Skip to main content

Privacy Policy

1. Privacy at a Glance

General Information

The following notes provide a simple overview of what happens to your personal data when you visit this website.

2. Data Collection on This Website

Who is responsible for data collection?

Data processing on this website is carried out by the website operator. You can find their contact details in the legal notice (Impressum).

How do we collect your data?

Your data is collected, on the one hand, when you provide it to us. This may, for example, be data you enter into a contact form.

3. Hosting and Content Delivery Networks

This website is hosted by an external service provider (Hetzner). The personal data collected on this website is stored on the servers of the host.

4. Payment Providers

We use Stripe as our payment service provider. During payment, your payment data is transmitted directly to Stripe and processed there.

5. Server Log Files

The host of our website automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:

  • Page visited on our domain
  • Date and time of the server request
  • Browser type and browser version
  • Operating system used
  • Referrer URL (previously visited page)
  • Hostname of the accessing computer
  • IP address

This data is not merged with other data sources. This data is collected on the basis of Art. 6(1)(f) GDPR (legitimate interest in the technically error-free presentation and optimization of the website). Server log files are automatically deleted after 14 days.

6. Security Logging and Login Data

What data is stored when you log in?

To protect your account and to detect unauthorized access, we store the following data each time you log in:

  • IP address
  • Approximate location (city, country) based on the IP address
  • Browser and device used (user agent)
  • Time of login
  • Success or failure of the login attempt

Why do we store this data?

This storage is based on our legitimate interest (Art. 6(1)(f) GDPR) in the security of your user account and our systems. In particular, the data serves:

  • To detect unauthorized access to your account
  • Fraud prevention
  • Traceability in the event of security incidents

How long is the data stored?

The login logs are automatically deleted after 90 days. You may request information about your stored login data at any time or request its early deletion.

Location Determination (GeoIP)

To determine your approximate location, we use a local GeoIP database (MaxMind GeoLite2). No data is transmitted to external services. The location data is not exact and merely serves to detect unusual login patterns (e.g., a login from a different country).

7. Third-Party Providers and Data Processing

Hosting

The website, customer accounts, database and billing data are hosted by Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany). The game servers you book run on several machines; some of them are operated by OVH in its Limburg an der Lahn data centre, Germany. During normal game operation, IP addresses of connecting players and content you store on the server may be processed there. Both providers process the data exclusively in Germany. Legal basis: Art. 6(1)(f) GDPR.

Payment Processing (Stripe)

Payments are processed via Stripe, Inc. (510 Townsend Street, San Francisco, CA 94103, USA). Stripe processes payment data (card number, name, expiry date) directly — we do not store any credit card data. Stripe is PCI DSS Level 1 certified. Privacy notice: stripe.com/de/privacy. Legal basis: Art. 6(1)(b) GDPR (contract performance).

CDN and DNS (Cloudflare)

We use Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) for DNS management and DDoS protection. In doing so, Cloudflare may process visitors' IP addresses. Privacy notice: cloudflare.com/privacypolicy. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in security).

Email Delivery (Resend)

Transactional emails (order confirmations, server notifications) are sent via Resend (Resend Technologies Inc., USA). In this process, your email address and message content are transmitted to Resend. Privacy notice: resend.com/legal/privacy-policy. Legal basis: Art. 6(1)(b) GDPR (contract performance).

Click tracking: Links contained in our emails are redirected via a tracking domain operated by Resend. This allows us to detect whether and when you click a link in an email. In doing so, your IP address, the time of the click, and information about your email program or browser are processed. We use this data to improve the relevance of our emails and to be able to recover abandoned orders. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the needs-based design and optimization of our communication). You may object to this processing at any time by contacting us at [email protected].

Web Analytics (Google Analytics 4)

We use Google Analytics 4 (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) to analyze user behavior. GA4 is loaded only after explicit cookie consent. Without your consent, no analytics data is collected. IP addresses are anonymized. Legal basis: Art. 6(1)(a) GDPR (consent).

Error Logging (Sentry)

To detect and remediate software errors, we use Sentry (Functional Software, Inc., 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA). In the event of an error, technical information (error message, stack trace, browser type) is transmitted to Sentry. No personal data such as email addresses or IP addresses is sent to Sentry (send_default_pii = false). Privacy notice: sentry.io/privacy. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in system stability).

Web Analytics (Ahrefs)

We use Ahrefs Web Analytics (Ahrefs Pte. Ltd., Singapore) as a cookieless web analytics tool. Ahrefs sets no cookies and stores no personal data. IP addresses are not stored permanently. The script is loaded without cookie consent, since, as a cookieless analytics tool, it does not require consent. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in website optimization).

Marketing Attribution (Source Measurement)

In order to measure through which of our content (e.g., guide articles) visitors reach an order, we store the source information from the referral link (utm_source, utm_medium, utm_campaign) as so-called first-touch attribution. For Google ads, we also store available click identifiers (gclid, gbraid, wbraid) and their capture time so a later order can be attributed to the ad click. This is done exclusively after your consent to analytics cookies: a cookie gsh_attr holds the first recorded source and the encrypted HttpOnly cookie gsh_gads holds the latest Google ad click (30 days each); if an account exists, these details are assigned to the account so that a later order can be attributed. Your analytics decision is stored in the cookie gsh_consent. Without consent, no permanent source storage takes place. Legal basis: Art. 6(1)(a) GDPR (consent). You can withdraw your consent at any time via the cookie settings.

Only if you additionally allow marketing cookies do we store this decision separately in gsh_marketing_consent. Upon the first successful live payment, available Google click identifiers, click and payment times, a pseudonymous transaction identifier, and payment value and currency may then be transmitted to Google through the Google Data Manager API. Email address, name, and IP address are not transmitted. The purpose is to measure which ad led to a new-customer purchase; each payment is transmitted at most once. The legal basis is Art. 6(1)(a) GDPR. Withdrawal in the cookie settings blocks future transmissions.

Invoicing (InvoiceNinja)

For invoice creation, we use a self-hosted instance of InvoiceNinja (InvoiceNinja, LLC, USA). The invoice data (name, address, email, invoice amounts) is processed exclusively on our own server at Hetzner in Germany. No data is transmitted to third parties. Legal basis: Art. 6(1)(b) GDPR (contract performance).

Data Processing (DPA)

We have concluded data processing agreements (DPA) pursuant to Art. 28 GDPR with the following service providers:

  • Hetzner Online GmbH — server hosting for website, database and invoices (data processing exclusively in Germany)
  • OVH — server hosting for part of the game servers, Limburg an der Lahn data centre (data processing exclusively in Germany)
  • Stripe, Inc. — payment processing (EU-US Data Privacy Framework certified)
  • Cloudflare, Inc. — CDN, DNS, and DDoS protection (EU-US Data Privacy Framework certified)
  • Resend — transactional emails

Community priority through a public X post

If you voluntarily participate in community priority, we process your account ID, adult-status confirmation, terms and review versions, status, review, grant and expiry times, and temporarily the link you submit to your public X post. To prevent reuse, we retain keyed HMAC checks derived from the X username and post ID. They are not intended to be reversed without the separate secret key. The purposes are the two-stage manual review, granting time-limited account-level start priority, and preventing abuse. The legal bases are Art. 6(1)(b) GDPR for providing the optional feature you request and Art. 6(1)(f) GDPR for preventing duplicate or abusive participation. Our legitimate interest is a fair allocation of this limited benefit.

We provide no X login, make no X API request, perform no automated scraping, and embed no X tracking. Authorised staff open only the public link you provide for two manual reviews at least 14 days apart. On withdrawal or rejection, we delete the participation data immediately. We delete unsubmitted drafts after 30 days. Following approval, we delete the post URL; the status, review, grant and expiry times, and HMAC checks remain until your customer account is deleted and are then erased.

8. Retention Period

We store your personal data only for as long as necessary for the respective purposes:

Type of Data Retention Period
Server log files14 days
Login logs90 days
User accountUntil deleted by the user
Contract and accounting dataGenerally 8 years where retained as accounting records under Section 257 HGB; longer only where another statutory basis applies
Invoices8 years (Section 14b UStG)
Server metrics (CPU, RAM)30 days
Cookies (analytics)Until consent is withdrawn
Marketing attribution (gsh_attr, gsh_gads)30 days
Community priority: draft30 days without submission
Community priority: post URLUntil final review; immediately on withdrawal or rejection
Community priority: review status, grant/expiry times and HMAC checksUntil deletion of the customer account
Support requests2 years after completion

9. Controller

Jens Röcker
Südeschstraße 32
48429 Rheine
Email: [email protected]

10. Your Rights as a Data Subject

You have the right at any time to: access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), and objection (Art. 21 GDPR).

Right to lodge a complaint with the competent supervisory authority: State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen), Postfach 20 04 44, 40102 Düsseldorf.

Last updated: August 2026