Skip to content

Privacy Policy

Last updated: September 20, 2026

1. An Overview of Data Protection

General Information

The following information provides a simple overview of what happens to your personal data when you visit our website or use our services. Personal data is any data that can be used to personally identify you. For detailed information on data protection, please refer to our privacy policy below.

Data Recording on Our Website and in the Game

Who is responsible for data recording?

Data processing on this website and in game operations is carried out by the website operator. Their contact details can be found in the “Information about the responsible party” section of this privacy policy.

How do we record your data?

Your data is collected when you provide it to us. This may include data you enter when making a purchase.

Other data is automatically recorded by our IT systems when you visit the website or play on our servers. This primarily includes technical data (e.g., internet browser, operating system, Minecraft username, or time of page access). This data is recorded automatically as soon as you enter our website or connect to our game servers.

What do we use your data for?

Some of the data is collected to ensure error-free provision of the website and game operations. Other data may be used to analyze your user behavior.

What rights do you have regarding your data?

You have the right to receive information about the origin, recipients, and purposes of your stored personal data at any time without charge. You also have the right to request correction, blocking, or deletion of this data. For this and other questions on data protection, you can contact us at any time at the address given in the imprint. Furthermore, you have a right of complaint to the competent supervisory authority.

2. General Information and Mandatory Information

Data Protection

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

When you use this website or play on our Minecraft servers, various personal data is collected. Personal data is data that can be used to personally identify you. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.

We would like to point out that data transmission over the Internet (e.g., when communicating by email) may have security gaps. Complete protection of data against third-party access is not possible.

Information about the responsible party

The responsible party for data processing on this website is:

Name and Address

Arens & Gerstner GbR

Claus-Gabriel-Hof 4

24937 Flensburg

Germany

Email Address

[email protected]

Phone Number

+49 461 90019894

Storage Duration

Unless a more specific storage period has been stated within this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you assert a legitimate request for deletion or revoke consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g., tax or commercial law retention periods); in the latter case, deletion will take place after these reasons cease to apply.

Information on Data Transfer to the USA and Other Non-EU Countries

Services provided by Stripe, Cloudflare and other international providers may process data outside the EU or EEA. Selecting a European region for one service does not guarantee exclusively European processing for all services. Service-specific information and transfer safeguards are described in the respective provider sections.

Revocation of Your Consent to Data Processing

Many data processing operations are only possible with your express consent. You can revoke consent you have already given at any time. An informal notification by email to us is sufficient. The legality of the data processing carried out until the revocation remains unaffected by the revocation.

Right to Object to Data Collection in Special Cases; Right to Object to Direct Advertising (Art. 21 GDPR)

If data processing is based on Art. 6(1)(e) or (f) GDPR, you have the right to object at any time to the processing of your personal data on grounds relating to your particular situation; this also applies to profiling based on these provisions. The respective legal basis on which processing is based can be found in this privacy policy. If you object, we will no longer process your affected personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims (objection pursuant to Art. 21(1) GDPR).

If your personal data is processed for direct advertising purposes, you have the right to object at any time to the processing of personal data concerning you for the purpose of such advertising; this also applies to profiling insofar as it is related to such direct advertising. If you object, your personal data will subsequently no longer be used for direct advertising purposes (objection pursuant to Art. 21(2) GDPR).

Right to Lodge a Complaint with the Competent Supervisory Authority

In the event of violations of the GDPR, data subjects have a right of complaint to a supervisory authority, in particular in the Member State of their habitual residence, their place of work, or the place of the alleged violation. The right to lodge a complaint is without prejudice to other administrative or judicial remedies.

Right to Data Portability

You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done insofar as it is technically feasible.

SSL/TLS Encryption

For security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line. When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

Information, Blocking, Rectification and Erasure

Within the framework of the applicable legal provisions, you have the right at any time to free information about your stored personal data, its origin and recipients, and the purpose of data processing, and, if applicable, a right to rectification, blocking, or erasure of this data. For this and other questions on the subject of personal data, you can contact us at any time at the address given in the imprint.

Right to Restriction of Processing

You have the right to request the restriction of the processing of your personal data. You can contact us at any time at the address given in the imprint for this purpose.

  • If you dispute the accuracy of your personal data stored by us, we generally need time to verify this. For the duration of the review, you have the right to request the restriction of the processing of your personal data.
  • If the processing of your personal data was/is unlawful, you can request the restriction of data processing instead of deletion.
  • If we no longer need your personal data, but you need it to exercise, defend, or assert legal claims, you have the right to request restriction of the processing of your personal data instead of deletion.
  • If you have lodged an objection pursuant to Art. 21(1) GDPR, a balancing of your and our interests must be carried out. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.

If you have restricted the processing of your personal data, this data - apart from its storage - may only be processed with your consent or for the assertion, exercise, or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or a Member State.

3. Data Recording on Our Website

Cookies

Our website uses so-called cookies. Cookies do not cause any damage to your computer and do not contain viruses. Cookies serve to make our offer more user-friendly, effective, and secure. Cookies are small text files that are stored on your computer and saved by your browser.

You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when closing the browser. Disabling cookies may limit the functionality of this website.

Cookies that are necessary for carrying out the electronic communication process or for providing certain functions you have requested are stored on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in storing cookies for the technically error-free and optimized provision of its services.

We use the following technically necessary cookies:

  • Language selection (to store your preferred language)
  • Shopping cart (to store your product selection in the shop)
  • Shop attribution and payment return (signed HTTP-only cookies that bind an allowlisted shop source and the Stripe payment created by this browser; no longer than two hours)
  • Buyer browser binding (up to 30 days) and session cookie (up to one day; sign-in ends after 12 hours), secure HTTP-only cookies
  • UI settings (e.g., hiding notification banners)

Server Log Files

The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:

  • Browser type and version
  • Operating system used
  • Referrer URL
  • Hostname of the accessing computer

IP addresses are not stored. This data is not merged with other data sources.

This data is recorded on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of its website.

Plausible Analytics

We use self-hosted Plausible Analytics to understand which pages and features people use and where problems occur, for example in the configurator or shop.

Plausible Analytics takes a particularly privacy-friendly approach to analyzing your visit. For this purpose, Plausible collects the following information, among others:

  • Date and time of your visit
  • Title and URL of the pages visited
  • Referrer URL
  • The country you are in
  • Browser, operating system and device type derived from the user agent

Plausible itself does not set analytics cookies. It processes the IP address and user agent to generate a website-specific identifier that changes daily, without storing those original values. Hashing alone does not automatically make data anonymous. We also record selected actions and error categories, but no chat content or private configurator links.

We run Plausible and its databases on our rented dedicated OVHcloud server in Germany. Access uses Cloudflare Tunnel; the infrastructure providers involved are described in the hosting section. Our website events contain no player names or player UUIDs. General shop entry sources are not linked to individual players’ game histories.

For more information on data protection at Plausible Analytics, please visit: https://plausible.io/data-policy

The legal basis for processing is Art. 6(1)(f) GDPR.

Processing of Data (Customer and Contract Data)

We collect, process, and use personal data only insofar as they are necessary for the establishment, content, or modification of the legal relationship (inventory data). This is done on the basis of Art. 6(1)(b) GDPR, which permits the processing of data for the fulfillment of a contract or pre-contractual measures.

The collected customer data is deleted after completion of the order or termination of the business relationship. Statutory retention periods remain unaffected.

Data Transfer upon Conclusion of Contracts for Services and Digital Content

We only transmit personal data to third parties if this is necessary in the context of contract processing, for example to the credit institution responsible for payment processing.

Further transmission of data does not take place or only if you have expressly consented to the transmission. Your data will not be passed on to third parties without express consent, for example for advertising purposes.

The basis for data processing is Art. 6(1)(b) GDPR, which permits the processing of data for the fulfillment of a contract or pre-contractual measures.

Purchase history and sign-in

For your purchase history and protected access to contract documents, we process your buyer email address, the billing name supplied by the payment provider when available, order ownership and stored contract records. The legal basis is Art. 6(1)(b) GDPR for contract performance. The Minecraft account and the buyer may belong to different people.

Sign-in uses a single-use email link valid for 15 minutes. An authenticated session ends after 12 hours and can be reset. Necessary secure HTTP-only cookies bind the browser for up to 30 days; the session cookie may remain for up to one day without extending the 12-hour authenticated session.

To prevent unauthorized access and abuse, we store hashed link, session and browser identifiers and expiry, consumption and revocation timestamps. Rate limits use short-lived hashed email and network identifiers. This relies on Art. 6(1)(f) GDPR, our legitimate interest in secure access. Buyer and withdrawal pages contain no usage analytics.

Public withdrawal form

Withdrawal does not require sign-in. We store the contact details you provide, your statement, any optional order reference and the receipt timestamp. A reference does not cause orders to be retrieved or disclosed. We review the statement manually.

Processing and acknowledging receipt fulfil statutory duties under Art. 6(1)(c) GDPR. Where a contract is reversed, processing relies on Art. 6(1)(b) GDPR. Abuse prevention relies on Art. 6(1)(f) GDPR. Acknowledgement of receipt is not a refund decision.

Transactional email through Cloudflare

We send sign-in links, order confirmations with stored contract documents and withdrawal acknowledgements through Cloudflare Email Service. The provider is Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. We transmit the recipient and sender addresses, reply-to address, subject and message content. Depending on the message, this includes a sign-in link, order and contract details or the withdrawal statement. Withdrawals are also sent internally by email for review.

Cloudflare processes technical metadata needed to send and deliver messages, such as delivery status and error reports. Sending supports contract performance under Art. 6(1)(b) GDPR, statutory acknowledgements under (c), and secure access and reliable delivery under (f). These messages are not advertising.

Our mailboxes for incoming email and replies are operated separately through OVHcloud. Information about Cloudflare, international transfers and the contractual data protection framework is provided in the hosting section and Cloudflare’s published Data Processing Addendum.

4. Data Recording in Game Operations

Minecraft Player Data

When you connect to our Minecraft servers, the following data is collected and processed:

  • Minecraft username
  • Minecraft UUID (unique player ID from Mojang/Microsoft)
  • Minecraft edition (Java or Bedrock)
  • Time of the first confirmed successful server join and a technical identifier to prevent duplicate confirmations
  • Game progress and server settings

The Minecraft username and UUID are publicly available information provided by Mojang/Microsoft and can be viewed by anyone, for example via services like NameMC.com.

This data is required for the provision of game operations and for assigning your purchases (ranks, tags) to your player account. Username and UUID are stored indefinitely. Server save files are deleted as soon as you delete your server or the maximum playtime has expired.

The legal basis for processing is Art. 6(1)(b) GDPR (contract fulfillment) and Art. 6(1)(f) GDPR (legitimate interest in providing the service).

Gameplay statistics

We analyse which Minecraft versions and game offerings are used, which presets, challenges, goals and settings players choose, and how long they actively play. We record connections, server changes, run attempts, pauses, outcomes, forfeits and selected menu actions, as well as whether our optional Java resource pack is offered, along with observed acceptance, downloads, successful activation, declines and loading failures. This helps us identify technical problems and improve our games.

Gameplay events are sent with the player UUID to our own API. There we replace the UUID with an identifier calculated from the UUID using a secret key before persistently storing the event for analysis. This identifier lets us count returning players, for example. The data is pseudonymous, not anonymous. Temporary local delivery buffers may contain the UUID. Events do not contain chat content, world seeds, payment details or private configurator links.

Whether or not gameplay statistics are enabled, we store the first confirmed successful server join with the player account. This confirmation is retained for the lifetime of the account so that an existing player is not counted as new again after a break. A login attempt alone is not a successful join. New players are included in analysis only when gameplay statistics are enabled and subject to objections to processing.

When you move between our servers or reconnect at our request, we may continue the current session so that the same visit is not counted more than once. Active play, pauses and spectator time are recorded separately; a connection gap does not count as playtime.

In the shop, we record only general entry sources, such as the Premium dialog or Challenges menu, along with landings, started checkouts and confirmed purchases by source. We do not link these statistics to individual gameplay histories. Payment and entitlement processing required for purchases remains separate.

Analysis takes place in our self-managed infrastructure with the providers listed in the Hosting section. We operate the analytics database and reporting interface on our rented dedicated OVHcloud server in Germany. Access is restricted to authorised people and services.

Individual analytics events are no longer available for analysis after 90 days and are then automatically deleted. Additional backup copies are retained for up to ten days. When restoring data, we apply the current retention cutoff, erasures and objections before making it available for analysis again. If those decisions cannot be reliably recovered, we discard the affected historical analytics data.

For comparisons across years, we also retain summarised monthly statistics over the long term, such as observed playtime and use of game presets. These statistics contain no player, session or run-attempt identifiers. We use coarse, rounded values and omit groups that are too small, along with breakdowns from which such groups could be calculated. Individual gameplay histories cannot be retrieved from these monthly statistics.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is to understand how our games are used, identify technical problems and improve the offering. Gameplay statistics are not used for automated decisions that change your ranks, purchases or game permissions.

You can object to personal gameplay analytics and request erasure of analytics data attributable to you through the privacy contact listed above. We verify account ownership when handling your request. A request does not change your rank or game permissions. We retain the suppression and erasure records needed to honour your request separately for as long as they are needed to prevent processing from resuming.

5. Hosting and Infrastructure

Hetzner

We operate part of our website and game-server infrastructure on a rented dedicated server in Germany with Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. For information about the provider’s data processing, see its privacy policy: https://www.hetzner.com/legal/privacy-policy

OVHcloud

We operate additional infrastructure, including Plausible, the analytics databases and Metabase, on a rented dedicated OVHcloud server in Germany. We administer these services ourselves. Information about data protection at OVHcloud: https://www.ovhcloud.com/de/terms-and-conditions/privacy-policy/

Cloudflare

We use Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, for the following purposes:

  • Cloudflare Email Service for transactional email
  • Cloudflare R2 for private checkout snapshots containing buyer email, Minecraft UUID, purchase details and stored contract documents, and verified order records containing the payment provider's billing name when available
  • Content Delivery Network (CDN) and DDoS protection for our website
  • Cloudflare Tunnel for secure connections
  • Cloudflare R2 for storing purchase receipts, full and partial credit notes, reversal invoices, and server save files
  • Cloudflare R2 for a private payment-fulfillment ledger containing a Stripe transaction reference, processing steps, and reversal status

Details of transactional email sending

Where available for the respective Cloudflare service, we use European regions. However, Cloudflare is a US provider, so international data transfers cannot be completely ruled out. Cloudflare states that it relies in particular on applicable adequacy decisions, Standard Contractual Clauses, and supplementary safeguards for such transfers.

When using our website, your IP address may be processed by Cloudflare. This is technically necessary for the operation of the CDN and DDoS protection. We ourselves do not store or log any IP addresses.

We store personal data in Cloudflare R2 exclusively in EU buckets. Files stored in Cloudflare R2 are not public. Only authorized people and services have access; buyers can obtain their own purchase and contract documents through protected retrieval. The separate fulfillment ledger contains no card data, email address, Minecraft username or Minecraft UUID. Checkout snapshots instead contain the contact and contract data listed above.

For more information, please see Cloudflare's privacy policy: https://www.cloudflare.com/privacypolicy/

Depending on the purpose, processing is based on Art. 6(1)(b) GDPR (contract performance and reversal), Art. 6(1)(c) GDPR (statutory retention obligations), and Art. 6(1)(f) GDPR (legitimate interest in secure and reliable operation).

New Relic (Monitoring)

We use New Relic, Inc., 188 Spear Street, Suite 1200, San Francisco, CA 94105, USA, to monitor the performance and stability of our infrastructure. We have configured the EU region for New Relic, so all data is processed and stored exclusively in data centers within the European Union.

As part of monitoring, the following data may be processed:

  • Performance metrics of our servers
  • Log messages from game servers (incl. Minecraft usernames and UUIDs)
  • Player actions such as executed commands or chat messages
  • Shop transactions and product assignments
  • Verified purchase conversions with amount, currency, edition, optional attribution source, and a hashed Stripe transaction reference

IP addresses are not transmitted to New Relic. Data is automatically deleted after 30 days (data retention).

For more information, please see New Relic's privacy policy: https://newrelic.com/termsandconditions/privacy

The legal basis for processing is Art. 6(1)(f) GDPR (legitimate interest in monitoring and troubleshooting our services).

6. Payments and purchase receipts

Stripe

On our website, we offer payment via Stripe. The provider of this payment service is Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA (hereinafter “Stripe”).

When you make a payment, the data you enter, in particular your email address, payment data, invoice amount, and currency, is transmitted to Stripe. To assign and fulfill the purchase, we additionally store the Minecraft UUID, Minecraft username, edition, purchased products, quantities, descriptions, prices, discounts, and technical fulfillment, invoice, and reversal references in Stripe metadata. Complete payment data such as credit card numbers is not stored by us.

Processing is necessary to perform and, where applicable, reverse the contract pursuant to Art. 6(1)(b) GDPR and to comply with statutory retention obligations pursuant to Art. 6(1)(c) GDPR.

For more information on Stripe's data protection, please visit: https://stripe.com/privacy

Purchase Receipts, Credit Notes and Reversal Invoices

For purchases in our shop, we generate purchase receipts. For full or partial refunds, we additionally generate credit notes. For lost payment disputes, we generate reversal invoices. These documents may contain the following data:

  • Invoice, credit note, reversal, refund, and Stripe transaction references
  • Email address
  • Minecraft username
  • Minecraft edition (Java or Bedrock)
  • Minecraft UUID
  • Purchased products, prices, and discounts
  • For credit notes and reversal invoices: refunded or reversed amount, affected purchase items where applicable, and refund or reversal reason

The email address is transmitted to Stripe for payment processing and is also stored in the purchase receipt. Complete payment data such as credit card numbers is processed exclusively by Stripe and is not stored by us.

Purchase receipts, credit notes and reversal invoices are retained in accordance with the applicable statutory retention periods.

7. Discord

Community Server

We operate a public Discord server for our community. If you join this server, the privacy policy of Discord Inc., 444 De Haro Street, Suite 200, San Francisco, CA 94107, USA, applies.

For more information, please see Discord's privacy policy: https://discord.com/privacy

Optional account linking

When you optionally link your Minecraft account to Discord, we process your Minecraft UUID, Discord ID, Discord username, confirmation timestamps and synchronization status. We use this data to associate your accounts and synchronize Verified and your current rank on our Discord server. Discord sign-in requests only your account identity; OAuth access tokens are not stored persistently. An encrypted, technically necessary website session lasts 30 minutes. You can unlink your accounts in the game using /discord unlink. This removes the association; data required for pending role removals is retained until those operations succeed. Expired or completed linking requests are removed after 24 hours by periodic cleanup.

Support Tickets

We offer a support ticket system via a Discord bot. The ticket data (messages, username, timestamps) is stored on our own server in Germany.

Access to ticket data is limited to the operator and appointed administrators. Data is not automatically deleted after the support case is closed but can be removed upon request.

The legal basis for processing is Art. 6(1)(b) GDPR (contract fulfillment/support) and Art. 6(1)(f) GDPR (legitimate interest in providing customer support).

8. Deletion of Your Data

You have the right to request the deletion of your personal data stored by us, provided there are no statutory retention obligations to the contrary.

The following data can be deleted upon request:

  • Minecraft username and UUID from our database (with an active purchase, acquired benefits will no longer be usable afterwards)
  • Server save files
  • Discord support tickets

Data that is required to fulfill statutory retention obligations cannot be deleted (e.g., purchase receipts for tax purposes).

To request deletion, please contact us at the email address given in the imprint.