Privacy Policy
1. Controller
Strategische Spiele Entwicklung UG (haftungsbeschränkt)Managing director: Valentin Schierhuber
Riedackerstr. 4 A
69509 Mörlenbach
Email: kontakt@cardgame.de
2. Collection and storage of personal data
a) When you visit the website
When you access our website, your browser automatically transmits information to our server. This information is stored temporarily in a so-called log file. The following information is collected without any action on your part and stored until it is deleted automatically:
- IP address of the requesting computer
- Date and time of access
- Name and URL of the file retrieved
- Website from which the access is made (referrer URL)
- Browser used and, where applicable, the operating system of your computer
The data listed are processed for the following purposes: ensuring a smooth connection to the website, ensuring convenient use of our website, evaluating system security and stability, and other administrative purposes.
The legal basis for this processing is Art. 6(1)(f) GDPR. Our legitimate interest follows from the purposes of data collection listed above.
b) When you register for and use the game
When you register for our card game, we collect the following data:
- Username
- Email address
- Password (stored encrypted using bcrypt)
- IP address at registration and login
- Time of the last login
- Game statistics (wins, losses, XP collected, etc.)
These data are required to enable you to use the game (Art. 6(1)(b) GDPR — performance of a contract).
3. Cookies and local storage
Our website uses session cookies that are required for operating the website and for authentication. These cookies are deleted automatically when your browser session ends.
In addition, we use localStorage in your browser to store your preferred display mode (dark/light mode). This data does not leave your browser and is not transmitted to our server.
4. Disclosure of data
Your personal data will not be transferred to third parties for purposes other than those listed below. We only disclose your personal data to third parties if:
- you have given your express consent to this (Art. 6(1)(a) GDPR)
- the disclosure is necessary for the establishment, exercise or defence of legal claims (Art. 6(1)(f) GDPR)
- there is a legal obligation to do so (Art. 6(1)(c) GDPR)
5. Rights of data subjects
You have the right:
- pursuant to Art. 15 GDPR, to request access to your personal data processed by us
- pursuant to Art. 16 GDPR, to request the rectification of inaccurate data without undue delay
- pursuant to Art. 17 GDPR, to request the erasure of your personal data stored by us
- pursuant to Art. 18 GDPR, to request the restriction of processing of your personal data
- pursuant to Art. 20 GDPR, to receive your personal data in a structured, commonly used and machine-readable format (data portability)
- pursuant to Art. 7(3) GDPR, to withdraw your consent once given at any time with effect towards us
- pursuant to Art. 77 GDPR, to lodge a complaint with a supervisory authority
6. Data security
During your visit to our website we use the widespread SSL (Secure Socket Layer) method in combination with the highest level of encryption supported by your browser. Passwords are stored exclusively as bcrypt hashes and therefore cannot be viewed in plain text, not even by us.
We use appropriate technical and organisational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction or unauthorised access by third parties.
7. Validity and changes to this privacy policy
This privacy policy is currently valid and is dated September 2026.
Due to the further development of our website or changes in legal or regulatory requirements, it may become necessary to amend this privacy policy.
This English version is a convenience translation; only the German version is legally binding.