurate public community records and directories, and keeping published information current and useful.
- Fleet Invite requests: legitimate interests in providing the community function a person has voluntarily requested and preventing abuse of that service.
- Authorised administration and audit trails: legitimate interests in controlling administrative access, attributing managed changes, resolving faults and supporting rollback or recovery.
- Defender game and leaderboard: legitimate interests in operating the community game, validating runs, preventing score abuse and maintaining the current Top 10.
- Email and other enquiries: legitimate interests in responding to communications and administering the community. Where a request concerns rights or another obligation under data-protection law, processing may also be necessary to comply with that legal obligation.
For processing based on legitimate interests, -PTF- limits the information used to what is reasonably needed for the stated purpose, considers less intrusive alternatives and provides correction, removal and objection routes. Website personal data is not used for advertising or behavioural profiling.
Recipients of personal data
Recipients include the service providers and destinations needed to operate -PTF- Armada. These include Cloudflare for DNS, website delivery and security, Turnstile, D1 database services, R2 publication snapshots and media storage, and email routing; Google services for authorised Firebase authentication and the dedicated community email destination; and Discord for the Home/About approximate public member or presence counts and for delivering Fleet Invite submissions to the private -PTF- invite queue.
Where -PTF- intentionally publishes community information — for example Fleet owner handles, published Activity entries, Resources creator/operator details or Defender Top-10 names — recipients also include people who access the public site or its public machine-readable responses, including search engines and permitted automated/AI retrieval systems. Publication is limited to information selected for those stated public community purposes; private administrative fields are not intentionally included in public snapshots or responses. -PTF- Armada does not sell personal data and does not disclose website data to advertisers or data brokers. Each service provider handles information under its own service and data-protection terms.
International data transfers
Cloudflare, Google and Discord operate internationally, so limited information may be processed outside the United Kingdom, including in the United States. Where UK rules on restricted international transfers apply, the relevant provider's transfer safeguards and contractual arrangements apply. Cloudflare states that its current customer Data Processing Addendum is incorporated into its self-service agreement and provides UK transfer mechanisms including the UK Extension to the EU-U.S. Data Privacy Framework where applicable and EU Standard Contractual Clauses with the UK Addendum for restricted transfers. Google and Discord also publish international-transfer safeguards for their services, including contractual or recognised transfer mechanisms where required. Which mechanism applies can depend on the service and destination. You can ask contact@ptfarmada.com for available information about the safeguards relevant to a particular -PTF- processing activity.
Data retention period and criteria
-PTF- Armada does not maintain its own visitor analytics database. Website and security logs held by service providers are kept according to the providers' operational retention settings. Invite rate-limit rows contain only the keyed visitor hash and accepted-request timestamps. Rows older than one hour stop counting toward the limit; expired rows are physically removed when a later valid invite request runs the backend cleanup, so they can remain longer if there is no subsequent valid invite traffic. The submitted faction and Character@Handle are not stored in that D1 rate-limit database after delivery to Discord. Email correspondence, authorised-admin audit/change records and related administrative records are kept only for as long as reasonably needed to deal with the enquiry, maintain security/accountability, resolve a community matter, support rollback/recovery, or maintain a legitimate administrative record.
Defender leaderboard and run-session retention is described separately above. Published Activity entries and their media are intended to form a historical archive and may remain public until they are corrected, unpublished or removed because they are no longer appropriate to retain. Resources directory records, editorial verification details and managed card images may be retained while a listing remains current or while needed for publication rollback and directory maintenance; unreferenced media can be removed when it is no longer needed. Generated R2 publication snapshots mirror currently published Fleet, Activity and Resources data and are replaced or repaired as the authoritative D1 state changes. Information that is no longer needed is not intentionally retained by -PTF- Armada.
Providing information
You are not under a statutory or contractual obligation to provide personal data merely to browse the public site. If you choose to request a fleet invite, the faction and exact Character@Handle are required to perform that request. If you contact -PTF- by email or exercise a data-protection right, enough information is needed to understand and respond to the request.
Data subject rights
Where UK GDPR rights apply, your rights may include access, rectification, erasure, restriction of processing, objection and data portability. The rights that apply depend on the circumstances and lawful basis and are not absolute. To exercise a data-protection right or make a data-subject request, email contact@ptfarmada.com.
Right to object
Where -PTF- Armada relies on legitimate interests to process your personal data, you have the right to object to that processing. Email contact@ptfarmada.com and explain what processing you object to. We will consider the objection against the reason the information is being used and any applicable legal requirements.
Data-protection complaints
If you think -PTF- Armada has not handled your personal data in accordance with data-protection law, you can make a complaint by emailing contact@ptfarmada.com. We will acknowledge a data-protection complaint within 30 days, investigate it appropriately and communicate the outcome without unjustifiable or excessive delay. You do not need to use legal terminology when making a complaint.
Right to lodge a complaint with the ICO
You also have the right to complain to the United Kingdom supervisory authority, the Information Commissioner's Office (ICO). The ICO's current complaint routes are available at ico.org.uk/make-a-complaint/ (opens in new tab).
Automated decision-making
Defender automatically validates and ranks game scores for its Top 10 leaderboard. -PTF- Armada does not use personal data from this website for automated decisions that produce legal or similarly significant effects, and does not profile visitors for advertising.