Privacy Policy
1. Controller
The controller responsible for processing personal data within the meaning of the General Data Protection Regulation (GDPR) is:
VidiScope GmbHValentin Schierhuber (Geschäftsführer)
Römerstr. 27
89250 Senden
Deutschland
Tel.: +49 731 25089010
E-Mail: office@vidiscope.com
Datenschutzanfragen: datenschutz@vidiscope.com
For any questions regarding data protection, please contact us preferably via the data protection email address given above.
2. General Principles
We process our users' personal data only to the extent necessary to provide a functioning game as well as our content and services. Processing generally takes place only with the consent of the data subject or on the basis of another legal permission. Where consent is obtained for processing personal data, Art. 6(1)(a) GDPR serves as the legal basis.
3. Hosting and Provision of this Service
World of Pharaos is operated on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The servers are located in Hetzner's data centers in Falkenstein and Nuremberg (Germany). We have entered into a data processing agreement with Hetzner pursuant to Art. 28 GDPR.
Each time a page of the game is accessed, the web server (nginx) automatically collects the following data in so-called log files:
- IP address of the accessing device
- Date and time of access
- URL requested
- HTTP status code of the response
- Browser used (user agent)
- Referrer URL (the previously visited page, if transmitted)
This data is collected to ensure smooth operation as well as to detect and defend against attacks (Art. 6(1)(f) GDPR, legitimate interest in the security and stability of our service). Log files are automatically deleted after 14 days.
To protect against data loss, we create encrypted backups, which are additionally mirrored to a second server also operated in Germany. Backups are retained on a staggered basis and deleted after 120 days at the latest.
4. Cookies and Local Storage
Our game uses only the technically necessary session cookie PHPSESSID. It allows us to recognize you during your visit (e.g. to keep you logged in) and is strictly required for the game to function. The cookie is set with the HttpOnly and SameSite=Lax attributes; on the production system it is additionally transmitted only over an encrypted connection (Secure). It becomes invalid at the end of your session or when you close your browser.
Your selected language (German/English) is stored exclusively in this session, not in a separate cookie.
We do not use any further cookies, tracking or analytics tools, or third-party cookies.
The legal basis for the technically necessary session cookie is Section 25(2) No. 2 TDDDG (German Telecommunications-Digital-Services-Data-Protection Act) in conjunction with Art. 6(1)(f) GDPR. No consent is required for this, as the cookie serves exclusively to provide the service you have explicitly requested.
5. Spam Protection for Forms
To protect registration from automated abuse (bots), we use a simple math captcha, a honeypot field invisible to humans, and a check of how quickly the form was filled in. All three mechanisms run entirely on our own servers; no data is transmitted to external providers (e.g. Cloudflare Turnstile, Google reCAPTCHA, or similar).
The legal basis is our legitimate interest in a functioning game free of abuse (Art. 6(1)(f) GDPR).
6. Registration and Player Account
Participation in the game requires creating a user account. During registration, we collect and store:
- Player name (nickname)
- Email address
- Your password – solely as a cryptographic hash (bcrypt); the plaintext password is never stored
- Date of registration
- IP address at the time of registration
- Time of your last login
This data is required to provide the game and manage your account; the legal basis is Art. 6(1)(b) GDPR (performance of the terms of use).
To protect against brute-force attacks on the login, we log login attempts (email address, IP address, timestamp, success/failure) in a separate table. The legal basis is our legitimate interest in the security of user accounts (Art. 6(1)(f) GDPR). These logs are automatically deleted after 30 days.
If you use the forgot-password function, we generate a time-limited reset token (stored as a hash, including expiry time, usage status, and the requesting IP address). Expired or already-used reset requests are automatically cleaned up. The legal basis is Art. 6(1)(b) GDPR.
If an account violates our terms of use, we store the reason, time, and duration of a suspension in order to track repeat violations and correctly enforce suspensions (Art. 6(1)(f) GDPR).
7. Email Communication
We send registration, password reset, and purchase confirmation emails via a mail server operated by us, VidiScope GmbH; no external email delivery provider is used. The legal basis for this account communication is Art. 6(1)(b) GDPR; we do not send newsletters or other promotional emails.
8. Gameplay and User-Generated Content
As part of using the game, we process your game progress (including your oasis, buildings, resources, troops, and position on the world map), your alliance membership, and battle reports. The legal basis is Art. 6(1)(b) GDPR (performance of the terms of use).
Messages you send to other players via the internal messaging feature (sender, recipient, subject, text) are automatically deleted 7 days after being sent (daily cleanup job). The legal basis is Art. 6(1)(b) GDPR.
In your profile, you may voluntarily provide additional information (e.g. date of birth, gender, origin, occupation, interests, homepage, free text, avatar image). This information is explicitly voluntary, is only stored with your consent (Art. 6(1)(a) GDPR), and can be changed or deleted by you in your profile at any time.
9. Payment Processing via Stripe
When you purchase Taler packs, we process: order ID, the associated player account, the selected pack, amount and currency, payment status, the Checkout Session ID and payment ID assigned by Stripe, the times of order, payment and crediting, and your consent to immediate provision (time and wording). We do not receive or store card details. The purpose is to process the purchase, credit the Taler, handle enquiries, refunds and chargebacks, and document your consent. The legal basis is Art. 6(1)(b) GDPR and, for documenting your consent, Art. 6(1)(f) GDPR (legitimate interest in establishing and defending legal claims).
For payment, we redirect you to Stripe Checkout, a service provided by Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland ("Stripe"). You enter your payment details (card number, expiry date, security code, cardholder name), email address and billing country directly with Stripe; Stripe also collects technical data (IP address, device and browser information). We only transmit the order ID, pack and amount to Stripe (and, where applicable, your email address to pre-fill the form). Stripe informs us of the payment status and the session and payment IDs. The legal basis is Art. 6(1)(b) GDPR. Where Stripe processes data for fraud prevention and to comply with its own legal obligations (e.g. anti-money laundering), Stripe acts as an independent controller.
Stripe may transfer data to affiliated companies and service providers outside the EU/EEA, in particular to Stripe, Inc. in the USA. Such transfers are based on the European Commission's adequacy decision on the EU-U.S. Data Privacy Framework (Art. 45 GDPR), insofar as the recipient is certified under it, and otherwise on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). Further information: https://stripe.com/privacy
We store order and payment data for as long as necessary to perform the contract and thereafter for the duration of the retention obligations under German commercial and tax law (Section 147 AO, Section 257 HGB; currently generally eight years for accounting records). The legal basis for this is Art. 6(1)(c) GDPR. These data remain stored after deletion of your account until the retention period expires and are deleted thereafter.
10. Disclosure to Third Parties
We disclose your data to third parties only to the extent necessary to provide the game or to process purchases. This concerns our hosting provider Hetzner Online GmbH (processor pursuant to Art. 28 GDPR, see Section 3), the payment service provider Stripe for Taler purchases (see Section 9) and, where required by law, our tax adviser and the tax authorities. We do not transfer data to any other third parties, do not sell your data, and do not use it for third-party advertising purposes. We do not use Google Analytics, Cloudflare, or comparable third-party services.
11. Transfer of Data to Third Countries
All processing carried out by us takes place exclusively on servers located in Germany. Personal data may be transferred to countries outside the EU/EEA only in the context of payment processing by Stripe; for details and safeguards, see Section 9.
12. Your Rights as a Data Subject
Under the GDPR, you have the following rights, which you may assert at any time via the data protection email address given in Section 1:
- Right of access to your stored data (Art. 15 GDPR)
- Right to rectification of inaccurate data (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
- Right to withdraw any consent given at any time with effect for the future (Art. 7(3) GDPR)
13. Right to Lodge a Complaint with a Supervisory Authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, place of work, or the place of the alleged infringement. The supervisory authority responsible for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)Promenade 18
91522 Ansbach
www.lda.bayern.de
14. Changes to this Privacy Policy
We reserve the right to amend this privacy policy to ensure it always complies with current legal requirements or to reflect changes to our service (e.g. new features) in the privacy policy. Your next visit will then be governed by the updated privacy policy.
Last updated: October 2026