Privacy policy
This policy explains what personal data we process on PLAYforMONEY, for what purpose, how long we keep it, who we share it with and what your rights are. It also describes cookies. Capitalised terms (e.g. Account, Offer, Session, Reward) have the same meaning as in the Terms of service.
Effective from: [DO UZUPEŁNIENIA: data wejścia w życie]
1. Controller
The controller of your data is [DO UZUPEŁNIENIA: nazwa firmy / imię i nazwisko], [DO UZUPEŁNIENIA: adres], tax ID (NIP): [DO UZUPEŁNIENIA: NIP] (we). For personal data matters, write via the “Contact” form (the “Account” category) or to kontaktatos@gmail.com. We have not appointed a data protection officer.
2. What data we process and where it comes from
Signing in with Steam
Steam (Valve) gives us your SteamID64 – we never learn your password. From the Steam Web API we fetch: nickname, avatar, profile address, the Steam account creation date, profile visibility and the number and age of bans (VAC, game, community, trade). During an open Session we check with Steam every few minutes which server you are playing on – Steam only reports this when your profile shows game details.
Minecraft account
When you join our account-linking server, Mojang confirms your nickname and UUID. We store only a hash of the one-time code. The connection's IP address is used on the fly for the attempt limit – we do not store it.
Data you provide yourself
Nicknames for games where an account cannot be confirmed, the content of Tickets, the e-mail address in a Ticket (required when not signed in, optional when signed in), any referral or promo code you enter, notification settings and language.
Data from using the Service
Accepted Offers and Sessions (server, time, presence reads, in-game score, the nickname and account ID used in the Session, the verification result), coins and transaction history, levels, achievements, bonuses, referrals (who referred whom), promo codes used, orders (Rewards, statuses, the moment a code was first revealed), notifications, the event log (e.g. sign-ins, accepting an Offer, orders, changes to linked accounts), blocks in partner servers' Offers (with the reason given by the server team) and – in Tickets and abuse cases – staff notes and flags.
Technical and security data
- a hash of the random device identifier from the
p4m_devcookie and a hash of the IP address – recorded at sign-in, when accepting an Offer and when placing an order, - a hash of the IP address with a Ticket (Ticket limit),
- browser information (User-Agent) with the sign-in session,
- the IP address processed on the fly for attempt limits – not stored in the database.
A hash (HMAC) is a one-way transformation with a secret key. We store neither the IP address nor the device identifier itself, but a hash is still personal data (pseudonymisation).
Players on partner servers – including those without an Account
Partner servers publish their player lists. With each read we store only a hash (HMAC) of the nickname – different for each server – and the time it was first and last seen. We do not store the nicknames themselves. We use the hashes for the “new players only” rule, to protect against taking over other people's nicknames and for players' return statistics for servers. We cannot tell who you are from a hash (Article 11 GDPR) – if you want to exercise your rights, give us the nickname and the server.
Partners (server owners)
Account data of server team members, roles and invitations, server and profile data, campaigns, player blocks set by the team (who and why), budget top-ups (amount, date, confirmation number, the person who requested it), correspondence about payments and data for sales documents: [DO UZUPEŁNIENIA: zakres danych do faktur].
Service staff
For staff members additionally: their role, the encrypted two-step verification key and hashes of backup codes.
3. Purposes and legal bases
- Account and Service features – sign-in, Offers, verifying and estimating play time, crediting coins and bonuses, the Shop and order fulfilment, notifications, data export: performance of a contract (Article 6(1)(b) GDPR).
- Tickets and complaints – performance of a contract (Article 6(1)(b)), the obligation to answer consumer complaints (Article 6(1)(c)) and, for messages from guests and other matters, our legitimate interest in answering correspondence (Article 6(1)(f)).
- Fraud prevention – device and IP traces, Steam account checks, flagging accounts, manual review of exchanges and referrals, nickname hashes from player lists: our legitimate interest in fair settlements with players and servers and in protecting the rewards programme (Article 6(1)(f)).
- Security of the Service – sign-in sessions, attempt limits, the event log, backups, staff two-step verification: legitimate interest (Article 6(1)(f)).
- Rankings and contests – publicly showing your nickname, avatar and hours played: legitimate interest in running community rankings (Article 6(1)(f)).
- Player list in the server panel – showing a server team who accepted its Offers, how long they played and what it cost, and blocks in that server's Offers: legitimate interest of Partners and ours in transparent settlements and preventing abuse (Article 6(1)(f)).
- Settlements with Partners, accounting and taxes – the contract with the Partner (Article 6(1)(b)) and legal obligations under accounting and tax law (Article 6(1)(c)).
- Reports of illegal content (DSA) – legal obligation (Article 6(1)(c)).
- Establishing, pursuing and defending claims – legitimate interest (Article 6(1)(f)).
We do not send advertising or newsletters, we do not use analytics or advertising tools and we do not sell data. Providing data is voluntary, but without a Steam or Minecraft account you cannot create an Account, and without an e-mail address we cannot reply to a guest's Ticket.
4. Profiling and automated decisions
- Play time and coins are credited automatically under the rules in the Terms of service and on the “How it works” page (e.g. rejecting a Session if you were on the server before accepting the Offer, skipping AFK stretches, daily limits). This is necessary for performing the contract (Article 22(2)(a) GDPR). You can challenge the result in a complaint – a person will review it.
- Our safeguards assess risk: Steam account age, bans, a private profile, a device shared with another Account, a device or network shared by the referrer and the referred player. The only effect of such an assessment is sending an exchange for manual review or withholding a referral bonus until clarified. Decisions to reject an order, reverse coins or block an Account are made by a person.
5. Who we share data with
- Hosting – Hostinger International Ltd. (Cyprus): the VPS on which the Service and its database run. It processes data on our behalf (data processing agreement). Server location: [DO UZUPEŁNIENIA: lokalizacja centrum danych VPS].
- Valve Corporation (USA) – an independent controller of Steam data. At sign-in we redirect you to Steam's page, and in Steam Web API requests we send your SteamID64.
- Mojang AB (Sweden, Microsoft group) – an independent controller of Minecraft accounts. When you link an account, our server asks Mojang to confirm the sign-in (it sends the nickname).
- E-mail provider we use to reply to guests' Tickets: [DO UZUPEŁNIENIA: dostawca skrzynki e-mail].
- Off-server backup storage (if enabled; the backup is encrypted): [DO UZUPEŁNIENIA: dostawca albo usuń ten punkt].
- Accounting firm – Partner settlement data: [DO UZUPEŁNIENIA: nazwa albo usuń ten punkt].
- Public authorities – where required by law.
- Partners (the team of a server whose Offers you accept) – as separate controllers they see in the server panel: your nickname and avatar on the Service, your in-game nickname from the last Session, the number of Sessions, credited time, cost and how Sessions ended (for the last 30 days). They can block you from their server's Offers and report abuse to us. They do not see your SteamID, UUID, IP address or device traces.
- Other users – your nickname, avatar and hours played in public rankings and contests. Members of a server team see each other's nicknames and avatars.
6. Transfers outside the EEA
Valve Corporation operates in the USA. Valve states that it participates in the EU-U.S. Data Privacy Framework, so the transfer relies on the European Commission's adequacy decision (Implementing Decision (EU) 2023/1795 of 10 July 2023). Valve's current status can be checked at https://www.dataprivacyframework.gov. We process all other data in the European Economic Area [DO UZUPEŁNIENIA: potwierdź lokalizację VPS i dostawców z punktu 5].
7. How long we keep data
- Account and related data – until the Account is deleted.
- When the Account is deleted we immediately delete: the Account's nickname, avatar and referral code, linked Steam and Minecraft accounts, game nicknames, sign-in sessions, device traces, Steam account check results, notifications, server team memberships, two-step verification data and e-mail addresses in Tickets. The nickname in the Session history is replaced with “Deleted account”.
- Settlement records – the coin ledger, orders, Session history (server, time, reads – without the nickname and game account ID, which we remove together with the Account), Ticket content and the event log – remain after the Account is deleted, linked to the anonymised Account, until the limitation periods for claims expire (generally 3 or 6 years, counted to the end of the calendar year – Article 118 of the Polish Civil Code).
- Hash of a deleted Steam or Minecraft account – as long as we grant welcome and referral bonuses (so they are not granted twice).
- Device and IP traces (hashes) – 180 days from last use.
- Sign-in sessions – until you sign out or after 30 days of inactivity.
- Nickname hashes from server player lists – 180 days from when last seen.
- Notifications – the latest 200 per Account; older ones are deleted automatically.
- Blocks in a server's Offers – until the server team lifts them or the server is removed from the Service.
- Guest Tickets – until the limitation periods for claims expire, as above.
- Partner settlement documents – 5 years from the start of the year following the financial year (Polish Accounting Act), or longer if tax law requires.
- Backups – 14 days on the server; the off-server copy (if enabled) – up to 60 days, encrypted.
- Technical server logs – [DO UZUPEŁNIENIA: okres przechowywania logów systemowych].
8. Your rights
- access and a copy – “Profile → Account and privacy → Download my data (JSON)” or via contact,
- data portability – the same JSON file,
- rectification – change your nickname and avatar on Steam (we update them at your next sign-in), game nicknames in your profile, anything else via contact,
- erasure – “Profile → Account and privacy → Delete account” or via contact,
- restriction of processing,
- objection to processing based on legitimate interest (e.g. to being shown in rankings) – on grounds relating to your particular situation,
- complaint to the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, Poland, https://uodo.gov.pl).
We reply without undue delay, within one month at the latest. We may ask you to confirm that the Account is yours (e.g. by a message sent from the signed-in Account).
9. Cookies and browser storage
We use only files that are necessary for the Service to work and for the services you request. We do not use analytics, advertising or tracking cookies, and we do not embed third-party content that could set its own cookies – fonts, scripts and images (including Steam avatars) are loaded from our domain. That is why we do not ask for consent: under Article 399(3) of the Polish Electronic Communications Law, consent is not needed when storing information is necessary to provide a service you request.
Cookies (over HTTPS, the names p4m_session, p4m_login and p4m_ref have the __Host- prefix):
p4m_session– the sign-in session (a random token; we store only its hash). The cookie lives up to 180 days, but the session expires when you sign out or after 30 days of inactivity.p4m_login– protects sign-in with Steam (a one-time state); 10 minutes, deleted after sign-in.p4m_dev– a random device identifier that protects against multiple accounts and abuse of the rewards programme (only its hash is stored); set at sign-in, valid for one year.p4m_ref– the code from a referral link; set only when you open a referral link, valid for 30 days or until you sign in.p4m_ann_hidden– the numbers of closed announcements, so they are not shown again; one year.p4m_demo_hidden– only in the demo version: the closed “DEMO” bar; until you close the browser.
Browser storage (localStorage and sessionStorage) – this data stays on your device:
p4m.cart.v1– the contents of your Shop cart (Reward numbers and quantities),p4m:dismissed-announcements– closed announcements (a copy of thep4m_ann_hiddencookie),p4m:demo-banner-hidden– the closed “DEMO” bar (until you close the tab).
You can delete or block cookies and browser storage in your browser settings. Without the p4m_session and p4m_login cookies you cannot sign in. Sign-in takes place on Steam's page, and links to servers' websites and Discords lead outside the Service – their owners' rules apply there.
10. Security
Connections to the Service are encrypted (HTTPS). In the database we keep hashes instead of session tokens, IP addresses and nicknames from server lists, and Reward codes are encrypted. Staff sign in with two-step verification and can access data only to the extent needed for their work. Backups are made daily.
11. Changes to this policy
We update this policy when the Service or the law changes. We announce significant changes on the Service.