Privacy Policy

Last updated: January 12, 2025

1. Introduction

Choose.place ("we", "our", or "us") is committed to protecting your privacy.This Privacy Policy explains how we collect, use, and safeguard your informationwhen you use our website and services.

2. Data Controller

Choose.place is operated from Serbia. For the purposes of data protection laws,we are the data controller responsible for your personal information.Our servers are located in the European Union (Germany) via Hetzner.

3. Information We Collect

Account Information

When you create an account, we collect your email address, username, andpassword (stored securely using bcrypt encryption).

Game Data

We collect information about your gameplay, including:

  • Game scores, completion times, and accuracy
  • Stamp transactions and balance history
  • Achievement progress and unlocked countries
  • Leaderboard rankings and challenge participation
  • Campaign and belt progression

Subscription Data

If you purchase a premium subscription, Paddle (our payment processor)collects payment information. We only store your subscription statusand Paddle customer ID - we never see or store your payment card details.

Technical Information

We automatically collect certain information when you visit our website,including your IP address (for security purposes), browser type, and device information.

4. Legal Basis for Processing (GDPR)

For users in the European Economic Area, we process your data based on:

  • Contract: Processing necessary to provide our services (account, gameplay, subscriptions)
  • Legitimate Interest: Security measures, fraud prevention, and service improvement
  • Consent: Marketing communications (only if you opt-in)

5. How We Use Your Information

  • Provide and maintain our gaming services
  • Process your account registration and manage your profile
  • Display leaderboards and enable competitive features
  • Track your progress, stamps, and achievements
  • Process subscription payments (via Paddle)
  • Send important service updates (account, subscription status)
  • Improve our games and user experience
  • Detect and prevent cheating and abuse

6. Data Retention

We retain your data for as long as your account is active. Specifically:

  • Account data: Until you delete your account
  • Game scores and progress: Until you delete your account
  • Stamp transaction history: Until you delete your account
  • Server logs (IP addresses): 30 days for security purposes

When you delete your account, we permanently delete your personal data within 30 days.Some anonymized, aggregated data may be retained for analytics.

7. Data Security

We implement appropriate security measures including:

  • HTTPS encryption for all connections
  • Secure password hashing (bcrypt)
  • EU-based servers (Hetzner, Germany)
  • Regular security updates

No method of transmission over the internet is 100% secure. We cannot guaranteeabsolute security, but we take reasonable precautions to protect your data.

8. Cookies

We use only essential cookies required for the service to function:

  • Session cookie: Keeps you logged in
  • CSRF token: Security protection

We do not use tracking cookies, advertising cookies, or third-party analytics.Since we only use essential cookies, no cookie consent banner is required.

9. Third-Party Services

We use the following third-party services:

Paddle (Payment Processing)

Paddle acts as our merchant of record and processes all payments.They collect payment information directly.See: Paddle Privacy Policy

Hetzner (Hosting)

Our servers are hosted in Germany by Hetzner.See: Hetzner Privacy Policy

10. International Data Transfers

Your data is stored on servers in the European Union (Germany). We do not transferyour personal data outside the EU/EEA. If this changes in the future, we willensure appropriate safeguards are in place.

11. Your Rights (GDPR)

If you are in the European Economic Area, you have the following rights:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate data
  • Erasure: Delete your account and all associated data
  • Portability: Export your data in a machine-readable format
  • Objection: Object to processing based on legitimate interest
  • Withdraw consent: Where processing is based on consent

To exercise these rights, please contact us or use the account settings in your profile.

You also have the right to lodge a complaint with your local data protectionauthority if you believe we have violated your rights.

12. Children's Privacy

Our service is not intended for children under 13 (or 16 in some EU countries).We do not knowingly collect personal information from children. If you believewe have collected such information, please contact us and we will delete it.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registeredusers of significant changes via email. The "Last updated" date at the topindicates when the policy was last revised.

14. Contact Us

If you have any questions about this Privacy Policy or want to exercise yourdata protection rights, please contact us.