1. Privacy at a Glance
We take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations, specifically the European Union General Data Protection Regulation (GDPR / DSGVO) and the German Telecommunications-Telemedia Data Protection Act (TDDDG).
This Privacy Policy informs you about the nature, scope, and purpose of personal data processed when visiting our website at cat-chess.com.
2. Data Controller
The data controller responsible for data processing on this website is:
MyQuests Online Marketing
Owner: Olivier Jacob
Holsteiner Chaussee 193
22457 Hamburg
Germany
Email: info@myquests.org
Phone / WhatsApp: +49 (0)176 2481 8231
3. Legal Bases for Processing & Statutory Information Duties (Articles 6, 13, and 14 GDPR)
Under Article 6, Article 13, and Article 14 of the European General Data Protection Regulation (GDPR), we process personal data only when a valid statutory legal basis exists and fulfill all mandatory information obligations upon data collection:
- Consent (Article 6(1)(a) GDPR): When you voluntarily submit your email address to join our mobile app waitlist.
- Contract Performance (Article 6(1)(b) GDPR): For digital transactions, shop orders, and delivery of optional in-game cosmetics.
- Legal Obligations (Article 6(1)(c) GDPR): For compliance with tax and accounting retention requirements (§ 147 AO, § 257 HGB).
- Legitimate Interests (Article 6(1)(f) GDPR): For collecting server log files necessary to ensure cybersecurity, server stability, fraud prevention, and fault-free delivery of our static web content.
4. Data Collection & Technical Hosting
Server Log Files
When accessing our website, the web server automatically records diagnostic data transmitted by your web browser in server log files (logfiles). These include:
- Browser type and version
- Operating system used
- Referrer URL (the previous webpage you visited)
- Hostname of the accessing device / truncated anonymized IP address
- Date and time of the server request
- HTTP status code and byte size of transferred assets
This data is not combined with other data sources. The legal basis for processing is Article 6(1)(f) GDPR. Our legitimate interest lies in the technically error-free presentation, security optimization, and DDoS defense of our platform.
Zero-Tracking & 100% Cookie-Free Architecture
We operate on a strict privacy-first principle with zero cookies and zero third-party tracking:
- 0 Cookies Set: We do not store persistent tracking cookies, session cookies, or marketing cookies on your device.
- No Third-Party Analytics: We do not embed Google Analytics, Google Tag Manager, Meta Pixel, or any behavioral tracking scripts.
- No Ad Beacons or Trackers: We do not serve third-party advertisements, tracking pixels, or sell user data to data brokers.
Because we do not use invasive tracking technologies or non-essential cookies, no intrusive cookie banner is required to browse our website.
Self-Hosted Typography (Zero Google Fonts CDN)
To ensure fast loading times and complete privacy, all typography (Inter font family) is self-hosted locally on our own static web server. When loading our pages, your browser establishes zero network connections to Google Fonts servers, guaranteeing that your IP address is never transmitted to Alphabet Inc. / Google LLC.
Mobile App Waitlist & Email Registration
If you choose to sign up for our mobile app waitlist (for upcoming iOS and Android releases), we collect your email address and platform choice.
This data is collected strictly based on your explicit consent under Art. 6(1)(a) GDPR and is used solely to notify you when the mobile apps become available. We never sell, share, or spam your inbox. You may withdraw your consent and request deletion of your email at any time by contacting privacy@cat-chess.com.
5. Your Rights as a Data Subject (Art. 15–21 & Art. 7(3) GDPR)
As an individual located in the European Union / European Economic Area, you have comprehensive statutory rights under Chapter III of the GDPR:
- Right of Access (Art. 15 GDPR): You have the right to obtain confirmation as to whether personal data concerning you is being processed and receive a copy of that data.
- Right to Rectification (Art. 16 GDPR): You have the right to request the prompt correction of inaccurate personal data.
- Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR): You have the right to request the deletion of your personal data stored by us.
- Right to Restriction of Processing (Art. 18 GDPR): You have the right to request restriction of processing where specific statutory conditions are met.
- Right to Data Portability (Art. 20 GDPR): You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
- Right to Object (Art. 21 GDPR): You have the right to object at any time to the processing of your personal data based on Art. 6(1)(f) GDPR.
- Right to Withdraw Consent (Art. 7(3) GDPR): You have the right to withdraw your consent at any time with future effect.
6. Right to Lodge a Complaint with a Supervisory Authority (Art. 77 GDPR)
Pursuant to Art. 77 GDPR, you have the right to lodge a complaint with a competent data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR. You may contact the supervisory authority in your habitual residence, place of work, or place of the alleged infringement.
7. Data Security & SSL/TLS Encryption
Our website employs modern SSL/TLS encryption (Transport Layer Security) across all connections to safeguard the transmission of sensitive information against unauthorized interception. You can verify the active encrypted connection by the "https://" prefix and lock icon in your browser address bar.
8. Payment Processing & In-App Purchases (Stripe)
For optional digital content purchases, cosmetic items, Shard packs, and Battle Passes, we use the payment service provider Stripe. The operating entity for users in the European Economic Area (EEA) is Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland (parent company: Stripe, Inc., 354 Oyster Point Blvd, South San Francisco, CA 94080, USA).
During checkout, required transaction details (e.g. email address, billing address, transaction amount, currency, IP address, and encrypted payment method tokens) are transmitted via a secure TLS connection to Stripe. Processing is conducted under the following legal bases:
- Contract Performance (Art. 6(1)(b) GDPR): To process payments and deliver purchased digital content to your account.
- Legal Obligation (Art. 6(1)(c) GDPR): To comply with statutory tax, commercial, and accounting retention laws (§ 147 German Tax Code / AO, § 257 German Commercial Code / HGB).
- Legitimate Interests (Art. 6(1)(f) GDPR): For fraud detection, risk prevention, and payment verification (Stripe Radar, 3D Secure / PSD2).
Transfers of personal data to Stripe, Inc. in the United States are safeguarded under the European Commission's EU-US Data Privacy Framework (DPF) and Standard Contractual Clauses (SCCs). Fiscal transaction records are retained for up to 10 years in compliance with statutory retention requirements. For further details, please review Stripe's Privacy Policy: https://stripe.com/privacy.
9. External Links
Our website contains links to external web properties, including our live web game at https://play.cat-chess.com/. We are not responsible for the privacy practices or content of third-party platforms.
10. Contact & Inquiries
For any questions regarding this Privacy Policy, your personal data, or exercising your GDPR rights, please contact our privacy coordinator:
Cat Chess Privacy Contact (MyQuests Online Marketing):
Email: info@myquests.org
Address: MyQuests Online Marketing, Holsteiner Chaussee 193, 22457 Hamburg, Germany