Skip to content
TL Tracker

Market

Deals Potentials Alerts NIX Database Market Trends

Yours

Ledger Rewards Help & Guide Premium
Loading…

Privacy Policy

Information on the processing of personal data in accordance with the GDPR

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Kevin Hawacker
Birkenweg 8
57632 Flammersfeld, Germany
Email: support@tl-tracker.com
Phone: +49 170 3342630

We are not required to appoint a Data Protection Officer under Art. 37 GDPR / § 38 BDSG. Write to the address above for any data protection matter.

2. What we process, and why

2.1 Visiting the site without an account

You can browse the public pages without signing in and without giving us anything. Serving a page necessarily processes your IP address, and the web server (Microsoft IIS) records it along with the timestamp, the requested URL, the HTTP status and your browser's user-agent string. These logs exist to keep the service running and to investigate faults and attacks.
Legal basis: Art. 6 (1) (f) GDPR — our legitimate interest in a working, secure service.

Your IP address is also held briefly in server memory to count requests against our abuse limits. It is never written to the database for this purpose and disappears within minutes.

2.2 Signing in with Discord

Sign-in is exclusively via Discord OAuth 2.0. We request the identify scope and nothing else — we cannot read your messages, your email address, your server list or anything else in your Discord account. Discord returns, and we store:

  • your Discord user ID
  • your username, display name and discriminator
  • your avatar hash (used only to render your own profile picture)

Legal basis: Art. 6 (1) (b) GDPR — performance of the user agreement you enter into by signing in.

2.3 Your session

A random session token is issued and set as the tl_auth cookie. The server stores only the SHA-256 hash of that token, so the token itself exists nowhere but in your browser. Alongside each session we record the time it was created, the time it was last used, its expiry, the IP address it was created from and your browser's user-agent string. Those last two let you recognise your own sessions on the account page and let us spot a stolen session. The account page shows you the device and the times — it deliberately never displays the IP address.
Legal basis: Art. 6 (1) (b) and (f) GDPR — running the login, and account security.

2.4 What you create in the service

Everything you make while signed in is stored against your Discord user ID: price alerts and potential alerts you set (including any Discord webhook URL you supply for delivery), items and potentials you favourite, the flip ledger entries you record, the character builds you import (the questlog.gg link you paste, the build and character name shown on it, and which pieces you mark as already owned), reward credits, completed quests, referral codes and referral relationships, and any support or blacklist suggestions you submit.
Legal basis: Art. 6 (1) (b) GDPR.

2.5 Alert delivery through Discord

When an alert you set fires, our bot sends it to you as a Discord direct message, or posts it to a Discord webhook URL if you configured one. The alert content and your Discord user ID are therefore transmitted to Discord for delivery. If you never create an alert, this never happens.
Legal basis: Art. 6 (1) (b) GDPR.

2.6 Paid memberships and payment

Payments are handled by CopeCart GmbH, Rosenstraße 2, 10178 Berlin, Germany, acting as reseller and as your contractual partner for the purchase (see our Terms, § 4). Your payment details — card or bank data, billing name and address — are entered on CopeCart's own checkout and are never seen, received or stored by us. CopeCart notifies our server of the outcome, and from that notification we store the order identifier, the plan purchased, the subscription status and the period end date against your account so we can grant and expire your access. CopeCart's privacy policy: copecart.com/de/datenschutz.
Legal basis: Art. 6 (1) (b) GDPR, and Art. 6 (1) (c) GDPR for the retention of accounting records.

2.7 Error logs

When a server error occurs we write a technical log entry so the fault can be fixed. Such an entry can incidentally contain the identifier of the account whose request failed. It contains no passwords and no payment data.
Legal basis: Art. 6 (1) (f) GDPR.

2.8 Usage measurement

So we can see which parts of the service are actually used, we record a small number of events: a page being opened, and a few specific actions such as pressing the sign-in or the upgrade button. Each event holds the date and time, the path of the page (never the query string), the name of the action, a short note about that action, and a random identifier your browser generates for itself and keeps in local storage. If you are signed in, the event is also linked to your account.
The short note is deliberately coarse and never identifies you. For a page being opened it records whether your window is phone, tablet or desktop sized — a bucket derived from the width, never an exact size. For other actions it records which entry or button it was, and sometimes the state you were in when you saw something, such as whether a credit balance already covered the price on offer. Requests carrying a search engine's own crawler signature are also marked as such here, so that automated traffic can be told apart from people; that mark is never applied to an ordinary browser. This note is included in the data export described in section 6.

This measurement runs entirely on our own server. There is no Google Analytics, no Plausible, no Matomo and no other analytics provider; no data is sent to anyone else, and nothing is used for advertising. We deliberately do not record your IP address, your browser's user agent, or the address of the site you arrived from.
If your browser sends a “Do Not Track” signal, we record nothing at all.
Deleting your browser's local storage for this site clears the random identifier, and a new one is generated on your next visit.
Retention: 180 days, after which the events are deleted. If you delete your account, the link between these events and your account is removed.
This only happens if you agree to it. We ask once, on your first visit, and nothing is measured and no identifier is stored until you answer — declining leaves no identifier on your device, and if you had agreed before, declining deletes the one you already had. The one thing we do keep either way is your answer itself, under tl_consent, so that we do not ask you again on every page. It holds only yes or no and the date, it is never sent to us, and clearing your browser data removes it. You can change your mind at any time with Cookie choice at the bottom of any page.
Legal basis: Art. 6 (1) (a) GDPR — your consent; and § 25 (1) TDDDG for keeping the identifier on your device.

2.9 Market data

Auction-house prices are fetched by our server from the game's official Throne and Liberty trade API. Your browser never contacts it, and no data about you is sent to it. The market data itself contains no personal data of our users.

2.10 No profiling, no automated decisions

We do not profile you, we do not advertise to you, we do not sell or share your data with anyone beyond the processors named here, and no decision with legal effect is made about you automatically (Art. 22 GDPR).

3. Cookies and local storage

We set four cookies, all of them strictly necessary to provide a service you have asked for. None of the four requires your consent, under § 25 (2) no. 2 TDDDG, and we do not ask you about them.
One thing we do ask about: the random identifier described in 2.8, which usage measurement keeps in your browser's local storage. That is not necessary to serve you a page, so it needs your agreement first — that is what the banner on your first visit is for, and it is the only thing the banner controls. Cookie choice at the bottom of any page reopens it.

  • tl_auth — your session after sign-in. HttpOnly, Secure, SameSite=Lax.
  • tl_oauth_state — a one-time random value that protects the Discord login against cross-site request forgery. Deleted as soon as you return from Discord.
  • tl_oauth_ret — remembers which page you were on when you clicked sign in, so you land back there. Short-lived.
  • tl_oauth_item — remembers the item you were about to set an alert on when sign-in interrupted you. Short-lived.

Your browser's local storage additionally holds your own display preferences — the region you picked, sort order, which filters are open, whether the side rail is collapsed. These are settings you made, they contain no identifier of any kind, and clearing your browser data removes them.
Where they are kept depends on whether you are signed in. Signed out, they never leave your browser. Signed in, the options you set in the Settings panel — theme, density, text size, home region, which regions to show, number and clock format, sticky headers, performance and background options, motion, contrast and focus rings, plus the landing page and rail behaviour — are additionally stored against your Discord user ID so they follow you from one device to the next. They are part of your account: the data export under section 6 includes them as displaySettings, and deleting your account deletes them. Sort order and which filters are open are never sent to us at all.

One further entry is not a display preference, so we name it separately. If you arrive through somebody's referral link, the referral code from that link is stored on your device under tl_ref for 30 days, which is the period in which a code can still be used. That code identifies the member who invited you. We keep it so the invitation is not lost while you sign in, and it is sent to us only at the moment you choose to use the code — never automatically. It is deleted as soon as you use it, if you let it expire, or whenever you clear your browser data. Dismissing the banner hides it for that browsing session without sending anything.

We use no third-party analytics, no advertising, no tracking pixels, no session recording and no third-party scripts of any kind. Fonts and charting code are served from our own server rather than a CDN. Our own usage measurement is described in 2.8, runs on our server, and only runs if you agree to it.

There is exactly one exception, and only once you are signed in: your own Discord avatar is loaded by your browser directly from Discord's image server (cdn.discordapp.com), because that is where Discord hosts it. That request discloses your IP address, your browser's user-agent and the page you were on to Discord — the same company you signed in with. A signed-out visitor makes no third-party request at all.

4. Recipients and third countries

  • Discord (Discord Netherlands B.V., Schiphol Boulevard 195, 1118 BG Schiphol, Netherlands, which is the controller for users in the EEA; and Discord Inc., 444 De Haro Street #200, San Francisco, CA 94107, USA) — sign-in, alert delivery, and hosting of the avatar image your browser loads on every page while you are signed in (section 3). Transfers to the USA are covered by the EU-US Data Privacy Framework and Discord's standard contractual clauses. discord.com/privacy
  • CopeCart GmbH, Berlin, Germany — payment and invoicing (EU, no third-country transfer).
  • Our hosting provider — the server on which this site runs, located in the European Union, acting as a processor under Art. 28 GDPR.
  • questlog.gg — only when you import a character build, and only for that request. Our server, not your browser, fetches the build from questlog.gg using the link you pasted, so what reaches them is the character name and build number contained in that link, from our server's address. Your Discord identity, your IP address and your browser are not disclosed to them, and nothing is sent to them at any other time.

Beyond these, your data is not passed to anyone, and none of it is sold.

5. How long we keep things

  • Web server logs: 30 days, then deleted automatically.
  • Sessions: until they expire or you revoke them; revoked and expired rows are cleared within 30 days.
  • Account and account content: for as long as your account exists. Delete the account and it goes immediately (section 6).
  • Error logs: technical fault records are rotated once the file passes a size threshold and the rotated copy is deleted after 90 days. They hold exception details, never request payloads, passwords or payment data.
  • Payment and invoicing records: retained as long as § 147 AO and § 257 HGB require — up to ten years — and only for that purpose. After account deletion these are held without the link to your account.

6. Your rights, and how to use them here

You have the right to:

  • Access the data we hold about you (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure — the "right to be forgotten" (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability in a machine-readable format (Art. 20 GDPR)
  • Objection to processing based on legitimate interests (Art. 21 GDPR)

Two of these do not require you to ask us at all. On your account page you can download everything we hold about you as a JSON file, and you can delete your account outright — both immediately, both without contacting anyone. For anything else, write to support@tl-tracker.com; we answer within 30 days as Art. 12 (3) GDPR requires.

Signing in with Discord is voluntary. You are under no obligation to provide any data; the consequence of not signing in is simply that the account-based features are unavailable to you.

7. Right to lodge a complaint

You may complain to a data protection supervisory authority, in particular in the EU member state of your residence or place of work. The authority competent for us is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz
Hintere Bleiche 34, 55116 Mainz, Germany
datenschutz.rlp.de

8. Data security

Traffic between your browser and our server is encrypted with HTTPS and forced onto it by HSTS. Session tokens are stored only as SHA-256 hashes, so a copy of our database does not let anyone sign in as you. Cookies are HttpOnly, Secure and SameSite-restricted. A strict Content Security Policy blocks third-party and injected scripts. Credentials live in server configuration outside the web root and are not reachable from the internet.

Last updated: August 2026

TL Tracker

Built by players, for players. Track auction house prices across EU, AS and US, catch underpriced listings, and trade with a community that knows the market.

Product

Deals Potentials NIX Item Database Market Trends Alerts Profit Ledger Rewards See the paid plans

Resources

Help & GuideService numbers

Legal

Legal Notice Privacy Terms
© TL Tracker Live market data

Throne and Liberty and all related game assets, item icons, names and trademarks are the property of NCSOFT Corporation and FirstSpark Games, published in the West and Japan by Amazon Games. TL Tracker is an unofficial, fan-made tool and is not affiliated with, endorsed by, or sponsored by NCSOFT, FirstSpark Games, or Amazon Games.