Privacy Policy
1. Privacy at a Glance
General Information
The following notes provide a simple overview of what happens to your personal data when you visit this website.
2. Data Collection on This Website
Who is responsible for data collection?
Data processing on this website is carried out by the website operator. You can find their contact details in the legal notice (Impressum).
How do we collect your data?
Your data is collected, on the one hand, when you provide it to us. This may, for example, be data you enter into a contact form.
3. Hosting and Content Delivery Networks
This website is hosted by an external service provider (Hetzner). The personal data collected on this website is stored on the servers of the host.
4. Payment Providers
We use Stripe as our payment service provider. During payment, your payment data is transmitted directly to Stripe and processed there.
5. Server Log Files
The host of our website automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- Page visited on our domain
- Date and time of the server request
- Browser type and browser version
- Operating system used
- Referrer URL (previously visited page)
- Hostname of the accessing computer
- IP address
This data is not merged with other data sources. This data is collected on the basis of Art. 6(1)(f) GDPR (legitimate interest in the technically error-free presentation and optimization of the website). Server log files are automatically deleted after 14 days.
6. Security Logging and Login Data
What data is stored when you log in?
To protect your account and to detect unauthorized access, we store the following data each time you log in:
- IP address
- Approximate location (city, country) based on the IP address
- Browser and device used (user agent)
- Time of login
- Success or failure of the login attempt
Why do we store this data?
This storage is based on our legitimate interest (Art. 6(1)(f) GDPR) in the security of your user account and our systems. In particular, the data serves:
- To detect unauthorized access to your account
- Fraud prevention
- Traceability in the event of security incidents
How long is the data stored?
The login logs are automatically deleted after 90 days. You may request information about your stored login data at any time or request its early deletion.
Location Determination (GeoIP)
To determine your approximate location, we use a local GeoIP database (MaxMind GeoLite2). No data is transmitted to external services. The location data is not exact and merely serves to detect unusual login patterns (e.g., a login from a different country).
7. Third-Party Providers and Data Processing
Hosting
The website, customer accounts, database and billing data are hosted by Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany). The game servers you book run on several machines; some of them are operated by OVH SAS (2 rue Kellermann, 59100 Roubaix, France) in its Limburg an der Lahn (Germany) and Roubaix (France) data centres. During normal game operation, IP addresses of connecting players and content you store on the server may be processed there. All of these locations are within the European Union; no transfer to a third country takes place. Legal basis: Art. 6(1)(f) GDPR.
Payment Processing (Stripe)
Payments are processed via Stripe, Inc. (510 Townsend Street, San Francisco, CA 94103, USA). Stripe processes payment data (card number, name, expiry date) directly — we do not store any credit card data. Stripe is PCI DSS Level 1 certified. Privacy notice: stripe.com/de/privacy. Legal basis: Art. 6(1)(b) GDPR (contract performance).
CDN and DNS (Cloudflare)
We use Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) for DNS management and DDoS protection. In doing so, Cloudflare may process visitors' IP addresses. Privacy notice: cloudflare.com/privacypolicy. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in security).
Email Delivery (Resend)
Transactional emails (order confirmations, server notifications) are sent via Resend (Resend Technologies Inc., USA). In this process, your email address and message content are transmitted to Resend. Privacy notice: resend.com/legal/privacy-policy. Legal basis: Art. 6(1)(b) GDPR (contract performance).
Click tracking: Links contained in our emails are redirected via a tracking domain operated by Resend. This allows us to detect whether and when you click a link in an email. In doing so, your IP address, the time of the click, and information about your email program or browser are processed. We use this data to improve the relevance of our emails and to be able to recover abandoned orders. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the needs-based design and optimization of our communication). You may object to this processing at any time by contacting us at [email protected].
Web Analytics (Google Analytics 4)
We use Google Analytics 4 (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) to analyze user behavior. GA4 is loaded only after explicit cookie consent. Without your consent, no analytics data is collected. IP addresses are anonymized. Legal basis: Art. 6(1)(a) GDPR (consent).
Usage Analytics (Microsoft Clarity)
On our public pages and in the ordering process we use Microsoft Clarity
(Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland)
to understand how visitors interact with our pages: click and scroll heatmaps as well as recordings of how a
session is operated (mouse movements, clicks, scrolling, visible page areas).
Clarity is loaded only after explicit cookie consent and only then sets the cookies
_clck and _clsk. Input into form fields is masked before transmission.
The customer area (server management, profile, invoices) is not recorded.
Microsoft processes the data as an independent controller in the Microsoft Azure cloud; a transfer to the
United States may take place and is safeguarded by standard contractual clauses. Recordings are deleted
after 30 days. Legal basis: Art. 6(1)(a) GDPR (consent). Further information:
Microsoft Privacy Statement.
First-party usage analytics in the server configurator
After your explicit consent, we also record in our own system which offered setting fields are used in the server configurator and whether the associated pseudonymous session subsequently reaches the next order step or checkout. In addition to its timestamp, event type, and pseudonymous session identifier, this additional field event contains only technical identifiers for the game, server software and field, the field type, the technical effect of the change, and whether the setting differs from its default. No account, IP, device, location, referrer, page, or campaign data is added to this field event. The entered value itself is not collected. This specifically includes passwords, tokens, world seeds, and free text. Raw events are deleted together with the associated analytics session no later than after the general analytics retention period of 180 days. Internal reports expose only aggregated field groups containing at least five sessions and do not contain session identifiers. We use this information to identify unnecessary or unclear inputs and improve the ordering flow. Legal basis: Art. 6(1)(a) GDPR (consent). You can withdraw your consent at any time through the cookie settings.
Error Logging (Sentry)
To detect and remediate software errors, we use Sentry
(Functional Software, Inc., 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA).
In the event of an error, technical information (error message, stack trace, browser type) is transmitted to Sentry.
No personal data such as email addresses or IP addresses is sent to Sentry
(send_default_pii = false). Privacy notice:
sentry.io/privacy.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in system stability).
Web Analytics (Ahrefs)
We use Ahrefs Web Analytics (Ahrefs Pte. Ltd., Singapore) as a cookieless web analytics tool. Ahrefs sets no cookies and stores no personal data. IP addresses are not stored permanently. The script is loaded without cookie consent, since, as a cookieless analytics tool, it does not require consent. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in website optimization).
Marketing Attribution (Source Measurement)
In order to measure through which of our content (e.g., guide articles) visitors reach an order,
we store the source information from the referral link (utm_source,
utm_medium, utm_campaign) as so-called first-touch attribution. For
Google ads, we also store available click identifiers (gclid, gbraid,
wbraid) and their capture time so a later order can be attributed to the ad click. This is done
exclusively after your consent to analytics cookies: a cookie
gsh_attr holds the first recorded source and the encrypted HttpOnly cookie
gsh_gads holds the latest Google ad click (30 days each); if an account exists,
these details are assigned to the account so that a later order can be attributed.
Your analytics decision is stored in the cookie gsh_consent. Without
consent, no permanent source storage takes place. Legal basis: Art. 6(1)(a)
GDPR (consent). You can withdraw your consent at any time via the cookie settings.
Only if you additionally allow marketing cookies do we store this decision separately in
gsh_marketing_consent. Upon the first successful live payment, available Google click
identifiers, click and payment times, a pseudonymous transaction identifier, and payment value and
currency may then be transmitted to Google through the Google Data Manager API. Email address, name,
and IP address are not transmitted. The purpose is to measure which ad led to a new-customer purchase;
each payment is transmitted at most once. The legal basis is Art. 6(1)(a) GDPR. Withdrawal in the
cookie settings blocks future transmissions.
Invoicing (InvoiceNinja)
For invoice creation, we use a self-hosted instance of InvoiceNinja (InvoiceNinja, LLC, USA). The invoice data (name, address, email, invoice amounts) is processed exclusively on our own server at Hetzner in Germany. No data is transmitted to third parties. Legal basis: Art. 6(1)(b) GDPR (contract performance).
Data Processing (DPA)
We have concluded data processing agreements (DPA) pursuant to Art. 28 GDPR with the following service providers:
- Hetzner Online GmbH — server hosting for website, database and invoices (data processing in Germany)
- OVH SAS (Roubaix, France) — server hosting for part of the game servers; data processing in the Limburg an der Lahn (Germany) and Roubaix (France) data centres, both within the EU
- Stripe, Inc. — payment processing (EU-US Data Privacy Framework certified)
- Cloudflare, Inc. — CDN, DNS, and DDoS protection (EU-US Data Privacy Framework certified)
- Resend — transactional emails
8. Retention Period
We store your personal data only for as long as necessary for the respective purposes:
| Type of Data | Retention Period |
|---|---|
| Server log files | 14 days |
| Login logs | 90 days |
| User account | Until deleted by the user |
| Contract and accounting data | Generally 8 years where retained as accounting records under Section 257 HGB; longer only where another statutory basis applies |
| Invoices | 8 years (Section 14b UStG) |
| Server metrics (CPU, RAM) | 30 days |
| Cookies (analytics) | Until consent is withdrawn |
Marketing attribution (gsh_attr, gsh_gads) | 30 days |
| Support requests | 2 years after completion |
9. Controller
Jens Röcker
Südeschstraße 32
48429 Rheine
Email: [email protected]
10. Your Rights as a Data Subject
You have the right at any time to: access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), and objection (Art. 21 GDPR).
Right to lodge a complaint with the competent supervisory authority: State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen), Postfach 20 04 44, 40102 Düsseldorf.
Last updated: August 2026