← Back to Baron Buff
BARON BUFF
Privacy Policy
Last updated: April 2, 2026
Baron Buff ("Baron Buff," "we," "us," or "our") provides game-related software and online services, including our website, application, desktop connector, subscriptions, premium features, one-time purchases, add-ons, and related features (collectively, the "Services").
This Privacy Policy explains how we collect, use, disclose, store, and protect personal data when you use the Services. Baron Buff operates from Brazil. Our infrastructure and certain service providers may process personal data in the United States and other countries.
1. Scope
This Privacy Policy applies to personal data processed when you:
- visit our website;
- create or use a Baron Buff account;
- sign in with email/password or Google;
- connect eligible game-related features;
- use profile, history, preference, premium, or billing features;
- make a purchase, subscribe, manage a subscription, or use a billing portal;
- contact us; or
- subscribe to product updates or marketing communications.
This Privacy Policy does not apply to third-party websites, products, or services that are not operated by Baron Buff.
2. Controller
For purposes of applicable data protection law, Baron Buff is the controller of the personal data described in this Privacy Policy.
Contact: [email protected]
3. Personal Data We Collect
We collect only the personal data reasonably necessary to provide, secure, support, and improve the Services.
3.1 Data you provide directly
Depending on how you use the Services, this may include:
- email address;
- display name or profile name;
- marketing communication preferences;
- billing name, billing address, country, tax or invoice details, where applicable;
- messages, requests, or support communications you send to us.
3.2 Account and authentication data
If you create an account or sign in, we may process:
- account identifiers;
- sign-up, sign-in, verification, and password-reset events;
- authentication, token, and session data needed to secure and operate the Services.
If you sign in with Google, we may receive basic account information made available through that sign-in flow, such as your email address, profile identifier, and profile information needed to authenticate you and create or access your Baron Buff account.
3.3 Payment, billing, and transaction data
If you make a purchase, subscribe, or use paid features, we or our payment processor may process:
- purchase and subscription records;
- billing and invoicing information;
- payment status, transaction identifiers, renewal dates, and cancellation status;
- country, currency, tax information, and tax identifiers where required for billing or invoicing;
- limited payment-method details or metadata made available to us by the payment processor, such as card brand, card expiration month/year, funding type, country, or last four digits, where applicable.
We do not store full payment card numbers or payment security codes in our own systems.
3.4 Game account and feature data
If you use connected product features, we may process:
- linked game account information detected through the connector flow, such as summoner name, tag, region, and a connector-verified internal identifier;
- saved preferences, including custom champion-pool settings;
- post-game history, saved outputs, and related metadata associated with your Baron Buff account;
- entitlement and access status for premium features, subscriptions, one-time purchases, or add-ons.
3.5 Technical and usage data
We may automatically collect limited technical data, such as:
- IP address and approximate location inferred from IP;
- browser, device, and operating system information;
- timestamps, log data, and security events;
- usage events, feature interactions, and navigation data;
- cookie and similar technology data;
- anti-fraud, abuse-prevention, and risk signals associated with account, authentication, or payment activity.
3.6 Data we do not collect
We do not collect:
- Riot Games account credentials;
- in-game chat content;
- precise geolocation;
- full payment card numbers or payment security codes in our own systems;
- special category or sensitive personal data unless expressly required and lawfully permitted.
4. How We Use Personal Data
We use personal data to:
- create, maintain, and secure Baron Buff accounts;
- authenticate users and manage login sessions;
- enable Google sign-in and account recovery flows;
- operate core product features;
- link eligible game accounts detected through the connector flow;
- save profile settings, communication preferences, entitlements, and game history;
- process purchases, subscriptions, renewals, cancellations, invoices, taxes, refunds, credits, and related billing operations;
- provide customer support and respond to requests;
- send service-related notices, including billing, account, security, and transactional communications;
- send marketing communications where permitted by law and, where required, based on consent;
- monitor, prevent, and investigate fraud, abuse, unauthorized access, payment risk, chargebacks, and other security issues;
- analyze product usage, performance, reliability, and commercial operations;
- comply with legal obligations and enforce our terms.
5. Legal Bases for Processing
Where the LGPD applies, we process personal data under one or more of the following legal bases, as applicable:
- performance of contract or preliminary procedures related to a contract, when processing is necessary to provide the Services you request;
- consent, including for marketing communications where consent is required;
- legitimate interests, including service security, fraud prevention, abuse prevention, product improvement, customer support, billing administration, and operational management, provided that such interests are not overridden by your rights and freedoms;
- compliance with legal or regulatory obligations, including tax, accounting, consumer, and recordkeeping obligations, where applicable;
- regular exercise of rights in judicial, administrative, or arbitration proceedings, where applicable.
You may withdraw consent at any time where processing is based on consent. Withdrawal does not affect prior lawful processing.
6. Cookies and Similar Technologies
We may use cookies and similar technologies for:
- essential site and security functions;
- authentication and session continuity;
- remembering preferences;
- analytics and performance measurement;
- billing, checkout continuity, fraud prevention, and account security;
- advertising or conversion measurement, if enabled in the future.
Where required by applicable law, we will request consent before using non-essential cookies or similar technologies.
7. Authentication and Payment Providers
We use Amazon Web Services Amazon Cognito to support account authentication and identity management. This may include email verification, password-reset flows, token-based session management, and related security features.
If you choose to sign in with Google, Google and Cognito may process your information to authenticate you and return you to the Services.
If you purchase paid features, we may use Stripe or another payment processor to process payments, manage subscriptions, support checkout, manage billing information, issue or display invoices, and support related billing operations. Payment processors may process personal data in accordance with their own privacy policies and legal obligations.
8. Sharing of Personal Data
We do not sell personal data.
We may share personal data only as reasonably necessary with:
- cloud and infrastructure providers, including AWS;
- security, CDN, and networking providers, including Cloudflare;
- authentication providers, including Amazon Cognito and, where you choose that method, Google;
- payment processors and billing service providers, including Stripe;
- analytics, communications, customer-support, fraud-prevention, tax, invoicing, or operational service providers, if used;
- professional advisors where reasonably necessary;
- authorities or third parties where required by law, legal process, or to protect rights, safety, and security.
We may also disclose information in connection with a merger, acquisition, financing, reorganization, sale of assets, or similar transaction, subject to applicable confidentiality and legal requirements.
9. International Transfers
Baron Buff operates from Brazil, and our main technical environment is hosted in the United States. As a result, personal data may be transferred to and processed in the United States and other countries where our service providers operate.
Where applicable, we will adopt appropriate safeguards and measures required by law for international transfers of personal data.
10. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to:
- maintain active user accounts;
- provide requested features, purchases, subscriptions, support, and account administration;
- preserve security, audit, fraud-prevention, and abuse-prevention records for a limited period;
- maintain billing, tax, accounting, chargeback, refund, and legal compliance records as required or permitted by law;
- resolve disputes and enforce agreements.
Retention periods may vary depending on the type of data and the purpose of processing. If you delete your account or a subscription ends, we may retain certain information for legitimate business purposes and where required or permitted by law, including security, fraud prevention, billing, tax, accounting, dispute resolution, and legal compliance purposes.
When personal data is no longer required, we will delete, anonymize, or securely isolate it, unless retention is legally required or permitted.
11. Your Rights
Subject to applicable law, including the LGPD where relevant, you may have the right to:
- confirm whether we process your personal data;
- access your personal data;
- request correction of incomplete, inaccurate, or outdated data;
- request anonymization, blocking, or deletion of unnecessary or excessive data, or data processed unlawfully;
- request portability, where applicable;
- request information about shared use of data;
- request information about consent and the consequences of refusing consent;
- withdraw consent, where processing is based on consent;
- request deletion of personal data processed based on consent, subject to legal exceptions;
- object to certain processing, where permitted by law;
- request review of decisions made solely on the basis of automated processing, where applicable under law.
To exercise these rights, contact us at [email protected]. We may request information necessary to verify your identity before processing a request.
12. Account and Billing Management
If you have a Baron Buff account, you may be able to access, update, or remove certain information directly through your account settings or billing flow, including:
- profile information;
- linked game accounts;
- communication preferences;
- saved feature preferences;
- subscription or billing information, where available.
You may also request deletion of your Baron Buff account by contacting us. In some cases, deleting your account will not require us to delete information we must retain for legal, security, tax, accounting, fraud-prevention, or dispute-resolution purposes.
13. Security
We use reasonable technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure. However, no system is completely secure, and we cannot guarantee absolute security.
14. Children
The Services are not directed to children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child has provided us personal data, contact us so we can take appropriate action.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in the Services, our processing practices, or applicable legal requirements. When we do, we will update the "Last updated" date at the top of this page. If legally required, we will provide additional notice or request consent.
16. Contact
For privacy-related questions or requests, contact:
[email protected]