This notice describes the data flows implemented in the current RACKET pre-release. The intended controller is Nature Extract GmbH, Felix-Hollenberg-Weg 32, 46539 Dinslaken, Germany, represented by Managing Director Dominik Büren. A dedicated privacy contact must still be published before commercial launch.
Data we process
Account identifiers and email supplied by the identity provider; player handle, profile, settings, progression, resources, inventory, Contacts, Intel, businesses, contracts, crews, social content, messages, reports, sanctions, command receipts, economy ledger entries, and security events; plus technical request and error data needed to operate the service.
Purposes and legal bases
We process account and gameplay data to provide the requested service and maintain persistent game state; security, moderation, fraud, and abuse signals to protect the service and players; legal records to comply with obligations; and optional communications or analytics only where an appropriate legal basis and required consent exist.
Service providers
Clerk provides authentication, Convex provides the authoritative database and game functions in the EU West region, and Cloudflare delivers the web application and edge security. Each provider may process technical data under its own contractual role and applicable data-processing terms.
Public and social data
Your handle, selected profile elements, operator rank, crew identity, public Wire posts, and public market activity may be visible to other players. Direct messages are limited to participants and authorized moderation access. New contacts enter through controllable message requests. Availability is self-declared; RACKET does not expose an exact last-active time or precise real-world location. Never publish sensitive personal information in game text.
International transfers
Provider corporate structures may involve processing outside the EEA. Before public launch, the controller must document each transfer mechanism, provider region, subprocessors, safeguards, and how copies of relevant safeguards may be obtained.
Retention
Active account and gameplay records are retained while the account is used. Security, ledger, moderation, and legal records may require longer retention. A final retention schedule with exact periods must be adopted before launch. Deleted accounts are anonymized in the implemented workflow where records must remain for economy or integrity.
The implemented deletion workflow removes social relationships, reactions, message requests, conversation preferences, and personal notifications, and redacts authored Wire posts and direct-message bodies. Moderation evidence may be retained where needed for safety or legal obligations.
Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection and may complain to a supervisory authority. The application includes a structured data-export function and an account-anonymization request, subject to identity verification and mandatory retention. Until a dedicated privacy email is published, written requests may be sent to the controller’s postal address above.
Cookies and local technology
Authentication requires provider cookies or equivalent storage. Optional analytics and marketing storage must remain disabled until the consent configuration and consent record are implemented where required. RACKET does not currently enable advertising.
Security
RACKET uses authenticated access, server-authoritative commands, optimistic concurrency, idempotency receipts, balanced ledgers, rate limits, staff authorization, audit logs, and encrypted provider transport. No system is risk-free; security concerns should be sent to the final published security contact.
Automated game decisions
Job and combat outcomes use server-authoritative rules and entropy to determine fictional gameplay consequences. They do not make legal or similarly significant real-world decisions about players.