Privacy Policy
1. Who is responsible for your data
The controller of your personal data is:
52-204 Wrocław, Poland
NIP (Tax ID): PL6681972344 · REGON: 363433999
E-mail: support@runmygame.eu
For any privacy matter — questions, requests, complaints — write to support@runmygame.eu. We have not appointed a Data Protection Officer, as we are not required to; the controller handles requests personally.
2. What data we process and why
a) Account data
E-mail address, display name, chosen language, authentication identifiers (including your Google account identifier if you sign in with Google), login timestamps.
Purpose & legal basis: providing the service you signed up for — performance of a contract (Art. 6(1)(b) GDPR).
b) Order and payment data
Order history, plan, amounts, currency, payment status, Stripe customer and payment identifiers, invoices. We never see or store your card number — card data is entered directly with our payment processor, Stripe.
Purpose & legal basis: processing payments and renewals — performance of a contract (Art. 6(1)(b)); keeping accounting records — legal obligation (Art. 6(1)(c)); preventing payment fraud and abuse — legitimate interest (Art. 6(1)(f)).
c) Server content and backups
Your game worlds, server configuration and backups. This content may incidentally contain personal data of the people who play on your server (player names, in-game chat). We store it solely to run your server and never look into it except when needed for support you requested or for security.
Purpose & legal basis: performance of a contract (Art. 6(1)(b)).
d) Service e-mails
We send transactional e-mails only: order confirmations, payment and renewal notices, server lifecycle warnings, password/security messages. We do not send marketing e-mails and we do not use newsletters.
Purpose & legal basis: performance of a contract (Art. 6(1)(b)).
e) Support communication
Messages you send us by e-mail, the contact form or Discord, and our replies.
Purpose & legal basis: handling your requests — performance of a contract or steps prior to it (Art. 6(1)(b)); keeping records of complaints — legal obligation (Art. 6(1)(c)).
f) Technical logs and audit trail
Standard technical logs (including IP addresses) generated when you use the website and Panel, and an audit trail of security-relevant account actions (e.g. logins, password changes).
Purpose & legal basis: security, abuse prevention, diagnosing faults — legitimate interest (Art. 6(1)(f)).
Providing account and payment data is necessary to use the Service — without it we cannot create your account or host your server. We do not use analytics or advertising trackers anywhere on our sites.
3. Who we share data with
We share personal data only with the providers we need to run the Service (processors or independent controllers, as indicated), and only the data each of them needs:
| Provider | Purpose | Location |
|---|---|---|
| Stripe Payments Europe, Ltd. (independent controller for payment processing) | Payment processing, invoices | Ireland / EU (see section 4) |
| Hetzner Online GmbH | Infrastructure hosting — all servers and data | Germany / Finland (EU) |
| Brevo (Sendinblue SAS) | Delivery of transactional e-mails | France (EU) |
| Google Ireland Ltd. | Sign-in with Google — only if you choose it | Ireland (see section 4) |
| EU-based mailbox provider | Our support mailbox | Poland (EU) |
We do not sell personal data and we do not share it with advertisers. Public authorities receive data only where the law obliges us.
4. Transfers outside the EEA
Your data is stored and processed in the European Union. Two providers may transfer limited data to the United States within their own operations: Stripe and Google (the latter only if you use Google Sign-In). Both rely on the EU–US Data Privacy Framework and/or EU Standard Contractual Clauses for such transfers. Details: stripe.com/privacy, policies.google.com/privacy.
5. How long we keep data
| Data | Retention |
|---|---|
| Account data | While your account exists; deleted or anonymised after account deletion, except data we must keep (below) |
| Orders, payments, invoices | 5 years from the end of the tax year in which the transaction took place (Polish accounting and tax law) |
| Server content | While your server is active; after expiry: kept through the suspension period, deleted when the server is removed (at least 21 days of grace + at least 30 days suspended — see the Terms) |
| Backups of a removed server | Up to 12 months after removal, then permanently deleted; earlier deletion on request |
| Support correspondence | Up to 3 years after the case is closed (defence against claims) |
| Technical logs & audit trail | Short rotation for technical logs; audit trail while the account exists |
6. Your rights
Under the GDPR you have the right to:
- access your data and get a copy;
- rectify inaccurate data (most account data you can edit yourself in the Panel);
- erase data ("right to be forgotten") — you can request account deletion at any time;
- data portability — the Panel includes a self-service export of your data, and your server files and backups can be downloaded directly;
- restrict processing and to object to processing based on legitimate interest;
- lodge a complaint with a supervisory authority — in Poland: Prezes Urzędu Ochrony Danych Osobowych (PUODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl; or the authority of your own EU country.
To exercise any right, write to support@runmygame.eu from your account e-mail address. We respond within one month at the latest.
7. Cookies and similar technologies
We use no analytics, advertising or tracking cookies. The only things stored on your device are strictly necessary for the site to work, which is why no cookie consent banner is shown:
| Name | What it does | Type / lifetime |
|---|---|---|
pf_lang (cookie + browser storage) | Remembers the language you picked, shared between runmygame.eu and the Panel | Functional preference; persistent |
| Panel session cookies (Keycloak) | Keep you logged in to the Panel securely | Strictly necessary; session |
| Stripe cookies | Fraud prevention during checkout, set by Stripe on its own checkout pages | See Stripe's cookie policy |
You can clear cookies and site data in your browser at any time; the site will simply forget your language choice.
8. Children
RunMyGame accounts are for adults (18+). We do not knowingly collect personal data from children. Children play on servers purchased and managed by an adult account holder; any personal data appearing inside a server's game world (such as player names or chat) is part of the customer's content described in section 2(c), and the account holder decides who may join their server.
9. How we protect your data
- All connections to the website, Panel and game panel APIs are encrypted (TLS).
- Data is hosted exclusively in EU data centres; game servers run isolated from one another.
- Access to production systems is restricted to the controller, protected by strong authentication.
- Passwords are handled by a dedicated identity server (Keycloak) and stored only as salted hashes; with Google Sign-In we never see any password.
- Security-relevant account actions are recorded in an audit trail; daily backups protect against data loss.
10. No profiling, no automated decisions
We do not profile you and we make no automated decisions producing legal or similarly significant effects. The only automation is the service itself (e.g. automatic suspension of unpaid servers, as described in the Terms).
11. Changes to this policy
If we change this policy in a way that affects you (for example a new provider), we will announce it by e-mail or in the Panel before the change takes effect. The current version is always at runmygame.eu/privacy/; the effective date is shown at the top.
SOFTWARE DEVELOPMENT Adrian Graczyk · ul. Obrońców Poczty Gdańskiej 88/4, 52-204 Wrocław, Poland · NIP PL6681972344 · REGON 363433999
support@runmygame.eu · Terms of Service · runmygame.eu