Data Privacy
Test-mode preparation draft updated: 01.09.2026
1. Controller
Paul Münchhausen
Richard-Wagner-Str. 22
66773 Schwalbach
Germany
Email: paul@muenchhausen.dev
Discord: @patimue
2. General Processing When Visiting the Website
When you visit our website, technical data is processed to ensure secure operation and provide the service. This includes:
- IP address
- Date and time of access
- Referrer URL
- Browser type and version
- Operating system
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and reliable operation).
3. Accounts and Authentication (Clerk)
LootSpectrum uses Clerk for authentication services. When you register or sign in, we process your email address and account identifiers.
If you sign in with Google or Discord, we receive basic profile information from these providers (for example: username, unique user identifier, email address, avatar).
Legal basis: Art. 6(1)(b) GDPR (contract performance).
4. Service Data Stored in Your Account
Depending on your usage, we may store:
- Email address
- Inventory events (case openings, trade-ups, drops)
- Preferences (price source, UI settings)
- Supporter entitlement decisions and time-bounded access grants
- Minimal subscription, cancellation, checkout and webhook projections
Public statistics are displayed in aggregated form and are not directly traceable to individuals.
5. Payments (Stripe)
The prepared supporter flow redirects to Stripe-hosted Checkout and Portal pages in Stripe test mode. LootSpectrum does not store card numbers or CVCs. Stripe receives payment, billing-address, tax-location, invoice, fraud-prevention and related data required for the selected test transaction.
LootSpectrum stores an opaque billing reference; allowlisted customer, subscription, plan, status and period fields; time-bounded one-time grants; checkout-attempt state; webhook deduplication state; and the minimum encrypted cancellation declaration and confirmation-outbox evidence. Raw webhook bodies, Checkout/Portal URLs, card data, billing addresses and unrestricted Stripe objects are not persisted.
The initial legal-basis mapping is Article 6(1)(b) GDPR for contract/payment coordination, cancellation and entitlement delivery; Article 6(1)(c) for legally required invoice/tax records; and Article 6(1)(f) for narrowly scoped security, webhook deduplication, reconciliation and claims records. This mapping remains subject to the recorded legal review before real-person testing.
Stripe may act as processor for some services and as an independent or joint controller for regulated payments, fraud prevention and compliance. The contracting entity, agreements, subprocessors and international-transfer safeguards must be verified before real-person test data is used.
Stripe privacy policy: https://stripe.com/privacy
6. Diagnostics and Security Logging
Vercel and Railway process operational logs for the website and API so we can keep the service stable and secure. These logs may include timestamps, request IDs, route templates, request methods, response status, duration, deployment/region context, and fixed error or outcome codes. Application logging is designed to omit request bodies, URL queries, credentials, payment data, and direct account or payment identifiers. Opaque API request IDs and bounded upstream correlation IDs may be retained; they can be pseudonymous technical personal data when combined with other provider or request records.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in stability and security).
Railway currently retains its platform logs for 7 days. The actual Vercel retention and any separately configured platform log drain must be identified and verified before launch; an unapproved or paid Better Stack/Logtail or other drain must be disabled. The prepared target is the shortest period needed for operations and no more than 30 days unless a documented, record-specific incident hold applies.
7. External Content and Links
Some content is loaded from third-party providers:
- Steam static image CDN (item images)
- Discord CDN (user avatars when linked)
- Affiliate partner link to tradeit.gg (only when you click it)
When these resources are loaded, your IP address is transmitted to those providers. Legal basis: Art. 6(1)(f) GDPR (service delivery).
8. Cookies and Local Storage
Current device access is limited to authentication and user-requested preferences such as theme selection. No Stripe analytics, marketing tag, or embedded payment component is added by this billing preparation; Checkout and Portal are hosted by Stripe. The necessity of each cookie/local-storage item must remain documented in the TDDDG inventory.
GDPR legal basis and the separate TDDDG device-access rule are assessed separately; the final inventory and notice require review before real-person billing tests.
9. Hosting and Processors
The website is delivered through Vercel and the API runs on Railway. Clerk provides authentication services and Stripe processes payments. The database hosting provider processes the minimum application data needed to operate the service. An optional Cloudflare email-delivery path exists for cancellation confirmations but is not claimed as active here. No Better Stack/Logtail application integration exists; any separately configured platform drain remains subject to the verification and removal gate above.
Provider-specific roles, destinations and transfer safeguards—including an applicable EU-U.S. Data Privacy Framework certification and contractual Standard Contractual Clauses where relevant—must be recorded and verified before real-person test data is used. Test mode is not a privacy exemption.
10. Retention
Prepared initial targets include 30 days for abandoned checkout attempts and synthetic test scenarios, 90 days for webhook deduplication and ended operational projections, and the applicable restricted legal period for minimum contract, cancellation, invoice and accounting evidence. Operational data is not retained merely because an accounting record must remain. Exact periods, deletion jobs, legal holds, provider deletion and backup restoration controls require approval and operational verification before real-person testing.
11. Your Rights
You have the right to access, rectification, deletion, restriction, objection, and data portability under the GDPR. To exercise your rights, contact us at the email above.
You also have the right to lodge a complaint with your supervisory authority. For Saarland, Germany this is the Landesbeauftragte fuer Datenschutz und Informationsfreiheit Saarland.
12. Changes
We may update this privacy policy when necessary. Significant changes will be communicated in the app or on the website.