Privacy
Your data belongs to you.
Here we explain which personal data Play2Bond processes, why we need it and which rights you have.
We want to make privacy understandable.
That is why we describe as clearly as possible what information arises when you use Play2Bond and how we handle it.
This policy applies to the website and the Play2Bond features currently available.
At a glance
Account and profile
For registration, login, profiles and suitable connections, we process account, profile and preference data.
Games and connections
Games and connections create session, action and result data needed for operation and evaluation.
Technical operation
Technical data may arise when you visit, as required for operation, security and troubleshooting.
Your control
Subject to legal requirements, you have rights to access, rectification, erasure and further data protection rights.
1. Who is responsible for processing
The controller under the General Data Protection Regulation (GDPR) is the person or organisation deciding the purposes and means of processing. The final details must be added before publication.
[VERANTWORTLICHER][ANSCHRIFT]AustriaEmail: [DATENSCHUTZ-KONTAKT]2. Data we process
We process only data required for the offered features or data you provide yourself.
Website and technology
Visits may create IP address, time, requested address, browser and device information, and technical error data. A specific logging and deletion period has not yet been set.
Account and login
We store details including email address, verification status, verification dispatch times and technical delivery information, user identifier, login status, password hash, security and lockout information, and roles. Verification messages are used for account security and feature access, without tracking pixels or marketing use. We do not store your password in plain text.
Profile and preferences
These include display name, date of birth, gender, country, region, language, avatar, profile status, preferred genders, age range and maximum distance.
Searches, connections and games
We process search status, proposals, decisions, participants, game identifier, culture, times and results. Details about temporary game state are provided below.
3. How we use data
We use data for the features and purposes described in this policy.
- Providing and securely operating the platform
- Creating and managing your account and profile
- Suggesting suitable connections based on your settings
- Running games and evaluating results
- Preventing misuse, administration and troubleshooting
Legal bases
Depending on the purpose, possible bases include performance of a contract or pre-contractual steps (Article 6(1)(b) GDPR), legitimate interests in secure operation and preventing misuse (point (f)), legal obligations (point (c)), or explicit consent where requested (point (a)). The final allocation, especially for sensitive profile data, still requires legal confirmation.
4. Cookies and local storage
Play2Bond currently uses only technically necessary cookies and temporary browser storage.
- Authentication
- An HTTP-only authentication cookie keeps you signed in. With persistent sign-in it may last up to 14 days and is renewed during use.
- Form protection
- A technically necessary protection value helps prevent unauthorised form requests.
- Language
- The .Play2Bond.Culture cookie stores your language choice for up to one year.
- Game animation
- Brick Bond stores a technical animation sequence only in browser session storage; it ends with the browser session.
The reviewed version contained no analytics, advertising or tracking cookies and no persistent local browser storage.
5. Matching and automation
Suggestions are selected by rules using gender, age, country, region and language. The stored maximum distance is not currently used for selection. Other participants see the profile details intended for the connection and game.
The technical preselection does not make a decision producing legal or similarly significant effects about you. You decide whether to accept or decline a proposal.
6. Games, AI practice and solo mode
For connections and AI practice, session and result data is stored persistently, including participants, game and version, seed, language, status, times and result.
Detailed active game state and individual actions are currently held temporarily in working memory and are lost when the service restarts.
AI practice
The opponent logic runs through deterministic rules within Play2Bond. In the reviewed version, no data is sent to an external AI or language-model service.
Solo games
Active solo game state, such as Moving Day state, is currently processed only temporarily. No persistent solo progress or score storage was found.
Chat and messages
For chat requests and conversations, we process your chat preference, consent status, participants, message type, message content or reaction, timestamps, unread status, and the related contact, encounter, or game context.
Messages are delivered to the conversation participants. Administrators have no general chat access. If you report a specific message, only that message is copied into the safety report for authorized moderation. Chat content is not automatically analyzed and is not sent to an external generative AI service.
Working retention values: closed personal conversations for 12 months and game or encounter communication for 90 days. A reported message snapshot follows the retention rules for safety reports. These periods and deletion details remain subject to legal review.
In-app notifications
For relevant activity within Play2Bond, we store the notification type, time, read status, a technical context reference, an optional actor reference, a server-generated internal target, and an aggregation count. We do not store message text in notifications.
Notifications are delivered only inside Play2Bond. No external email, push, browser-notification, or notification-service provider is used for this feature.
Working retention values are 90 days for read, 180 days for unread, and 30 days for dismissed notifications. Automatic deletion is not yet implemented; these periods and the final legal basis remain under review.
Game invitations
For direct game invitations, we process sender, recipient, game ID, status, timestamps and, after acceptance, references to the encounter, game session and readiness state.
These details are used to verify eligibility, prevent duplicate invitations and spam, and start an accepted game securely. Invitations contain no free text and are not sent to external services.
Blocking invalidates open invitations. Final retention periods and legal bases remain part of the legal review.
7. Administration and logs
Authorised administrators can manage accounts, roles, lockouts and profile status. Administrative actions are logged with actor, affected account, action, result and time.
The application writes technical console and error logs. No external logging service is configured; specific retention periods have not yet been set.
Safety reports and moderation
When you report a person, we process the selected category, optional explanation, context reference, time, processing status, and technical identifiers needed to review the safety information.
Authorized administrators may add internal moderator notes and document actions. The reported person does not receive the report, reporter identity, explanation, or internal review status.
- Purpose: platform safety, prevention of misuse, and review of possible rule violations
- Working legal basis: legitimate interests in a safe and reliable platform, subject to legal review
- Recipients: only authorized administrators and, where legally required, competent authorities
- No automatic sanction is triggered by the number or category of reports
Working retention value: open reports until completion and completed reports for 24 months. Longer retention may be required for account measures or legal obligations. These periods and deletion limits are still under legal review.
8. Hosting, recipients and transfers
In the current operating environment, Play2Bond is hosted at Hetzner using a web application, PostgreSQL database, HTTPS reverse proxy and persistent volumes. The product, exact location, backups and contract status still require operator confirmation.
Recipients may include the hosting provider, authorised administrators, the relevant game connection, and public authorities where legally required. No further operational service providers were found in the reviewed version.
A final statement on transfers outside the EEA can be made only after the hosting location, subprocessors and possible backup locations have been confirmed.
9. Retention and deletion
Data should be kept only as long as required for its purpose, legal obligations, claims or system security. It should then be deleted or anonymised.
Specific periods for accounts, profiles, connections, game results, administration and technical logs, and backups have not yet been defined. This is an open requirement for production publication.
Delete account
Automated self-service account deletion is not currently available. Until a reviewed deletion process exists, requests must be handled through the privacy contact still to be established.
10. Your rights
Subject to the legal requirements, you have rights including:
- Access
- Rectification
- Erasure
- Restriction of processing
- Data portability
- Objection
- Withdraw consent for the future
- Lodge a complaint with a supervisory authority
11. Minimum age
Profile validation currently requires a minimum age of 18. A complete approach to age verification and incorrect information still needs to be defined.
12. Security
The reviewed version uses measures including HTTPS, password hashing, role-based access, secure authentication cookies and persisted data-protection keys. No technical system is entirely risk-free, so safeguards are reviewed continuously.
13. Contact and complaints
For questions or to exercise your rights, contact the privacy address still to be established. You may also complain to a data protection authority, in particular the Austrian Data Protection Authority.
Österreichische DatenschutzbehördeBarichgasse 40–42, 1030 Wien, Österreichdsb.gv.at14. Changes to this policy
We update this policy when features, providers or legal requirements change. The current version and date will be published here.
Version: [VERSION] · Last updated: [MONAT JAHR]
Questions about privacy?
The binding privacy contact must be added before publication:
[DATENSCHUTZ-KONTAKT]