Privacy Policy

Your data on the grid

Privacy Policy

What Poco Loco uses to run creator-led races, process purchases, keep the service reliable, and publish community results.

Last updated: August 28, 2026

Diego standing with crossed arms

Who operates Poco Loco

Poco Loco is operated by BrokenChairMedia. This policy explains how we handle personal data when creators host races through supported streaming providers, players join racing sessions, and people use the website or desktop app.

Data we use

We use creator account data supplied by connected providers, such as username, avatar, immutable provider ID, and email when available, to identify creators and open the Arena. We also store the independent Poco Loco profile, connected Twitch, Kick, and Steam identities, player names, race entries, race results, XP totals, leaderboard rows, and the technical data needed to keep the service secure and reliable.

Twitch and Kick accounts, chat, and live status

Creators may sign in with Twitch or Kick so we can grant Arena access and connect races to the correct creator account. During active races, Poco Loco processes provider identity, message identifiers, selected human-written message fragments or supported commands, channel and live-status data, and Twitch Cheer Bits amounts where enabled. We use this data to join races, trigger supported gameplay, prevent duplicate handling, and score gameplay. Twitch and Kick remain independent services with their own terms and privacy notices.

Twitch Extension and Bits

If Poco Loco offers a Twitch Extension, viewers may use Bits for permitted in-extension gameplay experiences such as unlocking a racer, revealing a track option, or adding race time. When the Extension uses Twitch Identity Link, also called ID Share, or when a viewer confirms a Bits action, Twitch may share the viewer display name, numeric Twitch user ID, product SKU or action, transaction ID, transaction receipt metadata, channel/session details, and action time with Poco Loco. We use that data to fulfill the Bits-triggered gameplay action, prevent duplicate transaction handling, attribute gameplay and leaderboard activity, maintain admin reporting, prevent abuse, and respond to privacy or security requests. Twitch handles Bits balances and payment flows; Poco Loco does not collect payment-card data.

Connected accounts, Steam tickets, and account merges

You may connect Twitch, Kick, and Steam identities to one Poco Loco account. A Steam build sends a short-lived Steam authentication ticket directly from the protected desktop process to Poco Loco so Valve can verify the local SteamID and AppID. We retain a one-way ticket hash to reject reuse, not the raw ticket. When you explicitly merge two verified Poco Loco accounts, we retain an audited record of the merge, redirect former profile slugs, move connected identities and creator-owned history to the surviving account, revoke the source sessions, and keep the source account as a merged tombstone.

PocoPoints (PP), Mollie, and Steam Wallet

When you buy PocoPoints (PP), we store purchase UUIDs, payment provider, provider order and transaction references and statuses, amount, currency, bundle, credited time, wallet balance movements, credit lots, debit allocations, settlement or callback handling data, and refund, reversal, or support correspondence. Web checkout is hosted by Mollie. Steam checkout is authorized through the Steam Overlay and reconciled against Valve settlement reports. Mollie and Valve handle payment method details; Poco Loco does not store card, bank account, Steam Wallet, iDEAL, PayPal, or other payment method credentials.

Why and on what basis we process data

We process data to provide the service you request, build lobbies, assign cars, run races, award XP, show leaderboards, process purchases, prevent abuse, troubleshoot service issues, and comply with legal obligations. Depending on the activity, we rely on performing our contract with you, our legitimate interests in operating and securing Poco Loco, consent where required, or a legal obligation. We do not sell player or creator personal data.

Public gameplay and creator pages

Public track, creator, race, and leaderboard surfaces may show provider display names, avatars, creator channel links, track ownership, scores, ranks, race results, and related gameplay statistics. This lets communities find tracks, recognize creators, and compare race performance.

Analytics and third parties

We do not currently use Google Analytics or other third-party analytics on Poco Loco or a Poco Loco Twitch Extension. If that changes, we will update this policy before collecting analytics data.

Desktop runtime diagnostics

The desktop app has crash diagnostics enabled by default and lets you disable them in Settings. If an app rendering, graphics, or utility process fails, Poco Loco sends only the process category, standardized failure reason, exit code, app version, operating-system platform, and processor architecture to our authenticated operational logging. We do not upload a memory dump, page URL, username, provider identity, OAuth or session value, local path, or raw error text. Disabled diagnostics are not sent or queued for later.

Retention, security, and your choices

We keep data only for as long as needed for gameplay history, leaderboards, account-link and merge integrity, security, operations, and legal obligations. Purchase, ledger, settlement, refund, reversal, and support records may be kept for accounting, dispute handling, tax, abuse prevention, and legal obligations. Access is limited to operational needs and protected with appropriate technical and organizational measures. Depending on applicable law, you may ask to access, correct, delete, restrict, object to, or receive a copy of your personal data, withdraw consent, or complain to your local data protection authority. Contact [email protected] for account, privacy, payment, or refund requests. We may need to verify your identity before completing a request.

Cookies and local storage

The app uses session cookies and browser storage for login, security, interface preferences, and race display settings. Disabling these may prevent parts of the service from working.

This policy is part of the Poco Loco Terms of Use. If a translated or summarized version conflicts with this English version, this English version controls unless mandatory law says otherwise.