Effective 12 August 2026
Privacy policy.
RoundTrace is designed so identifiable VALORANT statistics are collected and displayed only after the player has connected their Riot account and opted in.
1. Who operates RoundTrace
RoundTrace operates the service available at api.codeoce.com. Privacy questions, access requests, and deletion requests may be sent to privacy@codeoce.com.
2. Information we collect after RSO is activated
When a player chooses to connect their Riot account, RoundTrace may process:
- Riot account identifiers supplied through Riot Sign On, including PUUID, game name, and tag line.
- VALORANT match history and match-detail data made available through Riot's supported APIs.
- Statistics derived from those matches, such as wins, losses, K/D, average combat score, agent usage, map performance, and recent form.
- Consent, policy-version, revocation, and deletion timestamps.
- RoundTrace session identifiers and developer API-key usage records.
- Limited technical information such as IP address, user agent, request time, error details, and security events.
RoundTrace does not ask for, receive, or store a player's Riot password.
3. Why we use information
We use this information to identify the player who opted in, provide their historical statistics, make those statistics available to authorized RoundTrace API clients, secure and operate the service, enforce rate limits, respond to support and privacy requests, and comply with applicable obligations.
4. Player opt-in and visibility
Personal gameplay statistics are opt-in only. A player must sign in through Riot Sign On and accept RoundTrace's data-sharing notice before their identifiable statistics may be displayed. Players who have not opted in are not available through RoundTrace player-statistics endpoints.
Linking makes the player's gameplay statistics available within RoundTrace and to developers using authorized RoundTrace API keys, subject to RoundTrace's terms and access controls.
5. Sharing
RoundTrace does not sell Riot account information. We may share opted-in statistics with authorized RoundTrace API clients because that is the requested function of the service. Infrastructure providers, including Cloudflare, may process data to host, secure, and operate RoundTrace. We may disclose information where legally required or necessary to protect the service and its users.
6. Retention and deletion
While a Riot account remains linked, RoundTrace retains the identifiers and match-derived information needed to provide the service. When a player revokes consent, RoundTrace immediately disables public and API visibility, stops future collection, and schedules identifiable gameplay data for deletion within 30 days. Limited security, audit, or legal records may be retained for longer where reasonably necessary.
8. Security
Riot and RoundTrace credentials are kept server-side. RoundTrace uses HTTPS, restricted Cloudflare bindings, hashed developer API keys, access controls, rate limits, and logging intended to detect misuse. No internet service can guarantee absolute security.
9. Player choices
Players may disconnect their Riot account, revoke future collection, request access to their stored information, request correction, or request deletion. Once RSO is active, self-service controls will be available in account settings. Requests may also be sent to privacy@codeoce.com.
10. Children
RoundTrace is not directed to children below the minimum age required to hold and authorize the relevant Riot account in their location. If we learn that information was collected without valid authorization, we will delete it.
11. International processing and changes
Cloud infrastructure may process information outside the player's country. We will update this policy when the product, legal requirements, or Riot requirements change. Material changes affecting consent will be presented before continued sharing.