Shardworlds
Home Lore Features Community

Privacy Policy

Last updated: 2026-08-27

1. Controller

Chris Schmidt
Darmstädter Str. 8, 64372 Ober-Ramstadt, Germany
Email: mad@shardworlds-game.com

2. Privacy Contact

For privacy requests, contact: mad@shardworlds-game.com

3. Data We Process and Why

  • Account data: username, email, password hash, language settings to provide your account.
  • Game/profile data: characters, game state, messages, trade/combat records to operate gameplay.
  • Billing/subscription data: subscription status, payment provider IDs, invoice events to perform the contract.
  • Security and abuse data: IP addresses, account and character references, login/session events, pseudonymous session, device, and browser characteristics, and limited technical metadata about requests, socket events, rate limits, and security incidents for abuse prevention and service security.
  • Support/legal data: requests (e.g., cancellations) to comply with legal obligations and communication duties.

4. Legal Bases (Art. 6 GDPR)

  • Art. 6(1)(b) GDPR (contract and pre-contractual measures)
  • Art. 6(1)(c) GDPR (legal obligations)
  • Art. 6(1)(f) GDPR (legitimate interests, especially service security and stability)
  • Art. 6(1)(a) GDPR (consent where required)

5. Security and Abuse Detection

To protect players, game data, and service availability, we analyze limited technical metadata for unusual access patterns, automation, data scraping, exploit use, circumvention attempts, and attacks. This may include time, method, normalized endpoint or event name, status, request frequency and duration, rate-limit events, referring origin, and pseudonymous session, device, and browser characteristics.

Processing is based on Art. 6(1)(b) GDPR where necessary to perform the contract securely and Art. 6(1)(f) GDPR. Our legitimate interests are the security, integrity, and availability of the service, prevention of fraud and technical abuse, and enforcement of the Fair Play and Technical Abuse Policy. Dedicated security incident records are generally kept for up to 90 days and retained longer only for an active investigation or the establishment, exercise, or defense of legal claims.

Automated systems may flag activity or apply short-term limits. A permanent sanction is not imposed solely by an automated heuristic and requires review of the available context. Dedicated incident records generally do not contain raw passwords, cookies, or complete request bodies.

6. Cookies and Similar Technologies

We use technically necessary cookies, including session cookies and language settings. For non-essential storage/access on end-user devices, consent is obtained where legally required.

7. Recipients / Processors

  • Hosting infrastructure providers
  • Stripe for payment processing
  • Email providers for transactional messaging (password reset, verification, notices)

8. Retention

We keep personal data only as long as necessary for the relevant purpose or as required by law. Data is then deleted or anonymized.

9. International Transfers

If service providers process data outside the EU/EEA, this is done only with appropriate safeguards (such as EU Standard Contractual Clauses) and GDPR compliance controls.

10. Your Rights

You have the right to access, rectification, erasure, restriction, portability, and objection. You can withdraw consent at any time with effect for the future.

11. Complaint with a Supervisory Authority

Competent or lead supervisory authority:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (HBDI)
https://datenschutz.hessen.de/

© 2026 Shardworlds. All rights reserved. | Crafted by the Archivists of Gaia.
Imprint Privacy Policy Terms Fair Play Cancellation Withdrawal