Privacy Policy
Last updated: 25 July 2026
This policy is incomplete and not yet legally valid.
The data controller, jurisdiction, and contact address have not been configured. Set NEXT_PUBLIC_LEGAL_ENTITY, NEXT_PUBLIC_LEGAL_JURISDICTION, and NEXT_PUBLIC_LEGAL_EMAIL before launch. These cannot be guessed — naming an entity that does not exist would be a false statement to users about who holds their data.
Who is responsible
The data controller for information collected through Coflplay is:
- Data controller
- [NOT CONFIGURED — set before launch]
- Jurisdiction
- [NOT CONFIGURED — set before launch]
- Contact
- [NOT CONFIGURED — set before launch]
We have not appointed a Data Protection Officer. We are not required to — we do not carry out large-scale systematic monitoring and we do not process special categories of data. Data protection questions go to the contact address above.
Minimum age
Coflplay is not for children under 13. We ask for a date of birth when you create an account and refuse the registration if it puts you under 13. That date is used once, to make that decision, and is never stored — we keep the answer, not the date.
If you believe a child under 13 has created an account, contact us and we will delete it and the data attached to it.
What we process, and why
Every purpose below is paired with the lawful basis we rely on for it. Where the basis is consent, you can withdraw it at any time and we stop.
| Purpose | Data | Lawful basis |
|---|---|---|
| Run your account and sign you in | Email, display name, password hash, session cookie | Performance of a contract (Art. 6(1)(b)) |
| Show player-aware tools and your Minecraft identity | Linked Minecraft username and UUID | Performance of a contract (Art. 6(1)(b)) |
| Deliver paid tiers, credits and refunds | Subscription tier, credit balance, purchase and refund history | Performance of a contract (Art. 6(1)(b)) |
| Send notification DMs you asked for | Discord user ID, watched auctions | Consent (Art. 6(1)(a)) — withdraw by unlinking Discord |
| Understand how the site is used | Analytics events and identifiers set by Google Analytics | Consent (Art. 6(1)(a)) — withdraw in cookie settings |
| Handle feedback and award credits for it | Feedback content, category, review outcome | Performance of a contract (Art. 6(1)(b)) |
| Keep the service secure and prevent abuse | IP address, sign-in attempt outcomes, rate-limit counters | Legitimate interests (Art. 6(1)(f)) — protecting accounts from credential-stuffing and the service from automated abuse |
Providing your email and password is a contractual requirement — without them we cannot create an account. Everything else is optional, and declining it only turns off the feature it powers.
We do not sell your personal data, we do not share it for cross-context behavioural advertising, and we do not make automated decisions that produce legal or similarly significant effects about you.
Who receives your data
We use the following categories of processor. Each one only receives what its job requires.
- Our hosting provider and database host — account data is stored in MongoDB on infrastructure we operate. This is where your account actually lives.
- Google (Google Analytics) — only after you accept analytics cookies. Decline and the script is never loaded.
- Discord — only if you link Discord, and only your Discord user ID, so we can deliver the DMs you asked for.
To show market data we query the Hypixel API, the Mojang API, and Coflnet. These requests do not include your account data — only the item, player, or auction being looked up. They are data sources, not recipients of your information.
Transfers outside the EU/EEA
Google Analytics involves transferring usage data to Google LLC in the United States. That transfer relies on the EU–US Data Privacy Framework, under which the European Commission has decided the US offers an adequate level of protection for certified organisations, and Google LLC is certified. Standard Contractual Clauses are kept as a fallback safeguard.
This only happens if you accept analytics cookies. If you decline, no analytics data leaves the site at all. You can request a copy of the safeguards we rely on using the contact details above.
Cookies & local storage
Our authentication session cookie is essential to keep you signed in and is always on — it can't be turned off without breaking the ability to log in. Your cookie-consent choice, recent searches, favourites, and pinned views are kept in your browser's localStorage — these stay on your device and are never sent to our servers.
We use Google Analytics to understand how the site is used. It is loaded only after you accept analytics cookies in the consent dialog — decline, and the script is never loaded and no analytics cookies are set. You can change your choice at any time from the cookie settings link, and Google Analytics sets its own cookies (_ga, _ga_*).
How long we keep things
- Account data — for as long as your account exists. Delete the account and it goes with it.
- Date of birth — never stored. Discarded the moment the age check returns an answer.
- Feedback and credit history — kept while your account exists, because it is the record of why credits were awarded to you.
- Watched auctions and favourites — until you remove them or delete your account.
- Security and rate-limiting data — kept only as long as needed to make the next throttling decision, which is a matter of minutes to hours.
- Analytics — retained by Google under its own retention settings.
Your rights
If the GDPR or UK GDPR applies to you, you have the right to: access the data we hold about you; have it corrected; have it erased; restrict how we use it; object to processing based on legitimate interests; receive your data in a portable, machine-readable format; and withdraw any consent you previously gave, without that affecting the lawfulness of what we did before you withdrew it.
To exercise any of these, use the contact address at the top of this page. We respond within one month. You can also reach us on Discord, but formal requests should go to the contact address so there is a record of when you asked.
Complaints
If you think we have handled your data badly, please tell us first — most things are faster to fix directly. You also have the right to complain to a data protection authority: the one where you live, work, or where you think the problem happened, or the authority for [NOT CONFIGURED — set before launch], where we are established.
In Denmark that authority is Datatilsynet — datatilsynet.dk.
Data breaches
If a breach occurs that is likely to risk your rights and freedoms, we notify the supervisory authority within 72 hours of becoming aware of it, and we tell you directly without undue delay where the risk to you is high.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected here with an updated date.