Privacy Policy
Shinsa (shinsa.net) is the community platform for Pump Dojo, a Pump It Up arcade community. It tracks members' arcade scores, hosts events, and connects players. This policy explains what we collect, why, and the choices you have. Questions: pumpdojo@gmail.com.
What we collect
- Account details — username, email address, and a password stored as a salted hash. Optional profile fields (bio, avatar, nationality, date of birth) are only shown as you configure them.
- Gameplay data — scores, plays, grades, ratings, and rankings, either entered in the app or imported from your linked arcade profile.
- Arcade profile credentials — if you link your PIUGAME account, your PIUGAME login is stored encrypted (AES-256-GCM) and used solely to sync your own scores on your behalf. It is never displayed, shared, or used for any other purpose.
- Optional health data — heart-rate readings you choose to record during play sessions. Never required, never shared.
- Venue activity — dojo check-ins, memberships, and bookings for the physical venue.
- Instagram business messages — when an authorised administrator connects Pump Dojo's professional account, we store the customer messages, Instagram-scoped identifiers, public profile details, attachment links, and timestamps needed to provide the shared support inbox described below.
Google user data (YouTube)
You can optionally link a YouTube account so Shinsa can find your own uploaded gameplay videos and live-stream archives, and attach timestamped replay clips to your plays.
- We request the read-only YouTube scope (
youtube.readonly). We can list and read metadata of your channel's videos. We cannot upload, edit, delete, or post anything. - We access video titles, IDs, durations, and publish times of your own channel's uploads — only to match them to your recorded plays and build replay links.
- OAuth tokens are stored encrypted and used only for this feature. We do not transfer YouTube data to third parties, do not use it for advertising, and no humans read it except as needed for support you request, security, or legal compliance.
- Unlinking YouTube in the app deletes the stored tokens. You can also revoke access at any time at myaccount.google.com/permissions.
Shinsa's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Instagram business messaging data
An authorised Shinsa administrator may connect an Instagram professional account so the Pump Dojo team can receive and answer customer messages in a shared admin inbox.
- We request
instagram_business_basicandinstagram_business_manage_messages. We use them only to identify the connected professional account, receive its customer conversations, and send replies requested by an administrator. - The shared inbox stores customer message text, supported attachment URLs, timestamps, Instagram-scoped IDs, and available profile details such as username, display name, profile photo, verification, and follow status. These are visible only to authenticated Shinsa administrators responsible for the business inbox.
- The professional account's access token is encrypted with AES-256-GCM. Instagram data is not sold, used for advertising or profiling, or used to train machine-learning models.
- Disconnecting Instagram deletes the encrypted token and Shinsa's stored copy of its threads and messages. Meta's deauthorization and data-deletion callbacks do the same automatically. This does not delete the original conversation from Instagram.
How we use data
- To run the service: profiles, leaderboards, score history, events, and replays you choose to share.
- To sync your own arcade scores when you link your PIUGAME profile.
- To operate the venue: check-ins, memberships, and loyalty progress.
- To let authorised Pump Dojo administrators receive and answer messages sent to the connected Instagram professional account.
We do not sell personal data, and we do not share it with third parties except payment processing (Square, for memberships — we never see your full card details) and hosting infrastructure required to run the service.
How we protect your data
Google user data and other sensitive information are protected by the following measures. Every claim here describes a control that is actually in place; we do not list aspirations.
- In transit. All traffic between your device and Shinsa, and between Shinsa and Google's APIs, is encrypted with HTTPS/TLS. The service is not reachable over plain HTTP.
- At rest. Google and Instagram OAuth tokens, and any linked arcade-account credentials, are encrypted with AES-256-GCM before they are written to the database. The encryption keys live in the server's environment configuration, not in the database, so a copy of the database alone does not reveal them.
- Passwords. Account passwords are hashed with bcrypt and are never stored, logged, or transmitted in plaintext. We cannot read your password.
- Least privilege. We request only the read-only
youtube.readonlyscope. The integration cannot upload, edit, delete, or post to your channel, and reads only the signed-in user's own channel — never anyone else's. - Access control. Every request for your data requires an authenticated session bound to your account, and administrative functions are restricted to named operator accounts. Google user data is not exposed through any administrative or public view.
- No onward transfer. Google user data is never sold, never shared with third parties, never used for advertising or profiling, and never used to train machine-learning models. It is not read by any person except where you request support, or where required for security or law.
- Deletion. Unlinking YouTube in the app deletes the stored tokens immediately. Deleting your account removes your data, and you can independently revoke our access at any time at myaccount.google.com/permissions.
- Limited retention. We store only the video and broadcast metadata needed to display your own replay links — identifiers, titles and timestamps. We do not download, copy, or host your video content.
If you believe your account or data has been compromised, contact pumpdojo@gmail.com and we will investigate and respond.
Retention & deletion
Data is kept while your account is active. You can delete your account at any time from My Account → Delete account in the app (you will be asked for your password to confirm). Deletion is immediate and cannot be undone. You can also email pumpdojo@gmail.com and we will action the request within 30 days.
When you delete your account we permanently remove:
- your profile (username, email, avatar, bio and every other profile field) and your login;
- everything you posted — posts, comments, stories, direct messages, replies, reviews, lists, event RSVPs and waiver signatures, live-session chat;
- your score history, imported plays, rankings, heart-rate readings and check-ins;
- your linked-service credentials and tokens (PIUGAME, YouTube), API tokens, push subscriptions and notifications;
- your follows, blocks and the reports you filed.
What we keep, and why:
- Payment and order records (amount, date, what was bought) are retained for accounting and tax purposes, re-attributed to an anonymous system account with your name, address and email removed.
- Public reference data you contributed to the World Max arcade map (machine and venue records) stays, no longer attributed to you.
- Other people's history that mentions you — a tournament bracket, a weekly-challenge leaderboard — keeps its shape with your entry shown as "Deleted player".
- Reports other members made about your content are kept for moderation records, with your identity removed.
Instagram shared-inbox data is tied to the connected professional account rather than an individual Shinsa member. An administrator can delete it immediately with the Disconnect Instagram control; it is also removed when Meta sends a valid deauthorization or deletion request.
Reports, blocks and moderation
- When you report content or an account we store the report (what you flagged, the reason you chose, any note you added, and your account as the reporter) so our moderators can review it. Reporters are never revealed to the person reported.
- When you block someone we store that relationship so we can hide their content and stop interactions between you. Blocks are private; the other person is not notified.
- Moderators can see reported content, who reported it and what action was taken. See our Community Guidelines for what we act on and how.
Changes
If this policy changes materially we will note it in the app. Continued use after a change means you accept the updated policy.