Legal informationPersonal data
Privacy Policy
What personal data games.enterprises processes, why it is needed, how it is retained, and what rights users have.
Last updated:
1. Who is responsible for the data
The Service operator and personal data controller is Katsiaryna Filosaf, an individual operating from Poland under the games.enterprises brand. For privacy questions, contact privacy@games.enterprises; the direct fallback address is 100games.enterprises@gmail.com and the telephone number is +1 (343) 655-5448.
Residential and postal address: ul. Rolna 1, 30-318 Kraków, Poland. If live subscriptions are enabled, subscription payments will be processed through Stripe.
2. Account data
When you register, we receive your email address, nickname, and password. The database also stores an internal user identifier, normalized versions of the email address and nickname for uniqueness checks, the dates on which the account was created and updated, and the selected language.
The password itself is not stored; a strong, salted cryptographic hash is retained instead. A random token is created for authentication; the database stores a hash of that token, the user identifier, and session creation and expiration times. The email address is not displayed to other players, but the nickname may appear publicly alongside a score or comment.
When Resend is active and we send an account-email verification code or a transactional message about a subscription or skin order, the recipient address, sender, subject, plain-text content, any plain-text contract attachments, message identifier, and technical delivery metadata are transmitted to Resend (Plus Five Five, Inc.). During controlled migration or recovery while the configured legacy authenticated SMTP transport is active, equivalent message and delivery data are transmitted through that provider; Google is the current production legacy provider. A verification message transmits the one-time six-digit code in plain text, and contract messages may include plain-text Terms and cancellation/refund attachments; we do not intentionally include passwords or full card details in these messages.
3. Game and social data
For supported server-based games, we process the game name, game submissions and single-use play identifiers, engine version, start and completion times, best and total scores, play count, and date last played. Leaderboard entries may include a public nickname, rank, score, and score time.
If you use social features, we store likes, saved and pinned games, the time of those actions, comment text, a comment identifier, and the time of posting. Other users can see a published comment, nickname, and associated public game information. The email address and internal identifier are not published.
4. Device and request data
When the site is accessed, the server and network proxy technically process the IP address, date and time, request method, path and query string, response status, response size, referrer, and browser or user-agent information transmitted by the device. The query string can include search or navigation parameters and, when a user opens the illegal-content notice tool, the comment identifier, game slug, and content URL used to prefill the notice. Origin headers and other security headers are used to validate requests. Do not place passwords, payment details, or other secrets in a URL.
To meter the anonymous 60-minute allowance and prevent repeated free use, we combine a necessary device cookie with an HMAC-pseudonymized representation of the IP address. The HMAC uses a secret key so the stored value is not the plain IP address, but it remains pseudonymous personal data rather than anonymous data. We do not use device fingerprinting. Changing or deleting the cookie does not necessarily reset eligibility because the IP pseudonym may still be used for anti-abuse checks.
The IP address is also used in short-lived rate limiters for registration, sign-in, and reading comments. A SHA-256 digest of the normalized email address is used to limit account sign-in attempts. These safeguards may restrict a duplicate allowance or trial but do not make decisions producing legal or similarly significant effects.
5. Cookies and local storage
We use strictly necessary cookies for sessions, language selection, and the device-linked free-play allowance. Games may save scores, puzzle state, statistics, or tutorial completion in localStorage on your device. A short-lived indicator that a language preference was saved may be placed in sessionStorage until the tab is closed.
Only after an affirmative marketing choice, we load Meta Pixel for dataset/pixel 1064531599294316. It sends Meta the page URL and referrer, time, browser and device/network information made available by the request (including IP address and user agent), Meta identifiers such as _fbp or _fbc where available, and the event name. Events are PageView, ViewContent with a game slug, CompleteRegistration, GameStart, and GameOver. We do not include an email address, account or user identifier, nickname, score, card data, or free-form content in these Pixel event parameters.
Meta Pixel is optional and is disabled until consent. On the initial banner, one click on Accept all both confirms that the visitor is at least 16 and permits Meta Pixel; Cookie settings keep age and marketing as separate checkboxes. A visitor under 16 can refuse marketing without losing games or account access. The Cookie Policy contains the complete storage list, retention information, and controls for accepting, refusing, or later withdrawing that consent.
6. Subscription, skin purchase, and payment data
Subscription enrollment and one-time skin purchases use Stripe-hosted Checkout. Stripe directly receives the card and billing details entered by the user and processes them for payment, fraud prevention, and legal compliance. We do not receive or store the full card number or security code.
For trial eligibility, subscription administration, skin orders and entitlements, access control, accounting, tax, support, refunds, and disputes, we receive and store relevant billing name or address, payer email, country, tax status, Stripe customer, subscription, price, invoice, Checkout Session, PaymentIntent, charge and transaction identifiers, subscription and payment status and dates, game and skin identifiers, selected-skin and entitlement status, currency, amount, tax applied, payment-method type, card brand and last digits, and refund, dispute, fraud-risk, revocation, and restoration information.
For a skin order we also retain evidence of the purchase terms and withdrawal-notice versions presented, the user's required confirmations, locale, timestamps, delivery status, and the source purchase linked to the entitlement. This evidence supports performance of the purchase, required consumer information, complaints, refunds, disputes, and legal claims.
Stripe may process data in countries outside the EEA under safeguards described in its privacy documentation at stripe.com/privacy. Stripe's exact role depends on the relevant processing and applicable law.
7. Why and on what basis we process data
For processing governed by the GDPR, the purposes, data categories, and legal bases are mapped as follows. Where processing is based on consent, it may be withdrawn for the future; where it is based on legitimate interests, you may object and we will assess your circumstances.
- Account creation, authentication, sessions, requested saves, leaderboards, and social features: account, session, game, and social data described above — performance of the user agreement or steps requested before entering it (Article 6(1)(b) GDPR).
- Free-play metering, security, abuse prevention, rate limiting, service resilience, and fault diagnosis: the necessary device cookie, IP address and HMAC pseudonym, request and access-log data, the pseudonymous email digest, and relevant account, game, or social records — performance of the access rules (Article 6(1)(b) GDPR) and our legitimate interests in operating a secure, fair, and reliable Service and preventing repeated free use (Article 6(1)(f) GDPR).
- Starting and administering the 30-day trial and monthly subscription, controlling access, processing payments, refunds, and disputes, and providing billing support: account and Stripe billing, subscription, and transaction data — performance of the subscription agreement or requested pre-contract steps (Article 6(1)(b) GDPR), compliance with accounting, tax, consumer, and payment obligations (Article 6(1)(c)), and fraud prevention and legal claims (Article 6(1)(f) GDPR).
- Reviewing, completing, supplying, and maintaining a one-time skin purchase; recording the account entitlement and selection; delivering a durable contract confirmation; and handling support, refunds, revocations, restorations, and disputes: account, order, entitlement, purchase-confirmation, and Stripe transaction data described above — performance of the skin purchase agreement or requested pre-contract steps (Article 6(1)(b) GDPR), compliance with accounting, tax, consumer-information, and payment obligations (Article 6(1)(c)), and fraud prevention and legal claims (Article 6(1)(f) GDPR).
- Verifying control of an account email and sending requested operational, security, pre-contract, and contract messages: recipient address, message content, identifiers, and delivery metadata — performance of the user, subscription, or skin-purchase agreement or requested pre-contract steps (Article 6(1)(b) GDPR), compliance with consumer-information and other communication duties (Article 6(1)(c)), and our legitimate interests in account security, delivery diagnostics, and legal claims (Article 6(1)(f)), as applicable to the message.
- Responding to support, privacy, and legal requests: contact details, request contents, relevant account records, communications, and technical evidence — performance of the agreement where the request concerns the Service (Article 6(1)(b)), compliance with legal duties (Article 6(1)(c)), and establishing, exercising, or defending rights (Article 6(1)(f) GDPR), as applicable to that request.
- Legal compliance and claims: the records and communications necessary for a specific statutory duty, lawful authority request, dispute, or claim — compliance with a legal obligation (Article 6(1)(c)) or our legitimate interest in protecting legal rights (Article 6(1)(f) GDPR).
- Optional Meta Pixel measurement, advertising attribution, campaign optimization, and creation or use of advertising audiences: page and game-event data, browser/device and network data, and Meta cookie identifiers described above — consent under Article 6(1)(a) GDPR and the required consent for optional terminal-equipment storage or access. Refusal has no effect on access to games or an account, and consent may be withdrawn for future events at any time through Cookie settings.
8. When data is disclosed
We do not sell personal data. After consent, disclosure of Pixel activity to Meta for audience and advertising services may be treated as sharing for targeted or cross-context behavioral advertising under some laws; refuse or withdraw marketing consent, or use a legally recognized opt-out signal, to stop future Pixel events from this browser. Timeweb Cloud provides hosting in Amsterdam, Netherlands: the production SQLite database and routine logical backups are stored on the production VPS in that region. The physical data-center identity and the location of the provider-level backup have not been confirmed.
Namecheap provides authoritative DNS and domain email forwarding, and Google provides the destination Gmail mailbox for incoming contact mail. After activation, Resend (Plus Five Five, Inc.) is the primary outbound transactional-email service. Under its published terms, Resend acts as our processor for submitted message and customer data and as an independent controller for the specified account, service-usage, security, and similar provider data. During controlled migration or recovery, the configured legacy authenticated SMTP provider may instead provide the outbound transport; that provider is currently Google in production. The Service does not automatically switch to the legacy transport after a Resend delivery failure, and we will update this notice before changing the legacy provider. Resend's privacy policy is at https://resend.com/legal/privacy-policy and its processor terms are at https://resend.com/legal/dpa. Stripe provides hosted Checkout, payment processing, fraud prevention, billing, and the customer portal. After marketing consent, the EEA recipient Meta Platforms Ireland Limited, Merrion Road, Ballsbridge, Dublin 4, D04 X2K5, Ireland receives the Pixel data described above to provide advertising measurement, attribution, optimization, and audience services under the Meta Business Tools Terms (https://www.facebook.com/legal/technology_terms) and Meta Privacy Policy (https://www.facebook.com/privacy/policy/). These providers receive the information needed for their respective services. Public nicknames, scores, and comments are disclosed to other visitors by the nature of those features.
We may disclose data where reasonably required by law, a court order, or a competent authority; to investigate fraud or threats; to establish, exercise, or defend legal claims; or as part of a reorganization or business transfer with appropriate safeguards and notice.
9. International processing
The operator is in Poland and the primary infrastructure is in the Netherlands, both within the European Economic Area. Resend states that all account data, including email metadata, logs, and API records, is stored in the United States regardless of the selected sending region, and its privacy policy states that data submitted from outside the United States is transferred to and processed there. Resend's published DPA incorporates the EU Standard Contractual Clauses for covered transfers outside the EEA and describes its participation in the EU-U.S. Data Privacy Framework; which transfer mechanism applies depends on the transfer and applicable law. Namecheap, Google, Stripe, and, after consent, Meta may also process relevant data outside the EEA under safeguards described in their published privacy or data-processing terms. Meta operates a global advertising service and may transfer Pixel data to Meta companies and infrastructure outside the EEA under the safeguards described in its terms and privacy materials. You may request further information at privacy@games.enterprises.
10. Retention periods
Account data, persistent game statistics, saves, reactions, and comments are retained while the account exists or while needed for the feature. A user may delete their comment using the available feature or request deletion of the account and associated data. Certain records may be retained temporarily for security, dispute resolution, or legal compliance.
- A session record and cookie remain valid for no more than approximately 30 days. After expiry, the record no longer authorizes requests and is deleted when its token is checked or when session-table maintenance runs as a new session is created. Signing out deletes the current record and cookie.
- Single-use game submissions have a short, technically defined lifetime and are deleted on completion, expiration, or cleanup.
- A rate-limit entry is effective only during its applicable short window. After that window it is ignored and replaced on the next request using the same key; stale entries are also removed during protective cleanup of the shared table or disappear when the process restarts.
- Network access logs are written to an active file capped at 20 MiB and up to 10 rotated archives. On the next rotation, archives older than 30 days are deleted; on a low-traffic site the active file and an archive awaiting the next rotation can remain longer. Records connected with an incident may be isolated for the period needed to investigate it, protect legal claims, or comply with law.
- Deleted data may remain in protected backups for a limited period; it is isolated from ordinary use and overwritten according to the backup-retention cycle.
- The __Host-games_device cookie and its server-side HMAC identifier have a maximum lifetime of one year and are refreshed while used. IP HMAC grant records are ordinarily deleted after 30 days without activity. Records tied to abuse or a dispute may be retained longer where reasonably necessary or legally required.
- The local games_privacy_consent record expires after 180 days, is replaced when you change the choice, and is removed if its consent version becomes invalid. It records the marketing decision and 16+ confirmation as separate values; both are reset on refusal or withdrawal. After confirmed registrations and only while marketing consent is active, games_meta_pending_registration may keep up to eight opaque random event IDs and timestamps in sessionStorage for no longer than 24 hours so each CompleteRegistration can be handed to a loaded Pixel after navigation. It contains no account fields and is removed after hand-off, when tab storage ends, or on withdrawal, GPC, or expiry. When Meta Pixel is permitted, Meta first-party identifiers _fbp and _fbc may remain for up to approximately 90 days unless you withdraw consent or clear them earlier. We attempt to delete those accessible first-party cookies on withdrawal. Meta retains received event data under its own current policies and business-tool settings; those periods are controlled by Meta and may vary by data and purpose.
- A local billing-email challenge is valid for 15 minutes and stores a keyed hash of the code rather than the code itself. It is removed after successful verification or exhausted attempts; after expiry it cannot be used and is deleted when next checked or replaced. The outbound provider necessarily receives the plain-text code as part of the message. Resend's documentation currently states that it retains email data — including message bodies, plain-text contract attachments, and verification-code messages — in the United States for 30 days across all plans, with flexible retention for Enterprise. Its privacy policy also describes retention where necessary for stated purposes, legal obligations, disputes, or enforcement of agreements.
- Subscription, skin-order, payment, consent-evidence, entitlement, revocation, financial, and tax records are retained for the period required to perform the paid agreement and by applicable accounting, tax, antifraud, consumer, dispute, and legal-claims rules. An active entitlement record remains linked to the account while the entitlement and account exist; records no longer needed are deleted or de-identified subject to mandatory retention.
11. Security
We use HTTPS, HttpOnly and SameSite cookies, salted password hashing, server-side session-token hashing, origin validation for state-changing requests, rate limiting, an isolated database, and restricted infrastructure access. Backups are maintained for service recovery.
No method of transmission or storage guarantees absolute security. If an incident creates a risk, we will assess it and notify affected individuals and authorities in the circumstances and within the time limits required by law.
12. Your rights
Depending on your location, you may have the right to be informed about processing, access and obtain a copy of data, correct or delete it, restrict or object to processing, receive a portable copy, withdraw consent, and not be subject to a significant decision based solely on automated processing. You may complain to a competent authority; the lead supervisory authority in Poland is the President of the Personal Data Protection Office (Prezes UODO), ul. Stanisława Moniuszki 1A, 00-014 Warsaw, uodo.gov.pl.
Send a request to privacy@games.enterprises from the email address associated with the account and describe what you seek. To protect the account, we may request proportionate identity verification. We respond free of charge and within the period set by law, except for manifestly unfounded or excessive repeated requests. If we deny a request in whole or in part, we will explain the grounds and available appeal routes.
13. Managing public data
Before posting a comment, remember that other users will see it. You can delete a comment through the interface while signed in. To correct or delete a nickname, score, or other public item that you cannot change yourself, contact privacy@games.enterprises.
14. Children
The Service is not intended for anyone under 13. A user aged 13 to 17 may use it only with any permission required by the law where they live. A subscription or skin purchase must be concluded by a person who is at least 18 and has legal capacity; a parent or legal guardian may purchase in their own name where lawful. If you believe a child under 13 submitted data, contact privacy@games.enterprises; we will investigate and delete the data where required.
15. Browser signals and advertising
We do not sell personal data. A Global Privacy Control signal disables Meta Pixel marketing consent in that browser. Do Not Track has no uniform legally binding interpretation, so use Cookie settings to refuse or withdraw Meta Pixel consent; we also honor other legally binding opt-out signals where applicable.
16. Changes to this Policy
We will update this Policy when data, purposes, recipients, or the law changes and will display a new date. Where required, we will give prominent notice of a material change before it takes effect. For a new optional purpose, we will request consent if the existing legal basis does not cover it.