Privacy Policy
1. Operator
AllianceMate is an independent alliance tool for Whiteout Survival, run by Wonder Walk, Inc., based in Delaware, United States. Contact: support@alliancemate.com.
AllianceMate is not affiliated with, endorsed by or sponsored by Century Games. Whiteout Survival and related names belong to their respective owners.
2. Data Collected
- Account: username, password (stored only as a salted hash), account creation time, last visit, display settings, and the invite link or code an account arrived from.
- Game screenshots and what is read from them: Chief Profile, alliance member lists, Bear Trap damage, battle result mail and troop screenshots. Reading extracts player names, game IDs, State numbers, alliance tags and ranks, Power, Furnace level, troop levels, damage and similar game numbers. Screenshots uploaded by R4/R5 can include the names and numbers of alliance members who have no account.
- Data entered on the site: Furnace & Troops, rally plans, Trap Layout positions, attendance, event schedules, alliance announcements, Away periods, support tickets and feedback.
- Discord (optional): when an account is linked to Discord, only the Discord user ID, username and avatar are stored (the "identify" permission). No email address, server list or messages.
- Discord bot (optional): when R4/R5 add the bot and link a channel, the server ID, the channel ID and name, the chosen role (ID and name), the Discord user ID of the R4/R5 who ran /setup and the IDs of messages the bot posts are stored. When a member taps That's Me and then Yes or picks a name in Discord, the Discord user ID, username and avatar are stored (same as Discord login); the server nickname and display name are only used to suggest a name and are not stored. When the bot gives a role, the Discord user ID, server and role are stored so the role can be removed when the chief leaves the alliance or is unlinked. Link attempts through the bot are counted per Discord user ID for rate limits and deleted within one day. The bot does not read channel messages.
- Waitlist: email address, plus State number, alliance tag, alliance size and current tool when provided.
- Payments: Alliance Plan payments are processed by Stripe. Card numbers and bank details go directly to Stripe and never reach AllianceMate. AllianceMate keeps the Stripe customer and subscription IDs and the amount, currency, status and dates of each order.
- Technical data: IP addresses are counted in memory for rate limits; web server logs (IP address, browser user agent, page requested, time) are kept up to 90 days for security and troubleshooting; error logs; last active time, shown only inside the alliance.
3. Use of Data
- Running the alliance tools: member lists built from screenshots, chiefs linked to accounts, attendance, rally plans, Trap Layout and event calendars for the alliance.
- Keeping the site safe: rate limits, abuse prevention, and a log of management actions so changes can be undone.
- Alliance Plan payments, receipts and refunds.
- Waitlist emails: launch news about AllianceMate only.
- Answering support tickets.
AllianceMate does not sell personal data, does not show ads and does not share personal data for advertising.
4. Who Sees What
Personal Power, Furnace & Troops and positions are visible by default only to verified members of the same alliance and to R4/R5 and State Managers. Other alliances, other states and unverified accounts see none of it.
- Not logged in: only the names on an alliance Members page (used for linking chiefs), no data.
- Logged in, not verified: only their own day and the chief they linked; alliance and state data stay hidden to stop impersonation.
- Verified members of the same alliance: member data and rally plans of the alliance, plus online status and the last time each member used AllianceMate (shown only inside the alliance).
- R4/R5 and State Managers: view and edit data within their own scope (every management action is logged).
- Verified members of other alliances in the same state: by default the Members page, rankings, Trap Layout and member data of the alliance (State Public, view only; R4/R5 can turn it off).
- Players from other states and visitors: only the public alliance info: name, member count, Alliance Leader and rank. Exceptions: the alliance is set to Public to All, or R4/R5 approves a request.
5. Visibility Settings
- Alliance data visibility: R4/R5 set it in Edit Alliance or Management: State Public (on by default, can be turned off) / Public to All (off by default).
- Leaderboard is opt-in: the state leaderboard shows only chiefs who turned on Show Publicly; off by default. The switch is on the Me page.
- Two-step verification: a Chief Profile screenshot only verifies the game chief; access inside an alliance also needs the Join Password or approval from R4/R5. Typing a name alone is not verification.
- Screenshots are only for reading: reading happens on our own machines; nothing is sent to any third party.
- Discord login: only the Discord user ID, username and avatar are stored. No email, server list or messages. Unlink on the Me page.
6. Sharing
- Hosting: data is stored on a cloud server in the United States.
- Stripe processes Alliance Plan payments under its own privacy policy: stripe.com/privacy.
- Discord receives the login request only when a user chooses Discord login: discord.com/privacy.
- Discord bot: for alliances whose R4/R5 added the bot, reminders, attendance images and copy text (including absent names) are sent to the linked Discord channel; R4/R5 can turn off attendance posts or unlink the channel in Alliance Info. Anyone in that channel who taps That's Me sees the names, ranks, former names and roles (Rally Leader, Joiner…) of chiefs not yet linked (no Power), the same as the Invite Link page. Link results, including the linked chief name, are shown only to the member who tapped.
- Legal requests: data is disclosed only when required by law or to protect the safety of users and the site.
7. Cookies and Local Storage
- session: keeps a user logged in; renewed on each visit, expires after 90 days without a visit. Necessary for the site to work.
- ev_game: remembers the game version of the site; 1 year.
- ew_ref / ew_src: set only when a page is opened from an invite link with a referral code; records which invite brought a new account; 30 days.
- Local storage on the device keeps display preferences such as theme and sort order.
No analytics, advertising or third-party cookies. Stripe Checkout runs on stripe.com under the Stripe cookie policy.
8. Retention and Deletion
- Account data is kept while the account exists.
- Delete Chief Record on the Me page unlinks the chief and deletes its record, history and positions. R4/R5 of the alliance or Support can delete personal data and screenshots. A wrongly linked name is fixed by R4/R5 as well.
- Deleting a whole account and its data: Delete Account on the Me page, the Support page or support@alliancemate.com; completed within 30 days.
- Screenshots are kept with the record they belong to; a deletion request through Support covers them as well.
- Waitlist entries are deleted after launch news is sent, or earlier on request.
- Payment records are kept as long as tax and accounting rules require.
- Database backups rotate out after [BACKUP DAYS] days; deleted data can remain in a backup until then. Web server logs: up to 90 days.
9. Rights
- Any user can ask for a copy of personal data, a correction, deletion or an export by writing to support@alliancemate.com. Requests are answered within 30 days; proof of account ownership can be required.
- EU and UK: data is processed to provide the service requested (contract), for security and alliance features that show members named in alliance screenshots (legitimate interests), for the waitlist (consent, which can be withdrawn at any time) and for payment records (legal obligation). A complaint can be made to the local data protection authority.
- California: AllianceMate does not sell or share personal information for cross-context behavioral advertising.
10. Children
AllianceMate is not for children under 13 and does not knowingly collect data from them. Accounts found to belong to a child under 13 are deleted. Reports: support@alliancemate.com.
11. International Use
AllianceMate is run from the United States. Data from users in other countries is transferred to and stored in the United States.
12. Security
Connections use HTTPS, passwords are stored only as salted hashes and admin access is limited and logged. No system is completely secure; security problems can be reported to support@alliancemate.com.
13. Changes
Updates to this policy are posted on this page with a new date. Significant changes are announced on the site before they take effect.
14. Contact
Wonder Walk, Inc. · support@alliancemate.com · Support · Terms of Service