Your group tipping game
Privacy Policy
Privacy Policy
Last updated 05.06.2026Controller
MICHAEL GREWELDING
Michael-Erhard-Str. 66
77855 Achern
Deutschland
Email: michael@grewelding.com
Overview
This privacy policy explains which personal data is processed when operating the tipping game, for which purposes this happens and which rights data subjects have.
Hosting and server log files
When the website is accessed, technically required access data such as IP address, date and time, requested URL, referrer, browser, operating system and status codes are processed. Processing serves security, troubleshooting and stable operation based on legitimate interests.
Registration, login and profile
For user accounts we process email address, password hash, display name, first name, last name, mobile phone, language, appearance settings, profile photo and optional security features such as 2FA status. This data is needed for account creation, login, profile management and game security.
Tip groups, tips and payments
In tip groups we process memberships, roles, invitations, submitted tips, point values, activities and, for paid groups, payment status, amount and due date. This is required to provide groups, rankings and admin functions.
Security and activity logs
Logins, failed logins, admin actions, group activities, technical errors and security events are logged for abuse prevention, traceability, troubleshooting and operational security.
Cookies and local storage
The application uses technically required session cookies such as tipspiel_session. Settings such as dark mode, color scheme or local UI state may be stored in the browser. Tracking or marketing cookies are not used unless separately enabled.
Sports data and external APIs
Sports, team, fixture and result data may be retrieved through administered sports data APIs. User data is not intentionally transmitted to sports data providers.
Legal bases
- Performance of contract and pre-contractual measures for account, groups, tips and rankings.
- Consent for optional features such as reminders, 2FA activation or voluntary profile data where required.
- Legitimate interests for security, abuse prevention, troubleshooting, log files and stable service delivery.
- Legal obligations where statutory retention, documentation or information duties apply.
Retention
Data is stored only as long as required for the stated purposes. Deleted profiles are marked as deleted and blocked for active use; statutory retention and documentation duties remain unaffected.
Recipients and processors
Only authorized administrators, technical service providers and processors receive access where required for operation, support, security or legal obligations.
Data subject rights
- Access to processed personal data.
- Rectification of incorrect or incomplete data.
- Erasure of personal data unless retention duties apply.
- Restriction of processing.
- Data portability in a structured format.
- Objection to processing based on legitimate interests.
- Withdrawal of consent with effect for the future.
- Complaint with a competent data protection supervisory authority.
Security
The application uses technical and organizational measures such as secure session cookies, CSRF protection, password hashes, rate limits, role permissions, security headers and optional two-factor authentication.