Privacy
What Arena Card does with your account data
Signing in here shows you your own profile from the game. This page says exactly what is handled to do that, where it is kept, and how to get rid of it.
Last updated
The short version
- — There is no database. Nothing about you is stored on our side between requests.
- — Your session lives in one cookie in your own browser, and expires after 24 hours.
- — We never see or ask for your game password. Sign-in uses a code the game sends you.
- — Signing out deletes the cookie, which is the whole of your data here.
Who operates this
Arena Card is operated by PT RoneAI Teknologi Internasional, trading as RoneAI, an Indonesian company domiciled in Boyolali Regency, Central Java. Indonesian Law No. 27 of 2022 on Personal Data Protection governs us, and this notice is written against it.
It is an unofficial, community-maintained project with no affiliation to Moonton. It reads data the game already holds about your own account, at your request.
What is handled, and why
| What | Why | Kept |
|---|---|---|
| Your in-game ID and zone | To identify which account to request a code for | In your session cookie, so you do not retype them |
| The verification code you enter | Exchanged once for a session token, then discarded | Not kept |
| The session token the game returns | Attached to each request so the game returns your data | In your session cookie, for at most 24 hours |
| Your profile, rank, statistics, matches and friends | This is the page you asked to see | Not kept. Fetched, rendered, discarded with the request |
| Your IP address and browser | Serving the request; abuse prevention by our host | Our host's standard request logs, under their retention |
We process this to fulfil your own request under Article 20(2)(b) of the Act — you asked to see your account, and it cannot be shown without these details. Server logs rest on Article 20(2)(f), our legitimate interest in keeping the service running.
Your session cookie, precisely
One cookie holds everything. It is JSON, base64-encoded, and signed with HMAC-SHA256 so we can detect tampering. It is marked HttpOnly, so scripts on the page cannot read it, and SameSite=Lax and Secure outside local development.
Signed is not the same as encrypted. The cookie is tamper-evident, not secret: anyone holding it could decode its contents and use your session until it expires. That is why it carries only your own credentials and nothing about anyone else, why it lasts 24 hours rather than indefinitely, and why you should sign out on a shared computer rather than just closing the tab.
Every request to the game is made by our server. The token is never handed to page scripts.
Who else is involved
- Rone Arena API — the API this app calls. It is operated by us, reads the game's public endpoints, and stores nothing about you.
- The game's own servers — they authenticate you, send the verification code, and hold the data being displayed. Their handling of your account is governed by their own terms, not ours.
- Our hosting provider — serves every request and keeps standard request logs under its own privacy terms.
Our provider is established outside Indonesia, so running the service involves a transfer out of the jurisdiction. We rely on Article 56(3): binding contractual protection under the provider's published data processing terms, because Indonesia has not yet published a list of countries meeting the equivalent-protection test in Article 56(2).
There is no analytics provider and no advertising network here.
Your rights
The Act gives you information (Article 5), correction (Article 6), access and a copy (Article 7), erasure (Article 8), restriction (Article 11), compensation (Article 12) and portability (Article 13). Where action is needed, the Act allows 3 × 24 hours rather than the thirty days European rules use — Articles 30, 31, 40 and 41.
For this app most of those have a very short answer: we hold nothing to access or correct. The complete set of data we have is the cookie in your own browser, and signing out deletes it immediately.
To change the underlying account data itself, go to the game — it is their record, and we only display it. For anything else, email [email protected]. If our answer does not satisfy you, you may complain to the Ministry of Communication and Digital Affairs, which supervises data protection until Lembaga PDP is established.
Security, children, and changes
Everything is served over HTTPS, and there is no data store here to breach. Report a vulnerability to [email protected] rather than opening a public issue — scope and safe-harbour terms are at rone.dev/security.
We do not knowingly process data from anyone under 18. If what this app does changes, this page changes with it and the date at the top moves.
Contact
- PT RoneAI Teknologi Internasional (RoneAI)
- Boyolali Regency, Central Java, Indonesia
- General and data protection: [email protected]
- Security reports: [email protected]
Site-wide terms are at rone.dev/terms.