Privacy Policy
1. Privacy at a Glance
General Information
The following notes provide a simple overview of what happens to your personal data when you visit this website.
2. Data Collection on This Website
Who is responsible for data collection?
Data processing on this website is carried out by the website operator. You can find their contact details in the legal notice (Impressum).
How do we collect your data?
Your data is collected, on the one hand, when you provide it to us. This may, for example, be data you enter into a contact form.
3. Hosting and Content Delivery Networks
This website is hosted by an external service provider (Hetzner). The personal data collected on this website is stored on the servers of the host.
4. Payment Providers
We use Stripe as our payment service provider. During payment, your payment data is transmitted directly to Stripe and processed there.
5. Server Log Files
The host of our website automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- Page visited on our domain
- Date and time of the server request
- Browser type and browser version
- Operating system used
- Referrer URL (previously visited page)
- Hostname of the accessing computer
- IP address
This data is not merged with other data sources. This data is collected on the basis of Art. 6(1)(f) GDPR (legitimate interest in the technically error-free presentation and optimization of the website). Server log files are automatically deleted after 14 days.
6. Security Logging and Login Data
What data is stored when you log in?
To protect your account and to detect unauthorized access, we store the following data each time you log in:
- IP address
- Approximate location (city, country) based on the IP address
- Browser and device used (user agent)
- Time of login
- Success or failure of the login attempt
Why do we store this data?
This storage is based on our legitimate interest (Art. 6(1)(f) GDPR) in the security of your user account and our systems. In particular, the data serves:
- To detect unauthorized access to your account
- Fraud prevention
- Traceability in the event of security incidents
How long is the data stored?
The login logs are automatically deleted after 90 days. You may request information about your stored login data at any time or request its early deletion.
Location Determination (GeoIP)
To determine your approximate location, we use a local GeoIP database (MaxMind GeoLite2). No data is transmitted to external services. The location data is not exact and merely serves to detect unusual login patterns (e.g., a login from a different country).
7. Third-Party Providers and Data Processing
Hosting
The website, customer accounts, database and billing data are hosted by Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany). The game servers you book run on several machines; some of them are operated by OVH in its Limburg an der Lahn data centre, Germany. During normal game operation, IP addresses of connecting players and content you store on the server may be processed there. Both providers process the data exclusively in Germany. Legal basis: Art. 6(1)(f) GDPR.
Payment Processing (Stripe)
Payments are processed via Stripe, Inc. (510 Townsend Street, San Francisco, CA 94103, USA). Stripe processes payment data (card number, name, expiry date) directly — we do not store any credit card data. Stripe is PCI DSS Level 1 certified. Privacy notice: stripe.com/de/privacy. Legal basis: Art. 6(1)(b) GDPR (contract performance).
CDN and DNS (Cloudflare)
We use Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) for DNS management and DDoS protection. In doing so, Cloudflare may process visitors' IP addresses. Privacy notice: cloudflare.com/privacypolicy. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in security).
Email Delivery (Resend)
Transactional emails (order confirmations, server notifications) are sent via Resend (Resend Technologies Inc., USA). In this process, your email address and message content are transmitted to Resend. Privacy notice: resend.com/legal/privacy-policy. Legal basis: Art. 6(1)(b) GDPR (contract performance).
Click tracking: Links contained in our emails are redirected via a tracking domain operated by Resend. This allows us to detect whether and when you click a link in an email. In doing so, your IP address, the time of the click, and information about your email program or browser are processed. We use this data to improve the relevance of our emails and to be able to recover abandoned orders. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the needs-based design and optimization of our communication). You may object to this processing at any time by contacting us at [email protected].
Web Analytics (Google Analytics 4)
We use Google Analytics 4 (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) to analyze user behavior. GA4 is loaded only after explicit cookie consent. Without your consent, no analytics data is collected. IP addresses are anonymized. Legal basis: Art. 6(1)(a) GDPR (consent).
Error Logging (Sentry)
To detect and remediate software errors, we use Sentry
(Functional Software, Inc., 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA).
In the event of an error, technical information (error message, stack trace, browser type) is transmitted to Sentry.
No personal data such as email addresses or IP addresses is sent to Sentry
(send_default_pii = false). Privacy notice:
sentry.io/privacy.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in system stability).
Web Analytics (Ahrefs)
We use Ahrefs Web Analytics (Ahrefs Pte. Ltd., Singapore) as a cookieless web analytics tool. Ahrefs sets no cookies and stores no personal data. IP addresses are not stored permanently. The script is loaded without cookie consent, since, as a cookieless analytics tool, it does not require consent. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in website optimization).
Marketing Attribution (Source Measurement)
In order to measure through which of our content (e.g., guide articles) visitors reach an order,
we store the source information from the referral link (utm_source,
utm_medium, utm_campaign) as so-called first-touch attribution. For
Google ads, we also store available click identifiers (gclid, gbraid,
wbraid) and their capture time so a later order can be attributed to the ad click. This is done
exclusively after your consent to analytics cookies: a cookie
gsh_attr holds the first recorded source and the encrypted HttpOnly cookie
gsh_gads holds the latest Google ad click (30 days each); if an account exists,
these details are assigned to the account so that a later order can be attributed.
Your analytics decision is stored in the cookie gsh_consent. Without
consent, no permanent source storage takes place. Legal basis: Art. 6(1)(a)
GDPR (consent). You can withdraw your consent at any time via the cookie settings.
Only if you additionally allow marketing cookies do we store this decision separately in
gsh_marketing_consent. Upon the first successful live payment, available Google click
identifiers, click and payment times, a pseudonymous transaction identifier, and payment value and
currency may then be transmitted to Google through the Google Data Manager API. Email address, name,
and IP address are not transmitted. The purpose is to measure which ad led to a new-customer purchase;
each payment is transmitted at most once. The legal basis is Art. 6(1)(a) GDPR. Withdrawal in the
cookie settings blocks future transmissions.
Invoicing (InvoiceNinja)
For invoice creation, we use a self-hosted instance of InvoiceNinja (InvoiceNinja, LLC, USA). The invoice data (name, address, email, invoice amounts) is processed exclusively on our own server at Hetzner in Germany. No data is transmitted to third parties. Legal basis: Art. 6(1)(b) GDPR (contract performance).
Data Processing (DPA)
We have concluded data processing agreements (DPA) pursuant to Art. 28 GDPR with the following service providers:
- Hetzner Online GmbH — server hosting for website, database and invoices (data processing exclusively in Germany)
- OVH — server hosting for part of the game servers, Limburg an der Lahn data centre (data processing exclusively in Germany)
- Stripe, Inc. — payment processing (EU-US Data Privacy Framework certified)
- Cloudflare, Inc. — CDN, DNS, and DDoS protection (EU-US Data Privacy Framework certified)
- Resend — transactional emails
Community priority through a public X post
If you voluntarily participate in community priority, we process your account ID, adult-status confirmation, terms and review versions, status, review, grant and expiry times, and temporarily the link you submit to your public X post. To prevent reuse, we retain keyed HMAC checks derived from the X username and post ID. They are not intended to be reversed without the separate secret key. The purposes are the two-stage manual review, granting time-limited account-level start priority, and preventing abuse. The legal bases are Art. 6(1)(b) GDPR for providing the optional feature you request and Art. 6(1)(f) GDPR for preventing duplicate or abusive participation. Our legitimate interest is a fair allocation of this limited benefit.
We provide no X login, make no X API request, perform no automated scraping, and embed no X tracking. Authorised staff open only the public link you provide for two manual reviews at least 14 days apart. On withdrawal or rejection, we delete the participation data immediately. We delete unsubmitted drafts after 30 days. Following approval, we delete the post URL; the status, review, grant and expiry times, and HMAC checks remain until your customer account is deleted and are then erased.
8. Retention Period
We store your personal data only for as long as necessary for the respective purposes:
| Type of Data | Retention Period |
|---|---|
| Server log files | 14 days |
| Login logs | 90 days |
| User account | Until deleted by the user |
| Contract and accounting data | Generally 8 years where retained as accounting records under Section 257 HGB; longer only where another statutory basis applies |
| Invoices | 8 years (Section 14b UStG) |
| Server metrics (CPU, RAM) | 30 days |
| Cookies (analytics) | Until consent is withdrawn |
Marketing attribution (gsh_attr, gsh_gads) | 30 days |
| Community priority: draft | 30 days without submission |
| Community priority: post URL | Until final review; immediately on withdrawal or rejection |
| Community priority: review status, grant/expiry times and HMAC checks | Until deletion of the customer account |
| Support requests | 2 years after completion |
9. Controller
Jens Röcker
Südeschstraße 32
48429 Rheine
Email: [email protected]
10. Your Rights as a Data Subject
You have the right at any time to: access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), and objection (Art. 21 GDPR).
Right to lodge a complaint with the competent supervisory authority: State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen), Postfach 20 04 44, 40102 Düsseldorf.
Last updated: August 2026