Privacy Policy
Last updated: February 22, 2026
1. Data Controller
Mystery Shaper
Waidmansdorfer Straße 16/3
9020 Klagenfurt, Austria
Email: office@mysteryshaper.com
2. Data We Collect
Account Data
When you register, we collect your name and email address. When signing in with Google, we receive your name and email address from Google.
Payment Data
Payment data (credit card number, billing address) is processed exclusively by our payment provider Paddle. We do not have access to your full payment details.
Usage Data
We collect anonymized usage data to improve our Service, including pages visited, features used, and device information.
Game Configurations
When you create a game, we store your chosen settings (location, time period, player count, etc.) for game generation and your later access.
3. Purpose of Processing
- Providing and operating the Service
- Processing purchases and delivering game materials
- Sending notification emails (game completion, password reset)
- Improving our Service through usage analysis
4. Legal Basis
We process your data based on:
- Contract performance (Art. 6(1)(b) GDPR): Account data, game configurations, transaction data
- Legitimate interest (Art. 6(1)(f) GDPR): Usage analysis for service improvement
5. Third-Party Processors
We use the following third-party services to operate our Service:
- Paddle (paddle.com) — Payment processing (Merchant of Record)
- Supabase (supabase.com) — Hosting, authentication, and file storage
- Vercel (vercel.com) — Frontend hosting
- Google Cloud (cloud.google.com) — Backend hosting and AI processing
- PostHog (posthog.com) — Product analytics
- Resend (resend.com) — Transactional emails
All processors are subject to appropriate data processing agreements.
6. Cookies and Tracking
We use:
- Essential cookies: Authentication session cookies for login
- Analytics cookies: PostHog for anonymized usage analytics
We do not use advertising cookies or third-party ad trackers.
7. Data Retention
Your account data is stored as long as your account is active. Game materials remain available in your account. You may request deletion of your account and all associated data at any time.
8. Data Transfers
Some of our processors are located outside the EU/EEA. Data transfers are based on Standard Contractual Clauses (SCCs) or equivalent safeguards under the GDPR.
9. Your Rights (GDPR)
You have the following rights regarding your personal data:
- Right of access — Request information about your stored data
- Right to rectification — Correct inaccurate data
- Right to erasure — Request deletion of your data
- Right to data portability — Export your data
- Right to object — Object to certain processing activities
- Right to restriction — Restrict how your data is processed
To exercise your rights, contact us at office@mysteryshaper.com. You also have the right to lodge a complaint with the Austrian Data Protection Authority (dsb.gv.at).
10. Children
Our Service is not directed at persons under 16 years of age. We do not knowingly collect data from children under 16.
11. Changes
We may update this Privacy Policy at any time. We will notify you of material changes by email or by notice on the website.
12. Contact
For privacy-related questions, contact us at:
Email: office@mysteryshaper.com