Who operates Poco Loco
Poco Loco is operated by BrokenChairMedia. This policy explains how we handle personal data when creators host races through supported streaming providers, players join racing sessions, and people use the website or desktop app.
Data we use
We use creator account data supplied by connected providers, such as username, avatar, immutable provider ID, and email when available, to identify creators and open the Arena. We also store the independent Poco Loco profile, connected Twitch, Kick, and Steam identities, player names, race entries, race results, XP totals, leaderboard rows, and the technical data needed to keep the service secure and reliable.
Twitch and Kick accounts, chat, and live status
Creators may sign in with Twitch or Kick so we can grant Arena access and connect races to the correct creator account. During active races, Poco Loco processes provider identity, message identifiers, selected human-written message fragments or supported commands, channel and live-status data, and Twitch Cheer Bits amounts where enabled. We use this data to join races, trigger supported gameplay, prevent duplicate handling, and score gameplay. Twitch and Kick remain independent services with their own terms and privacy notices.
Twitch Extension and Bits
If Poco Loco offers a Twitch Extension, viewers may use Bits for permitted in-extension gameplay experiences such as unlocking a racer, revealing a track option, or adding race time. When the Extension uses Twitch Identity Link, also called ID Share, or when a viewer confirms a Bits action, Twitch may share the viewer display name, numeric Twitch user ID, product SKU or action, transaction ID, transaction receipt metadata, channel/session details, and action time with Poco Loco. We use that data to fulfill the Bits-triggered gameplay action, prevent duplicate transaction handling, attribute gameplay and leaderboard activity, maintain admin reporting, prevent abuse, and respond to privacy or security requests. Twitch handles Bits balances and payment flows; Poco Loco does not collect payment-card data.
Connected accounts, Steam tickets, and account merges
You may connect Twitch, Kick, and Steam identities to one Poco Loco account. A Steam build sends a short-lived Steam authentication ticket directly from the protected desktop process to Poco Loco so Valve can verify the local SteamID and AppID. We retain a one-way ticket hash to reject reuse, not the raw ticket. When you explicitly merge two verified Poco Loco accounts, we retain an audited record of the merge, redirect former profile slugs, move connected identities and creator-owned history to the surviving account, revoke the source sessions, and keep the source account as a merged tombstone.
PocoPoints (PP), Mollie, and Steam Wallet
When you buy PocoPoints (PP), we store purchase UUIDs, payment provider, provider order and transaction references and statuses, amount, currency, bundle, credited time, wallet balance movements, credit lots, debit allocations, settlement or callback handling data, and refund, reversal, or support correspondence. Web checkout is hosted by Mollie. Steam checkout is authorized through the Steam Overlay and reconciled against Valve settlement reports. Mollie and Valve handle payment method details; Poco Loco does not store card, bank account, Steam Wallet, iDEAL, PayPal, or other payment method credentials.
Why and on what basis we process data
We process data to provide the service you request, build lobbies, assign cars, run races, award XP, show leaderboards, process purchases, prevent abuse, troubleshoot service issues, and comply with legal obligations. Depending on the activity, we rely on performing our contract with you, our legitimate interests in operating and securing Poco Loco, consent where required, or a legal obligation. We do not sell player or creator personal data.
Public gameplay and creator pages
Public track, creator, race, and leaderboard surfaces may show provider display names, avatars, creator channel links, track ownership, scores, ranks, race results, and related gameplay statistics. This lets communities find tracks, recognize creators, and compare race performance.
Analytics and third parties
We do not currently use Google Analytics or other third-party analytics on Poco Loco or a Poco Loco Twitch Extension. If that changes, we will update this policy before collecting analytics data.
Desktop runtime diagnostics
The desktop app has crash diagnostics enabled by default and lets you disable them in Settings. If an app rendering, graphics, or utility process fails, Poco Loco sends only the process category, standardized failure reason, exit code, app version, operating-system platform, and processor architecture to our authenticated operational logging. We do not upload a memory dump, page URL, username, provider identity, OAuth or session value, local path, or raw error text. Disabled diagnostics are not sent or queued for later.
Retention, security, and your choices
We keep data only for as long as needed for gameplay history, leaderboards, account-link and merge integrity, security, operations, and legal obligations. Purchase, ledger, settlement, refund, reversal, and support records may be kept for accounting, dispute handling, tax, abuse prevention, and legal obligations. Access is limited to operational needs and protected with appropriate technical and organizational measures. Depending on applicable law, you may ask to access, correct, delete, restrict, object to, or receive a copy of your personal data, withdraw consent, or complain to your local data protection authority. Contact [email protected] for account, privacy, payment, or refund requests. We may need to verify your identity before completing a request.
