Privacy Policy

Effective Date: September 30, 2026 • Version 1.3
← Return to Game

1. Introduction & Overview

HexSettlers ("we", "our", "the Game") is committed to protecting the privacy of our players. This Privacy Policy details the types of data we process, why we collect it, how we safeguard it, and the control you have over your personal data under the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA).

Privacy-by-Design: We follow strict data minimization principles. We do not sell your personal data, we do not operate advertising trackers, and we do not profile players for marketing purposes.

2. Information We Collect

We only collect the minimum information required to operate real-time multiplayer games, manage player accounts, support the optional social features, and maintain fair play:

  • Account Information (Registered Players): When you create an account, we store your email address, display name, and avatar preference via Supabase Auth. Passwords are never stored in plain text and are protected using industry-standard one-way cryptographic hashing (bcrypt). Guest players can enjoy the game without supplying an email.
  • Gameplay & Match Analytics: To calculate rankings, personal match history, and leaderboards, we store completed match data, including room code, game mode, turn records, victory points, dice production distribution, and Elo rating changes.
  • Social & Friends Data (Registered Players): If you use the in-game friends system, we store the relationships you create — the internal profile identifiers of the two players involved, the friendship status (pending, accepted, or blocked), and timestamps. Friend requests you send or receive, your friends list, and your blocked-players list are all derived from this single relationship record. Game invites you send share the room code, room name, and player count with the invited friend in real time; invite payloads are not stored permanently.
  • Live Presence (Online Status): While you are connected, your online/offline status is shared only with players on your accepted friends list. Presence is held in volatile server memory and is discarded the moment you disconnect; we do not retain a presence history.
  • Recent Opponents & Player Search: "Recent opponents" is computed on demand from your own match history (capped and never persisted as a separate list). Signed-in players may search other players by display name (minimum 3 characters, rate-limited) in order to send a friend request.
  • Security & Anti-Bot Telemetry (Cloudflare Turnstile): To protect authentication endpoints from credential stuffing and automated bot abuse, we utilize Cloudflare Turnstile. Turnstile runs privacy-preserving challenges in the browser without collecting cross-site behavioral cookies or biometrics.
  • Fair Play Device Fingerprinting: In Ranked matchmaking, the client computes an anonymized SHA-256 hash of general hardware and rendering characteristics (canvas rasterization, WebGL vendor/renderer strings, audio sample rate, screen dimensions, hardware concurrency, platform, and time zone) strictly to deter multi-tab win-trading and multi-accounting. The raw characteristics are never transmitted or stored — only the derived hash.
  • Temporary Connection Logs: IP addresses and network connection headers are processed in volatile memory and short-term buffers (rolling 48-hour retention) strictly for DDoS mitigation, rate limiting, and WebSocket connection stability.

3. Lawful Bases for Processing (GDPR Art. 6)

We process your data under the following legal bases:

  • Contractual Necessity (Art. 6(1)(b)): Delivering real-time multiplayer synchronization, matchmaking, account login, live presence, and the friends, invites, and blocking features you choose to use.
  • Legitimate Interests (Art. 6(1)(f)): Protecting server infrastructure against DDoS and spam, preventing cheat/bot exploits via Turnstile, preventing harassment through player blocking, maintaining competitive leaderboard integrity, and troubleshooting engine crashes.
  • Consent (Art. 6(1)(a)): Storing optional preferences (such as audio settings and your cookie consent selection).

4. Cookies & Local Storage

We strictly avoid third-party marketing cookies and trackers. We use local browser storage and first-party cookies only for essential game functionality:

  • Reconnection Tokens: catan_reconnect_token and catan_reconnect_room allow your browser to seamlessly restore your player seat if your network drops or tab refreshes during an active game.
  • Client Preferences: Audio settings (volume level and mute status) and your cookie consent choice are stored locally on your device under keys such as catan_cookie_consent. The consent banner offers "Essential Only" or "Accept All"; declining optional analytics has no effect on gameplay, and we do not load any advertising or behavioral analytics scripts in either case.
  • Zero Third-Party Advertising: We do not host ad networks, behavioral analytics SDKs, or social media tracking pixels.

5. Third-Party Service Providers

We utilize trusted infrastructure partners to host and secure HexSettlers:

  • Supabase: For managed authentication (JWTs) and PostgreSQL database storage, including your profile, match history, and the friendships/block relationships described above. Data is hosted in secure data centers.
  • Google OAuth (Google LLC): When you choose to sign in using Google, we access only your basic profile information (display name, email address, and profile photo) solely for authenticating your identity, displaying your in-game avatar, and managing your account. HexSettlers' use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We never sell, transfer, or use your Google profile data for advertising, marketing, or profiling.
  • Cloudflare & Cloudflare Turnstile: For DNS, SSL/TLS encryption, edge DDoS protection, and privacy-preserving bot detection on account registration and password recovery forms.
  • Sentry: For application error monitoring and stability diagnostics. All event payloads undergo automated client- and server-side data scrubbing to redact credentials, tokens, and personal email addresses before transmission.
  • Resend: For delivering transactional emails, such as password reset links and magic link authentication messages.

6. Social Features, Visibility & Blocking

HexSettlers includes optional social features that are only active for signed-in accounts:

  • Who can see what: Your display name, avatar, and online status are visible only to players you have accepted as friends, and to players who search for your display name while signed in. Guest players have no social profile and cannot send or receive friend requests.
  • Friend requests: You can send, accept, decline, or cancel requests at any time. Sending a request reveals your display name and avatar to the recipient so they can decide.
  • Game invites: Invites are only delivered to accepted friends and only when you are hosting a lobby that has not yet started. A friend who is blocked can never be invited.
  • Blocking: Blocking another player prevents them from sending you friend requests or game invites and hides the friendship relationship. A block is one-directional and the blocked player cannot remove it; only you can unblock, from your profile.
  • Rate limits: Friend requests, player searches, and game invites are rate-limited per account to prevent spam and scraping of player data.

7. Data Retention & User Rights

Under GDPR and CCPA, you retain full ownership and control over your personal data:

  • Self-Service Account Deletion (Right to Erasure): You can permanently delete your account at any time directly in-game by going to Profile > Danger Zone > Delete Account. This immediately purges your email, profile credentials, and Elo rating from our database, and cascade-deletes your friendships and blocks, while detaching your identity from past match records.
  • Right to Access & Rectification: You can view your match history, friends list, and blocked-players list, and edit your display name or avatar anytime from your player profile.
  • Automated Rolling Log Purging: Transient network logs, IP connection buffers, and live presence state are discarded on disconnect, with network logs purged on a rolling 48-hour schedule.

8. Security Architecture & Disclosure

We employ modern security safeguards, including TLS 1.3 encryption in transit, strict Content Security Policy (CSP), anti-clickjacking frame protections, row-level security on player data tables, and rate-limited endpoints. For responsible security vulnerability disclosures, please review our RFC 9116 security declaration at /.well-known/security.txt.

9. Contact & Data Requests

For data privacy inquiries, GDPR rights requests, or bug and security reports, you can reach out directly via email to the maintainers:

  • Maintainers & Support: [email protected] / [email protected]
HexSettlers Multiplayer Strategy Game
Terms of Service • Security (RFC 9116) • Home