guandan.online

Privacy Policy

How Guandan Online processes account data, authentication data, gameplay data, guest sessions, tokens, and security records.

Effective June 4, 2026

Controller

The controller responsible for personal data on guandan.online is Oscar Lin, Dublinstraße 25, 81829 München, Deutschland. Contact: contact@guandan.online.

Data We Process

Account data: email address, username, password hash, avatar, account timestamps, email-verification status, terms-acceptance status, and account settings.

Authentication and security data: refresh sessions, token metadata, user agent, IP address where stored by the server, verification codes or hashes, reset codes, and abuse-prevention records.

Game data: lobbies, seats, bot seats, match state, moves, passes, round results, game events, leaderboard-relevant data, guest-session timestamps, and technical logs needed to run and debug games.

Purposes and Legal Bases

The service processes account and game data to create accounts, authenticate users, run lobbies and matches, maintain game history, provide support, and protect the service.

For EU users, the legal bases include performance of a contract for account and gameplay features, legitimate interests for security and service integrity, and legal obligations where applicable.

Cookies, Tokens, and Local Storage

The app uses authentication tokens and local storage so users can stay signed in and resume sessions. These are necessary for account login and gameplay.

The service does not currently use advertising cookies, analytics cookies, or non-essential tracking cookies.

Processors and Infrastructure Providers

Hosting is provided through a netcup VPS. Email delivery is provided through Resend. DNS is provided through Cloudflare. Source-code hosting and deployment workflow use GitHub.

The service currently does not use analytics providers, error-tracking providers, advertising networks, or payment providers.

International Transfers

Some infrastructure or service providers may process data outside the European Economic Area. Where required, transfers are handled through the provider's applicable data-protection terms, adequacy decisions, or standard contractual clauses.

Retention

Guest sessions are temporary and may expire after inactivity. Permanent account data is generally kept while the account exists.

Game records, security logs, and verification records may be kept as long as needed to operate the service, prevent abuse, resolve disputes, comply with law, and maintain game or leaderboard integrity.

Your Rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data.

EU users may also lodge a complaint with a competent data-protection authority. Contact contact@guandan.online to exercise data rights.

No Sale of Personal Data

The service does not sell personal data.