YOUR DATA
Privacy Policy
How Mini-Games.info handles personal information.
1. Controller
Lutz Fauska EinzelunternehmenOwner: Lutz Fauska
Auf der Hüls 308
52068 Aachen, Germany
Privacy enquiries and requests can be submitted through our contact form. Our email address is also available in a spam-resistant format in the Legal Notice.
2. Scope and principles
This policy covers Mini-Games.info, user accounts and the services offered through this domain. We collect only information reasonably needed to operate, secure and improve the service. We do not currently sell personal information, share it for cross-context behavioural advertising, or use it for automated decisions with legal or similarly significant effects.
3. Information we process
Website access and security
Our hosting systems may process IP address, date and time, requested resource, referrer, browser and device information, response status and security events. This is used to deliver the website, diagnose faults, prevent abuse and protect the service. For EU/EEA users, the legal basis is Article 6(1)(f) GDPR (secure and reliable operation).
User accounts
When an account is created, we process username, selected country, email address, password hash, account status and relevant timestamps. Passwords are stored only as one-way hashes. Processing is necessary to provide the requested account and related functions (Article 6(1)(b) GDPR) and to protect accounts (Article 6(1)(f) GDPR).
Authentication and account emails
We process session identifiers, CSRF tokens, verification and password-reset tokens, login events and temporary rate-limit information. Verification tokens expire after 24 hours; password-reset tokens expire after 60 minutes and are single-use. Emails needed to activate or secure an account are transactional service messages.
Scores, settings and local data
For signed-in users, the service may store personal scores, play counts and associated game settings in the account. Additional preferences, settings and local results may remain only in the user’s browser. Account-based processing supports the requested service; local storage is described in the Cookie Policy.
Contact form
We process title, name, optional company, subject and message. The IP address is used temporarily to enforce anti-spam limits. Contact messages are processed to answer enquiries, take pre-contractual steps where requested, and protect the form from misuse (Article 6(1)(b) and (f) GDPR).
Optional update emails
We do not currently add account email addresses to a marketing list automatically. If update emails are introduced, they will be sent no more than once per week, and only when there is relevant news. Subscription will require a separate voluntary opt-in and verifiable confirmation. Every update email will contain a simple unsubscribe method. Consent may be withdrawn at any time without affecting prior lawful processing.
4. Hosting and recipients
The website, database and email infrastructure are hosted with STRATO in Germany. STRATO processes data as a service provider where required to provide hosting, database, backup and email services. Information may also be disclosed to public authorities when legally required, or to professional advisers where necessary to establish, exercise or defend legal claims.
5. International transfers
At present, the core service is hosted in Germany and no advertising, social-media embeds or external analytics are active. If services such as Google advertising, YouTube, Facebook or third-party analytics are introduced, they may involve recipients outside the EU/EEA, including the United States. Such services will not be activated before required consent controls and lawful transfer safeguards are implemented and this policy is updated.
6. Retention
- Unconfirmed accounts are scheduled for deletion after seven days.
- Active account information and account-based records are kept until the account is deleted, unless a longer period is legally required.
- Contact messages are normally retained for no longer than 12 months, unless needed longer for an ongoing matter or a legal obligation.
- Temporary rate-limit records are normally retained for minutes or hours.
- Server logs and backups are retained only for operational, security and legally required periods under the hosting and backup schedules.
- Browser storage remains until its stated expiry, the website removes it, or the user clears it.
7. Rights in the EU/EEA and United Kingdom
Subject to applicable law, individuals may request access, correction, deletion, restriction, data portability or object to processing. Consent can be withdrawn at any time. Signed-in users can permanently delete their account and associated account records directly under “My Account” → “Delete account”. Other requests can be made through the contact form; identity verification may be required.
EU/EEA users may lodge a complaint with a supervisory authority. The authority responsible for our place of establishment is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, www.ldi.nrw.de.
8. United States privacy notice
Residents of US states with applicable privacy laws may have rights to know or access personal information, correct inaccuracies, delete information, obtain a portable copy, and opt out of certain sale, sharing, targeted advertising or profiling. These rights depend on the law and whether it applies to our business. We do not currently sell personal information or use cross-context behavioural advertising. Requests and appeals may be submitted through the contact form.
9. Canadian privacy notice
Where Canadian privacy law applies, individuals may request information about the existence, use and disclosure of their personal information, request access, and challenge its accuracy. We limit collection, use, disclosure and retention to the purposes described here and use safeguards appropriate to the information. Privacy questions or complaints can be submitted through the contact form.
10. Children
The service is not directed to children. We do not knowingly collect personal information from children who cannot validly consent under applicable law. If we learn that such information was submitted without the necessary authorization, we will take reasonable steps to delete it.
11. Security
We use measures including HTTPS, password hashing, prepared database statements, restricted server-side configuration, CSRF and same-origin controls, secure session handling, limited login and contact attempts, and access controls. No internet service can guarantee absolute security.
12. Changes
We will update this policy when the service, legal requirements or data practices change. Material changes will be presented appropriately on the website. Planned advertising, social-media embeds or analytics will require a policy update before activation.