1. Subject matter and duration
The subject matter is the analytics service described in the Terms. Processing lasts as long as your network is connected, plus the time needed to delete backups on their normal schedule.
2. Nature and purpose
We collect telemetry from your connectors and store it per network so the dashboard can answer where players came from, whether they returned, what they did, and what they spent. We do not process it for any other purpose, we do not sell it, and we do not combine it with another network data.
3. Data subjects and categories of data
| Data subjects | Categories of personal data |
|---|---|
| Players on your network | Username, Mojang UUID or Floodgate XUID, identity type, connection hostname, join and leave times, session length, backend server name, confirmed cheat bans, and a keyed hash of the IP address when your connector is configured to send one |
| Buyers in your Tebex store | Premium UUID, transaction id, amount, currency, and package names |
We receive no special category data, no chat content, no inventories, and no payment card data from your network.
4. Your instructions
We process player data only on your documented instructions. What you configure in your connector and in the dashboard is that instruction. We tell you if an instruction looks unlawful to us rather than carrying it out quietly.
5. Confidentiality
Everyone with access to your data is bound to confidentiality and gets access only where the work needs it.
6. Security measures
These are the measures the running system actually applies. We do not list controls we have not built.
- Player IP addresses, when sent at all, are replaced with a keyed HMAC-SHA256 hash under a per-network key before storage. The raw address is discarded and never written.
- Every server-side query derives its network scope from the authenticated request. A network id from the browser is never trusted on its own.
- Connector credentials are per server, are stored as digests, are revocable from the dashboard, and rotate by pairing again. Pairing codes expire after ten minutes and are single use.
- The ingest API refuses any request that did not arrive through the trusted edge proxy, and applies rate limits before and after authentication.
- Tebex deliveries are accepted only on a per-network address and only with a valid signature. Stripe webhooks are verified the same way.
- Public traffic reaches the service through a Cloudflare Tunnel. The host opens no inbound port to the internet or to the local network, and TLS is terminated before anything reaches the application.
- Database backups run nightly and are deleted after 14 days.
We do not claim disk level encryption, a certified security standard, or a formal penetration test, because we have not done them.
7. Subprocessors
You give general authorisation for the subprocessors below. We give you notice before we add or replace one, and you may object and terminate if you do not accept the replacement.
| Subprocessor | Purpose |
|---|---|
| Cloudflare | Edge network for the site and the ingest API |
| Google sign-in for dashboard users | |
| Discord | Discord sign-in for dashboard users |
| Resend | Magic link email delivery |
| Stripe | Checkout, card handling, and subscription state |
Tebex is not our subprocessor. It is your store provider and a source of purchase events we receive from it under your own arrangement with them.
8. International transfers
The subprocessors above operate in and outside the European Economic Area. Where they process data outside it, they do so under their own published transfer mechanisms, including the standard contractual clauses.
9. Player requests
Requests from your players come to you, because you are the controller. Tell us and we help you answer them: we export what we hold on a player, and we delete a player or a whole network on request from the owner account. There is no self-serve button for this yet: we run it with a maintenance script and answer within 30 days.
10. Breach notification
If we become aware of a personal data breach affecting your network, we tell you without undue delay and give you what you need for your own notification duties.
11. Deletion and return
When your network is closed, or on request, we delete the network data. Copies inside existing backups go when those backups reach their 14 day age and are deleted. Ask before deletion if you want an export, because deletion is final.
12. Audit
On reasonable request we answer questions about how we process your data and give you the information you need to show compliance. We are a small team, so this is a conversation and documents, not a site visit.
13. Contact
Data protection questions and requests go to [email protected].