Datenschutz
Last updated: 7 Sep 2026
Protecting your personal data matters to us. This policy tells you, completely and in plain language, which personal data we process when you use Preis-Raten, for which purposes and on which legal basis, how long we keep it, whom we pass it on to and what rights you have. It fulfils the information duties of Art. 12 to 14 of the General Data Protection Regulation (GDPR).
The principle behind it fits into one sentence: the game works without an account, without your real name and without advertising trackers. Everything beyond that is either strictly necessary to run the service – or it asks you first.
Contents
- Controller and contact
- Data protection officer
- Definitions
- Legal bases at a glance
- General principles of our processing
- Visiting the site and server log files
- Hosting
- Encrypted transmission
- Cookies and storage on your device
- Consent management (consent banner)
- Playing without an account (guest access)
- User account and registration
- Signing in and sign-in tokens
- Password reset and e-mail
- Contacting us
- Gameplay: rounds, guesses, points
- Leaderboards and publication of your display name
- Profile, achievements and statistics
- Duels and challenges
- Streamer lobbies, overlays and channel rankings
- Chat bot integration
- Result cards and sharing
- Protection against abuse and manipulation
- Rate limiting and security logs
- Balance, prizes and payouts
- Advertising
- Internal reach and revenue statistics
- Fonts (Google Fonts)
- Item sources, product images and external links
- Recipients and processors
- Transfers to third countries
- Retention and deletion
- Your rights as a data subject
- Right to object under Art. 21 GDPR
- Withdrawing consent
- Right to lodge a complaint
- Is providing data required?
- Automated decision-making and profiling
- Protection of minors
- Technical and organisational measures
- Personal data breaches
- Changes to this policy
1. Controller and contact
The controller within the meaning of Art. 4 no. 7 GDPR and other data protection provisions is:
René Stubbe
Am Brangenberg 7
42551 Velbert
Germany
E-mail: info@priceygame.de
You can reach us at the above e-mail address for all questions, concerns and requests relating to data protection. No particular form is required; an informal message is enough.
2. Data protection officer
We have not appointed a data protection officer, and we are not required to. The conditions of Art. 37 (1) GDPR and § 38 (1) of the German Federal Data Protection Act (BDSG) are not met: we do not permanently employ at least 20 people on the automated processing of personal data, we do not process special categories of data on a large scale, and our core activity does not involve regular and systematic monitoring of data subjects on a large scale. Please direct your concerns to the address given in section 1.
3. Definitions
This policy uses the terms of the GDPR. The most important ones, briefly:
- Personal data (Art. 4 no. 1 GDPR) means any information relating to an identified or identifiable natural person – including information that contains no name but can be linked to a person, such as an IP address or a device identifier.
- Processing (Art. 4 no. 2 GDPR) covers every operation performed on such data: collecting, recording, storing, altering, retrieving, using, disclosing, restricting, erasing or destroying.
- Pseudonymisation (Art. 4 no. 5 GDPR) means that data can no longer be attributed to a specific person without additional information. We use it in particular in our anti-fraud measures: instead of an IP address, we store only a checksum of it.
- Profiling (Art. 4 no. 4 GDPR) is any automated processing that evaluates personal aspects. Where we use it – exclusively to prevent manipulation – it is described separately in sections 23 and 38.
- Controller (Art. 4 no. 7 GDPR) is whoever decides on the purposes and means of the processing – for this service, that is us.
- Processor (Art. 4 no. 8 GDPR) is whoever processes data on our behalf and solely on our instructions, such as our hosting provider.
- Recipient (Art. 4 no. 9 GDPR) is any body to which data is disclosed.
- Consent (Art. 4 no. 11 GDPR) is your freely given, specific, informed and unambiguous indication of your wishes.
4. Legal bases at a glance
We only process personal data where a legal basis permits it. The following come into consideration:
- Art. 6 (1) (a) GDPR – consent. You have consented to a particular processing operation, for example to the setting of advertising cookies. You may withdraw consent at any time (section 35).
- Art. 6 (1) (b) GDPR – contract. The processing is necessary to perform the usage agreement or to take pre-contractual steps. This covers the whole of gameplay, the account and the payout of a prize.
- Art. 6 (1) (c) GDPR – legal obligation. We must process the data because the law requires it, for example to retain payment records under tax law.
- Art. 6 (1) (f) GDPR – legitimate interests. The processing is necessary for our legitimate interests and your interests do not override them. We name the interest concerned expressly for every single processing operation so that you can weigh it up.
- § 25 (1) TDDDG (the German Telecommunications Digital Services Data Protection Act) for storing information on your device and accessing it – this requires your consent unless the operation is strictly necessary within the meaning of § 25 (2) no. 2 TDDDG.
We do not collect and do not need special categories of personal data within the meaning of Art. 9 GDPR – such as information about health, religion or political opinions. Please do not enter such information voluntarily in free-text fields such as your display name.
5. General principles of our processing
As a rule, we only collect and use personal data where this is necessary to provide a functioning website and our content and services. The following principles apply throughout:
- Data minimisation: we do not ask for anything we do not need. A cookie is enough to play – no name, no address, no e-mail.
- Purpose limitation: data collected for one purpose is not used for another.
- Storage limitation: what we no longer need and are not required to keep, we delete (section 32).
- Integrity and confidentiality: passwords are held only as hashes, sensitive identifiers only as checksums, and transmission is encrypted.
- No disclosure for advertising: we do not sell, rent out or trade user data. There is no address trading.
Personal data is deleted or blocked as soon as the purpose for storing it no longer applies. Storage beyond that only takes place where European or national legislation requires it; in that case the data is blocked or deleted once the relevant period expires.
6. Visiting the site and server log files
Every time our pages are accessed, our system automatically collects data from the requesting computer system:
- the IP address of the requesting connection,
- the date and time of access,
- the specific address requested and the access method used,
- the status code of the response and the volume of data transferred,
- the previously visited page, where your browser transmits it (referrer),
- browser type and version, operating system and language setting.
Purpose: this data is technically necessary to deliver the page and to establish the connection to your device. Beyond that it serves stability, troubleshooting and the detection and prevention of attacks. We do not evaluate it for advertising or analytics purposes and do not combine it with other data sources.
Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest is the secure, stable and trouble-free operation of the service. Briefly storing the IP address is indispensable for this: without it, the response cannot reach your device.
Retention: log entries are usually overwritten automatically after a few days. Entries documenting a specific suspicion of abuse are kept until the matter has been resolved and are deleted afterwards.
Objection: collecting and storing this data is mandatory for operating the website. There is no right to object in this respect, because without this data no page can be delivered.
7. Hosting
We do not run the website on our own hardware but with a hosting provider whose data centres are located within the European Union.
The provider processes on our behalf all data arising from the operation of the website – in particular the log data named in section 6 as well as the contents of our database. It acts solely on our instructions and not for its own purposes.
Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest is the professional,
resilient and secure provision of our service by a specialised provider.
Basis of the cooperation: a data processing agreement pursuant to Art. 28 GDPR is in
place, obliging the provider to maintain confidentiality, to apply technical and
organisational safeguards and to delete the data when the agreement ends.
8. Encrypted transmission
For security reasons and to protect the transmission of confidential content, this website
uses TLS encryption ("SSL"). You can recognise an encrypted connection by the fact that your
browser's address bar starts with https:// and shows a padlock symbol. While
encryption is active, the data you transmit to us cannot be read by third parties.
9. Cookies and storage on your device
Cookies are small text files stored by your browser. We only use cookies that are necessary to run the game. They contain no advertising identifiers, are not used to build usage profiles and are not transmitted to third parties.
Legal basis for accessing your device: § 25 (2) no. 2 TDDDG – the storage is strictly
necessary for us to provide the service you have expressly requested. The law does not
require consent for this.
Legal basis for the subsequent processing: Art. 6 (1) (b) GDPR (performance of the
usage relationship) and Art. 6 (1) (f) GDPR (security and recognition of your progress).
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
prsess / __Host-prsess |
cookie, strictly necessary | Session identifier. Keeps form input together and carries the protection against cross-site request forgery (CSRF) | until the browser is closed |
pr_guest |
cookie, strictly necessary | Recognises your guest progress so that points, streaks and achievements are not lost on every visit | 400 days |
pr_token |
cookie, strictly necessary | Keeps you signed in. Set only when you sign in with an account; the value is bound to your device and is invalidated immediately if anything looks wrong | 1 day, or 180 days with "stay signed in" |
pr_lang |
cookie, strictly necessary | Remembers the language you chose (German or English) | 1 year |
pr_consent |
local storage | Remembers your answer to the advertising notice so that it does not reappear on every visit | until you clear this site's data in your browser |
Your control: you can set your browser to inform you about cookies, to allow them only case by case, to exclude them generally or to delete them automatically when the browser is closed. Your browser's help pages explain how. Cookies already set can be deleted at any time.
Consequences of disabling them: without prsess and pr_guest
the game cannot be used in any meaningful way – every page view would start from scratch,
points and streaks would be lost, and forms could not be submitted for security reasons.
Without pr_token you would have to sign in again on every visit.
10. Consent management (consent banner)
Where advertising is enabled in this installation, we show a notice on your first visit that
lets you decide about non-essential cookies. Your decision – "Agree" or "Essential only" – is
stored exclusively locally in your browser (the pr_consent entry) and is not
transmitted to us or to third parties. As long as you have not agreed, no advertising cookies
are set and no personalised advertising is delivered.
Legal basis: Art. 6 (1) (c) GDPR in conjunction with § 25 TDDDG – we are obliged to
obtain and document your decision.
Withdrawal: clear this site's data in your browser. The notice will then reappear and
you can decide again.
11. Playing without an account (guest access)
You can start playing immediately without registering. So that your progress is not lost
between visits, we create a guest profile on your first visit, addressed by the
pr_guest cookie.
Data processed: a randomly generated access key, an automatically assigned display name, your results, the time of your last activity and the pseudonymous checksums described in section 23. No e-mail address, no name and no other identifying detail is requested.
Purpose: recognising your progress, continuing points and streaks, preventing abuse.
Legal basis: Art. 6 (1) (b) GDPR for performing the usage relationship;
Art. 6 (1) (f) GDPR for the recognition, with the legitimate interest of offering a usable
game.
Retention: guest profiles without activity are deleted after 400 days at the latest.
You can end the profile yourself at any time by clearing this site's data in your browser;
the record is then removed at the next clean-up.
12. User account and registration
You may create an account voluntarily. It is a precondition for inclusion in the leaderboards, for duels, for securing your progress across devices and for a payout.
Data processed: display name, e-mail address, password, the time of registration and of the last sign-in. We store the password exclusively as a cryptographic hash using a modern procedure (bcrypt or Argon2, depending on the server configuration); it is never held by us in plain text and cannot be reconstructed from the hash.
An existing guest profile is upgraded, not copied, when you register. Points, streaks and achievements are therefore fully retained and no second record is created.
Purpose: establishing and performing the usage relationship, authentication,
participation in rankings, communication about your account.
Legal basis: Art. 6 (1) (b) GDPR.
Recipients: none, apart from our hosting provider as a processor.
Retention: for the duration of the usage relationship. After the account is deleted,
the data is removed unless a statutory retention obligation stands in the way (see
sections 25 and 32).
13. Signing in and sign-in tokens
When you sign in we generate a random sign-in token, stored in the pr_token
cookie. We additionally record a checksum of your browser signature and the time the token
was last used.
Purpose: to keep you signed in without having to store your password for that purpose.
The checksum protects against stolen sessions: if the same token is used from a demonstrably
different device, we discard it immediately and log the event.
Legal basis: Art. 6 (1) (b) GDPR and Art. 6 (1) (f) GDPR, with the legitimate interest
in the security of accounts that carry a balance.
Retention: until the token expires (1 or 180 days), and immediately on sign-out. All
tokens are invalidated when the password is changed.
14. Password reset and e-mail
If you request a new password, we send a message to the address on file containing a link that is valid for one hour and can be used only once.
Data processed: e-mail address, the time of the request, a random single-use key and –
to limit abuse – the frequency of such requests per address and connection.
Purpose: restoring your access.
Legal basis: Art. 6 (1) (b) GDPR.
Recipients: our hosting provider's mail server, as a processor.
Retention: the key is deleted once used or expired.
If no account exists for the address requested, no message is sent. For security reasons the website nevertheless shows the same confirmation – otherwise the form could be used to find out which addresses are registered with us.
15. Contacting us
If you contact us by e-mail, we process your sender address, the content of your message and any other information you provide voluntarily.
Purpose: handling your enquiry and any follow-up questions.
Legal basis: Art. 6 (1) (b) GDPR where your enquiry relates to performing or
initiating the usage relationship; otherwise Art. 6 (1) (f) GDPR with the legitimate interest
in answering enquiries.
Retention: we delete your enquiry once it has been dealt with conclusively and no
statutory retention obligation applies. Enquiries relating to a payout are kept together with
the corresponding record (section 25).
16. Gameplay: rounds, guesses, points
For every round and every item we store what makes up the game: the guess you submitted, the recorded price, the resulting deviation, the points scored, the time taken, any jokers used, the game mode and the timestamp.
Purpose: running the game, calculating the score, showing your history, enforcing the
repeat lock (so that you do not receive the same item again shortly afterwards) and producing
the anonymous audience distribution shown after the reveal.
Legal basis: Art. 6 (1) (b) GDPR.
Note on the audience distribution: the bar chart shown after the reveal is calculated
from aggregated values. It contains no display names and allows no conclusions about
individuals; below a minimum number of other guesses it is not shown at all.
Retention: for the duration of the usage relationship, then deleted with the account.
17. Leaderboards and publication of your display name
Daily, weekly and season rankings are derived from your results. These rankings are publicly accessible – that is the purpose of a competition and it cannot be run without publication.
Publicly visible are only: your display name, your position, your score and – depending on the ranking – the number of items scored and your average. Not visible are your e-mail address, your balance, your payment details, your IP address and any other contact information.
You choose your display name yourself and can change it in your profile at any time. We expressly recommend not using your real name there. Guest profiles do not take part in the leaderboards.
Legal basis: Art. 6 (1) (b) GDPR. Creating an account and taking part in a scored
round is inseparably connected with publishing your position.
Retention: rankings of completed periods remain as part of the competition history;
after an account is deleted, the display name shown there is replaced by a neutral label.
18. Profile, achievements and statistics
Your profile shows your own statistics: total points, averages, longest streak, rounds played, achievements unlocked and – where applicable – your balance. We calculate these values from the data named in section 16; no additional data is collected for them.
Legal basis: Art. 6 (1) (b) GDPR. These statistics are visible only to you, except for the public information named in section 17.
19. Duels and challenges
In a duel, two people play the same items. Once it is finished, both participants see the other's display name, total score and individual results. The same applies to a challenge created from a completed round.
Data processed: the duel code, the accounts involved, both sides' results and the
timestamps.
Purpose: running the duel and showing the comparison.
Legal basis: Art. 6 (1) (b) GDPR – disclosure to the other side is the purpose of the
feature.
Note: passing on a duel link enables the recipient to take part. Only share such a
link with people you want to show your result to.
20. Streamer lobbies, overlays and channel rankings
A lobby is a round of its own for a livestream. If you take part, you enter a nickname of your choice; no account is required.
Data processed: the nickname you choose, your guesses, your points, the order in which
you joined and a session identifier used to attribute your input.
Disclosure: your nickname and score appear in the lobby, in the on-stream overlay and –
where the channel-wide leaderboard is enabled – there as well. The on-stream display is
public and may be recorded and further distributed by the streamer; we have no influence over
that.
Purpose: running the lobby and displaying the ranking on stream.
Legal basis: Art. 6 (1) (b) GDPR. Being shown on stream is the purpose of taking part;
anyone who does not want that does not join the lobby.
Retention: lobby data is deleted once the round has ended and a short grace period has
passed. In the channel ranking, the nickname and score remain for as long as the streamer
maintains the ranking; we will remove an entry on request.
Important: do not choose your real name or anything that identifies you as a nickname – it is shown publicly on stream.
21. Chat bot integration
Where a lobby is operated through a chat bot, that bot transmits the name you use in the respective chat and the number you guessed to us. We process this like a guess submitted in the lobby (section 20).
Legal basis: Art. 6 (1) (b) GDPR.
Note on responsibility: which data the chat service itself collects and processes is
governed exclusively by its own privacy policy. We have no influence over that and are not
responsible for it. We do not operate a bot of our own and do not write into third-party
chats; we merely make lines available that a bot can collect.
22. Result cards and sharing
After a round you can share your result. The result card contains your score, a coloured bar chart showing how accurate you were, and the name of the game – but never the actual prices and no contact details.
Sharing takes place through your device's share function or the clipboard. You alone decide who receives the card. There is no automatic transmission to third parties or to a social network, and we do not embed social network buttons that would transmit data simply because the page was opened.
Legal basis: Art. 6 (1) (b) GDPR for generating the card at your request.
23. Protection against abuse and manipulation
Because real money is distributed in the weekly ranking, we owe it to everyone who plays fairly to detect and prevent attempts at manipulation. We therefore check rounds for anomalies – for example several accounts from the same connection, technically impossible reaction times, uniform input patterns or a conspicuous accumulation of extremely accurate hits.
Data processed: pseudonymous checksums (hash values) of the IP address, the subnet and selected browser characteristics, timestamps of input, a risk score per event and a short description of the rule triggered. The IP address itself is not stored in plain text for this purpose.
Purpose: ensuring the integrity of the competition, preventing multiple accounts and
automated input, protecting the prize pot against unauthorised access.
Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest is a fair competition; at the
same time it is in the interest of all other participants, whose chances of winning would
otherwise be reduced. Without these checks, a competition with cash prizes could not
responsibly be run.
Recipients: none. This data never leaves our server.
Retention: 180 days. Where a case is open, until it is closed, and
deleted afterwards. Records underlying a payout that has already been refused are kept
together with that case.
Human decision: if a check raises a suspicion, the case is flagged for manual review. A ban, the removal of points or the rejection of a payout is always based on a decision taken by a human being and never on the automatically calculated value alone. See also section 38.
24. Rate limiting and security logs
To fend off large numbers of sign-in attempts, automated requests and denial-of-service attacks, we count certain operations per connection and time window. What we store is a pseudonymous counter key, the number of attempts and the end of the time window – not the content of the request.
We additionally log security-relevant events in the back office, such as administrator sign-ins and changes to settings.
Legal basis: Art. 6 (1) (f) GDPR with the legitimate interest in the security of our
systems and of our users' data; additionally Art. 32 GDPR, which obliges us to apply suitable
safeguards.
Retention: counters expire with their time window. Security logs are kept for up to
180 days.
25. Balance, prizes and payouts
If you reach a winning position in a completed ranking, we credit the amount to the balance in your profile. No further data is required for that.
For a payout we additionally process, depending on the method you choose:
- PayPal: the PayPal e-mail address you provide,
- Bank transfer: the account holder's name, the IBAN and, where required, the BIC.
In addition we process the amount requested, the time of the request, its processing status, a pseudonymous checksum of the connection the request came from, and a payment reference used to match the transfer.
We only ask for these details when you actually request a payout. Afterwards your profile shows them in shortened form only. They are never needed to play or to appear in a leaderboard.
Purpose: carrying out the payout, matching the payment, checking for duplicate requests
and for agreement between the account holder and the person entitled, meeting tax
record-keeping obligations.
Legal basis: Art. 6 (1) (b) GDPR for the payout itself; Art. 6 (1) (c) GDPR for
retaining the payment records; Art. 6 (1) (f) GDPR for the abuse check, with the legitimate
interest in protecting the prize pot against unauthorised payouts.
Recipients: the payment institution you choose or our own bank, insofar as this is
necessary to execute the payment; further, our tax adviser and, in the event of an audit, the
tax authorities.
Retention: payment records and the associated entries are subject to statutory
retention under § 147 of the German Fiscal Code (AO) and § 257 of the German Commercial Code
(HGB) and are kept for up to ten years, counted from the end of the calendar year in which
the transaction arose. This period continues to apply even if you have your account deleted
in the meantime. The data is then blocked against any further use and held solely to meet the
retention obligation.
26. Advertising
The service is funded by advertising, and the prize pot comes from that revenue. Adverts are delivered by an external advertising partner. When an advert is retrieved, that partner necessarily learns your IP address as well as information about your browser, operating system and screen size, and may set or read cookies of its own.
We do not set non-essential advertising cookies without your consent. If you decline in the consent notice, only adverts without such identifiers are delivered; no profiling then takes place.
Legal basis: § 25 (1) TDDDG in conjunction with Art. 6 (1) (a) GDPR (consent) for
storing information on your device and accessing it; Art. 6 (1) (f) GDPR for delivering
non-personalised advertising, with the legitimate interest in funding a service that is free
for you.
Recipients: the advertising partner used at the time, as a controller in its own
right.
Withdrawal: at any time with effect for the future, by clearing this site's data in
your browser. The notice will then reappear. The lawfulness of processing carried out until
withdrawal remains unaffected.
Video advertising: videos are delivered in a player on our own page; no third-party JavaScript is embedded for this. You may be credited with a joker for a video you choose to watch; we record that and when such a video was watched.
Frequency capping: so that advertising does not get out of hand, we record internally when which advertising format was delivered to which profile. These entries contain no advertising identifier, never leave our server and are deleted after 90 days at the latest. The legal basis is Art. 6 (1) (f) GDPR, with the legitimate interest in honouring agreed advertising limits and offering a usable game.
27. Internal reach and revenue statistics
To steer the service and to calculate the prize pot we keep purely internal statistics: the number of rounds played, the number of adverts delivered and the revenue generated from them per period. These evaluations are aggregated.
We do not use any external analytics services. In particular, Google Analytics, Matomo, the Meta pixel and comparable tools are not embedded, and no cross-site usage profiles are created.
Legal basis: Art. 6 (1) (f) GDPR with the legitimate interest in managing our own service commercially; for determining the prize pot also Art. 6 (1) (b) GDPR, since the size of the prize pot forms part of the terms of participation.
28. Fonts (Google Fonts)
For a consistent presentation, this website embeds typefaces from the Google Fonts service by default. They are loaded when a page is opened from a server operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Your IP address is transmitted to Google in the process, and Google may log the request.
Purpose: a consistent presentation of the typeface, optimised for all devices.
Legal basis: Art. 6 (1) (f) GDPR with the legitimate interest in a consistent
presentation of the service.
Recipients: Google Ireland Limited; a transfer to Google LLC in the USA cannot be
ruled out. The basis for this is the European Commission's Standard Contractual Clauses and
the adequacy decision for the EU-US Data Privacy Framework. Further information can be found
in Google's privacy information.
Note for operators of this installation: the back office allows the system font to be selected under Design → Font. Nothing is then loaded from Google, no connection to a Google server is made, and this section can be removed entirely. That is the more privacy-friendly setting.
29. Item sources, product images and external links
The items shown in the game come from our own, editorially maintained catalogue and – where enabled in the back office – from official application programming interfaces of trading platforms. We do not scrape third-party websites.
Images are delivered from our own server or, for items obtained through an interface, from the image servers of the platform concerned. In the latter case the platform learns your IP address when the image is loaded.
After the reveal, a link to the original listing may be offered for an item. Such a link may contain an affiliate identifier through which we receive a commission if a purchase is made. No additional cost arises for you. Data is only transmitted to the destination platform once you click the link; the platform concerned is solely responsible for the processing that then takes place.
Legal basis: Art. 6 (1) (f) GDPR with the legitimate interest in showing real listings and in funding the service.
30. Recipients and processors
We disclose your personal data to third parties only in the following cases:
- to our hosting provider as a processor under Art. 28 GDPR (section 7),
- to the advertising partner, where advertising is delivered (section 26),
- to payment service providers and banks, where this is necessary to execute a payout you have requested (section 25),
- to our tax adviser and the tax authorities, where required by law,
- to authorities and courts, where we are legally obliged to do so (Art. 6 (1) (c) GDPR) or where it is necessary to establish, exercise or defend legal claims (Art. 6 (1) (f) GDPR),
- where you have expressly consented (Art. 6 (1) (a) GDPR).
We do not pass on personal data beyond that. Selling, renting out or trading user data does not take place.
31. Transfers to third countries
A transfer of personal data to countries outside the European Union and the European Economic Area may occur in the context of the services named in sections 26, 28 and 29.
It takes place exclusively on one of the following bases: an adequacy decision of the European Commission under Art. 45 GDPR – such as the EU-US Data Privacy Framework for companies certified under it – or the Standard Contractual Clauses under Art. 46 (2) (c) GDPR, supplemented by additional safeguards.
We point out expressly that despite these guarantees, a level of data protection equivalent to European standards cannot be guaranteed in every individual case in third countries. In particular, it cannot be ruled out that authorities of the country concerned may access data without effective legal remedies being available against it.
32. Retention and deletion
We store personal data only for as long as it is necessary for the respective purpose or as long as statutory retention obligations require. Afterwards the data is deleted or – where deletion is not possible because of a retention obligation – blocked against any further use.
| Category of data | Period | Basis |
|---|---|---|
| Server log files | a few days | purpose fulfilled |
| Inactive guest profiles | up to 400 days | purpose fulfilled |
| Account and game results | until the account is deleted | purpose fulfilled |
| Sign-in tokens | 1 or 180 days, immediately on sign-out | purpose fulfilled |
| Anti-fraud checksums | 180 days | purpose fulfilled |
| Security logs | up to 180 days | Art. 32 GDPR |
| Advert deliveries (internal) | up to 90 days | purpose fulfilled |
| Lobby data | after the round ends | purpose fulfilled |
| Balance entries and payout records | up to 10 years | § 147 AO, § 257 HGB |
| Completed rankings (history) | permanent, anonymised after account deletion | Art. 6 (1) (f) GDPR |
33. Your rights as a data subject
You have the following rights in relation to us regarding your personal data. Exercising them is free of charge.
- Right of access (Art. 15 GDPR). You may request confirmation as to whether we process data concerning you. If we do, you are entitled to access that data and to information about the purposes of processing, the categories of data, the recipients, the envisaged storage period, the existence of your other rights, the source of the data and the existence of automated decision-making. On request we will provide you with a copy.
- Right to rectification (Art. 16 GDPR). You may request that inaccurate data be corrected without undue delay and that incomplete data be completed. You can also change your display name and e-mail address yourself in your profile at any time.
- Right to erasure (Art. 17 GDPR). You may request the erasure of your data without undue delay, in particular where it is no longer necessary for the purposes, where you have withdrawn consent or where it was processed unlawfully. The right does not apply where processing is necessary to comply with a legal obligation or to establish, exercise or defend legal claims – this concerns payment records in particular (section 25).
- Right to restriction of processing (Art. 18 GDPR). You may request that we only store your data and no longer use it – for example while we verify the accuracy of contested data or as long as an objection under Art. 21 GDPR has not been conclusively assessed.
- Right to data portability (Art. 20 GDPR). Where processing is based on consent or on a contract and is carried out by automated means, you may request the data you provided in a structured, commonly used and machine-readable format, or – where technically feasible – have it transmitted to another controller.
- Right to object (Art. 21 GDPR). See section 34.
- Right to withdraw consent (Art. 7 (3) GDPR). See section 35.
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR). See section 36.
- Right to be informed (Art. 19 GDPR). Where you have requested rectification, erasure or restriction, we will communicate this to every recipient to whom your data was disclosed – unless this proves impossible or involves disproportionate effort.
How to exercise your rights: an informal message to info@priceygame.de is enough. So as not to release your data to an unauthorised person, we need to attribute the request to your account; we may therefore ask which account or device it comes from. We only ask for further evidence where there is reasonable doubt about your identity. We reply without undue delay and at the latest within one month of receipt; in exceptional cases this period may be extended by two months, in which case we will inform you.
Deleting your account: on your request we delete your account together with your game results and replace your display name in completed rankings with a neutral label. What we cannot delete are the accounting records of payouts already made; they are subject to statutory retention and are blocked against any further use. Any balance not yet paid out can be paid to you beforehand, provided the minimum of € 10 has been reached.
34. Right to object under Art. 21 GDPR
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6 (1) (e) or (f) GDPR. This also applies to profiling based on those provisions.
If you object, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
Where your data is processed for direct marketing purposes, you have the right to object at any time and without giving reasons; the data will then no longer be processed for that purpose.
A message to info@priceygame.de is enough to object. No particular form is required.
35. Withdrawing consent
Where processing is based on your consent, you may withdraw it at any time with effect for the future. The lawfulness of processing carried out on the basis of that consent until withdrawal remains unaffected.
You withdraw your consent to advertising cookies by clearing this site's data in your browser; the notice will then reappear. Any other consent can be withdrawn informally at info@priceygame.de. Withdrawing is as easy as giving consent.
36. Right to lodge a complaint
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement, if you consider that the processing of data concerning you infringes the GDPR (Art. 77 GDPR).
We would ask you to contact us first – most concerns can be resolved directly and more quickly. You are of course not obliged to do so.
37. Is providing data required?
You do not have to provide us with any personal data in order to play; guest access is enough. An account requires an e-mail address, and a payout requires payment details. There is neither a statutory nor a contractual obligation to provide this data; without it, however, we cannot offer the respective function. No further disadvantages arise for you.
38. Automated decision-making and profiling
Automated decision-making, including profiling, which produces legal effects concerning you or similarly significantly affects you (Art. 22 (1) GDPR), does not take place.
The anti-fraud measures described in section 23 do evaluate behaviour within a round automatically and calculate a risk score from it. That score does not, however, lead to any decision on its own: it merely flags a case for review. Every measure that affects you – exclusion from a ranking, blocking of an account, refusal of a payout – is examined and taken by a natural person. In such a case you receive reasons, may put forward your own point of view and may contest the decision.
39. Protection of minors
Our service is not directed at children. Participation requires a minimum age of 16; a payout requires a minimum age of 18 or the consent of the legal guardians.
Where processing is based on consent and the data subject has not yet reached the age of 16, the consent is lawful only with the authorisation of the holder of parental responsibility (Art. 8 GDPR). If we learn that we are processing a child's data without the required authorisation, we delete it without delay. Parents and guardians can contact us about this at any time at info@priceygame.de.
40. Technical and organisational measures
In accordance with Art. 32 GDPR we take appropriate technical and organisational measures to ensure a level of security appropriate to the risk. These include in particular:
- consistently encrypted transmission (TLS) and modern security headers,
- storing passwords exclusively as hashes using a modern procedure,
- binding sign-in tokens to the device they were issued for, with automatic expiry,
- protection against cross-site request forgery (CSRF) for all modifying operations,
- the use of checksums instead of plain text for security-relevant identifiers,
- limiting the number of sign-in and request attempts,
- two-factor authentication and logging for the back office,
- strict separation of application and administration access,
- regular updating of the software in use,
- the principle of data minimisation already at the design stage ("privacy by design") and privacy-friendly default settings ("privacy by default").
We point out that data transmission over the internet can have security gaps. Complete protection against access by third parties is not possible.
41. Personal data breaches
Should a personal data breach occur despite all measures, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours (Art. 33 GDPR). Where the breach is likely to result in a high risk to your rights and freedoms, we will also inform the affected persons without undue delay (Art. 34 GDPR).
42. Changes to this policy
We adapt this privacy policy whenever the functions of our service, the services we use or the legal situation change. The version available on this page applies at any given time; the date stated at the beginning indicates its status. Where a material change requires renewed consent, we obtain it beforehand.