This notice explains how RACKET processes personal data. It applies to the public website, accounts, gameplay, community features, support and purchases. Version 2026-08-05-eu-transparency-v1.
Controller
Dominik Büren, Einzelunternehmer, trading as RACKET, Felix-Hollenberg-Weg 32, 46539 Dinslaken, Deutschland. Privacy contact: privacy@playracket.app. No data protection officer has been appointed. Privacy inquiries and statutory requests can be sent directly to the controller through the privacy contact.
Data, purposes and legal bases
- Website and security
- IP address, request metadata, device/browser data and security events to deliver and protect the service (Art. 6(1)(b) and (f) GDPR).
- Account and gameplay
- Email, authentication ID, handle, profile, settings, progression, inventory, game actions and receipts to perform the user contract (Art. 6(1)(b) GDPR).
- Public prologue
- The account-free prologue keeps its temporary choices only in the current page session. It does not create an account or persistent game save. Ordinary website delivery and security processing still applies.
- Age eligibility
- Country and date of birth are used before account creation to apply the account-age and parental-permission rules. For players below the independent account-consent age, a parent email, consent record, parent declaration, name and Stripe verification references are processed before RACKET accepts an account (Art. 6(1)(a), (b), (c) and (f) GDPR). The parent email is initially used only to deliver and administer that request.
- Community safety
- Posts, messages, relationships, reports, blocks, moderation evidence and sanctions to provide community functions and protect users (Art. 6(1)(b) and (f) GDPR).
- Purchases
- Product, gross and net price, currency, Stripe references, declared residence, billing and tax country, VAT amount, Neon grants and redemptions, entitlement, wallet restriction, subscription, refund and dispute status, plus legal-consent records. For a 13–17 player, the adult payer's name, email and declaration are also recorded for each Neon top-up. No reusable RACKET Stripe customer payment profile is created for that checkout (Art. 6(1)(b) and (c) GDPR).
- Optional analytics
- A consent event and coarse page-category events are processed only after active consent (Art. 6(1)(a) GDPR and § 25 TDDDG). Anonymous visitors and signed-in adults use separate event labels. Signed-in accounts are eligible only after adult status is confirmed. Consent can be withdrawn at any time.
Legitimate interests
Where processing relies on Art. 6(1)(f) GDPR, RACKET's legitimate interests are reliable service delivery, prevention and investigation of fraud and abuse, account and network security, enforcement and defence of legal claims, community safety, and improvement of service stability. These interests are balanced against the nature of the data, the user's reasonable expectations, the effect of processing and available safeguards. You may object on grounds relating to your particular situation.
Recipients and service providers
Clerk provides authentication; Convex hosts the authoritative game database and functions in the selected EU region; Cloudflare provides delivery, DNS and edge security; Stripe processes payments and may verify parental responsibility through a refundable card transaction and calculate tax when that product is configured; Resend delivers transactional account, authentication, parental-permission and legal request receipt emails; PostHog may provide consent-based analytics in its EU region. Providers receive only the data needed for their task and are bound by applicable data-processing terms. Payment credentials are entered at Stripe and are not stored by RACKET.
International transfers
Providers may use group companies or subprocessors outside the EEA. Where no adequacy decision applies, transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses and additional security measures. Copies or further information can be requested at privacy@playracket.app.
Visibility and social features
Handles, selected profile information, crew membership, public Wire posts and public rankings can be visible to other users. Direct messages are visible to their participants and may be accessed by authorized moderation personnel when reported or required for safety. Do not place real names, contact details or sensitive information in public or social fields.
Children and age controls
The public prologue is available without an account or parental permission. It has no cloud save, social features, rankings or purchases. The complete game requires an account. A player in the European Union under 18 must obtain verified permission from a parent or legal guardian before a Clerk account, player email, handle, social content or analytics profile is created. Outside the European Union the product minimum is 13, subject to stricter local law.
For the pre-account request RACKET records country, date of birth, the parent email and two random access-token hashes. The parent receives a direct notice and declares parental responsibility and consent. Stripe then makes a €0.50 card transaction with additional card authentication where available; the transaction is automatically refunded after signed provider confirmation. RACKET stores the consent text versions, purposes, country, time, method, parent name and provider references as evidence. If verification is not completed, the request expires and the parent email, name and access tokens are removed after 7 days.
While parental permission is required under the applicable product rule, the secure parent link provides a limited account summary and lets the parent withdraw permission, immediately restrict the account, or request deletion or anonymisation. Once the player reaches the independent registration age, withdrawing the historical permission no longer restricts the account. A request can also be sent to privacy@playracket.app. Real-money products are available from age 13; users under 18 need an adult payer and contracting party and can access only expressly allowed one-time cosmetics in approved countries. Subscriptions and saved payment methods are disabled. Optional analytics and session replay remain off for known minors. Payment review is available through the payment request form.
Retention
- Account and gameplay data: while the account is active; deletion or anonymization begins when account deletion is completed.
- Operational backups: overwritten on a rolling basis, normally within 30 days.
- Security and request logs: normally 90 days, longer only for an active incident or legal claim.
- Moderation records: normally 12 months after closure; serious safety or repeat-abuse evidence up to three years where necessary.
- Consent and contract records: for the limitation period needed to demonstrate compliance.
- Invoices, payment and tax records: for the applicable statutory German retention period.
- Legal requests: normally three years after final resolution.
Your rights
Subject to legal conditions, you have rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent. The profile contains data export and account deletion tools. Requests can be sent to privacy@playracket.app. You may also lodge a complaint with the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, poststelle@ldi.nrw.de, or another competent supervisory authority.
Storage, cookies and analytics choices
Strictly necessary authentication, security and preference storage is used to provide the service. The account-free prologue creates no persistent game save. On eligible public routes, PostHog analytics remains off unless the user actively consents; it is disabled for known minors. RACKET sends allowlisted consent and coarse page-category events plus the versioned player-experience-event-v1 session, navigation, activity, reward-choice, and result-presentation vocabulary. Product events use categorical activity/version/state fields and may include opaque activity/result receipt identifiers to verify that displayed values match settlement. Server-owned reward and progression events cannot be emitted by the client. Dynamic profile names, raw URLs, email addresses, dates of birth, messages, search text, exact balances, private strategy, and other free-text fields are not sent.
Autocapture, session replay, heatmaps, automatic exception and performance capture, surveys, person profiles and advertising tracking are disabled. Text and element attributes are masked as an additional safeguard. Browser Do Not Track and Global Privacy Control signals disable optional analytics. Known minors and signed-in accounts without confirmed adult eligibility are excluded. A withdrawal stops future collection and removes local PostHog identifiers without affecting earlier lawful processing. The documented operational target is a maximum analytics retention period of 90 days.
Automated game outcomes and security
Server-authoritative game rules and randomness determine fictional outcomes only; they do not produce legal or similarly significant real-world decisions. RACKET uses access controls, transport encryption, rate limits, idempotency, audit records and provider security controls. Security reports should be sent to security@playracket.app.
Changes
Material changes will be announced in the service. Where a new purpose requires consent, processing will not begin until that consent is obtained. The version and update date appear at the top of this notice.
Required information, sources and consequences
Account identifiers, eligibility information and the data marked as required during registration are necessary to create and perform an online account contract; without them, RACKET cannot create that account. Contract and payment details marked as required are necessary to conclude or administer the selected purchase; without them, the purchase or request cannot be processed. Optional profile fields, analytics consent and explanatory text marked optional may be omitted without losing the core service.
Personal data normally comes from you, your device and your use of the service. It can also come from an adult payer or guardian, payment and authentication providers, other players who report or interact with content, and security signals generated by service providers. If data about you is obtained from another source and Art. 14 GDPR requires a separate notice, RACKET will provide it within the statutory period.