Privacy Policy

Information under Article 13 of the EU General Data Protection Regulation (GDPR). The operator is established in Germany.

1. Controller

UDL Intermedia Group
Gütersloher Strasse 5 - 33415 Verl GERMANY
Email: info@1-mio-euro.com

2. Website delivery and hosting

The site is hosted by ALL-INKL.COM – Neue Medien Münnich, owner René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. When the website is requested, technically necessary connection and log data may be processed, including IP address, time, requested resource, transferred data volume, status code, referrer and browser/user-agent information. This processing serves secure and stable website delivery and abuse prevention. The legal basis is Article 6(1)(f) GDPR. The retention of technical server logs depends on the logging and security configuration used for the hosting account and they are deleted when no longer required unless statutory retention duties apply.

3. First-party traffic statistics and Popular ranking

We use our own server-side statistics without an external analytics provider. The system records the requested path, referring domain, device type, pageview and server-side generation time. The analytics tables do not store the raw IP address. A shortened IP network prefix and user agent are transformed into a pseudonymous hash that rotates daily. A visit is counted at most once per 30-minute window. Detailed analytics data is automatically cleaned after no more than 14 days. Requests carrying Do Not Track or Global Privacy Control signals are not included.

For the public Popular Top 100, we also record share actions and clicks on a domino's optional external website link. These events use the same daily rotating pseudonymous visitor hash and are counted at most once per visitor, domino, event type and 30-minute window. The popularity score uses a rolling seven-day window. The underlying detailed engagement events are cleaned after no more than 14 days.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are measuring reach and technical functioning, detecting problems, and operating the project's public game rankings with basic abuse resistance. The statistics module sets no analytics cookie and does not use localStorage or similar browser storage.

Country personalization: If the hosting or edge server provides a two-letter ISO country code for the current request, the homepage may use it only for the current response to show a country-specific battle message and preselect the “Country / Team” field. No external GeoIP API is called by the browser or our PHP code for this feature. The detected country code is not persistently stored by the personalization module, and the user can change the selection at any time. The legal basis is Article 6(1)(f) GDPR (user-friendly, contextual presentation of the global country battle).

4. Essential session

An essential PHP session may be used for security functions such as CSRF protection of the checkout form. It is not used for advertising or audience tracking. Any browser-side storage is limited to what is technically necessary to provide the service explicitly requested by the user. The associated personal-data processing is based on Article 6(1)(b) GDPR and, for security purposes, Article 6(1)(f) GDPR.

5. Orders, public domino data and builder rankings

For a purchase we process the data necessary to fulfil the order, including order reference, quantity, country/team, nickname, message, optional website URL, language, payment status and technical Stripe references. The nickname, country, message and optional website URL are intentionally displayed publicly on the purchased domino. Do not submit information that you do not want published.

For the Global and Daily Builder rankings, multiple paid purchases by the same person must be counted together. The email address supplied by Stripe after a completed checkout is therefore normalized server-side and immediately transformed into a non-publicly reversible HMAC key. The email address itself is not stored in our builder-ranking table. Public ranking data consists only of nickname, selected country and the number of actually paid dominoes. The pseudonymous builder key may remain stored for the operating lifetime of the rankings so that all-time positions and a once-reached Global Top 100 status remain consistent.

The legal basis is Article 6(1)(b) GDPR for contract performance and delivery of the rankings that form part of the project, supplemented by Article 6(1)(f) GDPR for abuse prevention and consistent game state. Public domino content is generally kept visible for the operating lifetime of the project because the lasting public placement is part of the purchased service. Content may be hidden in cases such as refunds, rights violations, security risks or legal obligations. Payment and accounting information may be retained for statutory commercial and tax retention periods under Article 6(1)(c) GDPR.

6. Payments through Stripe and selected payment methods

Checkout is provided through Stripe. Depending on the chosen payment method, transaction data is processed by Stripe and, where applicable, the selected payment provider (for example PayPal). Full card data or online-banking credentials are not stored on our web server. For users in the EEA, Stripe entities involved may include Stripe Payments Europe, Limited, Stripe Technology Company, Limited and, for regulated payment services, Stripe Technology Europe, Limited, all in Ireland.

Processing for payment is based on Article 6(1)(b) GDPR and statutory documentation duties on Article 6(1)(c) GDPR. See the Stripe Privacy Policy for Stripe's own processing and international transfer safeguards.

7. Contact and reports

If you contact us by email or report a domino, we process the message and contact details to deal with the request. The legal basis is Article 6(1)(b) GDPR for contract-related matters and otherwise Article 6(1)(f) GDPR for communication, abuse prevention and protection of legal rights.

8. Recipients

Where necessary for the relevant purpose, recipients may include the hosting provider, Stripe and the selected payment provider, technical service providers, public authorities or legal advisers. This project does not disclose personal data to third parties for advertising purposes.

9. Your rights

Subject to the statutory requirements, you have rights including access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20) and objection to processing based on legitimate interests (Article 21). You also have the right to lodge a complaint with a competent data protection supervisory authority (Article 77).

10. Version

Version: September 2026. The policy will be updated if the services used or the data processing materially changes.