Privacy Policy
Information on the processing of personal data in accordance with the GDPR
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Kevin Hawacker
Birkenweg 8
57632 Flammersfeld, Germany
Email: support@tl-tracker.com
Phone: +49 170 3342630
We are not required to appoint a Data Protection Officer under Art. 37 GDPR / § 38 BDSG. Write to the address above for any data protection matter.
2. What we process, and why
2.1 Visiting the site without an account
You can browse the public pages without signing in and without giving us anything. Serving a page
necessarily processes your IP address, and the web server (Microsoft IIS) records it along with
the timestamp, the requested URL, the HTTP status and your browser's user-agent string. These
logs exist to keep the service running and to investigate faults and attacks.
Legal basis: Art. 6 (1) (f) GDPR — our legitimate interest in a working, secure service.
Your IP address is also held briefly in server memory to count requests against our abuse limits. It is never written to the database for this purpose and disappears within minutes.
2.2 Signing in with Discord
Sign-in is exclusively via Discord OAuth 2.0. We request the identify scope and
nothing else — we cannot read your messages, your email address, your server list or anything
else in your Discord account. Discord returns, and we store:
- your Discord user ID
- your username, display name and discriminator
- your avatar hash (used only to render your own profile picture)
Legal basis: Art. 6 (1) (b) GDPR — performance of the user agreement you enter into by signing in.
2.3 Your session
A random session token is issued and set as the tl_auth cookie. The server stores
only the SHA-256 hash of that token, so the token itself exists nowhere but in your browser.
Alongside each session we record the time it was created, the time it was last used, its expiry,
the IP address it was created from and your browser's user-agent string. Those
last two let you recognise your own sessions on the account page and let us spot a stolen
session. The account page shows you the device and the times — it deliberately never displays
the IP address.
Legal basis: Art. 6 (1) (b) and (f) GDPR — running the login, and account security.
2.4 What you create in the service
Everything you make while signed in is stored against your Discord user ID: price alerts and
potential alerts you set (including any Discord webhook URL you supply for delivery), items and
potentials you favourite, the flip ledger entries you record, the character builds you import
(the questlog.gg link you paste, the build and character name shown on it, and which pieces you
mark as already owned), reward credits, completed quests, referral codes and referral
relationships, and any support or blacklist suggestions you submit.
Legal basis: Art. 6 (1) (b) GDPR.
2.5 Alert delivery through Discord
When an alert you set fires, our bot sends it to you as a Discord direct message, or posts it to
a Discord webhook URL if you configured one. The alert content and your Discord user ID are
therefore transmitted to Discord for delivery. If you never create an alert, this never happens.
Legal basis: Art. 6 (1) (b) GDPR.
2.6 Paid memberships and payment
Payments are handled by CopeCart GmbH, Rosenstraße 2, 10178 Berlin,
Germany, acting as reseller and as your contractual partner for the purchase (see our
Terms, § 4). Your payment details — card or bank data, billing name and
address — are entered on CopeCart's own checkout and are never seen, received or stored
by us. CopeCart notifies our server of the outcome, and from that notification we store
the order identifier, the plan purchased, the subscription status and the period end date
against your account so we can grant and expire your access. CopeCart's privacy policy:
copecart.com/de/datenschutz.
Legal basis: Art. 6 (1) (b) GDPR, and Art. 6 (1) (c) GDPR for the retention of accounting records.
2.7 Error logs
When a server error occurs we write a technical log entry so the fault can be fixed. Such an
entry can incidentally contain the identifier of the account whose request failed. It contains
no passwords and no payment data.
Legal basis: Art. 6 (1) (f) GDPR.
2.8 Usage measurement
So we can see which parts of the service are actually used, we record a small number of events:
a page being opened, and a few specific actions such as pressing the sign-in or the upgrade
button. Each event holds the date and time, the path of the page (never the query string), the
name of the action, a short note about that action, and a random identifier your browser
generates for itself and keeps in local storage. If you are signed in, the event is also linked
to your account.
The short note is deliberately coarse and never identifies you. For a page being opened it
records whether your window is phone, tablet or desktop sized — a bucket derived from the
width, never an exact size. For other actions it records which entry or button it was, and
sometimes the state you were in when you saw something, such as whether a credit balance already
covered the price on offer. Requests carrying a search engine's own crawler signature are also
marked as such here, so that automated traffic can be told apart from people; that mark is never
applied to an ordinary browser. This note is included in the data export described in section 6.
This measurement runs entirely on our own server. There is no Google Analytics, no Plausible, no
Matomo and no other analytics provider; no data is sent to anyone else, and nothing is used for
advertising. We deliberately do not record your IP address, your browser's user agent,
or the address of the site you arrived from.
If your browser sends a “Do Not Track” signal, we record nothing at all.
Deleting your browser's local storage for this site clears the random identifier, and a new
one is generated on your next visit.
Retention: 180 days, after which the events are deleted. If you delete your account, the
link between these events and your account is removed.
This only happens if you agree to it. We ask once, on your first visit, and nothing is
measured and no identifier is stored until you answer — declining leaves no identifier on
your device, and if you had agreed before, declining deletes the one you already had. The one
thing we do keep either way is your answer itself, under tl_consent, so that we
do not ask you again on every page. It holds only yes or no and the date, it is never sent to
us, and clearing your browser data removes it. You can change your
mind at any time with Cookie choice at the bottom of any page.
Legal basis: Art. 6 (1) (a) GDPR — your consent; and § 25 (1) TDDDG for keeping
the identifier on your device.
2.9 Market data
Auction-house prices are fetched by our server from the game's official Throne and Liberty trade API. Your browser never contacts it, and no data about you is sent to it. The market data itself contains no personal data of our users.
2.10 No profiling, no automated decisions
We do not profile you, we do not advertise to you, we do not sell or share your data with anyone beyond the processors named here, and no decision with legal effect is made about you automatically (Art. 22 GDPR).
3. Cookies and local storage
We set four cookies, all of them strictly necessary to provide a service you have asked for.
None of the four requires your consent, under § 25 (2) no. 2 TDDDG, and we do not ask you
about them.
One thing we do ask about: the random identifier described in 2.8, which usage measurement
keeps in your browser's local storage. That is not necessary to serve you a page, so it needs
your agreement first — that is what the banner on your first visit is for, and it is the
only thing the banner controls. Cookie choice at the bottom of any page reopens it.
- tl_auth — your session after sign-in. HttpOnly, Secure, SameSite=Lax.
- tl_oauth_state — a one-time random value that protects the Discord login against cross-site request forgery. Deleted as soon as you return from Discord.
- tl_oauth_ret — remembers which page you were on when you clicked sign in, so you land back there. Short-lived.
- tl_oauth_item — remembers the item you were about to set an alert on when sign-in interrupted you. Short-lived.
Your browser's local storage additionally holds your own display preferences — the region you
picked, sort order, which filters are open, whether the side rail is collapsed. These are
settings you made, they contain no identifier of any kind, and clearing your browser data
removes them.
Where they are kept depends on whether you are signed in. Signed out, they never leave your
browser. Signed in, the options you set in the Settings panel — theme, density, text
size, home region, which regions to show, number and clock format, sticky headers, performance
and background options, motion, contrast and focus rings, plus the landing page and rail
behaviour — are additionally stored against your Discord user ID so they follow you from one
device to the next. They are part of your account: the data export under section 6 includes
them as displaySettings, and deleting your account deletes them. Sort order and
which filters are open are never sent to us at all.
One further entry is not a display preference, so we name it separately. If you arrive through
somebody's referral link, the referral code from that link is stored on your device under
tl_ref for 30 days, which is the period in which a code can still be used. That
code identifies the member who invited you. We keep it so the invitation is not lost while you
sign in, and it is sent to us only at the moment you choose to use the code — never
automatically. It is deleted as soon as you use it, if you let it expire, or whenever you clear
your browser data. Dismissing the banner hides it for that browsing session without sending
anything.
We use no third-party analytics, no advertising, no tracking pixels, no session recording and no third-party scripts of any kind. Fonts and charting code are served from our own server rather than a CDN. Our own usage measurement is described in 2.8, runs on our server, and only runs if you agree to it.
There is exactly one exception, and only once you are signed in: your own Discord avatar is
loaded by your browser directly from Discord's image server
(cdn.discordapp.com), because that is where Discord hosts it. That request
discloses your IP address, your browser's user-agent and the page you were on to Discord — the
same company you signed in with. A signed-out visitor makes no third-party request at all.
4. Recipients and third countries
- Discord (Discord Netherlands B.V., Schiphol Boulevard 195, 1118 BG Schiphol, Netherlands, which is the controller for users in the EEA; and Discord Inc., 444 De Haro Street #200, San Francisco, CA 94107, USA) — sign-in, alert delivery, and hosting of the avatar image your browser loads on every page while you are signed in (section 3). Transfers to the USA are covered by the EU-US Data Privacy Framework and Discord's standard contractual clauses. discord.com/privacy
- CopeCart GmbH, Berlin, Germany — payment and invoicing (EU, no third-country transfer).
- Our hosting provider — the server on which this site runs, located in the European Union, acting as a processor under Art. 28 GDPR.
- questlog.gg — only when you import a character build, and only for that request. Our server, not your browser, fetches the build from questlog.gg using the link you pasted, so what reaches them is the character name and build number contained in that link, from our server's address. Your Discord identity, your IP address and your browser are not disclosed to them, and nothing is sent to them at any other time.
Beyond these, your data is not passed to anyone, and none of it is sold.
5. How long we keep things
- Web server logs: 30 days, then deleted automatically.
- Sessions: until they expire or you revoke them; revoked and expired rows are cleared within 30 days.
- Account and account content: for as long as your account exists. Delete the account and it goes immediately (section 6).
- Error logs: technical fault records are rotated once the file passes a size threshold and the rotated copy is deleted after 90 days. They hold exception details, never request payloads, passwords or payment data.
- Payment and invoicing records: retained as long as § 147 AO and § 257 HGB require — up to ten years — and only for that purpose. After account deletion these are held without the link to your account.
6. Your rights, and how to use them here
You have the right to:
- Access the data we hold about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure — the "right to be forgotten" (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability in a machine-readable format (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
Two of these do not require you to ask us at all. On your account page you can download everything we hold about you as a JSON file, and you can delete your account outright — both immediately, both without contacting anyone. For anything else, write to support@tl-tracker.com; we answer within 30 days as Art. 12 (3) GDPR requires.
Signing in with Discord is voluntary. You are under no obligation to provide any data; the consequence of not signing in is simply that the account-based features are unavailable to you.
7. Right to lodge a complaint
You may complain to a data protection supervisory authority, in particular in the EU member state of your residence or place of work. The authority competent for us is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz
Hintere Bleiche 34, 55116 Mainz, Germany
datenschutz.rlp.de
8. Data security
Traffic between your browser and our server is encrypted with HTTPS and forced onto it by HSTS. Session tokens are stored only as SHA-256 hashes, so a copy of our database does not let anyone sign in as you. Cookies are HttpOnly, Secure and SameSite-restricted. A strict Content Security Policy blocks third-party and injected scripts. Credentials live in server configuration outside the web root and are not reachable from the internet.
Last updated: August 2026