Legal
Privacy Policy
Information on the processing of personal data in accordance with the GDPR
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
First name Last name
Street and house number
Postal code City, Germany
Email: your@email.com
2. Data Collected and Purposes
2.1 Discord OAuth Authentication
Discord OAuth 2.0 is used for sign-in. In this process, the following data is transmitted by Discord and stored in our database:
- Discord user ID
- Username and display name
- Avatar hash (for displaying the profile picture)
- No access to messages, email, or other private data
Legal basis: Art. 6 (1) (b) GDPR (performance of a contract / pre-contractual measures).
2.2 Session Tokens
After a successful sign-in, a random session token is set as a cookie
(tl_auth). On the server, only the SHA-256 hash of this token
is stored. The original token never leaves your browser unhashed.
Sessions expire automatically and can be revoked at any time by logging out.
2.3 Server Logs (IIS)
The web server (Microsoft IIS) logs IP addresses, timestamps, requested URLs, and HTTP status codes by default. These logs are used solely for troubleshooting and security. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest).
2.4 Market Data
Market price data is retrieved server-side from the game's official Throne and Liberty trade API. These requests are made by our server, not by your browser — no personal data of users is transmitted to these services.
3. Cookies
We use only functional cookies that are strictly necessary for the operation of the service:
- tl_auth: session cookie for authentication. Not a tracking cookie.
No analytics, advertising, or tracking cookies are used. A cookie banner is therefore not required under current law, provided that only technically necessary cookies are used.
4. External Services
4.1 Discord
Sign-in takes place via Discord (Discord Inc., 444 De Haro Street, Suite 200, San Francisco, CA 94107, USA). During the login process, data is transmitted to Discord. Discord privacy policy: discord.com/privacy
4.2 Fonts
All fonts are hosted locally on our own server (self-hosted). No connection to Google Fonts or any other external font provider is established, and no IP address is transmitted to third parties when fonts are loaded.
4.3 Game Trade API
Market price data is retrieved server-side from the game's official trade API. In this process, no personal data of visitors is transmitted.
5. Retention Period
Personal data is deleted as soon as the purpose of storage no longer applies:
- Sessions: after expiry or revocation (logout)
- User data (Discord ID, name): can be deleted at any time on request
- Server logs: after no more than X days/weeks
6. Your Rights (GDPR)
You have the right to:
- Access: which data we have stored about you (Art. 15 GDPR)
- Rectification: of inaccurate data (Art. 16 GDPR)
- Erasure: of your data ("right to be forgotten", Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Objection to processing (Art. 21 GDPR)
- Data portability (Art. 20 GDPR)
To exercise your rights, contact us by email at: your@email.com
7. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority depends on your place of residence. A list of the German supervisory authorities can be found at: bfdi.bund.de
8. Data Security
The transmission between browser and server is encrypted via HTTPS. Session tokens are stored server-side only as a SHA-256 hash. Database access credentials are stored in the server configuration and are not publicly accessible.
Last updated: Month Year