1. Controller and contact
The controller is Tim Buschmann, Schloßstraße 1, 23701 Eutin, Germany. Send privacy requests to dcaskocafe@gmail.com. Discord is an additional support channel and is not required to exercise your rights.
2. Sign-in and connected accounts
Google or Discord provide the confirmed account identifier and authorised account information, particularly email address, display name and profile image. These data originate from your sign-in provider. Auth.js handles sign-in; application data are stored in a PostgreSQL database at Supabase.
Before sign-in we ask for your age. The service is available from age 16. We retain the age you declare, the accepted terms version and acceptance time as a record of registration. This is a self-declaration, not an identity-document check.
Optional platform connections process identifiers and authorised information required for the selected feature. A connected Riot account, for example, may enable confirmed game information. Only connections actually offered in “Connected accounts” are available. You can disconnect them. Access credentials are not displayed to other users.
3. Profiles, matching and communication
We process profile information you provide: gamer name, declared age, profile and background images or avatar, descriptions, languages, games, playstyle, interests and availability. Interactions include likes, passes, unlocks, matches, messages, reactions, read state, invitations, planned and confirmed sessions, activity and points transactions.
Recommendations and explanations compare games, languages, availability, preferences and activity. They do not guarantee a contact. Declared ages and freely entered details are not labelled independently verified. Recommendations do not make a legal or similarly significant decision about you.
Other signed-in users see profiles within the visibility rules. Conversation partners receive the information needed for communication and planning. Hidden profile details appear after the relevant unlock. Users under 18 are matched separately from adults. The Safety Center provides profile visibility, online-status and blocking controls.
Messages are stored on the server and are not end-to-end encrypted. Avoid sensitive data, credentials, precise home addresses and other people's private information in profiles or conversations.
4. Asko Cafe, boosts and Discord sharing
For a connected Discord identity, Game.space may use the Asko Cafe bot to check membership and an active server boost. We process the Discord identifier, membership, boost status and check times. An existing boost may unlock Premium. Game.space does not create its own self-call system: invitations lead to Asko Cafe and its existing voice channels.
Sharing your Discord contact with a match uses the dedicated permission feature. You can revoke sharing or an enabled call-information permission in Game.space; this cannot retrieve copies already made by other people.
Barkeeper and Discord process server information needed for their own features; the existing bot runs through Wispbyte. When you open or join Discord, its own privacy information also applies. Joining Discord is not required for a privacy request.
5. Support, security and moderation
We use contact details, descriptions, content references and relevant evidence you submit to handle requests and reports. A signed-in report may contain the affected profile and up to five relevant messages. Authorised people use these data to handle the case, prevent abuse and, where necessary, review a measure. Private chats and reports are not publicly accessible.
Technical security and administration data help prevent unauthorised use, duplicate credits and manipulation. Email requests are handled through the stated Gmail mailbox. Send only necessary information, never passwords or bot tokens.
6. Notifications and device storage
Push notifications require separate browser or operating-system permission. Activation stores the technical delivery endpoint, necessary delivery keys and device label. Notifications show a general alert, not the message text. Delivery uses your browser or device provider's push service. You can turn off push and message sound in settings and disconnect devices.
Sign-in and account linking use necessary session and security cookies and short-lived age-check records. Your language choice is kept in a cookie for up to one year and in browser storage. Settings and drafts may remain in local storage until removed.
The installable app caches public files for faster visits and offline display. Private conversation pages and Community API responses are not stored in that offline cache. An account identifier may remain in IndexedDB to associate authorised push notifications. You can clear browser data; you may then need to sign in again.
The website uses no advertising or third-party analytics tracker. Storage indispensable for explicitly requested features is used under section 25(2) of the German TDDDG. Accepting terms is not blanket consent for optional processing.
7. Hosting, recipients and international processing
Vercel provides the website and server functions; Supabase provides the application database. Germany is the stated location for primary application servers. This does not mean every provider processes all data exclusively in Germany or the EU.
Vercel, Supabase, Google and Discord work with international entities and subprocessors. Depending on the feature, data may be processed outside the EU/EEA, particularly in the United States. Google or Discord profile images may be loaded from their servers, transmitting necessary connection information including an IP address. Accessing the website also generates technical connection data at hosting providers.
The linked provider information explains their roles, subprocessors and available transfer safeguards, such as EU standard contractual clauses. Ask dcaskocafe@gmail.com about the contracts and safeguards specifically applying to Game.space and for a copy of relevant safeguards. A German server region alone does not replace these safeguards.
Data are shared as needed for operation with technical providers, your selected conversation recipients and people authorised to handle support or security cases. Authorities or other bodies receive data only with an appropriate legal basis. We do not sell profile or message data. The site's own artwork, game logos and font files are served through the website.
8. Purposes and legal bases
Requested account, profile, matching, messaging, points and Premium functions are processed to perform the user relationship (GDPR Article 6(1)(b)). Without information necessary for sign-in or a feature, that feature cannot be provided. Optional profile information can be omitted or changed.
Security, abuse prevention, proportionate moderation, necessary technical diagnosis and defence of legal claims rely on legitimate interests in a safe, functional service (Article 6(1)(f)). Your interests, particularly those of minors, must be considered. Legal obligations rely on Article 6(1)(c). An additional feature requiring explicit consent relies on Article 6(1)(a); consent can be withdrawn for the future.
Optional internal quality measurement is off by default. Only after your separate consent (Article 6(1)(a)) does it collect loading and response times, device category and an allowed page category. Its measurement table contains no message texts, names, complete URLs or IP addresses. Account association provides access control and measurement limits. “Do Not Track” is also respected. There is no advertising analysis or transfer to an external analytics service. Your choice is stored in a cookie for up to one year. You can change it here or in settings; withdrawal ends future measurement without affecting the lawfulness of earlier measurement.
Optional performance measurement
Optional performance measurement
Help us improve loading times and layout stability. We collect technical measurements, page category and mobile/desktop only, without messages or profile names. Optional; turn it off here at any time.
Off: No new measurements are sent.9. Retention and deletion
Account, profile and interaction data remain for the relevant functions until removed, disconnected or the account is deleted. Security, support and moderation records are needed while handling a case, necessary follow-up, legal duties or establishing and defending specific claims. Case closure, the nature of the matter and applicable statutory periods determine retention.
Activity older than 90 days is cleaned up on the next relevant account access. Cleanup thresholds are 30 days for performance measurements and 32 days for their daily limits. Cleanup happens in bounded batches during database access, not as a promise of daily erasure of every copy.
Account deletion removes related data from the active application database. Shared match conversations are also removed and become unavailable to conversation partners. A technical marker comprising a one-way digest of the account identifier and deletion time remains to block old sessions. This is pseudonymised, not completely anonymous. No automatic expiry is currently configured for this security marker.
Backups and technical logs may follow separate provider deletion cycles; active database deletion does not instantly erase every backup. Ask by email about a specific deletion. Deleting Game.space does not delete your Google, Discord or other platform accounts.
10. Your rights
Subject to the legal conditions, you have rights of access, correction, erasure, restriction, portability and objection. You can withdraw consent for the future. Where processing relies on legitimate interests, you can object for reasons arising from your particular situation. We may request only additional information needed to confirm identity.
The Safety Center lets you download data, manage contacts and connections, change visibility and delete your account. The self-service download does not replace your right to a complete response, which may require supplementary review. Write to dcaskocafe@gmail.com; no Discord account is necessary.
You can complain to a data protection authority, particularly in your country of residence or where a suspected infringement occurred. The operator's competent authority is the Landesbeauftragte für Datenschutz Schleswig-Holstein at ULD, Holstenstraße 98, 24103 Kiel, Germany.
