Privacy Policy

Last Updated: 31.07.2026

1. General Information

This Privacy Policy informs you about the nature, scope, and purpose of the processing of personal data (hereinafter "data") within our online game "A Dark Cave" and its associated websites, functions, and content.

Data Controller:
Julian Bauer
Königsberger Straße 1
97072 Deutschland
Email: support@a-dark-cave.com

2. Your Rights as a Data Subject

You have the right:

3. Data Processing Details

a) When visiting the website:

When you access our website, our server automatically stores information in server log files that your browser transmits. These are: browser type/version, operating system used, referrer URL, hostname of the accessing computer, and time of the server request. This data is not merged with other data sources. The basis for this data processing is Art. 6(1)(f) GDPR, our legitimate interest in the technically flawless presentation and security of our website.

b) Account Creation (Cloud Save):

If you choose to create an account, we collect your email address and a password hash. This data is necessary to create and manage your account and to provide the cloud save functionality. The legal basis is Art. 6(1)(b) GDPR (performance of a contract).

c) Game State Storage:

For authenticated users, your complete game state is stored in our database to allow you to continue your game across different devices. This may include progress, settings, play statistics, and related gameplay data. We may also store limited internal product analytics linked to your account (for example aggregated in-game button-click counts, and first-touch campaign or UTM parameters from the link you used to arrive, if any). The legal basis is Art. 6(1)(b) GDPR (performance of a contract) and, for limited analytics, Art. 6(1)(f) GDPR (legitimate interest in improving the game and measuring marketing effectiveness).

d) Leaderboard:

If you complete the game, we may store a leaderboard entry linked to your account (for example play time, completion time, game mode, and email address used for the account). Public leaderboard displays use a username you choose or a masked form of your email, not your full email address. The legal basis is Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in operating the leaderboard).

e) In-Game Purchases:

When you make a purchase, we store a record of the transaction (user ID, item, price, timestamp). This is necessary for contract fulfillment and for support purposes. We do not store any financial data like credit card numbers. The legal basis is Art. 6(1)(b) GDPR (performance of a contract).

f) Optional marketing emails:

We may send promotional emails (updates, discounts, rewards) only if you opt in via a separate optional checkbox at sign-up or later in your profile. The legal basis is Art. 6(1)(a) GDPR (consent). You can withdraw consent at any time without affecting your account or cloud save: use the unsubscribe link in any marketing email, or use the subscribe / unsubscribe control in the in-game profile menu.

To demonstrate consent and withdrawals, we store a marketing preference record for your account, including: email (as provided), whether you opted in, how the choice was recorded (e.g. sign-up, Google sign-up, settings, or unsubscribe link), consent text and prompt version numbers, and timestamps for when you consented or withdrew. Unsubscribe links use a single-use token (we store only a cryptographic hash of the token until it is used or expires).

g) Anonymous session and campaign metrics:

Independently of whether you create an account, we may store anonymous first-party product metrics: a random session identifier with approximate session duration, and (when you arrive via a campaign link) UTM or similar campaign parameters (for example source, medium, campaign). These records are not linked to your email or account. We retain them for about one year. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in understanding how the game is used and which campaigns bring visitors).

4. Cookies and Local Storage

We use session storage on your device to maintain your authentication state and for short-lived first-party session / campaign identifiers used for the anonymous metrics described in section 3g. This is a technically necessary function for operating and measuring the service. The legal basis is § 25(2) No. 2 TDDDG.

For users playing without an account, we use IndexedDB in your browser to save your game progress locally. This is essential for the game's functionality. The legal basis is § 25(2) No. 2 TDDDG.

We do not use advertising or third-party tracking cookies. We do use limited first-party product analytics as described above (session duration and campaign / UTM landing metrics). Optional marketing emails are only sent with your separate consent (see section 3f).

5. Third-Party Services

We use third-party services to provide and improve our Game. We have concluded Data Processing Addendums (DPAs) with these providers where required.

a) Supabase:

We use Supabase Inc. (USA) for our backend infrastructure, including authentication and database hosting. Supabase processes your email address, password hash, and game data on our behalf. We have configured our Supabase project to store all data within the EU (Frankfurt region). The legal basis for this is Art. 6(1)(b) and Art. 6(1)(f) GDPR. We have entered into a DPA with Supabase to ensure that your data is handled in compliance with the GDPR.

b) Stripe:

For processing payments, we use Stripe Payments Europe, Ltd. (Ireland). When you make a purchase, you are redirected to Stripe's payment interface. Stripe collects payment information (e.g., credit card details) directly. We do not receive or store this sensitive financial data. Stripe is responsible for the secure processing of your payment data. The legal basis for using Stripe is Art. 6(1)(b) GDPR (performance of a contract).

c) Resend:

We use Resend Inc. (USA) to send email on our behalf, including account-related messages (e.g. sign-up or password reset, where applicable) and, if you have opted in, promotional emails as described in section 3f. Resend processes the recipient address and the content needed to deliver each message. The legal basis is Art. 6(1)(b) GDPR for emails necessary to provide the service, and Art. 6(1)(a) GDPR for marketing emails (consent). We have entered into a DPA with Resend where required for processor relationships.

d) Replit:

We host the A Dark Cave website and application backend via Replit, Inc. Replit processes technical data necessary to deliver the service (for example connection and server log data). Replit runs published apps on Google Cloud infrastructure. The legal basis is Art. 6(1)(b) and Art. 6(1)(f) GDPR. We use Replit under its terms and data processing terms applicable to our account.

e) Playlight:

We integrate the Playlight game discovery SDK in the browser. When the SDK loads, Playlight may collect technical information such as IP address, browser type/version, pages visited, and access times, as described in Playlight's own privacy policy. We do not send your account email address to Playlight. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in offering optional game discovery features). Playlight acts as an independent service with its own privacy practices for data it collects through the SDK.

6. International Data Transfers

Your core account and cloud game save data are stored with Supabase in the EU (Frankfurt region). Some providers process data outside the European Economic Area (for example Resend in the United States, and hosting infrastructure used by Replit). Where a transfer to a third country requires safeguards under Art. 46 GDPR, we rely on appropriate mechanisms such as Standard Contractual Clauses in the provider's Data Processing Addendum, and any additional frameworks those providers lawfully rely on.

7. Data Retention

We store your data for the following periods:

8. Data Security

We take appropriate technical and organizational measures to protect your data from unauthorized access, loss, or alteration. Communication with our servers is encrypted via SSL/TLS.